Loading…
Loading…
Plain English
The privacy policy is the document that governs. It is also long, because it has to be complete. This page answers the questions people actually arrive with, and links to the part of the policy that governs each answer. Where the two ever disagree, the privacy policy wins: this page is a guide to it, not a replacement for it. Last updated: 2026-08-14.
The questions, in the order people ask them
No. AGI does not train AGI-owned models on your prompts, responses or files. That is a flat answer with one thing worth understanding behind it: in Managed Cloud we send your prompt to the model provider serving the model you picked, and what they do with it is governed by their terms, not ours. We are not making a promise on their behalf, and section 02 of the privacy policy says so in those words.
In Managed Cloud your conversations are stored by us, so the honest answer is not “nobody”: it is that access is limited to people who need it to operate or support the service, and that two layers of access control scope every request to the account that owns it. What those layers are, and where they stop, is section 01 of the privacy policy and the measures table in the DPA, which states the limit of each control next to the control.
More than anything else on this page. There are three modes and they give genuinely different answers. In Local, the conversation runs on your machine and we receive nothing. In BYOK, the request goes from your client straight to the provider on your own key and we are not in the path. In Managed Cloud, it goes through us and we store it. One caveat people get wrong: Local and BYOK are desktop, CLI and VS Code capabilities: the web app is cloud-only, so anything you do in a browser is Managed Cloud. The full comparison is section 00 of the privacy policy.
No. We do not sell personal data and we do not share it for cross-context behavioural advertising. We run no advertising and set no advertising cookies. The list of third parties that do receive data, and exactly what each one gets, is at /subprocessors . That page names its own past mistakes at the bottom, which is the fastest way to judge whether to believe it.
It differs by the kind of data, and rather than round it off here, section 05 of the privacy policy gives a row per category with the job that enforces it. Two things worth knowing before you read it: where no automatic expiry exists, it says so instead of quoting a number, and it has a table of what deliberately survives deleting your account.
Both are self-serve in account settings: export returns your data as a download, and deletion is scheduled 24 hours out and then performed. You get no confirmation email, but cancellation is self-serve too: sign back in and cancel from Settings > Account any time before the 24 hours are up. Everything else (access, correction, deleting an address we hold without an account) goes through /privacy/requests, which works whether or not you have an account.
Almost nothing. Running your account and the assistant does not run on consent: it runs on the agreement you made when you signed up, which is why there is no cookie wall here. Consent is asked for exactly three things: crash reporting, analytics, and email you asked us to send. All three are off until you turn them on, each is asked separately, and each can be withdrawn on its own at /privacy/requests without affecting the others or your access to anything.
The United States. We do not offer data residency in the EU, the UK or India, so using Managed Cloud means your data is transferred there. If residency is a requirement for you, we do not currently meet it, and you should know that before you sign up rather than during procurement. The transfer mechanisms are section 08 of the privacy policy and section 06 of the DPA.
Cancelling a subscription does not delete your account or your content. The account continues on the free tier and your data stays until you delete it. What we cannot promise is a shutdown commitment, because no code enforces one; the honest position is that export works today and you should use it if that risk matters to you. The billing mechanics themselves are on the refund policy.
Those are not badges anyone issues, so a yes would be worth nothing. What we can give you is the working: a per-regime status ledger with dates and what would prove each line at /trust, the India-specific notice at /privacy/india, and a security page that lists what we have not done at /security. We hold no SOC 2 report and no ISO 27001 certificate, and we say so in the same places we say what we do have.
Why this page cannot drift
A friendly summary of a legal document is a liability the moment the document changes and the summary does not, you end up with two published answers and no way to tell which is current. So this page deliberately states no retention window, no recipient name and no commitment of its own. Every concrete fact above is a link into the policy that owns it. If you are editing this page and find yourself typing a number, link to the section instead.