Privacy Policy
Last updated: 2 October 2026
This Privacy Notice explains how Agently, Inc. ("Agently", "we", "us") collects, uses, shares and protects personal information when you visit agently.dev, use the Agently web app, the Agently Mac app, Jarvis (including in Slack and by voice) and our MCP server (together, the "Service"), and the rights you have over that information.
1. Who Is Responsible for Your Information
Agently as controller. Agently is the controller of the personal information we collect to run our business: your account details, billing records, support conversations, website visits, sign-ups and newsletter subscriptions, and how you use the Service.
Agently as processor. When a company uses Agently, the content its members put into or connect to their workspace (files, pages, messages, knowledge, tasks, conversations and data synced from connected tools) is processed by Agently on behalf of that company, which is the controller. That processing is governed by our agreement with the company, including our Data Processing Addendum. If your information is in a workspace that belongs to someone else (for example, you are a colleague, customer or contact of an Agently customer), please contact that company first; we will help them answer your request.
2. Information We Collect
-
Account information: name, surname, email address, job title, avatar, language and voice preferences, and authentication identifiers when you create an account, including when you sign up through a third-party identity provider such as Google.
-
Workspace content: files, documents, pages, messages, knowledge, tasks, conversations with Jarvis, notes and other content that you or your team upload to or create in the Service, and data from third-party tools you choose to connect to your workspace.
-
Contact book and people directory: names, email addresses and how often you deal with people, learned from the mail, calendar, Slack and Linear accounts you connect, and people you or your colleagues add to your company profile. A member's contact book is private to that member.
-
Google user data: if you connect a Google integration, the limited data described in the Google User Data section below.
-
Voice: when you talk to Jarvis, the text of your spoken requests. See the Voice section below for how audio is handled.
-
Payment information: billing details processed by our payment processor, Stripe. We do not store full payment card numbers on our servers.
-
Usage and device information: interactions with the Service, log data, IP address, browser and device type, and information collected through cookies or similar technologies (see our Cookie Policy).
-
Support and communications: information you provide when you contact support or report a problem, which can include a description, technical diagnostics from your browser, a screenshot you choose to attach, and the conversation the report is about.
-
Website sign-ups: your email address and, if you give them, your name, company and answers to our short questionnaire, along with the campaign link that brought you to our site.
Workspace content may include personal data relating to third parties where you upload it or sync it from a source you connect, for example the names and contact details of colleagues, customers or prospects appearing in documents, messages or CRM records. You are responsible for ensuring you have a lawful basis to place that content in the Service and to disclose it to any AI assistant you connect.
3. How We Use Personal Information and Our Legal Bases
If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, we rely on the following legal bases:
| What we do | Legal basis |
|---|---|
| Create and manage your account, provide the Service, run Jarvis, agents, routines and automations at your request, and provide support | Performance of our contract with you or your company |
| Process payments and manage subscriptions | Performance of our contract |
| Keep billing and tax records | Compliance with legal obligations |
| Send service, billing and security notices | Performance of our contract |
| Send product updates and occasional feedback requests to account holders | Legitimate interests (keeping customers informed); you can unsubscribe at any time |
| Send our newsletter and early-access emails to people who signed up for them | Consent |
| Measure use of our website and app with analytics cookies (Google Analytics, Mixpanel in the browser) | Consent, given through our cookie banner |
| Record product events on our servers (for example, that an account or workspace was created) and keep an analytics profile with your name and email address in Mixpanel | Legitimate interests (understanding and improving the Service); you can object at any time |
| Keep the Service secure, prevent fraud and abuse, debug problems and keep logs | Legitimate interests (protecting our users and the Service) |
| Respond to legal requests and enforce our Terms | Compliance with legal obligations, and legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and expectations. Where we rely on consent, you can withdraw it at any time without affecting processing before you withdrew.
We do not sell personal information, and we do not use it for advertising.
4. AI Processing and Model Training
Agently's features are powered by third-party AI model providers. Content you ask Jarvis or an agent to work with is sent to the model provider that handles the request, through that provider's commercial API.
-
We do not train AI models on your content or your personal information.
-
Anthropic and OpenAI process requests through their business APIs. Under their commercial terms, they do not use data sent through these APIs to train their models by default.
-
Your own AI plan. In the Agently Mac app, a member can choose to run chats on their own Claude or ChatGPT plan. Those requests go to that provider under the member's own account, and that provider's terms and settings apply, including its settings on model training.
-
Your Mac. If you let Jarvis use your Mac (for example to look at your screen, an app or a file), what it needs to see, such as a screenshot, is sent to the AI model to complete the task. Steps that look sensitive ask for your approval first.
