Loading…
Loading…
India · Digital Personal Data Protection Act, 2023
This is the itemised notice the DPDP Act requires us to give you before we process your personal data. It sits alongside the main privacy policy, which describes the same processing in more detail; where the two differ on your rights in India, this page governs. Last updated: 2026-08-13. Managed Cloud is in public alpha.
00 · Who is responsible
AGI Automation LLC, c/o registered agent, 5900 Balcones Drive STE 100, Austin, TX 78731, USA, is the Data Fiduciary for the processing described here: it decides why and how your personal data is processed. You are the Data Principal. AGI has no establishment in India and no data centre in India; your data is hosted in the United States, which section 06 explains.
01 · The mode decides what we hold
Most of this notice depends on which mode you run, because Local, BYOK and Managed Cloud are separate trust boundaries and your data goes to genuinely different places in each. Read this first.
| Mode | Where your prompts go | What we hold |
|---|---|---|
| Local | To a model runtime on your own machine. Nothing is transmitted to us and nothing is silently routed to BYOK or Managed Cloud. | Nothing about the conversation. It lives in SQLite on your disk, where this notice has nothing to describe. |
| BYOK | From your client straight to the provider you targeted, on your own API key. We are not in that request path. | Your account and settings. Not the prompt traffic. Your key is encrypted on your device and the master password is not recoverable by us. |
| Managed Cloud | Through our gateway to the provider serving the model you selected. | Conversations, files, projects, memories, schedules and settings, so they sync across your devices. |
02 · What we process, and for which purpose
The Act requires the purpose to be specific and the data to be limited to what that purpose needs. Each row below is one purpose, not a category we might later reuse.
| Personal data | Purpose it is processed for | Why we may process it |
|---|---|---|
| Email address, account identifier, authentication metadata | Creating and securing your account. Held by our identity provider; we do not store your password. | Your request: you asked us to create the account, and the account cannot exist without it. |
| Billing identifiers, plan, invoice metadata | Taking payment and managing your subscription. Card details go to Stripe directly and never reach us. | Performing the paid service you signed up for. |
| Conversations, files, projects, memories (Managed Cloud only) | Running the assistant and syncing your work across your devices. | Providing the Managed Cloud service you chose to use. Local and BYOK do not produce this data for us. |
| Error reports and performance traces (Sentry) | Diagnosing crashes. Content-scrubbed, but a stable user id is retained so a crash can be tied to a session, so they are pseudonymous, not anonymous. | Your consent. Off until you turn it on. |
| Aggregated page views (Google Analytics 4) | Understanding which parts of the product get used. | Your consent, recorded per purpose. The gate fails closed: if your choice cannot be read, analytics stays off. |
| Email address given on the early-access list | Telling you when enterprise features open. Optionally, product updates: a separate box you can leave unticked or withdraw on its own. | Your consent, recorded before the address is stored. |
| Server logs and an append-only security audit log | Debugging, preventing abuse, and investigating security incidents. Bearer tokens are redacted. | Keeping the service secure and available. |
What we do not do with it. AGI does not train AGI-owned models on your prompts, responses or files. We run no advertising, set no advertising cookies, and do not sell or share personal data for cross-context behavioural advertising.
03 · The consent we ask for, one purpose at a time
Consent under this Act has to be specific, unbundled, and given by a clear affirmative action. So every box is unticked when you meet it, an optional purpose never blocks a necessary one, and every decision (including the boxes you leave unticked) is recorded against the revision of this notice that was on screen. These are the purposes we ask about:
| Purpose | What it covers | Required? |
|---|---|---|
| Store my email address on the enterprise early-access list. | Your address is stored so we can reach you when enterprise organisation and SSO features open. It is used for that and nothing else. To be straight about the mechanism: nothing in the product mails this list automatically, so the announcement is sent by a person. | Required for the thing you asked for |
| Also email me product updates and launch news. | Occasional email about new releases and capabilities, sent by a person rather than an automated system. Separate from the early-access list, so you can withdraw it without leaving that list. | Optional, declining costs you nothing |
| Allow aggregated usage analytics. | Aggregated page views via Google Analytics 4, used to understand which parts of the product get used. Off unless you turn it on. This is the same choice as the analytics switch in the cookie banner. | Optional, declining costs you nothing |
Withdrawing is as easy as giving: change any of them at /privacy/requests, with no email and no support ticket. Withdrawal stops the future processing that depended on it; it does not undo processing that already lawfully happened, and it does not delete your account. That is a separate request on the same page. AGI is not registered with a Consent Manager under section 6(7), so consent is given to us directly rather than through one.
04 · Who else receives it
The published list, with what each one receives and where it runs, is at /subprocessors. In summary: an identity provider holds your login, Stripe holds your payments, our hosting and database vendors hold what you store in Managed Cloud, object storage holds your files, and error/analytics vendors receive only what section 02 describes and only with your consent.
That published list is currently incomplete, and we would rather say so here than let you rely on it. A review completed on 2026-08-13 found recipients that receive personal data and are not on it: an email provider used for support escalations and scheduled-task notifications, a video-generation provider that receives the prompt text you type, a geocoding service that receives location queries you make, and the Apple and Google store APIs that receive purchase identifiers on mobile. Correcting that page is a tracked open item. If your decision to use this service depends on the full recipient list, ask the grievance contact in section 08 before you sign up.
