Privacy
Last updated: July 25, 2026
Who Operates AgentScape
AgentScape is the operator of the AgentScape service. This notice explains the information processed when you browse the public directory, create an account or company workspace, publish an agent, connect a device or provider, or run a governed workflow.
Information We Process
- Account identity, email-verification state, authentication events, MFA enrollment state, and workspace memberships.
- Agent listings, publisher information, reviews, policy decisions, installations, tool grants, budgets, and run metadata.
- Device identifiers, connection health, security denials, audit events, and operational diagnostics.
- Information you intentionally send to an agent or connected provider while using a governed workflow.
- Billing contact details, plan and subscription status, Stripe customer/subscription identifiers, invoices, credits, measured usage, and payment outcomes.
Credentials And Connected Services
When you choose to connect a supported service, AgentScape may store an encrypted OAuth refresh token, model-provider API key, or connector client secret. These credentials are encrypted with purpose-specific, versioned keys and are decrypted only for an authorized operation. AgentScape does not place provider credentials in public listings or browser assets.
For Slack, a company administrator installs the workspace app once and each member separately links a personal Slack identity. Personal searches and reads use that member's user-scoped token; the shared bot token is stored separately for approved app actions. Disconnecting a personal link does not silently uninstall the company app.
Payments And Usage Metering
Stripe processes checkout, payment methods, invoices, subscription changes, refunds, disputes, and related fraud-prevention information. AgentScape receives provider identifiers and payment status but does not store full card numbers. For managed processing, AgentScape stores immutable usage and rate-card records and sends Stripe an idempotent meter event containing the Stripe customer identifier, a non-secret event identifier, timestamp, and settled retail usage quantity. Prompts and agent outputs are not included in Stripe meter events.
How We Use Information
Information is used to provide the directory and workspace controls, authenticate users and devices, enforce permissions and budgets, investigate abuse, deliver requested integrations, recover from failures, and maintain a tamper-evident administrative record.
Public Information
Public agent pages expose approved listing metadata such as purpose, capabilities, allowed uses, prohibited uses, risk tier, data classes, publisher details, and trust signals. Private workspace data, contact email addresses, and credentials are not part of public listing responses.
Analytics And Local Storage
Optional PostHog pageview analytics run only after consent. Automatic interaction capture and session replay are disabled, analytics use memory-only persistence, and pageview URLs exclude query strings so invitation codes, password-reset tokens, and connector state are never included. The consent choice is stored locally in your browser. AgentScape does not use analytics for targeted advertising or sell personal information.
Service Providers
AgentScape uses infrastructure and delivery providers such as Vercel, Neon, Cloudflare, PostHog, Resend, and Stripe. Google, Slack, and selected model providers process information only when you connect or invoke those services. Each provider processes data under its own terms and privacy commitments.
Retention And Deletion
Operational events are normally retained for 90 days and health probes for 30 days. Expired OAuth state is removed automatically. Administrative audit events are retained for integrity and security review. Billing ledgers, meter-delivery records, invoices, payment outcomes, and related audit evidence may be retained longer for accounting, dispute, fraud-prevention, tax, and legal obligations. Account and workspace data remain until deletion is requested or required, subject to those needs and backup cycles.
Your Choices
You can decline optional analytics, disconnect supported connectors, rotate or remove runtime credentials, update account information, and request account deletion through the product. For access, correction, deletion, or privacy questions, contact the privacy contact shown after production configuration is complete.
Security Reports
Report a suspected vulnerability to the configured security contact. Do not include live credentials or unnecessary personal information in the initial report.