AgentKey
Overview Services Capabilities FAQ Pricing Blog
Login

Legal

Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how AgentKey collects, uses, and protects information when you use our API routing services. It also describes your rights and how to exercise them.

At a glance

  • We collect only what's needed — account details, hashed API keys, and usage metadata.
  • Your query and response content is relayed, not stored on our servers.
  • We never sell your data or use it to train AI models.
  • Payments go through Stripe — we never see your card number.
  • Product analytics are off until you opt in.
  • Product emails are optional — one-click unsubscribe, no sign-in needed.
  • View, export, or delete your data anytime from your dashboard.

This summary is for convenience only and does not replace the full policy below.

01 Scope and definitions

This Policy applies to information processed by AgentKey when you use our website, console, CLI, REST API, or remote MCP endpoint (collectively, the "Service"). Capitalized terms not defined here have the meanings given in our Terms of Service.

  • "Personal data" means any information relating to an identified or identifiable natural person.
  • "Process" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • "Third-Party Provider" has the meaning given in the Terms of Service — independent API providers reachable through AgentKey's routing layer.

02 Information we collect

We collect only the information needed to operate and secure the Service. Specifically:

Account information. When you sign in, we collect your email address, profile image, and a unique identifier issued by our authentication provider. We do not store your password — authentication is handled by our identity provider (see §04).

API credentials. We store hashed representations of the API keys you create, along with the key name, prefix, and creation timestamp. The full key value is shown to you once at creation and is not retrievable thereafter.

Usage logs. For each API request routed through AgentKey, we record the timestamp, endpoint path, HTTP status, response latency, credit cost, and the API key that made the call. We do not log request bodies or response bodies in normal operation — the content of your queries and the data returned by third-party providers is relayed back to you and is not retained on our servers. We may temporarily process this content in memory only as needed to route the request and, in narrowly scoped incidents, enable short-lived diagnostic logging to investigate errors or abuse, which is disabled by default and purged on a short cycle.

Billing data. If you subscribe to a paid plan or purchase credits, our payment processor (see §04) handles card details. We receive only a customer reference, the amount paid, and the transaction status — never card numbers or CVCs.

Device and installation data. When you install our CLI or skill plugin, we may receive an anonymous installation identifier and basic telemetry (CLI version, install method) so we can deliver updates and measure adoption.

Marketing attribution data. When you arrive through a paid campaign, the URL may contain campaign identifiers, UTM parameters, and a platform click identifier (such as Google, Meta, or X click IDs). Those current-visit parameters may pass directly to the Console and be associated with a new account if you register during that visit. With analytics consent, we additionally remember the latest paid touch for up to 30 days so attribution can survive a later visit. We do not use this information for cross-site behavioral advertising.

Communications. If you contact us by email or community channel, we retain the content of that exchange to respond to and resolve your inquiry.

Email delivery and engagement data. For each message we send you, we record which message it was, when it was sent, and what our delivery provider reported back — delivered, bounced, opened, link clicked, unsubscribed, or reported as spam. We store a one-way hash of your address alongside these records rather than the address itself. See §07.

03 How we use information

We use the information described above to:

  • Authenticate you and authorize your access to the Service;
  • Route your API requests to the appropriate Third-Party Provider and return responses;
  • Meter and bill your usage of credits;
  • Detect, prevent, and investigate abuse, fraud, and security incidents;
  • Provide customer support and respond to your inquiries;
  • Send you service notices, and — where you have not opted out — occasional product and onboarding email, and measure whether those messages were useful (see §07);
  • Maintain, debug, and improve the Service;
  • Measure the effectiveness of our own paid marketing campaigns;
  • Comply with our legal obligations and enforce our Terms of Service.

We do not sell personal data. We do not use your personal data to train machine learning models.

04 Third-party processors

We rely on a small set of established processors to operate the Service. Each handles a narrow function, processes data on our behalf under a data processing agreement, and applies its own additional privacy controls:

  • Authentication. Clerk (clerk.com) — sign-in, session management, and identity. We never see your password.
  • Payments. Stripe (stripe.com) — payment processing for subscriptions and credit purchases. Card details go directly to Stripe; we receive only transaction metadata.
  • Product analytics. PostHog (posthog.com) — pseudonymous event analytics so we can understand how the console is used and prioritize improvements. See §06.
  • Advertising measurement. Google (Google Ads) — conversion measurement and remarketing across our site and the Console, only for visitors who grant advertising consent. See §06.
  • Email delivery. Where we use a third-party email delivery provider, it receives your email address and the content of the message for the sole purpose of delivering it and reporting the outcome. Where we send from our own mail infrastructure instead, no third party receives your address for this purpose. See §07.
  • Hosting and infrastructure. Cloud infrastructure providers used to run our servers and store data.

We periodically review these processors for security and privacy posture. We will update this Policy if we add or replace a processor that meaningfully affects how your information is processed.

05 Third-party providers

AgentKey acts as a routing layer. When you call an endpoint backed by a Third-Party Provider, your request (and any data within it) is forwarded to that provider. The provider then returns a response, which we relay back to you.

Notice: Third-Party Providers operate under their own privacy policies and terms of service. AgentKey does not control how they collect, process, or retain data on their side. If your use case involves personal data, you should independently review the policies of any provider you call.

Where Third-Party Data retrieved through the Service contains personal data, you act as the data controller for that data under applicable law. AgentKey is not a controller in respect of personal data you obtain via Third-Party Providers.

