Interim public-beta privacy notice
InterfaceDelta Privacy Notice
Who operates InterfaceDelta
InterfaceDelta is operated by InterfaceDelta, Inc. Privacy questions may be sent to privacy@interfacedelta.com.
Account and authentication information
We process the email address used for passwordless sign-in, email-verification state, single-use verification-token records, database session records, and related authentication timestamps and identifiers. We do not store passwords. Authentication email contains a short-lived magic link.
Required account information
An email address is required for passwordless authentication and account and monitor functionality. Without an email address, we cannot provide those features.
Monitoring and notification information
We store account-to-target monitor subscriptions, alert preferences, verified notification destinations, notification state, bounded error codes, attempt timestamps, deterministic idempotency information, and an email-provider message identifier where supplied. Drift emails contain bounded factual change information and an InterfaceDelta detail link; they do not contain a complete Passport or raw protocol payload.
Public target observations
For submitted public HTTPS targets, we process public endpoint metadata, canonical Passport observations, fingerprints, historical comparisons, and deterministic compatibility changes. Public Passport, history, share, and badge surfaces are separate from private account and delivery data. Public target history may persist independently of an account and is not automatically removed when an account is deleted.
When a signed-in account initiates a browser inspection, we store a private link between that account and the resulting public Passport observation so the account can find its inspection again. This link does not establish ownership of the inspected target and is not exposed through public Passport, history, share, REST, or MCP responses. Deleting the account removes the private link while the public observation may remain.
Publisher-provided information
Public machine-readable metadata is supplied by target publishers and may contain names, contact details, descriptions, or other personal information. InterfaceDelta treats it as untrusted public target data, bounds and escapes it for display, and does not infer that the submitter owns or controls the target.
Transactional email
We send authentication magic links and opted-in qualifying drift notifications. We do not send marketing email. Open tracking and click tracking are disabled for these messages.
Service providers
We use Vercel to host the web application, Neon for PostgreSQL storage, Railway to run the recurring worker, Resend to send authentication and transactional alert email, and WorkOS to provide OAuth authorization when you connect an external agent or MCP client to your account. These providers process relevant technical, account, target, or delivery data to provide their services.
Connecting an agent or MCP client
Signing in to this website does not involve WorkOS. Website sign-in continues to use our own email magic-link system, and your account record stays with InterfaceDelta.
WorkOS is used only when you authorize an external client, such as a coding agent, to reach your account through our MCP interface. During that authorization we send WorkOS the minimum identity information it needs to issue and manage the client’s access: your InterfaceDelta account identifier and the email address on your account. We do not send your monitored targets, observation or alert history, API tokens, or browsing information.
WorkOS then shows you which client is requesting access, issues the access and refresh tokens that client uses, and records the authorization so it can be withdrawn. You can disconnect a client at any time; withdrawing the authorization stops it from renewing its access, and any access token it already holds expires within minutes. Deleting your InterfaceDelta account removes its access immediately.
Uses and disclosures
We use information to authenticate accounts, provide inspections and monitoring, maintain public observation history, send requested transactional email, enforce limits, diagnose failures, protect the service, and meet legal obligations. We do not create advertising profiles, sell user data as a product practice, or use account data for advertising.
Legal bases where applicable
Where data-protection law requires a legal basis, we process account and service information to provide the account, inspection, monitoring, and notification services you request. We rely on legitimate interests where applicable to secure and operate the service, prevent abuse, improve reliability, and maintain factual history of observed public interfaces. We rely on consent or user choice where legally required for optional notifications. You may change notification preferences through the product.
Retention and deletion
We retain account, authentication, and session information only as operationally necessary to provide and protect the service. Account-specific information is removed according to the account deletion behavior described below. Infrastructure-provider and security logs are retained according to operational needs and provider retention practices. Public target observations and historical comparisons currently have no automatic expiry.
International processing
Information may be processed in the United States and other countries where InterfaceDelta and its service providers operate. Where applicable law requires safeguards for international transfers, we will use legally required safeguards.
Privacy rights where applicable
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of your personal information; withdraw consent where processing relies on consent; and complain to an appropriate data-protection authority. Contact privacy@interfacedelta.com to make a request. These rights may be subject to lawful limits and verification of the request.
Automated decisions
InterfaceDelta does not use account personal information for solely automated decisions that produce legal or similarly significant effects on the account holder. Deterministic compatibility classifications concern observed target interfaces.
Technical data and command-line tools
Hosting and infrastructure providers may process ordinary request, security, delivery, and operational logs. InterfaceDelta’s command-line tool does not include hidden product telemetry. Target services and network intermediaries can observe inspection requests sent to public endpoints.
Choices and contact
You can sign out, change monitor alert preferences, unsubscribe from targets, or delete your account through the product. Account deletion removes the account’s authentication/session data, subscriptions, verified email destination, related private delivery records, and private links to browser inspections initiated by the account, and stops future account email. It does not automatically remove public target observations or history. Privacy requests and questions may be sent to privacy@interfacedelta.com. We may update this notice; the displayed version and effective date identify the notice then in effect.
Operator
InterfaceDelta is operated by InterfaceDelta, Inc.. Legal contact: legal@interfacedelta.com.



