Loading…
Loading…
What we collect, what we do not, and how that changes depending on which mode you run. AGI does not use customer conversation content to train AGI-owned models. We do not sell your data. Website users can use AGI managed cloud, with a small free Auto Economy cap and higher-capacity paid plans rolling out. Local and BYOK are supported on desktop and developer surfaces. Managed cloud is open by default, not invite-only. Last updated: 2026-08-14. Managed Cloud is in public alpha.
00 · The mode decides the answer
Most privacy policies have one answer. This product has three, because Local, BYOK and Managed Cloud are separate trust boundaries and your data goes to genuinely different places in each. Read this table first; the rest of the page is detail.
| Mode | Where your prompts go | What we hold |
|---|---|---|
| Local | To a model runtime on your own machine. Nothing is transmitted to us and nothing is silently routed to BYOK or Managed Cloud. | Nothing about the conversation. Conversations live in SQLite on your disk. |
| BYOK | From your client straight to the provider you targeted, on your own API key. We are not in that request path. Available on the desktop app, the CLI and the VS Code extension. The web app is cloud-only and has no user-key path, so anything you do in a browser is Managed Cloud. | Your account and settings. Not the prompt traffic. Your key is encrypted on your device and the master password is not recoverable by us. |
| Managed Cloud | Through our gateway to the provider serving the model you selected. Managed Cloud is in public alpha. | Conversations, files, projects, memories, schedules and settings, so they sync across your devices. This is the only mode where we act as your processor. See the DPA. |
01 · What we collect
| Category | Examples | Why, and how it is protected |
|---|---|---|
| Account | Email, account ID, authentication metadata held by our identity provider. | Authentication. We do not store your password ourselves. |
| Billing | Stripe customer ID, plan, invoice metadata. Card details go to Stripe directly and we never see or store them. | Subscription management. |
| Conversations (Managed Cloud) | Threads, messages, tool calls, and references to attached files. | Cross-device sync. Two layers of access control: every route resolves the authenticated user and scopes the query to them, and Postgres row-level security policies are forced on the user-scoped tables behind the sync paths that bind the request identity per connection. It is defence in depth, not one absolute switch. |
| Files you upload or generate | Attachments, generated images, and other stored media. | Stored in Cloudflare R2 and catalogued in Neon. The product gives clients an authenticated same-origin file route that requires both the owning account and its active Personal or organisation workspace to match. Missing, deleted, foreign, and inactive-workspace files all return the same not-found response, and those responses are private and not stored by browser caches. Generated videos use a separate private bucket. Images and other non-video files remain in a public R2 bucket: normal product responses do not expose its raw URLs, but anyone who obtains an underlying storage URL can access that object without signing in. |
| Conversations (Local) | SQLite on disk. Not silently routed to BYOK or Managed Cloud. | We hold none of it. |
| BYOK keys | Encrypted on device. Master password unrecoverable by us. | You stay in control of provider auth. |
| Telemetry | Error and performance reports via Sentry, and page-view analytics via Google Analytics. Both are opt-in and load only after you consent; the consent gate fails closed, so a failure to read your choice means analytics stays off. No prompt content is sent to either. | Operational visibility. Error reports are content-scrubbed and send no default personal data, but they do retain a stable user id so a crash can be tied to a session, so they are pseudonymous, not anonymous. |
| Logs and security events | Server logs with bearer tokens redacted, plus an append-only security audit log of account-lifecycle and administrative events. | Debugging, abuse prevention, and incident investigation. |
| Things you send us on purpose | Feedback (your subject, message, and optionally a diagnostic log we scrub for secrets before storing), content reports (the category, your note, and a short excerpt of the message you are reporting), and support conversations. | Answering you and fixing what you reported. A support escalation emails the transcript and the contact address you gave to our support inbox, which is one of the three things in this product that can send email at all. |
| Records you create by using the product | Your search history, and the memories the assistant keeps about you when you enable them. | Making search and the assistant useful across sessions. Both are yours to clear: search history has a clear action, and memory is off unless you turn it on. |