Model providers. In Managed Cloud, the prompt and any attached content go to the provider serving the model you selected, and for routed models the request passes through OpenRouter. Those providers handle that content under their own terms and data-use policies; our no-training statement is about AGI-owned models and is not a promise on their behalf. In BYOK the request goes from your client straight to the provider on your key, governed by your own account with them. In Local, none of them are contacted.
05 · How long we keep it
The Act requires erasure once the purpose is no longer being served, unless retention is required by law. Every row below is a job or a mechanism that exists in the product, and the ones we do not control are named as such. The full schedule, including billing records, is section 05 of the privacy policy.
| Data | Retention |
|---|---|
| Account and its content | Kept while your account is active. Permanently erased 24 hours after a deletion request, by a daily scheduled job that also deletes your identity at our authentication provider. |
| Conversations (Managed Cloud) | Kept until you delete them or delete your account. There is no automatic expiry on ordinary conversations today, and we will not describe one until it runs. |
| Temporary chats | About 30 days, hard-deleted by a daily job. |
| Deleted files | 30 days in the recently-deleted bin, then the underlying objects are removed. |
| Security audit log | 90 days as a policy. The routine that enforces it is run by an administrator, not on a schedule, so treat it as the policy rather than an automatic guarantee. |
| Consent records | Kept for as long as the account exists, including withdrawn consents, because a record that consent was once held is the evidence this Act asks us to be able to produce. Erased with the account. |
| Early-access list email addresses | No maximum age is enforced today. The address is removed on request via the grievance contact below. We will not publish a window until a job deletes them. |
| Server logs and backups | Vendor-governed. We do not operate a process that reaches into vendor snapshots to remove individual records, and we will not claim a number we do not set. |
06 · Where it goes, and out of India
Your personal data is processed and stored in the United States. AGI does not offer data residency in India, so using this service means your personal data leaves India. The Act permits transfer outside India except to territories the Central Government restricts by notification; whether any notification affects the United States is a question of the live notification list on the date you read this, and we will not assert an answer to it here. If you need Indian data residency, we do not have it, and you should not sign up expecting it.
07 · Your rights, and what actually happens
| Right | How to use it, and what the product really does |
|---|---|
| Access: a summary of your data and who it has been shared with | Signed in, export your data from the account export endpoint at any time. It is rate limited and each export is recorded in the security audit log. The list of recipients is section 04 and /subprocessors; the export does not enumerate them per record. |
| Correction, completion and updating | Profile and settings are editable in the product. For anything you cannot edit yourself, use the request form below and say what is wrong; we correct it. |
| Erasure | Request account deletion in the product. Erasure is scheduled 24 hours later and then performed. Two limits, stated plainly: you get no confirmation email, because the only email this product sends is support-escalation and scheduled-task notification: there is no account-lifecycle email path; and there is no self-serve way to cancel a scheduled deletion, so inside that 24-hour window you must reach us. |
| Withdraw consent | /privacy/requests , per purpose, immediately, without contacting anyone. |
| Grievance redressal | Section 08. Use it before approaching the Data Protection Board: the Act expects you to have exhausted our route first. |
| Nominate someone to exercise your rights if you die or become incapacitated | Not self-serve. There is no nomination field in the product today. Send the nomination to the grievance contact in section 08 and we will record it against your account manually. This is an open item, not a finished feature. |
The Act also places duties on you: do not impersonate someone else when giving your data, do not suppress material information when it is legally required, and do not file false or frivolous grievances.
08 · Grievance redressal
Email contact@agiworkforce.com with the subject line “DPDP grievance”, or post to AGI Automation LLC, c/o registered agent, 5900 Balcones Drive STE 100, Austin, TX 78731, USA. We aim to respond within 30 days. That target is our commitment, not a statutory deadline we are quoting.
Subject-line routing is used because this is the one mailbox proven to receive mail; a dedicated grievance address is not provisioned, and we would rather publish a working inbox than a dedicated one that bounces. If our response does not resolve it, you may complain to the Data Protection Board of India.
09 · Children, stated honestly
Under this Act a child is anyone under 18, and processing a child’s data requires verifiable consent from a parent or guardian. AGI accounts are for people aged 18 and over, and the terms permit 13- to 17-year-olds only under an account opened and supervised by a parent, guardian or school. We do not currently perform verifiable parental consent or age verification. That is a gap against this Act, we are naming it rather than implying otherwise, and it is tracked as an open item. We do not knowingly collect a child’s personal data; if you believe we have, use the grievance contact above and we will delete it. We do not run behavioural advertising or tracking directed at children in any mode.
10 · Security and breach
We are required to protect your data with reasonable security safeguards, and to notify the Data Protection Board and every affected Data Principal if there is a breach. Our operational posture is at /security. The internal procedure for a breach (who declares it, what goes in the Board notification, and what you would receive) is written down and rehearsed against a 72-hour clock. The email this product can send today is support-escalation and scheduled-task notification; there is no account-lifecycle mailing path, so a user-facing breach notice would be delivered in-product and at a public URL rather than by email. We would rather tell you that now than discover it during an incident.
11 · Language, and changes
This notice is published in English. The Act entitles you to it in any language in the Eighth Schedule to the Constitution; translations are not yet published, and that is an open item. The current version is always at this URL with the revision date at the top, and material changes are recorded on /changelog. No mailing path for policy changes exists in the product, so we do not promise emailed notice of a change.