Legal
Privacy Policy
Published August 13, 2026 · effective September 12, 2026
1. Scope
This policy explains what personal data AgentSky (agentsky.dev, the app, APIs, and CLI — together, the “Service”) collects, why, how long we keep it, and who we share it with. It applies to everyone who visits our site, runs an agent, or reaches an agent through a channel we operate.
Our Terms of Service govern the contract; this policy describes the practice. Where the Terms grant us a license over your Content, the setting that controls it is described in section 4 below and in section 7 of the Terms.
2. What we collect
Account data — name, email, organization, and authentication identifiers from the identity provider you sign in with.
Billing data — plan, credit balance, usage counts, invoices, and the payment identifiers our payment processor returns to us. We never receive or store your full card number.
Content — the prompts, files, connector data, and agent configuration you provide (“Input”), and the output, logs, and execution traces your agents produce (“Output”). Content routinely contains whatever you put in front of an agent, including source code and data pulled through connectors.
Connector data — the data an agent reads or writes through a connector you authorize, for the duration of the request. Connector access tokens are held by our managed OAuth broker, not stored by AgentSky.
Device and usage data — IP address, browser and operating system, pages viewed, and requests made, collected through our servers and through analytics cookies.
Support and correspondence — what you send us by email or through support channels.
3. How we use it
To provide the Service: authenticate you, run and recover your agents, route requests to models and connectors, deliver messages over your channels, and show you your workspace.
To bill you: meter usage, charge your balance, and produce invoices.
To keep the Service safe: detect abuse, fraud, and attacks, enforce our Terms, and debug failures.
To comply with law and to establish, exercise, or defend legal claims.
To correspond with you about the Service, and — if you have agreed to it — about our products.
To develop, evaluate, and improve the Service and the harnesses and models we route to. This use applies only to Content covered by the trace contribution setting described next.
4. The settings that control your Content
Storing your Content and using your Content are separate, and each has its own setting in your Workspace. You choose the value of each; we do not decide it for you, and the current value is always shown there. Section 7 of the Terms states the license each setting grants.
Trace history — when enabled, we store your Content so we can display it back to you: session history, replay, and debugging for you and your Workspace members. We do not use Content stored under this setting for anything else, and we do not access it except as necessary to operate, secure, or troubleshoot the Service, or as required by law.
Processing-related storage — regardless of your settings, we hold Content for as long as needed to execute a request. We do not access it except as necessary to operate, secure, or troubleshoot the Service, or as required by law.
Trace contribution — off by default. When you enable it, we may use Content you submit afterwards to operate, evaluate, and improve the Service and the harnesses and models we route to, publish results such as harness and model comparisons on our Arena and leaderboards, and license or sell that Content in anonymized form. Before doing so, we take reasonable measures designed to remove direct and indirect identifiers and prevent the Content from being associated with you or your account. We maintain it in de-identified form and do not attempt to re-identify it. Turning the setting off ends this use for Content you submit afterwards; it does not withdraw results already published or licensed in anonymized form.
Categorization of Inputs — we categorize Inputs in anonymized form to track and share usage metrics. Unless trace contribution is enabled, Inputs are not retained or associated with you or your account after categorization.
Provider training routing — some model providers store or train on what is sent to them. Your Workspace carries separate settings for paid and free models controlling whether we may route your requests to providers that do not offer a training opt-out. Where a provider offers an opt-out, we take it.
Zero Data Retention — available to Enterprise Workspaces under an enterprise agreement. Content is held only for as long as needed to route and execute the request and is not written to durable storage by AgentSky; trace history and trace contribution do not apply. Where the model provider offers Zero Data Retention, we pass that option through. Write to support@agentsky.dev for an enterprise agreement or a data processing addendum.
AgentSky does not use your Inputs or Outputs to train models.
5. Model providers
Running an agent sends your Content to the model provider you selected. Those providers process what they receive under their own terms, and their own retention and training practices apply. We describe each provider's practice accurately to the best of our knowledge and update it as they change.
The model picker identifies the provider that will receive your Content. Because provider practices change independently of AgentSky, review that provider's current data policy before selecting it.
If you do not want your Content sent to a provider that retains it, leave provider training routing off and choose a model whose provider commits to zero retention, or use an Enterprise Workspace.
6. Who else receives data
Service providers who process data on our behalf under contract: cloud hosting and sandbox infrastructure, our identity provider, our payment processor, error monitoring, analytics, and email delivery. They may use the data only to provide their service to us.
Platforms you connect. When you attach a connector or a channel, data flows to that platform at your direction and under its terms.
Legal and safety recipients, where we are required by law or where disclosure is necessary to protect rights, safety, or the integrity of the Service.
A successor, if we are involved in a merger, acquisition, or sale of assets. We will give notice before your data becomes subject to a different privacy policy.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
7. How long we keep it
Agent runtime and stored state — until you delete the agent, then purged within 30 days from active systems and 90 days from backups.
Trace history, when the setting is on — until you delete the session or the agent, subject to the same purge windows.
Content covered by trace contribution — up to 24 months, so that harness and model comparisons remain valid over time. Anonymized, aggregated results derived from it may be kept indefinitely.
Request, security, and abuse logs — ordinarily 30 days, longer where an investigation or legal obligation requires it.
Account data — for the life of the account, then purged within 30 days of deletion.
Billing records — for as long as tax, accounting, and payment-dispute obligations require, generally up to seven years.
Content under Zero Data Retention — not written to durable storage; held only for the duration of the request.
8. Security
Agents run in isolated, managed sandboxes. Data is encrypted in transit and at rest, access to production systems is limited to the people who need it and is logged, and connector tokens are held by our managed OAuth broker rather than in our application database.
No system is perfectly secure. Do not put credentials or secrets into a prompt; use a connector or a secret reference instead.
9. Your rights
You can access your agents' stored state through the Service, delete an agent, and change the settings in section 4 at any time. To export your account data, correct account details that you cannot edit, or delete your whole account, write to support@agentsky.dev.
Depending on where you live, you may also have the right to request a copy of your personal data, ask us to correct or delete it, object to or restrict a use, withdraw consent, and complain to a supervisory authority. We will not treat you differently for exercising a right.
To make a request, write to support@agentsky.dev from the address on your account. We respond within the period the applicable law requires, and we may need to verify your identity first.
10. International transfers
We operate from the United States, and our infrastructure and model providers may process data in the United States and other countries. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, write to support@agentsky.dev and we will delete it.
12. Changes to this policy
We may update this policy. Material changes will be announced through the Service or by email before they take effect. A change that would widen how we use Content applies only to Content you submit after the change takes effect; we do not apply a new use retroactively.
13. Contact
Questions, requests, or complaints about privacy: support@agentsky.dev.