| Profile details you choose to add | Display name, avatar, and optional fields such as a phone number, stored with your settings. | Personalising the product. Optional means optional: nothing here is required to use an account. |
| Early-access list | Your email address, if you ask us to tell you when enterprise features open. | Only what you consented to, recorded per purpose before the address is stored. You can be asked about product updates separately and decline that without leaving the list. |
| Devices and downloads | Push tokens for the mobile apps. For a desktop download: a hashed IP, the user-agent, the referring page and a coarse country in the download record, and separately, your unhashed IP address in our server logs. | Delivering notifications you asked for, and understanding which builds are being downloaded. Two honest caveats. The hash in the download record uses a fixed salt, so it is pseudonymous rather than anonymous: anyone holding both the hash and a candidate address can confirm a match. And the download endpoint separately writes the raw IP to application logs for abuse detection, which the hashing does not cover. Both are improvements we owe you rather than controls we are claiming. |
| Directory-provisioned identities (Enterprise) | When your employer connects a directory, the name, email and directory identifier it sends us for each user it provisions. | Creating and deactivating accounts on your organisation’s instruction. Your employer decides what is sent; we act on it. |
Why this table grew on 2026-08-14. A review compared it against every write path in the product and found the six categories above missing: the things you send us on purpose (feedback with its diagnostic logs, content reports and support transcripts), search history and memories, profile fields, the early-access list, device tokens and download records, and directory-provisioned identities. All of it was already being collected; this page had not kept up. If you add a collection point and do not add a row here, that is the defect this paragraph exists to prevent.
Hosted AI providers we may route requests to (Managed Cloud): Anthropic, OpenAI, Google, xAI, DeepSeek, Perplexity and Moonshot directly; MiniMax, Qwen and Zhipu through OpenRouter, which therefore also handles those requests. Which one depends on the model you select. OpenRouter is additionally the failover for every other chat model in the catalogue, so if a direct route fails, prompt content for a model from any provider can pass through it. We would rather say that than let the three named families imply a narrower answer. The full current list with regions is at /subprocessors. BYOK routes from your client directly to the provider; Local contacts none of them.
The rest of this notice is written to the person holding the account. This part is written to everyone else. Text typed or pasted into a chat, files uploaded to it, and whatever a connector fetches when an account holder points the agent at a mailbox, calendar, drive or CRM routinely carries personal data about people who never signed up: a colleague on the thread, a guest on the invite, a name in the spreadsheet. So do the identities an employer’s directory provisions for people who may never sign in. We do not ask those people for anything and we do not contact them; nothing in the product does.
What happens to it. It is kept as part of the record it arrived in and gets that record’s treatment: the storage described in the table above and the clock in section 05, nothing separate. In Local it never reaches us. In BYOK it goes from the account holder’s client to their provider, not to us.
On what basis. In Managed Cloud we hold it as the account holder’s processor and act on their instruction under the DPA; they are the controller, and bringing your data in was their decision, not ours. Our own processing rests on our contract with them rather than on any consent from you, and the terms make them confirm they were entitled to give it to us, including having given any notice or obtained any consent your law required first. That duty is theirs and we cannot discharge it for them.
What you can do about it. File an access, correction, erasure or grievance request at /privacy/requests without signing in: the form asks for a contact address, not an account. Two limits, said here rather than discovered later: we can only act on a record we can locate, so the request needs enough detail to find it; and where the data sits inside a customer’s account we hold it on that customer’s instruction, so we will usually have to route your request to them rather than act on it ourselves.
02 · What we do not collect
AGI does not train AGI-owned models on customer prompts, responses, or files. In Managed Cloud, we send prompts and attached content to the provider serving the model you select and receive its response; for routed models, the request passes through OpenRouter. Those third parties handle that content under their applicable terms and data-use policies; this statement about AGI-owned models is not a promise on their behalf. In BYOK mode, provider handling is governed by your own provider account and terms.