-
Custom connectors. If you add a remote MCP server to your workspace, Agently sends it the requests your agents make to it, at your direction, under that server operator's terms.
5. Voice
-
Mac app wake word: the Mac app listens for "Hey Jarvis" using Apple's on-device speech recognition. That listening happens on your Mac; the audio does not leave your device.
-
Live voice: when you talk with Jarvis in real time, your audio is streamed to OpenAI's real-time voice API so it can understand and answer you. Agently does not store the audio, and we ask OpenAI not to store the session.
-
Voice requests: the text of a request you hand to Jarvis by voice, and its result, are kept for 30 days and then deleted automatically.
6. Google User Data
Agently offers optional integrations with Google services (Gmail, Google Calendar, and Google Drive) through Google's OAuth 2.0 consent flow. If you choose to connect a Google account, Agently requests only the following limited scopes:
-
Gmail (
gmail.send): used solely to send emails that you or your AI agents compose and that you initiate or approve from within Agently. Agently cannot read, modify, or delete your email or access your inbox. -
Google Calendar (
calendar.events): used to create, view, and update calendar events at your request. -
Google Drive (
drive.file): used to access only the specific files you select through the Google file picker (for example, when you import a document into your workspace knowledge base). Agently cannot access any other files in your Drive.
Our handling of Google user data is further limited as follows, notwithstanding anything else in this Privacy Notice:
-
We use Google user data only to provide and improve the user-facing features described above, at your direction.
-
We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
-
We do not use Google user data for advertising, and we do not sell it.
-
We transfer Google user data to third parties only as necessary to provide these features (for example, to our hosting and infrastructure providers), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to you.
-
Humans do not read Google user data unless (a) you have given affirmative agreement, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
-
Google user data is encrypted in transit. You can disconnect a Google integration at any time from your workspace settings, which revokes Agently's access; you can also revoke access from your Google Account permissions page. Upon disconnection or account deletion, associated Google user data is deleted in accordance with the retention terms below.
AI processing of Google user data
Where Google user data is processed by our AI model providers, it is processed solely to deliver the user-requested features described above, via each provider's commercial API:
-
Anthropic (Claude API): powers the AI assistant. Content you ask the assistant to work with (for example, calendar events it retrieves at your request, or documents you imported from Google Drive into your knowledge base) may be included in requests to the Claude API. Under Anthropic's Commercial Terms of Service, Anthropic does not train its models on this data.
-
OpenAI (API Platform): powers document indexing (embeddings) for the workspace knowledge base, short summaries, and voice. Content you import from Google Drive is processed through the OpenAI API for indexing. Under OpenAI's API terms, OpenAI does not use API inputs or outputs to train its models.
We integrate with these providers directly through their APIs. No AI aggregators, gateways, or model hubs are used for Google user data. Neither provider uses Google user data transmitted by Agently to create, train, or improve generalized AI/ML models, and Agently does not use Google user data to train any model of its own.
Retention and deletion of Google user data
-
Gmail: Agently is send-only and does not access or store your mailbox. Emails you send through Agently are recorded in your workspace activity history.
-
Google Calendar: event details are processed when you ask the assistant to work with your calendar and may be recorded in your workspace conversation and activity history.
-
Google Drive: files you choose to import are stored in your workspace knowledge base. You can delete any imported item at any time from within your workspace, which removes it from our systems.
-
Disconnection: disconnecting a Google integration immediately revokes Agently's access tokens and stops all further data flow from your Google account.
-
Deletion: Google user data is deleted within thirty (30) days of account deletion or of a verified deletion request sent to support@agently.dev, except where longer retention is required by law. Residual copies in encrypted backups are purged within ninety (90) days.
Agently's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Connected AI Assistants (MCP)
Agently publishes a Model Context Protocol ("MCP") server that lets an AI assistant you already use (such as ChatGPT, Claude, or an AI-enabled code editor) read from, and if you permit it write to, your workspace's company brain. This connection does not exist until you create it, and it remains scoped to the single workspace tied to the credential you issue.
How the connection is authorized
You begin it by minting a workspace API key in Agently (Settings → API keys), or by completing an OAuth authorization from the assistant. Each key is bound to one workspace, carries either read-only or read-and-write permission, and can be revoked by you at any time. Revoking a key ends that assistant's access immediately.
