Legal

Privacy Policy

Last updated: July 17, 2026

Agentdoze lets you host AI agents that wake on demand, keep a workspace, and reply across chat channels. Running those agents means we necessarily process the prompts, files, and messages you route through them, and we send that content to the AI models and tools you choose. This policy explains what we collect, why, who we share it with, and the controls you have. Questions? Email contact@agentdoze.com.

1. Who we are

Agentdoze (“Agentdoze”, “we”, “us”, or “our”) is an independent service operated by the agentdoze team, available at agentdoze.com. Agentdoze is currently run as an individual/solo project rather than through an incorporated company; the operator is the person responsible for your personal data — the “data controller” under the EU/UK GDPR, and the responsible “organisation” under Singapore’s Personal Data Protection Act 2012 (“PDPA”). We handle personal data in accordance with the PDPA and, where it applies to you, the GDPR. For any privacy question or request — and as our designated data-protection contact — you can reach us at contact@agentdoze.com.

This policy applies to the Agentdoze website, dashboard (“console”), and gateway API. It does not cover third-party services you connect to Agentdoze (for example your own AI provider, or a Slack or Telegram workspace), which are governed by their own privacy policies.

2. Information we collect

We collect the following categories of data:

  • Account & identity. Your email address, display name, and a securely hashed password (we never store passwords in plain text). If you sign in with Google or GitHub, we receive the basic profile information those providers release — typically your name, email address, and account identifier.
  • Organization membership & governance. Organizations you create or join, your role, invitations, resource creators, spending limits, and redacted security-audit events. Organization owners and administrators can view this governance metadata, but not another member's private Agent content or console conversation transcripts.
  • Agent configuration. The agents you create and their settings: names, compute tier, memory, schedules, prompts, and channel connections.
  • Agent content & workspace. The prompts you send, the files and state your agents keep in their persistent workspace, and the conversation logs (messages and agent replies) exchanged across every channel. This content is stored so your agents can keep context and so you can review history in the console.
  • Credentials you provide. If you bring your own AI provider key (BYOK) or connect a channel, we store the relevant API keys, tokens, and connection secrets so agents can use them. These are held encrypted and used only to operate your agents.
  • Billing & usage. Your credit balance, subscription status, and usage events (such as active compute seconds and built-in model token counts) used for metering and billing. Card payments are handled by our payments provider (see §6); we do not receive or store your full card number.
  • Technical & log data. Standard information generated when you use the service, such as IP address, browser/user-agent, request timestamps, and error and runtime logs used to operate, secure, and debug the platform.

3. How your agents process content (AI models & tools)

Agentdoze is an AI agent host, so operating your agents means sending your content to AI models and tools. Please read this section carefully.

  • AI model providers. When an agent runs, the relevant prompt, workspace context, and message content are transmitted to a large-language-model provider to generate a response. If you use the built-in model, this is served through Volcengine Ark. If you bring your own key, your content is sent to the provider you configured — for example OpenAI, Anthropic, DeepSeek, or a custom endpoint you specify. Your content is subject to that provider’s privacy and data-use terms.
  • Tools & search. If an agent uses web search or similar tools, the relevant query is sent to the configured search provider (such as Brave Search or Tavily) to fulfil the request.
  • Autonomy. Agents can act on schedules and incoming messages without you being present. You are responsible for the prompts, data, and permissions you give an agent, and for reviewing what it produces.

A shared Agent uses one Agent-wide workspace, skills directory, and long-term memory across its members' conversations. Console transcripts remain visible only to the member who created them, but information an Agent writes into shared memory or workspace files may influence later turns by other organization members. Use a private Agent when you need a separate runtime and memory boundary.

4. Connected channels & platforms

You may connect agents to external messaging channels — Slack, Telegram, WhatsApp, email, a web chat widget, or our REST API. When you do, messages sent to or from those channels pass through the relevant platform and are processed by Agentdoze to route the conversation to and from your agent. Your use of each platform is also governed by that platform’s own terms and privacy policy, and you are responsible for having the right to connect it and to process the messages of people who contact your agent there.

5. How we use information & legal bases

We use the data above to:

  • Provide, operate, and maintain the service — creating and running agents, delivering messages, and metering usage;
  • Process payments, manage credits and subscriptions, and prevent abuse of free credits;
  • Secure the platform, detect fraud and abuse, and troubleshoot problems;
  • Respond to your support requests and communicate service-related notices; and
  • Comply with legal, tax, and accounting obligations.