When you BYOK against Anthropic, OpenAI, Google or another provider, the request goes from your client to the provider. We do not see, log, or store that traffic.
Local mode uses on-device or local model routes and does not silently send chats, files, or developer sessions to BYOK providers or Managed Cloud.
We run no advertising, set no advertising cookies, and do not sell or share personal data for cross-context behavioural advertising.
03 · How we use it, and on what basis
One row per purpose, rather than a sentence listing four bases and leaving you to work out which applies to what. Where a row says legitimate interests, it also says why we think ours do not override yours. That balancing test is the part a bare list omits.
| Purpose | Data used | Basis, where the GDPR or UK GDPR applies |
|---|---|---|
| Creating and running your account | Email, account identifier, authentication metadata, settings. | Performance of a contract. You asked us to run an account; it cannot exist without these. |
| Running the assistant (Managed Cloud) | Conversations, files, projects, memories, schedules. | Performance of a contract. This is the service itself. Local and BYOK do not produce this data for us at all. |
| Taking payment | Billing identifiers, plan, invoice metadata. Card numbers go to Stripe and never reach us. | Performance of a contract, and legal obligation for the records tax and accounting law requires us to keep. |
| Answering you | Support conversations, feedback, content reports. | Performance of a contract when you are a customer; legitimate interests otherwise. You initiated the contact, and we cannot reply without keeping what you sent. |
| Keeping the service secure and available | Server logs, the security audit log, rate-limiting state, account status. | Legitimate interests. Every user has an interest in the service not being taken over or abused, the data is operational rather than content, and you cannot opt out of it without also opting out of being protected by it. |
| Understanding which builds are downloaded | Download records: hashed IP, user-agent, referrer, coarse country, plus the raw IP in server logs, as section 01 says. | Legitimate interests. Narrow, and the honest caveats about the fixed salt and the raw log entry are in section 01 rather than buried here. |
| Crash and error reporting | Error reports with a stable user id, content-scrubbed. | Your consent. Off unless you turn it on in settings. No prompt content is sent. |
| Product analytics | Aggregated page views. | Your consent. Nothing loads until you give it, and the gate fails closed: if your choice cannot be read, analytics stays off. |
| Telling you when something opens | The email you gave the early-access list. | Your consent, recorded per purpose against the revision of this notice you were shown, before the address is stored. |
| Complying with the law | Whatever a valid legal process compels, narrowed to the minimum. | Legal obligation. |
India works differently and has its own page. Under the Digital Personal Data Protection Act, 2023 consent is the default ground rather than one of several, so the analysis is not the same as the table above. It is at /privacy/india, and it governs for data principals in India where the two differ.
04 · Sharing
We share data only with the subprocessors listed at /subprocessors, and only as necessary to run the service. We do not sell data. We may disclose data if compelled by valid legal process; we narrow such disclosures to the minimum required. If AGI is involved in a merger or sale of assets, personal data may transfer as part of it, and this policy continues to apply until the acquirer publishes its own.
05 · Retention
Every row below is a job or a mechanism that exists in the product, with the ones we do not control named as such. We would rather publish a shorter schedule that is true than a complete-looking one that is not.
