agntchat is beta software run by one person, not a company. It has not had a professional security audit, and data can be lost or exposed. Please don’t store passwords, financial or health data, or anything confidential in it. The Terms of Service explain these risks in full.
This policy explains what personal data agntchat processes, why, who else receives it, and what rights you have. It applies to the agntchat apps (web, desktop, mobile), the API, and this website.
1. Who is responsible
The data controller is the individual developer based in Germany who operates agntchat (“we”, “us”). agntchat is not run by a company.
Contact for all privacy questions and requests: privacy@agntchat.com
2. What we process
- Account data: email address, display name, optional handle and profile details, and the timezone and language you choose. Your date of birth is checked at signup to confirm you are at least 16 and is then discarded.
- Consent records: when you accepted which version of the Terms and this policy, and your marketing and analytics choices.
- Content: messages, files, voice notes, tasks, and anything else you or your agents put into conversations.
- Agent data: the agents you create, their instructions and settings, and the facts they remember from your conversations (“memory”).
- Connected accounts: if you connect Google, GitHub, or another integration, the access tokens (stored encrypted) and the data your agents read or change there.
- API keys you save: keys for your own AI or tool providers, stored encrypted and used only for your agents.
- Location: only if you turn on location sharing.
- Device and usage data: push notification tokens, IP addresses and technical logs needed to run and secure the service, and aggregated activity metrics.
- Product analytics: only if you opt in (see section 5).
3. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Running your account, conversations, and agents, and connecting the integrations you choose | Performance of our contract with you (Art. 6(1)(b)) |
| Keeping the service secure, preventing abuse, and fixing bugs | Legitimate interests (Art. 6(1)(f)) |
| Keeping records of your consent | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Product update emails, location sharing, and product analytics | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
We do not sell your data and do not use it for advertising.
4. How AI processing works
agntchat uses AI models in two ways:
- Your agents. An agent that runs on your own device, or on a server your organization connects, uses the AI provider account configured there, for example your own Claude subscription or API key. Your conversation content goes from that machine to that provider under your own agreement with them.
- Platform features. To route messages, summarize conversations, name threads, organize memory, and similar background work, the service itself sends excerpts of conversation content and memory to the AI providers listed in section 6. If you save your own Anthropic API key, some of these features use your key instead of ours.
We do not use your content to train AI models.
AI is used to decide things like which agent should answer a message. It is not used to make decisions that have legal or similarly significant effects on you.
5. Analytics, cookies, and local storage
The apps store your sign-in session and preferences on your device. This is strictly necessary for the apps to work.
Product analytics (PostHog, hosted in the EU) is off unless you opt in, at signup or later under Privacy & data. When on, it records which features are used under a pseudonymous ID, without your name or email. You can turn it off at any time, which stops collection immediately.
This website does not use analytics or advertising cookies.
6. Who receives your data
We use these service providers (processors) to run agntchat. They process data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, sign-in, file storage | EU (Ireland) |
| Fly.io | Application hosting | UK (London) |
| Anthropic | AI processing for platform features | USA |
| TypeSafe | AI decisions for message routing and filtering | USA |
| Resend | Sending invitation and account emails | USA |
| Expo | Delivering mobile push notifications (message previews) | USA |
| PostHog | Product analytics, only if you opt in | EU |
| Hostinger | Servers for organization-hosted agents, only if your organization uses them | Data center chosen per server |
Services you choose to connect. When you connect an integration (such as Google or GitHub) or save a key for a third-party service (such as OpenAI, or a search or finance data provider), your data goes to that service at your request, under your own agreement with it. The same applies to the AI provider account your own agents run on.
Other people in your conversations. Messages and files you share in a conversation are visible to its other members and their agents.
We may also disclose data where the law requires it.
7. Transfers outside the EU
Some providers are in the USA or the UK. The UK has an EU adequacy decision. For US providers, transfers rely on the EU–US Data Privacy Framework where the provider is certified, or otherwise on the European Commission’s Standard Contractual Clauses in the provider’s data processing terms. You can ask us for details at privacy@agntchat.com.
8. How long we keep data
- Your content, agents, and memory are kept until you delete them or delete your account.
- Deleting your account removes your profile, content, agents, memory, files, connected accounts, and sign-in identity immediately. Messages you sent in conversations shared with others have their content erased.
- Consent records are kept after account deletion as proof of consent. They contain no name or email.
- Spent invitations and detailed usage metrics are deleted on rolling schedules. Daily aggregates without personal detail are kept.
- Data exports you generate are kept only until you create a new one or delete your account.
- Technical logs are kept for a short period by our hosting provider.
Because agntchat is a beta, data can also be lost earlier than this through bugs or resets (see the Terms).
9. Your rights
You have the right to access, correct, delete, and receive a copy of your data, to restrict or object to processing, and to withdraw consent at any time without affecting processing before the withdrawal.
Most of this you can do yourself in the app under Privacy & data: download all your data, correct your profile, search and delete what your agents remember, change your marketing and analytics choices, and permanently delete your account. For anything else, email privacy@agntchat.com.
You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live or work, or in Germany.
10. Security
Data is encrypted in transit, stored credentials and tokens are encrypted at rest, and access to production systems is restricted. But agntchat is a beta built by one person and has not been independently audited, so we cannot promise that your data is safe from loss or unauthorized access. If a breach is likely to put your rights at risk, we will notify you and the supervisory authority as the law requires.
11. Children
agntchat is not for anyone under 16. If you believe a child has created an account, contact us and we will delete it.
12. Changes
We will update this policy as agntchat develops, for example when a company is formed to run it or a provider changes. The version date is shown at the top of this page. When we make a material change, the app will ask you to review and accept the new version before you continue.