What leaves Agently
When your assistant calls a tool on this server, we return content drawn from your workspace's brain. Depending on the request and on what you have added to that workspace, a response may include:
-
passages and summaries from saved files and indexed document sources
-
shared workspace and agent notes, with their paths, revisions and categories
-
source attribution describing where a fact came from (for example, "Synced from Slack #sales, 2026-08-03"), together with short excerpts of the underlying source content, which may include the names of people, including individuals who are not Agently users, where they appear in that content
-
identifiers used to navigate between related entries, and the identifier of an item saved through the write tool so that it can later be retracted
-
skills from the Agently marketplace: the instructions of skills approved for the public marketplace or authored in your workspace, together with the creator's display name, job title, workspace name, install count and use count. Publishing a skill to the marketplace makes that attribution visible to every workspace that fetches it.
We do not send private memory notes, your Agently chat history, your credentials, your billing details, or content belonging to any workspace other than the one the credential is bound to.
Who receives it, and under whose terms
The recipient is the operator of the assistant you connected, for example OpenAI in the case of ChatGPT or Anthropic in the case of Claude, along with the infrastructure that assistant runs on. Once a response reaches that assistant, that provider's own privacy policy and retention terms govern what happens to it, including whether it is retained or used to improve their models. Agently cannot control or retrieve data after it has been delivered to a client you authorized. Please review your assistant provider's terms before connecting a workspace that holds sensitive material.
Writes and reviewed captures
If you issue a key with write permission, the assistant can save new content into your brain when you ask it to. Content saved this way is treated exactly as content you add in the app and is subject to this Privacy Notice in full. The assistant can also retract an item it saved.
Your assistant can also prepare a proposed "Save to Brain" card. The draft is returned to the assistant and is not stored by Agently until you choose to save it. A saved capture includes the content you approved, any source links, the capture time and the sharer's name, and is visible to the workspace.
What we record about these calls
For metering and billing we store, for each call: the workspace, the name of the tool invoked, an identifier for the API key used, the name of the connecting client, and the time of the call. We do not store the text of your queries, the assistant's messages, or the content of the responses we return. These records are kept as described in Data Retention below.
Your controls
You may revoke any API key at any time; issue read-only keys so that no assistant can write to your brain; delete individual items from your brain; disconnect a synced source to stop new content flowing in; or delete the workspace.
8. Cookies and Analytics
We use cookies and similar technologies that are necessary to run the website and app (for example, to keep you signed in and to remember your cookie choice). We also use Google Analytics on our website and app, and Mixpanel in our app, to understand how they are used, and we ask for your consent before using them.
On agently.dev, analytics do not load until you choose Accept all in our cookie banner, and you can change your choice at any time from the Cookie settings link in the footer. The Agently app is moving to the same banner and the same saved choice; once it is live there, you can also change it in Settings → Privacy. Our Cookie Policy lists each cookie and how long it lasts.
Separately from cookies, our servers record a small number of product events (such as an account or workspace being created) in Mixpanel, linked to your account, on the basis of our legitimate interests. You can object to this by contacting us.
Email communications
We send emails to account holders, including service and account notices (such as billing and security messages), product updates, and occasional feedback requests. Emails are delivered through our email service provider (Resend), which processes recipient addresses and delivery metadata on our behalf.
Some of our emails contain open and click tracking (a small tracking pixel and instrumented links) that tells us whether an email was opened or a link was clicked, along with related technical metadata. We use this information to measure whether our communications are useful and to maintain deliverability.
Every promotional or update email includes an unsubscribe link; opting out stops these emails (and their associated tracking). Service-related communications (billing, security, and operational notices) cannot be opted out of while you hold an account.
9. Who We Share Information With
We share personal information only as needed to run the Service:
-
Service providers (subprocessors) that host, power or support the Service on our behalf, such as our cloud hosting, database, AI model, email, payment and analytics providers. They may use the information only to provide their services to us. The current list, with what each one does and where, is on our Subprocessors page.
-
Integrations you connect: when you or your team connect a tool such as Slack, Gmail, Outlook, Notion or a CRM, Agently exchanges data with that tool at your direction. Those tools act under your own agreements with them.
-
AI assistants you connect: where you authorize an external AI assistant to reach your workspace through our MCP server, we disclose workspace content to the operator of that assistant, at your direction (see section 7).
-
Your workspace: content you share in a workspace is visible to its other members according to the workspace's settings.
-
Affiliates, successors, or acquirers in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to this Privacy Notice.
-
Regulatory authorities, courts, or law enforcement where required by law.
-
Other parties with your consent.
We may also share aggregated or de-identified statistics that do not identify you.
10. International Transfers
Agently, Inc. is a United States company, and the Service is hosted in the United States. Members of our team may also access information from the countries where they work, including Canada. If you are in the EEA, the United Kingdom or Switzerland, your personal information is transferred to and processed in the United States, which does not have an adequacy decision covering all recipients.
