This policy describes how AgentConnect handles information related to your use of the product. It is a template for a product being prepared for public use — finalize it with the actual data flows, provider names, and retention choices before launch.
When you create an account we collect the information you provide — at minimum an email address and a password, and optionally a display name. When you use the product we record the actions you take that are part of the product's audit model: who did what, when, and on what, where that recording is part of the product's designed behaviour.
We use your account information to operate the service: authenticate you, present your workspace, record your activity for audit and collaboration purposes, and send you transactional communications that are part of the product's operation (for example account-security emails, invitation emails, and task notifications).
We do not sell your personal information. We do not use your account data to build a marketing profile of you across unrelated services. We do not include secrets, full tokens, or unnecessary personal data in transactional emails. Where a communication is transactional, it is sent because it is part of the product's operation, not because you are on a marketing list.
You are responsible for the data you bring into AgentConnect through providers, tasks, artifacts, and messages. AgentConnect does not take ownership of that data. Where you connect a provider, we do not access more than the scopes you grant.
We retain your data for as long as the product needs it to operate your workspace and meet our obligations, and for as long as you do not request deletion where deletion is available. Retention and deletion are explicit product features where they exist — they are not hidden.
You can export or delete your data where the product provides those features. You can revoke sessions from your account. You can adjust notification preferences so you receive the operational mail you want and fewer of the ones you do not.
Security is described on the security page. In short: authentication is required for the app surface, access is scoped by role, and consequential actions can require approval. We do not expose secrets or raw provider errors in the product.
The product may use cookies or similar mechanisms for authentication and for consent-aware analytics. Where analytics are used, they respect consent choices. We do not use third-party trackers that are invisible to the user.
We may update this policy. Material changes will be communicated in advance where practical. Questions can go through the contact page.
Replace this template with the final privacy policy, including the actual data processors, jurisdictions, and retention periods, before launch. Do not publish placeholder legal text as if it were final.