| Data | Retention | How it is enforced |
|---|---|---|
| Account and its content | Kept while your account is active. Permanently erased 24 hours after a deletion request. | The request records a deletion timestamp and schedules erasure 24 hours out; a daily scheduled job then erases your user-scoped records and stored objects and deletes your identity at our authentication provider. |
| Billing records | Erased with the account, or aged out at the end of the statutory record-keeping period (8 years), whichever comes first for that row. | Your subscription, credit ledger and usage rows are erased with everything else. Three things survive on purpose, and you should know about them: an organisation’s billing history keeps the ledger row with your user id removed, because the record belongs to that organisation rather than to you; double-charge protection keys and any payment still moving when you delete are kept, because deleting those can charge you twice or lose money we owe you; and Stripe holds its own record of your payments and invoices under its retention, not ours: card numbers go to Stripe directly and never reach us. A daily scheduled job now enforces a maximum age on the rows that outlive an account. Books of account (the credit ledger and the organisation usage ledger) are kept 8 years and then deleted, and the request-shaped metadata beside them is emptied after 2 years because the amount, the type and the date are the record, not the routing detail. Metering events are deleted after 2 years and their metadata emptied after 180 days. Double-charge protection keys are deleted once their 24-hour window closes, completed settlement jobs 90 days after they finish, and payment-webhook receipts 180 days after processing, with any error text they captured cleared after 30 days. Two things carry no maximum age and we will not pretend otherwise: your current plan row and your current credit balance, because ageing those out would cancel a live subscription or delete credits you paid for. They go when the account goes. |
| Conversations (Managed Cloud) | Kept until you delete them or delete your account. | There is no automatic expiry on ordinary conversations, and no per-organisation retention window is enforced on them today. We will not describe one until it runs. |
| Temporary chats (Managed Cloud) | About 30 days. | A daily scheduled job hard-deletes temporary conversations past the window; messages go with them. |
| Deleted files | 30 days in the recently-deleted bin, then the bytes are removed. | A daily scheduled job hard-deletes the records and deletes the underlying objects from storage. If an object deletion fails, the record survives and the next run retries it. |
| Sandboxes | Within 24 hours of creation, or sooner once its resume mapping is gone. | A daily scheduled job enforces a 24-hour age cap on every sandbox (matching the resume mapping’s own 24-hour expiry) and reclaims it at that cap or as soon as the mapping no longer points to it, whichever comes first. |
| Security audit log | 90 days. | A database routine deletes entries older than 90 days, run by a scheduled job every night: /api/cron/purge-security-audit-logs at 02:30 UTC, registered in vercel.json. This entry previously said the routine was run by an administrator rather than on a schedule; that stopped being true when the cron was added, and the policy is corrected here rather than left understating what happens. |
| Server logs and backups | Vendor-governed. | Platform logs and database or object-storage snapshots are retained according to our hosting vendors’ own configuration. We do not operate a separate process that reaches into vendor snapshots to remove individual records, and we will not claim a number we do not set. |
“Delete my account” erases an enumerated list of 70 user-scoped tables and your stored files. A short list of things is kept on purpose, and you should know what before you decide, not after.
| What is kept | Why |
|---|---|
| Security and organisation audit log entries naming you | Both audit trails are append-only integrity controls, enforced by database privilege rather than by our code. On the security trail the application role can add an entry but cannot update or delete one; on the organisation trail it cannot insert either, and writes go through a privileged routine instead. That is the point of an audit trail. Erasure does not purge them. We are recording that as a gap rather than describing the erasure as total: a separate privileged routine exists to purge them, and it is not part of the automatic path. |
| A record that you were erased | A suppression entry survives so the system can tell that this subject must stay erased. Deleting it would erase the evidence that the erasure happened. |
| Double-charge protection keys and payments still moving | Deleting these can charge you twice or lose a settlement owed to you. They outlive the account they protected. |
| Rows that belong to an organisation rather than to you | An organisation’s billing ledger keeps the row with your user id removed; files you added to a shared project keep the file and drop the attribution; abuse reports you filed about someone else keep the report and drop you. Deleting an organisation because its creator left would erase every other member. |
| Stripe’s own records | Your payments and invoices sit with Stripe under its retention, not ours. Card numbers go to Stripe directly and never reach us. |
| Anything given without an account, keyed to an address | An early-access email, a consent decision or a rights request made without signing in is not reachable by account deletion, because there is no account to delete. Nothing ages those out automatically either. Use the request form at /privacy/requests and we will remove them. |
06 · What you can change yourself
Controls that exist in the product right now, separated from the statutory rights in the next section on purpose. A right you have to write in and ask for is not the same thing as a switch you can reach, and a policy that mixes them makes the product sound more self-serve than it is.
