Privacy Policy
Last updated: August 2026 — how AgentCorp collects, uses, and protects your data.
1. Information We Collect
We collect information you provide directly: account details (name, email, organization), data you upload or generate through agent interactions, and configuration preferences. We also collect usage data automatically — request logs, credit consumption, error traces, and browser telemetry. We do not collect payment card data directly; that is handled by our payment processor.
2. How We Use Your Information
We use your information to operate and improve the platform, to authenticate your identity, to process billing, to send service-related communications, and to investigate abuse. We do not sell your personal data to third parties. We do not use your organizational data to train AI models without explicit, written opt-in consent.
3. Data Isolation and Multi-Tenancy
All organizational data is isolated at the database level using row-level security. Your agents, documents, tasks, and knowledge base entries are inaccessible to other organizations. Infrastructure-level employees may access data only when required to resolve a support issue or security incident, subject to internal access controls and audit logs.
4. Data Retention
We retain your data for as long as your account is active. Upon account closure, we delete primary data within 30 days. Derived artifacts (aggregated, de-identified analytics) may be retained for up to 12 months. Backups containing your data may persist for up to 60 days after deletion from primary storage. A limited set of records is kept longer where we have a legal basis to do so — audit and security logs, and financial, usage and compliance records — as set out in our Data Retention policy and on our account deletion page.
5. Cookies and Tracking
We use essential cookies for authentication and session management via Clerk. With your consent, we use PostHog (product analytics), Google Analytics (web analytics, with Google signals and ads personalization disabled), and Customer.io (a customer-engagement platform that also powers our lifecycle emails); all of these load only after you accept cookies and can be declined at the cookie banner. We do not use advertising or ad-retargeting trackers, and we do not sell your data to advertising networks. You can control cookie behavior through your browser settings; disabling essential cookies will prevent you from logging in.
6. Third-Party Services
We rely on a limited set of vetted sub-processors to operate the platform. Each is engaged under a written agreement that requires it to process data only on our documented instructions and to maintain appropriate technical and organizational safeguards. Our current sub-processors are:
- Clerk — Authentication & user identity
- Supabase — Primary database & file storage
- Railway — Application hosting & compute
- Stripe — Payments, subscriptions & invoicing
- Anthropic — Primary AI model processing (Claude)
- xAI (Grok) — Secondary AI model processing (marketing agent)
- Twilio — WhatsApp / SMS messaging channel
- Customer.io — Lifecycle & transactional email
- Intercom — In-product customer support messaging
- PostHog — Product analytics (consent-gated)
- Google (Google Analytics 4) — Web analytics (consent-gated; Google signals & ads personalization disabled)
- Recall.ai — Meeting notetaker — recording & transcription (media deleted after transcript capture; 24h max retention)
- Sentry — Error & performance monitoring
- Arize — AI output observability & evaluation
A complete, current list including processing location and data categories is maintained at /legal/subprocessors. We provide at least 14 days' notice before adding or replacing a sub-processor.
7. Security
We implement encryption in transit (TLS 1.2+) and at rest for all stored data. API access is protected by short-lived, signed JWTs. We conduct regular dependency audits and penetration testing. In the event of a breach affecting your data, we will notify you within 72 hours of discovery.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at privacy@agentcorp.work. We will respond within 30 days. We will not discriminate against you for exercising your privacy rights.
9. International Transfers
Our primary infrastructure and all durable data storage are hosted in the United States. One exception: meeting recordings captured by the notetaker are processed transiently in the European Union (Frankfurt) by our meeting sub-processor and deleted within 24 hours — only the resulting transcript is stored, in the US. If you are located outside the US, your data may be transferred to and processed in the US. By using AgentCorp, you consent to these transfers. We apply appropriate safeguards for cross-border transfers in accordance with applicable data protection laws.
10. Mobile Applications
This section covers the AgentCorp mobile apps for iOS/iPadOS (work.agentcorp.ios) and Android (com.agentcorp.app), in addition to everything above. Push notifications: when you enable notifications, your device is issued a push token by Apple (APNs) or Google (FCM), and we store that token against your account so we can route notifications to you. The token is a device identifier linked to your identity; we use it only to deliver notifications, we never sell or share it with data brokers, and we never use it to track you across other companies' apps or websites. Signing out or deleting your account removes your registered devices. On-device storage: your session token is held in the iOS Keychain or in Android Keystore-backed encrypted storage, and is erased along with all cached workspace data the moment you sign out. Notifications and home-screen widgets deliberately show counts and short titles only — never customer, financial, or document content. Voice input: dictation is transcribed by your device's own speech recognition, which on some devices and languages is processed by Apple rather than on-device; either way we receive only the resulting text, and we neither store nor transmit the audio. Camera and microphone are accessed only at the moment you use a feature that needs them, and the apps work without those permissions. The apps display no advertising, contain no advertising identifiers, and perform no cross-app or cross-site tracking, so no App Tracking Transparency prompt is shown. You can delete your account and all associated data from within the apps (Settings → Danger zone) or at agentcorp.work/legal/account-deletion.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 14 days before they take effect via email or in-platform notice. The date at the top of this page reflects the latest revision.
The data controller for the purposes of this policy is AgentCorp. AgentCorp's registered entity details and address are provided on request and are set out in your signed order form or Master Services Agreement.
Privacy questions? Email privacy@agentcorp.work