Skip to content

Privacy Policy

Last updated: 2026-08-05

What we collect

  • Email address: when you sign in. Used for authentication and account-related emails.
  • Optional product-update preference: only when you actively tick the separate sign-in checkbox or enable it in Account. We use it for occasional Agenstry product and research emails; every message includes one-click unsubscribe.
  • Session cookies: to keep you logged in. Server-side, signed, HttpOnly, Secure (in production).
  • API key usage logs: count of API calls per key, last-used timestamp. Used for rate limiting and billing.
  • Billing data: handled by Stripe; we store only the Stripe customer ID and subscription status, never card details.
  • Server logs: IP, user-agent, path. Used for debugging + abuse prevention. Auto-deleted after 30 days.
  • Advertising measurement: the Google tag measures campaign visits and four product milestones (sign-up, starting an agent claim, creating a first API key, starting checkout) using Consent Mode v2. Advertising cookies are used only after you grant Marketing consent. No personal data is sent with a conversion: each one carries a currency, a zero-or-purchase value, and a salted one-way hash used purely to deduplicate repeat fires. We do not send your email address, your account ID, or any other identifier to Google — enhanced conversions are switched off.
  • First-touch acquisition data: after you grant Analytics consent, we store bounded campaign labels, the first landing path, and a non-reversible HMAC hash of a Google or Microsoft advertising click ID in a signed 30-day first-party cookie. Raw advertising click IDs are not retained. These fields are copied to a newly created account for internal campaign-to-signup measurement.

What we don't do

  • No third-party product-behaviour analytics and no advertising storage or personalized advertising without explicit Marketing consent.
  • No selling of data, ever.
  • No training of AI models on your data or queries.

Third parties

  • Stripe: payment processing (PCI DSS Level 1, GDPR-compliant DPA)
  • Resend: transactional email delivery (US-based, EU SCC in place)
  • Sentry (optional): error tracking
  • Google Ireland: consent-controlled Google Ads conversion measurement and attribution
  • Fly.io: hosting (EU-hosted by default)

Public agent data

We index publicly-published /.well-known/agent-card.json endpoints. If you operate an agent and want it removed from our index, email hello@agenstry.com or block our crawler via robots.txt (User-agent: AgenstryBot).

Your rights

Under GDPR you can request export or deletion of your account data at any time. Email hello@agenstry.com and we respond within 30 days.

Contact

Agenstry · hello@agenstry.com