Who is responsible
Suncly, Tallinn, Estonia. Contact: team@suncly.com. Legal entity name, registration number and registered address: to be supplied by the owners.
This website
- The site is static. It sets no cookies of its own and runs no analytics or advertising scripts.
- The hosting provider receives the technical data any web request carries (IP address, user agent, requested page) in its server logs. Provider and log retention: to be supplied by the owners.
- The pilot access form sends the email address and optional note you enter either to the endpoint configured for the site or, when none is configured, to your own mail client addressed to team@suncly.com. We use it only to reply to you about pilot access. Storage location and retention of these requests: to be supplied by the owners.
- The review workspace at /app stores the evaluation bundles and review notes you load in your browser's local storage only. Nothing you load there is sent to Suncly or to any server. You can remove it from the workspace settings or by clearing your browser's site data.
The Suncly software
Suncly is a command-line tool you run on your own machine or network. In its current version it has no hosted component and sends no data to Suncly. What it reads, stores and redacts is described on the security and data handling page, in summary:
- It fetches the Agent Card URL you give it and calls the agent endpoint named in that card, and nothing else.
- It reads one credential from an environment variable inside the Runner process and redacts it from every transcript before storage.
- It writes evidence (entity records, redacted transcripts, signing keys, report folders) to the folders or database you configure. The evidence store is append-only; deletion is done by you, by removing files or dropping the database.
- It makes no call to any model provider in this version.
Transcripts may contain whatever the agent under test sends back. If an agent returns personal data in a sandbox response, that data is in your transcripts; the redaction rules target credentials and tokens, not personal data in general.
Your rights and how to contact us
Requests about personal data held in connection with pilot access can be sent to team@suncly.com. Applicable law and supervisory authority: to be supplied by the owners.
Changes
This notice will be updated when the hosted service, account system or payment layer is introduced. Effective date: to be supplied by the owners.