Privacy Policy
Last updated: August 2026
1. Information We Collect
We collect the following categories of information:
-
Account information — name, email address, and authentication identifiers when you create an account, including when you sign up through a third-party identity provider such as Google
-
Workspace content — files, documents, pages, messages, and other content that you or your team upload to or create in the Service, and data from third-party tools you choose to connect to your workspace
-
Google user data — if you connect a Google integration, the limited data described in the Google User Data section below
-
Payment information — billing details processed by our payment processor; we do not store full payment card numbers on our servers
-
Usage and device information — interactions with the Service, log data, IP address, browser and device type, and information collected through Cookies or similar technologies
-
Communications — information you provide when you contact support or otherwise communicate with us
2. How We Use Personal Information
We use personal information to:
-
Provide, operate, and maintain the Service
-
Create and manage user accounts
-
Execute AI agents, automations, and workflows
-
Process payments and manage subscriptions
-
Communicate with users, including support, service notices, product updates, and occasional feedback requests sent to account holders (see the Email Communications section below)
-
Monitor performance, reliability, and security
-
Improve functionality, accuracy, and user experience
-
Train, test, and improve machine learning systems using aggregated, anonymized, or de-identified data (this does not apply to Google user data — see the Google User Data section below)
-
Detect, prevent, and investigate fraud, abuse, misuse, or security incidents
-
Enforce contractual obligations and protect the integrity of the Service
-
Comply with legal, regulatory, and law-enforcement requirements
We may combine information from multiple sources and process it in accordance with this Privacy Notice.
3. Google User Data
Agently offers optional integrations with Google services (Gmail, Google Calendar, and Google Drive) through Google's OAuth 2.0 consent flow. If you choose to connect a Google account, Agently requests only the following limited scopes:
-
Gmail —
gmail.send: used solely to send emails that you or your AI agents compose and that you initiate or approve from within Agently. Agently cannot read, modify, or delete your email or access your inbox. -
Google Calendar —
calendar.events: used to create, view, and update calendar events at your request. -
Google Drive —
drive.file: used to access only the specific files you select through the Google file picker (for example, when you import a document into your workspace knowledge base). Agently cannot access any other files in your Drive.
Our handling of Google user data is further limited as follows, notwithstanding anything else in this Privacy Notice:
-
We use Google user data only to provide and improve the user-facing features described above, at your direction.
-
We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
-
We do not use Google user data for advertising, and we do not sell it.
-
We transfer Google user data to third parties only as necessary to provide these features (for example, to our hosting and infrastructure providers), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to you.
-
Humans do not read Google user data unless (a) you have given affirmative agreement, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
-
Google user data is encrypted in transit. You can disconnect a Google integration at any time from your workspace settings, which revokes Agently's access; you can also revoke access from your Google Account permissions page. Upon disconnection or account deletion, associated Google user data is deleted in accordance with the Data Retention section below.
AI processing of Google user data
Agently's features are powered by third-party AI model providers. Where Google user data is processed by these providers, it is processed solely to deliver the user-requested features described above, via each provider's commercial API:
-
Anthropic (Claude API) — powers the AI assistant. Content you ask the assistant to work with (for example, calendar events it retrieves at your request, or documents you imported from Google Drive into your knowledge base) may be included in requests to the Claude API. Under Anthropic's Commercial Terms of Service, Anthropic does not train its models on this data.
-
OpenAI (API Platform) — powers document indexing (entity extraction and embeddings) for the workspace knowledge base and voice synthesis. Content you import from Google Drive is processed through the OpenAI API for indexing. Under OpenAI's API terms, OpenAI does not use API inputs or outputs to train its models.
We integrate with these providers directly through their APIs — no AI aggregators, gateways, or model hubs are used. Neither provider uses Google user data transmitted by Agently to create, train, or improve generalized AI/ML models, and Agently does not use Google user data to train any model of its own.
Retention and deletion of Google user data
-
Gmail — Agently is send-only and does not access or store your mailbox. Emails you send through Agently are recorded in your workspace activity history.
-
Google Calendar — event details are processed when you ask the assistant to work with your calendar and may be recorded in your workspace conversation and activity history.
-
Google Drive — files you choose to import are stored in your workspace knowledge base. You can delete any imported item at any time from within your workspace, which removes it from our systems.
-
Disconnection — disconnecting a Google integration immediately revokes Agently's access tokens and stops all further data flow from your Google account.
