Legal · Last updated July 27, 2026

Privacy Policy

Information we collect

The AMBIENT maintainers do not set first-party cookies or create visitor profiles on the Vercel website. The site does not receive, proxy, or store any account credential or OAuth token; submission requires no sign-in.

Infrastructure and third parties

The site is hosted by Vercel, and the results database and evidence storage are hosted by Supabase. Like most hosting providers, they may process request information such as IP addresses, device or browser details, timestamps, and requested URLs for delivery, reliability, abuse prevention, and security. That processing is governed by Vercel’s Privacy Notice and Supabase’s Privacy Policy.

The site loads typefaces from Google Fonts, so a visitor’s browser may make a request to Google. Links to GitHub, Vercel, and other external services are governed by those services’ own privacy notices. AMBIENT does not control their data practices.

Running the benchmark

You run AMBIENT locally from GitHub. A run stays on infrastructure you choose except for requests sent to model providers you configure.

When you submit, the uploaded bundle is processed server-side for certification and is not retained if it fails: an uncertified bundle is discarded after the checks run and only the check report is returned to you. The submission endpoint does not publish anything a failed bundle contained.

A certified bundle becomes public evidence: the zip you uploaded is stored in the evidence bucket and linked from its leaderboard row, and the benchmark's memory writes and queries recorded inside it become publicly readable. Do not include credentials, private conversations, or personal data in a bundle.

Certified evidence bundles are retained publicly so results stay reviewable; to request removal of a bundle you submitted, open a repository issue and the row will be revoked together with its evidence.

Sharing a run

The website accepts run bundles solely for certification, and publishes only bundles that pass. The submitter is responsible for removing credentials, private conversations, personal information, and material they do not have permission to publish before uploading.

Retention and security

The maintainers do not operate a visitor-profile database, user-account system, or results database. Space-run artifacts expire from application storage after up to 30 minutes; OAuth tokens are not included in those artifacts. Hosting, model, and linked service providers retain their own operational records according to their policies. No internet service can promise absolute security.

Your choices and contact

You may block third-party requests with browser controls, avoid external links, and download the repository directly from GitHub. For a privacy question, open an issue in the AMBIENT repository without including sensitive personal information; request a private contact channel if needed.

Changes

Material changes will be reflected on this page with an updated date. The repository history provides a public record of policy revisions once those changes are published.