Security and privacy

The part that says no

An agent that can change your website is a security question before it is a marketing one. This page is the list of things IntellQ cannot do, what it stores about your visitors, and what it refuses to store. Each answer describes a limit in the code rather than an intention.

What it can change

The browser surface is the whole attack surface. It is deliberately small enough to read in a minute.

What can the agent change on my page?

Four operations, on elements you marked with data-intellq-slot and nothing else: set the text of a slot, show one, hide one, or point one at a path on the same origin. There is no fifth operation. A link to another domain is refused in the browser as well as on the server, so a change cannot become an off site redirect.

Can it inject HTML, script or styles?

No. Text is applied with textContent, which writes characters rather than markup. Even if a model asked for a script tag, the browser code has no path that would make one. Nothing is ever loaded from a third domain to apply a change.

Can it touch an element I did not mark?

No. Slots are matched by comparing the data-intellq-slot attribute value, not by building a selector from a string the server sent. There is no document.querySelector call that takes a value from the network.

Does the model write code?

No. An optional model may rank a shortlist of strategies the server defined, and its answer is validated against that list before it is used. An answer outside the list falls back to the deterministic ranking. The model cannot issue HTTP calls, run shell commands, reach your systems, or invent an offer that is not already in your guardrails.

What if I want it to stop, right now?

The kill switch stops every live change on the next request from every browser. Nothing is deleted, no history is lost, and turning it back off resumes exactly where it was. Autonomy level 0 is the permanent version of the same thing: it observes and never acts.

What it stores

Behaviour, in aggregate, with the identifying parts left out on the way in rather than scrubbed later.

Do you store IP addresses?

No. Country, region and city come from the CDN's own geolocation headers, which is all the live board needs. The address itself is never written to the database, and it is never used to guess who somebody is.

Is there session replay?

No, and there will not be. Block level attention records three things per block: the block's id, the whole seconds it was at least half on screen while the tab was in front, and how many clicks landed inside it. Twelve blocks a page, one event a page. No text from inside the block, no form values, no keystrokes, no cursor positions, nothing that could rebuild a screen.

What counts as an identified visitor?

Only a visitor your own site vouched for. Your server signs a short lived assertion with the secret for that site, the browser hands it over, and IntellQ verifies the signature, the audience, the expiry and a single use id before it believes a word of it. Identity is never inferred from an IP address, an email in a URL, or a fingerprint.

What does the Conversion Genome hold?

Aggregates. Page templates with ids collapsed, event names, traffic sources, journey shapes, per context conversion rates, which strategies worked and which failed, and the blocks that hold attention. No names, no emails, no visitor ids, no query strings. Anything that looks like an email address in a path is replaced before it is stored, because a query string is where an email hides.

How long is behavioural data kept?

Each workspace has a retention window, 180 days by default and adjustable. Behavioural data is the most sensitive thing in the system, so it expires rather than accumulating.

Does one workspace ever see another's data?

No. Every read takes the workspace id from the session and filters on it; there is no console read that accepts an id which could name another workspace's row without that filter. The Genome, the strategy statistics and the experiment arms are per workspace, so one customer's traffic never teaches another customer's agent.

Consent and control

Consent is a switch that actually switches something off, and you are the controller of everything it collects.

Does it need consent?

If you turn on consent required, the agent reads nothing and applies nothing until your own banner calls intellq.consent(true). Not reduced tracking: no behaviour events, no attention, no directives. A visitor who declines is left alone for the rest of the visit.

Who is the data controller?

You are. IntellQ processes website behaviour on your instruction, for your workspace. Export and deletion run per workspace, and attaching the workspace to Apavin does not move the data anywhere new.

What about visitors who just bought?

They are suppressed. A visitor who converted inside the suppression window is put in a context the agent will not act on, so nobody gets sold the thing they bought yesterday.

Approvals and audit

Who may act, what is written down when they do, and where it all runs.

Who can approve a change?

An owner or an admin. Operator seats can read the agent's work and cannot approve, deploy or promote anything. Every transition is idempotent, so a double click cannot deploy twice.

Is there an audit trail?

Yes, on every change: proposed, submitted, approved or refused, deployed, promoted, rolled back, with who did it and when. Actions the agent took on its own are attributed to the agent, never to a person who happened to be signed in. Every visitor level decision is recorded with the evidence behind it and the policy reasons it was allowed or blocked.

What is in the decision trace?

The signals and features that put the visitor in a context, the strategy that was chosen, and why it was allowed. It is evidence, not a transcript of a model thinking. Hidden reasoning is not shown in the console because it is not collected.

Where does it run?

On Vercel, with a Postgres database in the same region as the workload, and the tag script served from a CDN edge or from your own subdomain by CNAME. Credentials for third party providers are encrypted at rest with a key that lives in the environment, and they are stripped from every API response.

Subprocessors

The services that hold or handle data on IntellQ's behalf. An AI provider appears here only if you connect one, and then it is your account and your key.

VercelApplication hosting and CDN
NeonPostgres database
CashfreePayments for Indian workspaces
PayPalPayments everywhere else
Your AI providerOnly if you connect one, on your own key and your own account

Reporting something

If you find a way to make the agent do something this page says it cannot, write to sales@apavin.com with the steps. You will get a person, not a ticket robot, and a fix before a press release.