-
Deletion — notwithstanding the general retention terms in the Data Retention section below, Google user data is deleted within thirty (30) days of account deletion or of a verified deletion request sent to [email protected], except where longer retention is required by law. Residual copies in encrypted backups are purged within ninety (90) days.
Agently's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Protect Your Information
We protect personal information — including sensitive data such as Google user data — with the following mechanisms:
-
Encryption in transit — all data transmitted between your browser, our services, and third-party APIs (including Google APIs) is encrypted using TLS (HTTPS).
-
Encryption at rest — personal information stored in our databases and file storage is encrypted at rest with industry-standard encryption (AES-256) by our cloud infrastructure providers.
-
OAuth token protection — Google OAuth access and refresh tokens are stored in a dedicated, encrypted credential vault operated by our OAuth infrastructure provider — never in our application database. Tokens are scoped to the minimum permissions described in the Google User Data section and are revoked immediately when you disconnect an integration.
-
Access controls and tenant isolation — every workspace is isolated at the data layer; members can only access data belonging to workspaces they have been invited to. Internal access to production systems is restricted to authorized personnel on a least-privilege, need-to-know basis.
-
Authentication — user authentication is handled by our identity provider using industry-standard credential hashing; Agently never stores plaintext passwords.
-
Auditability — every action the AI assistant performs through a connected integration (including every email sent and calendar event created) is written to an audit log attributable to the initiating user.
-
Monitoring — we operate continuous error and security monitoring across our services.
-
Incident response — in the event of a security incident affecting personal information, we will notify affected users and applicable authorities without undue delay, as required by applicable law.
5. Data Retention
We retain personal information for the duration of your account and for up to twelve (12) months after account deletion, unless a longer retention period is required by law or necessary for security, dispute resolution, enforcement, or compliance purposes. Data may persist in backups and logs until overwritten in accordance with our retention policies.
6. Sharing of Your Information
We may share personal information with:
-
Service providers performing services on our behalf
-
Payment processors
-
Affiliates, successors, or acquirers in connection with a merger, acquisition, financing, restructuring, or sale of assets
-
Regulatory authorities, courts, or law enforcement where required or permitted by law
-
Other parties with your consent
We may also share aggregated, anonymized, or de-identified information that does not reasonably identify you.
Agently does not sell personal information.
7. Third-Party Tracking and Analytics
We may use analytics tools (such as Google Analytics and Mixpanel) to understand usage and improve the Service. These providers may collect information through Cookies or similar technologies under their own privacy policies.
Opting out of analytics or interest-based advertising does not eliminate all tracking or all advertisements. Agently is not responsible for third-party opt-out mechanisms or representations.
Email Communications
We send emails to account holders, including service and account notices (such as billing and security messages), product updates, and occasional feedback requests. Emails are delivered through our email service provider (Resend), which processes recipient addresses and delivery metadata on our behalf.
Some of our emails contain open and click tracking (a small tracking pixel and instrumented links) that tells us whether an email was opened or a link was clicked, along with related technical metadata. We use this information to measure whether our communications are useful and to maintain deliverability.
Every promotional or update email includes an unsubscribe link; opting out stops these emails (and their associated tracking). Service-related communications — billing, security, and operational notices — cannot be opted out of while you hold an account.
8. Control Over Your Information
You may request access to, correction of, or deletion of your personal information by contacting us at [email protected]. We may deny or limit requests where permitted by law, including to protect security, comply with legal obligations, or retain necessary records.
You may opt out of promotional communications, but service-related communications (such as billing, security, or operational notices) cannot be opted out of.
9. Children’s Privacy
The Service is not directed to children under the age of 13. Agently does not knowingly collect personal information from children under 13 and will delete such information if discovered.
10. Links to Third-Party Services
The Service may contain links to third-party websites or services. Agently is not responsible for their content, security, or privacy practices.
11. Region-Specific Rights
Depending on your jurisdiction, you may have additional rights under applicable data protection laws. Requests will be handled in accordance with applicable law and may require identity verification.
12. Changes to This Privacy Notice
We may update this Privacy Notice at any time. Changes are effective upon posting unless otherwise stated. Continued use of the Service constitutes acceptance of the revised Privacy Notice.
13. Contact Us
If you have any questions about this Privacy Notice or our privacy practices, contact us at:
Agently, Inc.