1.Who we are
A vs B is an A/B testing and feature flag platform at avsb.cloud. Companies use it to test changes on their own websites and apps and to measure what actually works.
This policy covers two kinds of people: you, when you create an account and use our dashboard, and the visitors on our customers’ sites, where our measurement snippet runs. It explains what is collected from each, why, and for how long.
The short version: we collect what the service needs to work, we do not sell personal data, and there are no ads anywhere in the business.
For your account and everything you do in the dashboard, we are the data controller. For the visitor events recorded on a customer’s site, that customer is in charge of the data and we process it on their instructions.
For anything in this policy, write to the privacy address. A person reads every message.
2.What we collect
Account and organisation data. Your name, your email address, your sign-in credentials, the organisation and projects you belong to, and your role in them.
Billing records, not payment details. We keep your plan, your subscription status, and your invoices. Your payment details are entered with Paddle, our merchant of record, and we never see or store your card number.
Configuration data. The experiments, variations, feature flags, metrics, audiences, segments, and any custom code you create in the platform.
Visitor event data. The events the snippet and the SDKs record on your own sites. The kinds we track are exposure, click, pageview, custom, and segment. What any one of those carries is decided by what you choose to send from your own site.
Technical metadata. IP address, user agent, and timestamps, recorded for security and abuse prevention.
3.How we use it
To run the service: to keep the same visitor in the same variation, to serve the right variation, to calculate experiment statistics, and to show you results.
To send transactional email, to bill paid plans, and to help you when you contact us.
To investigate security incidents and to prevent abuse of the service.
We do not sell personal data. We do not show ads, and we do not let anyone else advertise on top of what we collect.
4.What the AI copilot sends, and when
The AI copilot lives inside the visual editor. It sends nothing anywhere until you submit a message.
When you submit a message, what goes with it is your message, the markup of the part of your page around what you are editing, the colours, type, and spacing measured from that page, the page address and title, anything you pasted into the composer, and any image you attached.
Only the relevant markup travels: the section you are working on, the sections either side of it, and your site header. It is cleaned before it leaves the browser. Scripts, style blocks, and other non-visual tags are removed. Web addresses are shortened, so tracking parameters do not travel with them. The whole bundle is capped in size and trimmed to fit.
A screenshot of the page and a close-up of the section you are editing are also sent, but only when you opened the editor from the browser extension. A session opened from the on-page snippet works from the markup and the measurements alone.
Your messages and the replies are stored in the platform, attached to the project or experiment they belong to, so a conversation resumes where you left it. There is no button today that deletes a single conversation. See "Your rights" below.
Requests are carried to the AI model by a third-party model-routing provider. Its role is covered in "Who else processes your data" below.
Our account with that provider is configured so that prompts and page content are not retained by the routing service, and are not used to train models.
We keep a usage record for each AI request so we can meter your plan allowance and our own costs. That record holds the size and cost of the request. It does not hold your message or your page.
5.How long we keep it
While your account is open, account and configuration data is kept for as long as your subscription is live.
Event-level analytics data is kept for the window included in your plan. These are the windows listed on the pricing page:
- Free: 90 days
- Pro: 1 year or 2 years, by volume
- Enterprise: 2 years
6.What deletion means here
When you delete your account, or ask us to delete it, your data is deleted from our live systems straight away. We mean deleted: the records leave the database. We do not keep a copy hidden behind the interface.
Short-term recovery copies exist so we can survive a disaster, and they expire on their own. Our main database keeps a 6-hour recovery window. Our analytics store keeps an automatic backup for about a day. Nothing survives past 30 days at the outside.
After an account closes, we keep only what the law makes us keep, such as billing records held by our merchant of record for tax purposes.
8.Who else processes your data
Running A vs B takes infrastructure we buy rather than build. These companies process data on our behalf, each under its own data-processing terms:
If this list changes, this page changes with it.
- Vercel: hosts the dashboard and this website.
- Neon: runs our main database.
- ClickHouse Cloud: stores visitor event data for analytics.
- Cloudflare: delivers the snippet and experiment files, stores uploads, and sends our email.
- Paddle: our merchant of record. Handles checkout, payment details, and invoices.
- OpenRouter: carries AI copilot requests to the model that answers them.
- Sentry: collects error reports when something in the product breaks, with personal detail scrubbed before sending.
9.International transfers
The providers above operate in the United States and the European Union, so personal data is processed in both.
When personal data leaves the UK or the European Economic Area, it travels under the standard contractual protections recognised by UK and EU law, such as standard contractual clauses and, where a provider holds one, an approved data-privacy certification.
10.Your rights
You can ask for a copy of your personal data, ask us to correct it, or ask us to delete it.
If you are in the EU or the UK, that includes your rights under the GDPR and the UK GDPR. If you are in California, it includes your rights under the CCPA and the CPRA.
Copilot conversations are part of your personal data. There is no self-serve delete for a single conversation yet, so send that request to the address below and it is handled like any other deletion request.
Send any of these to the address below and we will respond within the statutory window.
11.Children’s data
A vs B is a business tool. It is not directed at children, and nobody under 16 may use it.
If we learn we are holding a child’s personal data, we delete it.
12.Telling you about a breach
If a security incident exposes personal data we hold about you or your visitors, we tell the affected customers without undue delay, with what we know and what we are doing about it.
Where the law sets a notification window, such as the 72-hour rule for telling a regulator under UK and EU GDPR, we follow it.
13.Changes to this policy, and how to reach us
When this document changes, the date at the top changes with it. A material change is announced before it takes effect.
Questions about this policy go to the privacy address. Anything else goes through the contact form.