Skip to content

Privacy

What we collect, where it goes, and the parts of it that leave our machines — including the one most people do not expect. Written from the product as it is built, with the answers nobody has decided yet left visibly empty.

This is a draft, prepared for legal review

Every factual statement below was written from what this product actually does, checked against the code that does it. None of it has been reviewed by a lawyer. It is published so that it can be checked and corrected, not because it is finished — and the blanks in it are blanks, not promises. Do not rely on this document as a binding agreement until it has been reviewed and dated.

English is the version that governs

This document is written in English, and the English text is the one with legal force. The Russian and Ukrainian versions are translations offered so that the same people who use the product can read it in their own language. Where a translation and the English text disagree, the English text is the one that means anything.

1. Who we are

Agentfy.ai is a platform for building AI agents that answer for a business, remember what they are told, and act inside the tools that business already uses. This document is about the data that passes through it.

The company that operates the platform, the country it is registered in, and the address it can be written to are not stated here. They are left empty rather than guessed at, because a wrong answer to any of them would make everything below unenforceable and misleading at the same time.

Left blank on purpose — the owner must fill this in The legal entity behind Agentfy.ai: its registered name, its form, and its registration number.

Left blank on purpose — the owner must fill this in The registered address, and the country the service is operated from.

2. What this covers

Four surfaces, and they are not equivalent. This website, which is public and asks nothing of you. The cabinet, where a team signs in and builds its agents. The agents themselves, which run on our machines and reach out to other services on your behalf. And the chat a team can place on its own website, where the person typing has no account with us at all.

It does not cover the services you connect to it. Once your agent signs into a shop you own, or calls a tool server you registered, what happens on the other side is governed by whoever runs it — and by whatever you agreed with them.

3. We are two different things at once, and the difference matters

Towards a team that signs up, we hold your data and you decide what goes in it. You are our customer; the agents, the knowledge and the conversations are yours.

Towards your customers, we are one step further away. When a team puts a chat on its own website, the people who write into it become records here — an identifier we issued, when they came and through which agent, and, if the team's own backend told us, their name, email address and phone number. Agents also keep notes about them. Those people are the team's customers, not ours. The team decides what is collected and why; we hold and process it on the team's instructions.

The practical consequence is worth saying plainly: if you are one of those customers and want to know what is held about you or want it removed, the business you were talking to is the one to ask. We act on what that business tells us.

4. What we collect

An account: your email address, the name you choose to give, and a password kept only as a hash. Nothing else is required to sign up.

What a team builds: agents and their instructions, uploaded knowledge, skills, files, the notes an agent keeps about its work and about the person it works for, and the conversations it has. This is the substance of the product, and it stays until you delete it.

People who talk to your agents: one record per visitor, holding the identifier we issued them, when they first and last appeared, which agent they arrived through, and — only when your own website told us — their name, email address and phone number. What an agent learns about a person is kept beside that record.

Calls, if you record one: the text of what was said, phrase by phrase, with a marker for which side of the call said it, and a transcript file when the call ends. The sound itself never reaches our servers.

Credentials you save for an agent: encrypted before they are stored, and described in their own section below.

Operational records: how much of each model was used, so that usage can be counted and billed; ordinary server logs; and a record of what a platform administrator did to whose data.

5. This website in particular

The page you are reading is a set of static files. It sets no cookies, runs no analytics, embeds no tracker, and has no form to fill in. Detection of your browser language is switched off, so nothing about you is even guessed at. Your browser asks for files and receives them; that is the whole exchange.

The cabinet is a different application, and signing in there does involve a session. Following a link from this site into it takes you out of the scope of this section and into everything else in this document.

6. What we use it for

Running the product: answering, remembering, searching by meaning, and acting in the tools an agent was given. Almost everything we hold exists because an agent needs it to do the thing it was asked to do.

Keeping the service working and accountable: counting usage so it can be billed, investigating faults, and stopping abuse of the platform.

We do not sell what we hold, we do not rent it out for advertising, and we do not use one team's content to serve another. We do not train any model on your content ourselves; what the providers named below do under their own agreements is one of the blanks in this document.

7. The legal grounds

Which law governs this processing, and which lawful ground applies to each purpose above, follows from where the operating company is established and where you are. That question is open, and answering it by picking a familiar-sounding phrase would be worse than leaving it open.

Left blank on purpose — the owner must fill this in The applicable data protection law, and the lawful basis relied on for each purpose listed above.

8. Who else sees it

Some of what you put in leaves our machines, because the things this product does cannot be done on our machines alone. There are four such flows and they are named here rather than hidden behind a phrase like AI model providers.

Anthropic. Every conversation with an agent is sent to Anthropic's models, together with whatever that turn needs to make sense: the agent's instructions, its notes, the knowledge your team gave it, and the definitions of the tools it may use. This is the core of the product and there is no way to use an agent without it.

OpenAI. Finding a note or a document by meaning rather than by matching words requires the text to be turned into a numeric vector, and that is done by OpenAI's embedding model. Memory notes, team knowledge and past chat messages are sent there for that purpose.

Google. Speech recognition — both in voice mode and in call recording — is performed by the browser and sent to Google's servers. It has its own section below, because it is the flow people least expect and the one that involves other people's voices.

Tool servers a team registers itself. Those are your choice rather than ours, and they have their own section too.

