Privacy policy
What we process when you visit the site or run a workspace, how information is shared, and your choices.
Last updated 19 September 2026.
1. Responsibility and scope
The publisher identified in the legal notice is responsible for Agentik’s account administration, security, billing and website processing. This policy covers website visitors, account holders and workspace users. For personal data submitted on an organisation’s instructions through a tool, the respective controller and processor roles depend on the agreed processing terms and the selected provider.
2. Data we process
We receive information from you, your sign-in provider, workspace administrators, your agents and the services involved in the requests you make. Tool providers may return information about third parties, including professional contact details, when you request a search or enrichment tool.
- Accounts and workspaces: name, email address, identity-provider identifier, membership, role, invitations and settings.
- Credentials and security: hashed API keys, key labels and permissions, authentication grants, timestamps, audit events, network information such as IP prefix, country and network operator, and user agent. New plaintext API keys are shown at creation and are not retrievable from their stored hash.
- Executions and billing: tool and run identifiers, input fingerprints for idempotency, provider task references and metering evidence, prices, reservations, charges, refunds, status, timing and sanitised errors. The execution ledger does not store raw tool inputs or outputs as a payload history.
- Payments: Stripe customer and transaction references, purchase and billing details needed for payment, accounting and disputes. Card entry takes place with Stripe; Agentik does not store full card numbers.
- Transactional email: recipient addresses, message content and delivery references for selected authentication messages, invitations, welcome messages, payment confirmations and alerts. Pending message bodies are encrypted in the delivery queue.
- Support: messages you send, assistant responses, conversation references and authorised account information used to answer you. Do not send passwords, API keys, payment-card details or sensitive tool payloads to support.
- Website use: page and device information for service operation and Vercel Web Analytics; consent choices stored in your browser; advertising events only if marketing is configured and you consent.
3. Purposes and legal bases
Account access, requested tool execution, payments and support are processed to perform our contract with you, or in our legitimate interests in providing an organisation’s users with the contracted service. Necessary account and request information is required to provide those features.
Security, abuse prevention, service diagnostics and limited audience measurement support our legitimate interests in protecting and improving the service. Accounting, tax records and lawful disclosure requests are processed to meet applicable legal obligations. Optional advertising relies on consent, which can be withdrawn without affecting earlier lawful processing.
Spending rules and security checks may automatically reject a request or pause a key. Contact us for a review if you believe access was restricted incorrectly.
4. Recipients and international processing
Authorised personnel and the service providers listed in our register can process the information needed for their role. Workspace administrators can access workspace information within their permissions. Selected tool providers receive the requests needed to fulfil your calls; a catalog listing does not mean every provider receives your data. We may disclose information when legally required or necessary to establish or defend legal claims.
Providers may process data outside your country, including in the United States. We do not promise EU-only processing. Applicable transfers require a valid legal mechanism, such as an adequacy decision or contractual safeguards, for the actual service and recipient. Contact us for the safeguards and processing locations applicable to your use; a link to a vendor’s public DPA does not establish that all account-specific arrangements have been completed.
5. Cookies and browser storage
Authentication cookies and similar storage support sign-in and service security. Agentik stores your marketing choice in local storage under agentik-consent. Vercel Web Analytics is designed to measure site usage without analytics cookies; its privacy documentation explains its event processing.
When an X advertising pixel is configured, it loads on public marketing pages only after acceptance. Rejecting marketing leaves it off. Reopen Cookie settings in the footer to withdraw consent; withdrawal stops future loading and cannot undo requests already sent to a third party. You may also clear cookies and site storage in your browser.
6. Retention and deletion
Account and membership records are needed while a workspace remains active. Closure and erasure requests are reviewed against outstanding executions, security investigations and legal recordkeeping duties; there is no automatic promise that all account records are erased within 30 days.
Scheduled database cleanup targets key-usage records and run network context older than 90 days, delivered security events older than 180 days, and processed run events older than 90 days. Expired OAuth codes and tokens become eligible for cleanup after one additional day. Cleanup runs in batches, so eligibility is not an exact deletion timestamp.
Financial ledger entries, run receipts, audit records and unresolved incidents do not currently have a blanket automatic deletion deadline. Their retention depends on reconciliation, applicable legal duties and the need to resolve disputes. Contact us for the retention applicable to a particular record and to request deletion where those grounds no longer apply.
Queued email payloads are erased after sending, cancellation or expiry; delivery metadata remains. Delivery windows depend on message type: ten minutes for relayed authentication messages, 72 hours for invitations and up to seven days for other transactional messages. Retries stop after ten attempts or 23 hours from the first attempt. These delivery windows do not extend the validity of an authentication code.
Support conversations become inaccessible through the application after 30 days and can be removed from history earlier. Removal revokes application access; it does not establish physical deletion from every workflow store, backup or model provider. Infrastructure backups, provider logs and analytics have their own retention settings and terms.
7. Your rights and contact
Where applicable, you can request access, correction, erasure, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. If your organisation controls the data, contact its administrator first; we can assist with requests concerning our processing.
Use the contact in the legal notice. We may need proportionate information to verify your identity, but will not ask for your password or API key. We normally respond within one month; where the law permits an extension, we will explain it. You may complain to the CNIL or your competent data-protection authority.
8. Security and policy changes
Safeguards include encrypted transport, hashed API keys, workspace access checks, revocation, optional spending restrictions and security monitoring. No system is completely secure. Personal-data incidents are assessed and notified to affected customers and authorities as required by applicable law.
We update this policy when our practices change. The date above identifies the current version; material changes will be communicated where required.