| Control | Where it is, and exactly what it does |
|---|---|
| Export your data | Account settings. Returns your account data as a download. It is rate limited, and every export is written to the security audit log. It does not yet cover every category this page lists. Where something is missing, use the access request in the next section. |
| Delete your account | Account settings. Erasure is scheduled 24 hours out, then performed by a daily job that also deletes your identity at our authentication provider. Read the survivors table in section 05 first. Cancellation is self-serve: sign back in and cancel from Settings > Account any time before the 24 hours are up. |
| Withdraw a consent | /privacy/requests. Per purpose, one click, immediate. Withdrawing an optional purpose never costs you access to anything you did not withdraw. |
| Turn analytics off | The cookie preferences dialog, reachable from /cookies. It is already off until you turn it on; this is how you change your mind. |
| Turn crash reporting off | Settings. A separate switch from analytics, in a different place, because they are different vendors doing different things. We would rather say that than imply one toggle covers both. |
| Clear your search history | Settings. Removes the stored history for your account. |
| Memory | Off unless you enable it. When on, the assistant keeps facts about you across sessions, and you can remove them. |
| Temporary chat | The composer. A temporary conversation is hard-deleted by a daily job about 30 days later, messages with it. |
| Delete a conversation or a file | In the product. Deleted files sit in a recently-deleted bin for 30 days, then the bytes are removed from storage. |
| Choose where a request goes | The mode selector. Local keeps the conversation on your machine and sends us nothing; BYOK goes from your client straight to your provider on your key. Both are desktop, CLI and VS Code capabilities: the web app is cloud-only. |
07 · Your rights, and how to use them
Depending on where you live and subject to applicable exceptions, privacy laws such as the GDPR, UK GDPR, and CCPA may give you rights of access, correction, deletion, portability, objection or restriction, and non-discrimination. Two requests are self-serve in the product:
| Export | Signed in, you can export your data from the account export endpoint at any time. It is rate limited and each export is recorded in the security audit log. |
| Deletion | Request account deletion from the product. Erasure is scheduled 24 hours later and then performed. You get no confirmation email, because the only email this product sends is support escalation, scheduled-task notifications and operational alerts to us: there is no account-lifecycle mail. Cancellation is self-serve: sign back in and cancel from Settings > Account any time before the 24 hours are up, and the request is discarded without touching your data. Once that window has closed the product refuses to cancel, so the request cannot be revived after erasure begins. |
| Everything else | Email contact@agiworkforce.com from your account address with the subject line “Privacy request”. Applicable law determines the response period. You may use an authorised agent where the law allows. |
EU, UK and Swiss residents may also lodge a complaint with their supervisory authority. California residents: we do not sell or share personal information, so there is no opt-out to exercise, and the CCPA service-provider terms we operate under are in section 06 of the DPA.
08 · International transfers
AGI data is hosted in the United States. We do not offer EU or UK data residency, so European customers’ data is transferred to and processed in the US. For EU, UK and Swiss personal data we rely on the Standard Contractual Clauses with the UK Addendum and the Swiss adaptations, set out in section 06 of the DPA. AGI has not appointed a representative under GDPR Art. 27; the current position is at /legal/eu-representative.
09 · Children
AGI accounts are for people aged 18 and over; 13- to 17-year-olds may use it only under an account opened and supervised by a parent, guardian or school, as set out in section 02 of the terms. We do not knowingly collect personal data from children under 13, or under the higher digital-consent age where one applies. If you believe a child has provided us data, email us and we will delete it.
10 · Changes
We may update this policy. The current version is always at this URL with the revision date at the top, and material changes are recorded on /changelog. No mailing path in this product can reach an arbitrary list of customers, so we do not promise emailed notice of a change.
11 · Contact
AGI Automation LLC, c/o registered agent, 5900 Balcones Drive STE 100, Austin, TX 78731, USA. Email contact@agiworkforce.com.