Privacy Policy
Last updated: 2026-08-05
What we collect
- Email address: when you sign in. Used for authentication and account-related emails.
- Optional product-update preference: only when you actively tick the separate sign-in checkbox or enable it in Account. We use it for occasional Agenstry product and research emails; every message includes one-click unsubscribe.
- Session cookies: to keep you logged in. Server-side, signed, HttpOnly, Secure (in production).
- API key usage logs: count of API calls per key, last-used timestamp. Used for rate limiting and billing.
- Billing data: handled by Stripe; we store only the Stripe customer ID and subscription status, never card details.
- Server logs: IP, user-agent, path. Used for debugging + abuse prevention. Auto-deleted after 30 days.
- Advertising measurement: the Google tag measures campaign visits and four product milestones (sign-up, starting an agent claim, creating a first API key, starting checkout) using Consent Mode v2. Advertising cookies are used only after you grant Marketing consent. No personal data is sent with a conversion: each one carries a currency, a zero-or-purchase value, and a salted one-way hash used purely to deduplicate repeat fires. We do not send your email address, your account ID, or any other identifier to Google — enhanced conversions are switched off.
- First-touch acquisition data: after you grant Analytics consent, we store bounded campaign labels, the first landing path, and a non-reversible HMAC hash of a Google or Microsoft advertising click ID in a signed 30-day first-party cookie. Raw advertising click IDs are not retained. These fields are copied to a newly created account for internal campaign-to-signup measurement.
What we don't do
- No third-party product-behaviour analytics and no advertising storage or personalized advertising without explicit Marketing consent.
- No selling of data, ever.
- No training of AI models on your data or queries.
Third parties
- Stripe: payment processing (PCI DSS Level 1, GDPR-compliant DPA)
- Resend: transactional email delivery (US-based, EU SCC in place)
- Sentry (optional): error tracking
- Google Ireland: consent-controlled Google Ads conversion measurement and attribution
- Fly.io: hosting (EU-hosted by default)
Public agent data
We index publicly-published /.well-known/agent-card.json endpoints. If you operate
an agent and want it removed from our index, email hello@agenstry.com
or block our crawler via robots.txt (User-agent: AgenstryBot).
Your rights
Under GDPR you can request export or deletion of your account data at any time. Email hello@agenstry.com and we respond within 30 days.
Contact
Agenstry · hello@agenstry.com