Review who can access the work
- In Settings → Team, review each person’s role and assigned accounts. Edit or remove access when responsibilities change.
- Check website permissions separately. A website viewer cannot manage its collection or keys; a team account grant does not automatically grant every website. Manage website access.
- Review external clients in Settings → AI & Agents → AutoAdy API keys. Revoke unused manual keys or Connected apps OAuth connections. A credential acts with its AutoAdy identity’s access. Manage credentials.
Protect credentials and shared links
- Store API keys and server credentials in private settings or a secret store. Keep them out of browser code, repositories, screenshots, and support messages.
- If an AutoAdy key is exposed, Revoke it immediately, then replace it in the client before resuming work. An expired key also needs replacement or reconnection.
- Anyone with a complete client-report link can view that report without signing in. Open and check the report before sharing, and send it only to the intended recipients.
- The Email Agent address is a secret credential. Treat it as carefully as an API key.
Understand which service handles the work
The Privacy Policy describes data used to provide AutoAdy and sharing with service processors. For your work, these are the practical distinctions:
Model-provider keys pay for eligible internal AI work; AutoAdy API keys authenticate external clients to AutoAdy. They are different credentials.
With your own OpenAI or Claude key selected, eligible Agent text uses that provider connection and billing. With AutoAdy credits selected, work uses AutoAdy’s supported credit flow. Check the chosen mode and the provider’s terms before submitting sensitive material. Connect and choose an AI provider.
For a tracked website, collection depends on its installed script and consent state. Install tracking with consent; ownership verification alone does not mean visitor events are being collected.