Skip to policy
AGENTNETES
Home Privacy Terms
Contact Us
Policy · Version 1.2 · Effective 2026-09-24

Privacy Policy

How Agentnetes handles account data, encrypted credentials, cloud sync, telemetry, marketplace activity, and website enquiries.

Privacy Policy Terms of Service

Contents

  1. Who we are
  2. What we collect
  3. How we use your data
  4. Who we share with
  5. Data location & transfers
  6. Your rights
  7. Security
  8. Children
  9. Changes
  10. Contact

This policy is drafted in plain language and covers what Agentnetes does today. It is provided in good faith; if your jurisdiction imposes additional obligations, those take precedence. If anything here is unclear or incorrect, write to [email protected] and we will respond.

1. Who we are

Agentnetes ("we", "us") is an orchestration platform for autonomous AI agents. The service consists of a cloud-hosted platform control plane and a local daemon (Mission Control), with its browser-based dashboard, that runs on your machine.

2. What we collect

2.1 Account data

When you sign in with Google, we receive from Firebase Authentication:

  • Your Google account UID (a stable opaque identifier).
  • Email address.
  • Display name and profile photo URL (if you have set one).

We do not receive your Google password or any contacts or calendar data.

2.2 Vault (encrypted credential storage)

When you save an API key for a third-party provider (Anthropic, OpenAI, etc.) through Agentnetes, the key is client-side encrypted with a key derived from your UID before it leaves your device. We store only the ciphertext in Firestore. We cannot read your keys; if you lose access to your account, they are unrecoverable by us.

2.3 Cloud sync (optional)

If you enable cloud sync, snapshots of your agents, missions, tasks, and namespaces are saved to Firestore tied to your UID. These enable multi-device continuity. You can disable sync and delete snapshots at any time from Settings.

2.4 Usage telemetry (opt-in)

When enabled, we record per-model, per-day aggregate counters: number of calls, input/output token totals, estimated cost in USD, and outcome (success / failure / cancelled). No prompts, completions, or task contents are transmitted. This data feeds the marketplace reputation rollup — so an agent's public quality signal reflects real usage. You can turn telemetry off in Settings at any time. Your contribution stops immediately; aggregated historical rollups remain on agents you already used.

2.5 Marketplace activity

Publishing an agent, subscribing to one, filing an abuse report, or being the subject of one are stored indefinitely unless you request deletion. Subscription records are retained for tax and dispute purposes for seven years as required by Stripe's agreements; after that they are purged.

2.6 Technical logs

Cloud Run and Firebase Hosting record connection metadata (IP, timestamp, user agent, status code, URL path) for up to 30 days as part of standard operations. These logs are used to debug failures and protect against abuse; they are not cross-referenced with your account unless an abuse investigation requires it.

2.7 Website enquiries

When you use a contact form on our website, we collect the details you provide, such as your name, work email address, company, area of interest, and message. We also record where the enquiry began (for example, the page, section, or service you selected), the submission time, a submission identifier, and email delivery status. Basic connection information used to secure the form is covered in §2.6.

We use this information only to receive, route, and respond to your enquiry, maintain a record of the conversation, and prevent abuse. Form submissions are delivered to [email protected]. Submitting an enquiry does not add you to a marketing list, and we do not use enquiry details to send promotional messages unless you separately ask us to do so.

Enquiry submissions and related correspondence are normally retained for up to 24 months after our last exchange, then deleted or anonymized. We may keep them longer where an active business relationship, legal obligation, or dispute requires it. Records used only to prevent repeated or abusive submissions are retained for no more than 30 days.

3. How we use your data

  • To authenticate you and authorize your actions.
  • To sync your state across devices (only when you enable sync).
  • To process marketplace subscriptions and charge for paid agents via Stripe.
  • To compute aggregate reputation signals displayed on marketplace listings.
  • To investigate abuse reports and enforce our policies.
  • To receive, route, and respond to website enquiries.
  • To communicate with you about account, billing, and security matters (transactional email only — no marketing).

4. Who we share with

  • Google Cloud / Firebase — our infrastructure provider. Data resides in Firestore (us-central1) and Cloud Run (us-central1).
  • Resend — our email delivery processor for website enquiries. Resend receives the contact details, message, source information, and delivery metadata needed to send the enquiry to our inbox. We do not use Resend to market to people who submit the form. Resend's privacy policy applies: resend.com/legal/privacy-policy.
  • Marketplace publishers — when you subscribe to an agent, the publisher learns that a user subscribed and what namespace the agent targets. Your email is not shared with the publisher.
  • Authorities — if compelled by valid legal process, we disclose what we must. We challenge requests that appear overbroad and, where not prohibited, notify affected users.

We do not sell personal data. We do not share with advertisers. There is no advertising on Agentnetes.

5. Data location & transfers

Our services are hosted in your own cloud. Standard Contractual Clauses will be in place to comply with GDPR and other relevant frameworks.

6. Your rights

Regardless of jurisdiction, you can:

  • Access — request a copy of everything we have tied to your account.
  • Correct — update details held about you (most fields are user-editable in Settings).
  • Delete — request full deletion of your account and associated data. Some records may persist for up to 90 days in backups and up to 7 years for billing (see §2.5).
  • Export — download your namespace data as a tarball via the existing /api/v1/namespace/{ns}/export endpoint.
  • Object — opt out of telemetry without losing service access.

Email [email protected] with “Privacy request” in the subject line. We respond within 30 days.

7. Security

Credentials are client-side encrypted before transit. All service endpoints enforce HTTPS. Firebase Auth issues short-lived ID tokens (1 hour lifetime) that our backend verifies on every authenticated request. Internal access to Firestore is restricted via IAM roles bound to specific Cloud Run service accounts. We do not use long-lived API keys for server-to-server auth.

8. Children

Agentnetes is not directed at children under 13. If we learn that we hold data from someone under 13, we delete it. Publishers must not target agents at children under 13 without verifiable parental consent.

9. Changes

Material changes to this policy are announced via a banner in the Mission Control dashboard and an in-product notice. Non-material changes (typo fixes, clarifications) are updated silently. The “Effective” date at the top of this document always reflects the current version.

10. Contact

General enquiries: [email protected]
Privacy contact: [email protected]
Data controller: Agentnetes
EU representative: not currently designated. Users in the EEA may contact us directly at the email above.

AGENTNETES

Agentic orchestration across workflows, people and systems.

Home
© 2026 AgentnetesPrivacyTerms