We protect these transfers with the European Commission's Standard Contractual Clauses (together with the UK International Data Transfer Addendum and the Swiss adjustments), which are built into our Data Processing Addendum for customers and into the data processing terms of our providers, and, where a provider is certified, the EU-US Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of the relevant safeguards by emailing support@agently.dev.
11. Data Retention
We keep personal information only as long as we need it:
-
Your account and workspace content: for as long as your account and workspace exist. You can delete individual items, conversations and pages at any time. Nothing in your workspace is deleted automatically while your account is active, except the items listed below.
-
After you delete your account or workspace, or after we confirm a deletion request: we delete the associated personal information, including copies held by our service providers, within 30 days. Encrypted database backups are overwritten on a rolling basis and no longer contain it after a further 30 days.
-
Billing records: for as long as tax and accounting laws require, even after your account is deleted.
-
Voice requests: 30 days, then deleted automatically.
-
Data exports: if you download a copy of your data, the export file is deleted after 7 days.
-
Website sign-ups and newsletter subscriptions: until you unsubscribe or ask us to delete them.
-
Support requests: while your account exists, or until you ask us to delete them.
-
Analytics: Google Analytics keeps data for the retention period set in our account, no longer than 14 months. Your Mixpanel profile and events are kept until your account is deleted.
-
Operational logs: kept by our hosting provider for a limited period for security and debugging, then deleted.
We may keep information for longer where the law requires it, or where it is needed to establish, exercise or defend a legal claim.
12. How We Protect Your Information
-
Encryption in transit: all data transmitted between your browser, our services, and third-party APIs is encrypted using TLS (HTTPS).
-
Encryption at rest: personal information stored in our databases and file storage is encrypted at rest with industry-standard encryption (AES-256) by our cloud infrastructure providers.
-
OAuth token protection: access and refresh tokens for the integrations you connect are stored in a dedicated, encrypted credential vault operated by our OAuth infrastructure provider, not in our application database. Credentials for custom connectors (remote MCP servers) you add are encrypted with AES-256 before we store them. Tokens are revoked when you disconnect an integration.
-
Hashed keys: workspace API keys and MCP access tokens are stored only as one-way hashes.
-
Access controls and tenant isolation: every workspace is isolated at the data layer; members can only access data belonging to workspaces they have been invited to. Internal access to production systems is restricted to authorized personnel on a least-privilege, need-to-know basis.
-
Authentication: user authentication is handled by our identity provider using industry-standard credential hashing; Agently never stores plaintext passwords.
-
Auditability: every action the AI assistant performs through a connected integration (including every email sent and calendar event created) is written to an audit log attributable to the initiating user.
-
Incident response: if a security incident affects personal information, we will notify affected customers and users, and the relevant supervisory authorities where required, without undue delay and within the time limits set by law.
13. Your Rights
Depending on where you live, and in particular if you are in the EEA, the United Kingdom or Switzerland, you have the right to:
-
Access the personal information we hold about you and get a copy of it
-
Correct information that is inaccurate or incomplete (you can edit your profile in Settings → Profile)
-
Delete your personal information ("right to be forgotten")
-
Restrict how we use your information, for example while we check a request
-
Data portability: receive the information you gave us in a structured, commonly used, machine-readable format, and have it sent to another company where technically possible
-
Object to processing based on our legitimate interests, and to direct marketing at any time
-
Withdraw consent at any time where we rely on it, for example through the cookie settings or the unsubscribe link in our emails
-
Complain to a data protection supervisory authority, in particular in the EEA country where you live or work, or where you believe your rights were infringed. In the United Kingdom, this is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
How to make a request: email support@agently.dev, or use Settings → Privacy in the app where available. We will answer within one month. If a request is complex or we receive many, we may extend this by up to two further months and will tell you why. We may need to verify your identity before acting on a request. Making a request is free unless it is clearly unfounded or excessive.
If your request is about content in a workspace that belongs to a company, we will pass it to that company (the controller) and help them respond.
14. Children's Privacy
The Service is intended for business use by adults. It is not directed to anyone under 16, and we do not knowingly collect personal information from children. If we learn that we have, we will delete it.
15. Links to Third-Party Services
The Service may contain links to third-party websites or services. Agently is not responsible for their content, security, or privacy practices.
16. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. We will post the new version here with a new "Last updated" date, and if a change materially affects how we use your personal information, we will tell account holders by email or in the app before it takes effect.
17. Contact Us
If you have any questions about this Privacy Notice, our privacy practices, or want to exercise your rights, contact us at:
Agently, Inc.