Privacy Policy
Agent as a Business is a platform for packaging, publishing, and operating agent capabilities. This policy explains what we collect, why we collect it, and who processes it on our behalf. It covers https://agentaab.com, https://app.agentaab.com, and https://api.agentaab.com.
Two kinds of people, two kinds of data
We deliberately separate the two roles this platform serves, and we store their data separately.
- Creators sign in to the console to build and operate an Agent Business. We hold the account identity, the businesses and capability configurations they create, billing and payout settings, and an audit trail of console actions.
- End Users consume a Creator's published app or API. Their identity, quota, and credits are scoped to that single app and are never merged into a cross-app profile. We do not build advertising profiles, and we do not sell personal data to anyone.
What we collect
- Account data — the email address and profile fields supplied at sign-in.
- Configuration data — the capabilities, releases, offers, and channels a Creator configures.
- Invocation data — request and response records for capability runs, retained to meter usage, bill accurately, and let Creators debug their own businesses.
- Billing data — subscription and payout state. Card and bank details are handled by our payment processors and never reach our servers.
- Operational logs — IP address, user agent, and timestamps, used for rate limiting, abuse prevention, and security investigation.
Processors we rely on
We keep this list short and specific rather than hiding behind "trusted third parties".
- Cloudflare — hosting, edge runtime, database, object storage, and DDoS protection. Data is processed on Cloudflare's global network.
- Logto — Creator authentication and session management.
- Stripe and Airwallex — payment processing and payouts. They receive the billing details required to complete a transaction; we receive only the result.
- Model providers — when a capability runs, its prompt and inputs are sent to the model provider that capability is configured to use. Which provider that is, is set by the Creator and visible in the capability's configuration.
Retention
Account and configuration data is kept while the account is open. Invocation and log data is kept only as long as it is needed to meter usage, produce billing records, and investigate abuse. Closing an account removes the account and its configuration; anonymised billing records are kept where tax and accounting law requires it.
Your rights
You can request access to, correction of, export of, or deletion of your personal data by writing to [email protected]. Depending on where you live, you may also have the right to object to processing or to lodge a complaint with your local data protection authority. We answer these requests within 30 days.
Cookies
We set the cookies needed to keep you signed in and to protect forms against abuse. We do not use advertising or cross-site tracking cookies.
Changes
If we change this policy in a way that materially affects how we handle your data, we will update the date at the top of this page and notify account holders before the change takes effect.
Contact
Questions about this policy: [email protected]. Security reports: [email protected] (see our security.txt).