Left blank on purpose — the owner must fill this in What each of these providers is contractually permitted to do with the data we send them — in particular whether it may be retained, reviewed by a human, or used to train a model — and the link to the agreement that says so.

9. Voice and recorded calls: the sound leaves the machine

When you speak to an agent, or turn on call recording, the audio is not recognised on your computer. It is sent to Google's servers, transcribed there, and returned as text. There is no private path for this today: the browser can recognise speech locally, but not on the audio of a captured call, and that was measured rather than assumed.

For a recorded call this is not only your own voice. It is everyone on the line. Their words travel to Google exactly as yours do and are stored here as text afterwards.

We cannot tell the other participants anything. Nothing shown on your screen is visible to them, and there is no signal a page can send down somebody else's meeting. So the product does the one thing it can: it hands you a sentence to say out loud and a box to tick saying that you said it. Ticking it is recorded on the call; leaving it unticked is recorded too, at the head of the transcript and in the conversation, so that the omission stays visible to whoever reads it later. The tick does not gate the recording, because a box that must be ticked teaches people to tick boxes. Whether the people on the call were actually told is your responsibility and your law's, not a checkbox's.

What we keep afterwards is the text, phrase by phrase, and a transcript file assembled when the call ends. The audio is not uploaded to us and is not stored by us.

10. Tool servers you connect yourself

A team can register an outside tool server and let its agents use what it offers. When an agent calls a tool there, the arguments of that call travel to whoever runs that server — and those arguments can contain anything the conversation contained, because that is what makes the tool useful.

Choosing the server is your decision and we do not make it for you; we restrict which addresses may be reached, and we do not vouch for what is at the other end. Disclosing that the data goes there is our job, and this paragraph is it.

11. Credentials you save

Keys, tokens and passwords you save for an agent are encrypted before they are written down. Each record has its own encryption key, and that key is itself wrapped by a master key held only by the application. They are decrypted for the moment an agent needs one and no longer.

They are never handed back to you. The screen that manages them shows names, never values; there is no request that returns a value; and a value cannot appear in a log by accident, because every line this platform logs is filtered for anything shaped like a credential before it is written.

If you export an agent in order to move it somewhere else, the export carries the names of the credentials that agent needs and none of the values. The copy arrives with a named but empty vault and a list of what has to be filled in again.

12. Where it physically is

The model, embedding and speech providers named above operate outside the countries most users of this product are in. Using the product therefore means data crossing borders, and there is no configuration that avoids it.

Where our own servers are, and what safeguard covers those transfers, is not stated here yet.

Left blank on purpose — the owner must fill this in The countries our own infrastructure runs in, and the transfer mechanism relied on for data leaving them and leaving the user's own country.

13. How long we keep it

Your content stays until you delete it. Deleting an agent takes with it what belonged to that agent — its conversations and their attachments, its notes, its saved credentials, the diagnostic recordings it produced — and this is enforced by a rule over the database schema rather than by anybody remembering: a table naming an agent or a team either falls with them or is listed, by name and with a written reason, as one that deliberately does not.

Three things do expire on their own. A diagnostic recording of what was actually sent to the model is off by default and, when a team turns it on, is deleted after seven days. Raw usage records are kept for forty-five days and then survive only as totals. The record of what a platform administrator did is kept for a year, and is deliberately one of the things that does not fall with the agent it describes — the entry saying an agent was deleted is the one entry nobody can afford to lose.

Retention periods for everything else, and what happens to a team's content when an account is closed, have not been decided.

Left blank on purpose — the owner must fill this in How long each kind of content is kept after it is deleted or after an account is closed, and how long backups hold it.

14. How it is protected

Credentials are encrypted as described above, and every log line is filtered so that a credential cannot be printed by mistake. A team's data is read only within the team the signed-in member belongs to, and the identity of that team comes out of the verified session rather than out of anything a request can put in it — which is the difference between a rule and a habit.

No platform is safe because somebody says it is. If you find a way through any of this, the address to write to is one of the blanks below, and filling it in is more urgent than any sentence in this section.

15. Your rights, and what the product can already do

Whatever your local law gives you, the product itself already lets you see and change most of what is held: your account, your agents, their instructions and knowledge, the notes they keep, the people who wrote to them and what was learned about those people, and the name of every credential in force. Credentials can be removed one at a time or all at once, an agent can be deleted, and deleting it takes its data with it.

The formal list of rights, the address a request has to be sent to, and the deadline for answering it all follow from the law that applies — which is the open question two sections up.

Left blank on purpose — the owner must fill this in The rights available in each region we serve, the route for exercising them, the response deadline, and the supervisory authority a complaint can be made to.

16. Children

This is a tool for businesses. It is not designed for children and is not offered to them. A minimum age is not stated here, because the number depends on the same unanswered question about which law applies.

Left blank on purpose — the owner must fill this in The minimum age for using this service, and what happens if we learn that a user is below it.

17. Changes to this policy

This document will change, starting with the blanks in it. How a change will be announced, and which version is in force from which date, has not been decided.

Left blank on purpose — the owner must fill this in The effective date and version of this policy, and how users are told when it changes.

18. Contact

Where to write about anything in this document is not stated here. The footer of this site carries a general address, which is not the same thing as a route for a request about personal data, and pretending it is would be the kind of small untruth this document exists to avoid.

Left blank on purpose — the owner must fill this in The address for privacy requests, and whether a data protection officer or a representative in the EU or the UK has been appointed.