This notice describes how Gen Digital Inc. (“Gen,” “we,” “our,” or “us”) collects and uses personal data in connection with Agent Trust Hub, currently available at ai.gendigital.com/trust-hub. It is a product-specific supplement to, and should be read together with, our General Privacy Notice, which explains our overall privacy practices, the rights available to you, and how we protect personal data across Gen products. Where this notice and the General Privacy Notice differ, this notice controls for your use of Agent Trust Hub.
1. What Agent Trust Hub does
Agent Trust Hub helps you understand how the apps and AI assistants you use collect, use, share, and retain your data. You can look up accounts associated with an email address or username, optionally check your Gmail for account evidence, browse a library of app privacy ratings, or submit an app or policy link for analysis. Each report turns a privacy policy or terms document into a plain-language rating, an explanation, source quotes, and practical controls you can consider.
Agent Trust Hub reviews published documents and account signals. It does not inspect an app’s internal systems and does not verify that an app’s actual practices match its published policy.
2. Data we process and how long we keep it
The table below describes the personal data Agent Trust Hub processes for each feature and why we process it. We keep personal data only for as long as we need it to provide the relevant feature, operate and secure the service, and meet our legal obligations, and we retain different categories of data for different lengths of time depending on that purpose.
| Feature | Data | Why we process it, and how long we keep it |
|---|---|---|
| Account lookup (“See my data”) | The email address or username you enter | Briefly held in your browser’s session storage so the scan page can run your search, then cleared |
| Account lookup | Scan subjects (hashed) and, separately, the plain-text email address you searched | To run the lookup, apply usage limits, and let you reopen or delete your results. The email address is recorded separately to operate and support the service. Scan results are kept for a limited period and then automatically removed, or sooner if you use the delete control |
| Gmail account evidence (optional) | OAuth tokens and message metadata only (sender, subject, date, and authentication headers; not message bodies or attachments) | To identify likely accounts by matching senders in our catalog over a recent, limited lookback window. Kept only in your browser’s memory for that session and not written to our servers or browser storage. We attempt to revoke Google’s access when the scan finishes, fails, or you leave the page |
| Gmail account evidence | The Gmail address you connect | Recorded to document that a connection occurred, and kept for as long as needed to operate and support the service |
| App / policy analysis | The app or policy link you submit; the retrieved policy text, source URL, hash, and version history | Kept for as long as the report remains part of our library, to provide a reusable, dated record and let others see the same analysis |
| App / policy analysis | The generated report (score, grade, supporting quotes, model/prompt version, and usage statistics) | Kept for as long as the report remains part of our library, and may later be regenerated or refreshed |
| Waitlist (“Opt-out for me”) | Email address, the app name (if applicable), the feature requested, and a timestamp | Kept separately from scan data, for as long as needed to act on your interest or until the feature becomes available |
| Rate limiting (all features) | Hashed network/subject identifiers (not raw IP addresses) | Kept on a short, rolling basis to apply usage limits and prevent abuse |
3. What we do not do
- We do not delete your accounts with third-party apps, change their privacy settings, or send a deletion request on your behalf.
- Joining the waitlist through “Opt-out for me” does not contact the app, change any setting, or delete anything. It only records your interest in a feature we plan to build.
- Deleting your scan results does not delete your waitlist entry or any related email event, and does not affect your accounts with the third-party services identified in your results.
- A result marked “unknown” or a missing report means we could not check or find that item; it is not evidence that no account exists or that a service handles data safely.
4. Connecting your Google (Gmail) account
Connecting Gmail is optional and uses Google’s own consent process; you are not required to connect Gmail to use Agent Trust Hub. When you connect, we look for account evidence by reading message metadata only (sender, subject, date, and authentication headers) for senders in our catalog. We do not read message content or attachments.
Agent Trust Hub uses the same Google integration as Norton Family Assistant. The current implementation requests the gmail.modify scope. Today, Agent Trust Hub only uses this to read message metadata as described above. It does not send mail, delete anything, or otherwise change your mailbox. We request the broader scope now because we intend to use it to help carry out opt-out and deletion requests on your behalf (for example, sending a request to a company by email) once that feature is built; until then, we do not use any of the additional permissions gmail.modify grants beyond the read-only metadata access described above. We’ll update this notice when that feature becomes available.
Our access to and use of information received through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke Agent Trust Hub’s access to your Google account at any time in your Google Account settings.
5. Who we share data with
We use the following categories of service providers to operate Agent Trust Hub:
- Policy discovery providers (currently You.com and Exa) to locate and retrieve the privacy policies and terms we analyze.
- AI model providers (currently xAI, accessed directly or through the Vercel AI Gateway) to read retrieved policy text and produce the structured findings, quotes, and score in each report.
- Hosting and storage providers (currently Vercel and Turso/libSQL) — to run the service and store scan, report, and account data.
We do not sell your personal data.
6. Your rights and choices
You may have rights to access, delete, correct, or restrict the personal data we hold about you, as described in our Gen Privacy Center. To exercise these rights for Agent Trust Hub data, or with any other questions, contact us at nll_privacy@GenDigital.com.