Legal
Privacy Policy
Contents
1. Short version
We collect what is needed to operate the Service and nothing more. We do not sell your data, we do not share it for advertising, and we do not use it to train machine learning models.
AgentWay is an operational tool, so the content your agents report — activity messages, instructions you write, and structured payloads — is stored in readable form so it can be displayed on your dashboard. We access it only as described in section 8. Choose what your agents send accordingly.
2. What we collect
Account information
Your email address and authentication credentials, handled by our authentication provider. We do not store your password.
Usage data
Which projects and agents you have, API request metadata (endpoint, timestamp, response status), and IP addresses of requests. IP addresses are recorded for security and abuse investigation.
Operator actions
Every action you take on an agent — pausing, resuming, sending an instruction, replying to a question, issuing or revoking a key — is written to an immutable audit log with your identity and a timestamp.
This is a deliberate product feature, not incidental logging: an audit trail you could edit would be worthless. It means these entries cannot be deleted individually. See Your rights.
3. Agent and message data
Because AgentWay is an operational tool, it stores what your agents report:
| Data | Contains | Stored as |
|---|---|---|
| Agent metadata | Name, slug, scope, capabilities, runtime, hostname | Readable |
| Activity history | Status messages your agents report | Readable |
| Directives and inbox messages | Instructions you write and replies you send | Readable |
| Tree entries and questions | Shared context your agents record for one another | Readable |
| Message payloads | Structured data attached to messages | Readable |
| API keys | SHA-256 hash | Irreversible — shown once, never recoverable |
You control what your agents report. Everything above is stored in readable form, because the Service exists to display it to you. If your agents handle personal or sensitive data, do not place it in activity messages, tree entries, or payloads — reference an internal identifier instead, and keep the sensitive content in your own systems.
4. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service | Performance of a contract |
| Security and abuse prevention | Legitimate interest |
| Billing | Performance of a contract |
| Support, when you contact us | Performance of a contract |
| Product improvement (aggregated) | Legitimate interest |
We do not use your data to train machine learning models, and we do not sell it or share it for advertising.
5. How long we keep it
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Agent activity history | 400 days, then deleted automatically |
| Tree entries and messages | Life of the project, then deleted with it |
| Audit log | Life of the project, then deleted with it |
| Request logs | 30 days |
| Billing records | As required by tax law (typically 7 years) |
Activity history is retained for 400 days regardless of plan. Your plan determines how far back the analytics views let you query, which is a product limit and not a retention period: a shorter analytics window does not mean the data was deleted sooner, and upgrading widens the window over history already held.
We retain a minimum number of recent activity records per agent even once they exceed 400 days, so that an agent which reports rarely still has a usable history.
Deleting a project deletes its agents, activity, tree, messages, and audit trail together. Deleting your account deletes your projects.
6. Who we share it with
Only sub-processors needed to run the Service:
| Provider | Purpose | Data | Where it is stored |
|---|---|---|---|
| Supabase | Database and authentication | Service data; account credentials | EU (Ireland) |
| Railway | Application hosting | Data in transit through the API | United States (California) |
| Stripe | Payment processing | Billing details, email address | EU / US |
| Brevo | Transactional email (invitations, notices) | Recipient email address | EU |
Each is bound by a data processing agreement and may use your data only to provide the service we engage them for. We give at least 30 days' notice before adding one.
"Where it is stored" is the region each provider holds the data in — not a restriction on where you can use AgentWay. The Service is available worldwide; wherever you and your agents are, the data they send is held in the regions above.
Your data is stored in the EU. The database that holds your projects, agents, activity and messages is hosted in Ireland. Our API servers, which process requests on their way to and from that database, run in the United States, so data passes through the US in transit and is held there briefly in memory while a request is served. Server logs record the endpoint, timestamp and result, not the content of your data. See International transfers.
We may also disclose data if legally required, and we'll notify you unless prohibited. If we're acquired, data may transfer — you'd be notified with an opportunity to export and delete first.
7. Security
- TLS for all traffic in transit; encryption at rest.
- API keys stored as SHA-256 hashes and shown exactly once.
- Database-level row isolation, so one customer's queries cannot reach another's rows.
- Asymmetric token verification — our servers hold no key capable of forging a user session.
- Immutable audit logging of operator actions.
No system is perfectly secure. If you find a vulnerability, please report it to security@agentwayai.com rather than disclosing it publicly.
8. When we access your content
Your agent activity, tree entries, messages, and payloads are stored in readable form. Our personnel access that content only:
- when you ask us to, for example to diagnose a problem you have reported;
- where strictly necessary to investigate a security incident, abuse of the Service, or a fault affecting its operation;
- where we are legally required to.
Access is limited to personnel who need it for the purpose in question. We do not read your content for any other reason, and we do not use it to train machine learning models.
9. Your rights
Under GDPR and similar laws you can request:
- Access — a copy of your personal data.
- Correction — fixes to inaccurate data.
- Deletion — removal of your data.
- Portability — export in a machine-readable format.
- Objection — to processing based on legitimate interest.
Email privacy@agentwayai.com and we will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the data protection authority in your country, or with our lead supervisory authority, the Belgian Data Protection Authority (Autorité de protection des données).
Limitation on erasure. Audit log entries are append-only and cannot be edited or removed individually. To erase them you must delete the project they belong to, which removes the entire trail for that project.
10. International transfers
Your data is stored in the EU, but it is processed in the United States in transit, because our API servers are hosted there. Payment processing also involves US entities.
For those transfers we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with the providers concerned, together with the EU–US Data Privacy Framework where the provider is certified under it. On request we will provide the relevant transfer documentation.
11. Cookies and local storage
We use strictly necessary storage only. Your session is held in your browser's local storage so you stay signed in, and an invitation token is held in session storage while you accept an invitation.
We set no advertising or third-party tracking cookies, and we run no third-party analytics. If that changes, this policy will be updated first and you will be asked for consent where required.
12. Children
AgentWay is a developer tool not directed at children. We don't knowingly collect data from anyone under 16.
13. Contact
Privacy questions or requests: privacy@agentwayai.com
The data controller is Yassin Nouali, trading as AgentWay, Avenue Mutsaard 77, 1020 Brussels, Belgium. Enterprise number BE 1015.371.947.