Last updated 7 August 2026
HB-Eval is an independent research project. This policy was drafted in-house and has not been reviewed by a lawyer. It describes what the system actually does; where it is silent, assume nothing is promised.
HB-Eval is operated by Abuelgasim Mohamed Ibrahim Adam, an independent researcher. It is not a company, and there is no corporate entity behind it. Enquiries and data requests go to abuelgasim.hbeval@outlook.com.
Account data. Your email address, and a password hash if you use email sign-in. We never see your password.
Agent metadata. Names and identifiers you give your agents, and encrypted credentials for them. Agent secrets are encrypted before storage, and the API key is stored only as a hash.
Evaluation and monitoring data. The reliability metrics your agent produces, step counts, threshold breaches, halt decisions and the policies that caused them, plus the measured overhead of monitoring itself.
What we do NOT collect. The content of your agent’s prompts and responses does not reach us on the monitoring path. The SDK computes metrics locally and sends numbers. On the evaluation path, the task you submit is encrypted in transit with a key we hold for that transaction and is not retained after scoring.
Technical data. IP addresses appear in our hosting providers’ logs for security and rate limiting. We do not use advertising or analytics trackers, and there are no third-party cookies.
To operate the service you asked for — evaluating and monitoring agents you registered — and to enforce quotas and prevent abuse. That is contractual necessity and legitimate interest respectively, under GDPR Article 6(1)(b) and 6(1)(f).
Contributing anonymised results to the Observatory happens only on your explicit consent, under Article 6(1)(a), and can be withdrawn at any time in Settings.
Three providers, each named because “selected third parties” tells you nothing you can act on:
Data may be processed outside your country, including in the United States, under those providers’ own transfer mechanisms. We do not sell data, and we do not share it with anyone else.
The automatic cleanup runs daily, and the last successful run is published on our status page — so this section can be checked rather than taken on trust.
Under GDPR and comparable laws you may access, correct, export, delete, restrict or object to processing of your data, and lodge a complaint with a supervisory authority.
Two of these are self-service and immediate, in Settings: Export gives you everything held about your account as JSON, and Delete removes the account and everything linked to it.
If you had consented to the Observatory, anonymised copies are taken before deletion proceeds, and the deletion is cancelled if that copy fails. Those copies carry no identifier and cannot be traced back to you — which also means they cannot be retrieved or removed on request afterwards. That is the trade anonymisation makes, and it is why the consent is explicit.
Off by default. If you turn it on, aggregate reliability figures from your runs contribute to public statistics.
Contributions carry no user identifier, no agent identifier and no task content. Aggregates are withheld entirely until at least five independent accounts have contributed, so no figure can be traced to a single participant.
Agent secrets are encrypted at rest. Requests are authenticated, signed, and protected against replay. Row-level security constrains what any account can read.
No system is perfectly secure, and we make no guarantee that ours is. If you find a vulnerability, please write to the address above rather than disclosing it publicly.
The service is not intended for anyone under 16, and we do not knowingly collect their data.
Material changes will be reflected in the date at the top of this page. Continuing to use the service after a change means you accept it; if you do not, you can export and delete your data at any time.
See also the Terms of Service and the service status page.