Under the PDPA, we collect, use, and disclose personal data with your consent — including deemed consent, where you voluntarily provide data in order to use a feature — or where permitted without consent under the PDPA’s exceptions (such as its legitimate-interests and business-improvement provisions). Where the GDPR applies, we rely on these legal bases: performance of a contract (to provide the service you sign up for), legitimate interests (to secure, improve, and support the platform), consent (where you connect optional integrations), and legal obligation (for billing and compliance records). We do not sell your personal data, and we do not use your agent content to train our own models.

6. Service providers & subprocessors

We rely on a small set of infrastructure providers to run Agentdoze. They process data only to provide their service to us:

  • Cloudflare — hosting, edge compute, agent container runtime, key/secret storage, and object storage for workspace snapshots.
  • Neon — managed PostgreSQL database (our system of record for accounts, agents, schedules, messages, and usage).
  • Creem — payments and subscription billing, acting as merchant of record for card processing.
  • Volcengine Ark — the built-in AI model provider (used only when you choose the built-in model).
  • Your chosen AI, search, and email providers — e.g. OpenAI, Anthropic, DeepSeek, Brave, Tavily, or an email-sending provider — used to fulfil agent requests you configure.
  • Google and GitHub — only if you choose to sign in with them (OAuth).
  • Messaging platforms — Slack, Telegram, WhatsApp (Meta), and similar, only for channels you connect.

7. International data transfers

Agentdoze runs on globally distributed infrastructure, and the providers listed above may process data in countries other than your own — including, depending on the model and providers you choose, the United States, the European Union, Singapore, and China. Where the PDPA applies, we take reasonable steps so that any recipient outside Singapore is bound to a standard of protection comparable to the PDPA; where the GDPR applies, we rely on appropriate safeguards such as the providers’ standard contractual clauses. By choosing a model or channel provider, you direct us to transfer the relevant content to that provider so your agent can function.

8. Data retention

We keep your account, agent configuration, workspace, message history, and usage records for as long as your account is active, so the service works and you can review history. When you delete an agent or your account, we delete the associated configuration, workspace snapshots, and content within a reasonable period, except where we must retain limited billing, tax, or security records to meet legal obligations or resolve disputes. Backups and logs are rotated on a rolling basis.

If a member leaves or is removed from an organization, shared resources remain with that organization. Private Agents created by that member are sealed and suspended for 30 days so access can be restored if the same account rejoins; after that period they are deleted. Organization billing and security records may remain with the organization after an individual member leaves.

9. Security

We take reasonable technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS), encryption at rest for stored API keys and secrets, scoped access to production systems, and isolation between agent workspaces. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. Keep your account credentials and any API keys confidential, and notify us promptly if you suspect unauthorised access.

If a data breach occurs that results in, or is likely to result in, significant harm to affected individuals or is otherwise notifiable, we will notify Singapore’s Personal Data Protection Commission (PDPC) and affected individuals as required by the PDPA, and comply with equivalent breach-notification duties under the GDPR where they apply.

10. Your rights & choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Under the PDPA, you may request access to and correction of the personal data we hold about you, and you may withdraw any consent you have given (which may mean we can no longer provide parts of the Service). Many of these you can exercise directly in the console — you can edit your profile, delete agents and their data, disconnect channels and keys, and delete your account from Settings. For anything else, or to make a formal request, email contact@agentdoze.com and we will respond within the time required by law. If you are in Singapore, you may also lodge a complaint with the Personal Data Protection Commission (PDPC); if you are in the EEA/UK, with your local data-protection authority.

11. Deleting your data

You can delete individual agents (which removes their workspace and history) or your entire account from the console at any time. Account deletion removes your personal data and agent content from our active systems, subject to the limited legal-retention exceptions noted in §8. If you connected third-party channels or providers, remember to also remove Agentdoze’s access from those platforms.

Deleting your personal account does not delete resources owned by a team organization. You must first leave each team organization or transfer ownership where required. A team organization owner can delete the organization, which removes its Agents, credentials, conversations, and active billing data after external credentials and runtimes have been disabled.

12. Cookies

Agentdoze uses strictly necessary cookies to keep you signed in and to remember basic preferences such as light/dark theme. We do not use third-party advertising or cross-site tracking cookies. Because these cookies are essential to operate the service, disabling them may prevent you from signing in.

13. Children

Agentdoze is not intended for children. You must be at least 16 years old (or the age of digital consent in your country, if higher) to use the service. We do not knowingly collect data from children; if you believe a child has provided us data, contact contact@agentdoze.com and we will delete it.

14. Changes to this policy

We may update this policy as the service evolves or the law changes. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the console or by email. Your continued use of Agentdoze after an update means you accept the revised policy.

15. Contact us

For any questions, requests, or concerns about this Privacy Policy or your data, contact the agentdoze team at contact@agentdoze.com.