06 Cookies and analytics

We use a small number of cookies and similar technologies (including browser localStorage). We group them into four categories:

  • Strictly necessary — required for the Service to function (security, signing you in, and remembering your cookie choices). These are always active and do not require consent.
  • Functional — support a feature you actively requested, such as remembering an invite link you deliberately followed so your sign-up can be attributed to the person who invited you. These are first-party, short-lived, and not used for advertising.
  • Analytics — PostHog product analytics and cross-visit browser storage of first-party paid-campaign attribution that help us understand usage, measure campaign results, and improve AgentKey. These analytics cookies are off by default and persist only after you grant consent. They are first-party or pseudonymous, are not used to build advertising profiles, and we do not sell the data.
  • Advertising — Google Ads conversion measurement and remarketing, on this site and in the Console, so we can tell which ads bring people to AgentKey and may show you our ads on other sites. These are off by default and are enabled only if you grant advertising consent, which is a separate choice from analytics. Until you do, the Google tag runs with all storage denied under Google Consent Mode: it writes no cookies and its requests carry no advertising identifiers. Granting this consent involves sharing online identifiers with Google — see the US state privacy section for what that means.
NamePurposeCategoryDurationSet by
agentkey_consentStores your cookie-consent choiceStrictly necessary180 daysAgentKey (first-party)
__session, __clientKeep you signed in to the ConsoleStrictly necessarySession / up to 1 yearClerk (auth provider)
agentkey_invite, agentkey_refRemember an invite (/@handle) you followed so your sign-up is attributed to the inviterFunctional24 hoursAgentKey (first-party)
agentkey_paid_touchRemember the latest Google, Meta, or X paid-campaign touch before registrationAnalytics (consent required)30 daysAgentKey (first-party)
ph_* / PostHogProduct analytics: pseudonymous usage, page views, feature interestAnalytics (consent required)Up to 12 monthsPostHog
_gcl_* / Google AdsMeasure ad conversions and show you our ads on other sitesAdvertising (consent required)Up to 90 daysGoogle

You control analytics and advertising separately, at any time, through the "Cookie Settings" link in our footer (in some regions also labeled "Do Not Sell or Share My Personal Information"), which lets you grant or withdraw either consent independently. We also honor your browser's "Do Not Track" signal. You can clear cookies in your browser at any time; clearing the necessary cookies will sign you out of the console.

07 Email we send you

We send two kinds of email, and they are governed differently.

  • Service (transactional) email — billing and payment notices, security alerts, password and sign-in messages, account deletion confirmations, and replies to your support requests. These are part of the Service you signed up for. They are sent on the basis of performing our contract with you (and, for security notices, our legitimate interest in protecting your account), and they cannot be turned off while your account is open.
  • Product and lifecycle email — occasional messages helping you connect an agent, try your first task, and get more out of AgentKey, together with notices when your monthly free credits are nearly used. These are optional. Every one of them contains a one-click unsubscribe link that works without signing in, and you can also turn them off at any time under Account settings → Email notifications in the console.

Legal basis for product email. Where you are in a jurisdiction that requires prior consent for commercial email, we send product and lifecycle email only if you have opted in. Where soft opt-in to existing customers is permitted, we rely on our legitimate interest in helping people use a service they registered for, balanced against your right to object — which you exercise by unsubscribing. Opting out of product email never affects service email, and never affects your account or your credits.

What we record about email we send. For each message we store the campaign it belongs to, the language it was sent in, the time it was sent, whether the provider accepted or bounced it, and — where the provider reports it — whether it was opened, whether a link was clicked, and whether you unsubscribed or reported it as spam. We store a one-way hash of the recipient address rather than the address itself, and we store the template identifier rather than a copy of the message text.

Open and click measurement. This is not performed at all when we deliver from our own mail infrastructure. Where it is available and enabled, open tracking works through a small image loaded when a message is displayed; link measurement records only the path of the link followed, never any query parameters. We treat this as measurement requiring consent on the same basis as analytics cookies (see §06), and we do not enable it for recipients in regions where prior consent is required and has not been given. Open figures are unreliable in any case: several mail providers fetch tracking images automatically on behalf of recipients who never opened the message.

What we do not do. We do not sell or rent your email address, we do not share it with advertisers or data brokers, we do not build advertising profiles from your email activity, and we do not include the content of the queries you send through the Service in any message we send you.

Retention. Individual open and click records are deleted after twelve (12) months. Records that we sent you a message, and whether it was delivered, are kept for a longer period as part of our own compliance record, but they cease to identify you once your account is deleted (see §08). If you unsubscribe and later delete your account, we keep the one-way hash of your address on our suppression list so that we do not begin emailing you again — this is the same hash described in §08, and it cannot be used to contact you.

Depending on the deployment, email is delivered either from our own mail infrastructure or through a third-party delivery provider acting as our processor; see §04. Where delivery is handled in-house, the engagement data described above is limited to what our own systems record — in practice the fact that a message was accepted for delivery, and any rejection reported at the time of sending. Open and click measurement is not available in that configuration and is not performed.

08 Data retention

We retain information only as long as needed for the purposes described in §03, or as required by law.

  • Account data is retained while your account is active.
  • API key hashes are retained until you revoke the key, plus a short window for audit.
  • Usage logs are retained for operational and billing reconciliation purposes, typically up to twelve (12) months, then aggregated or deleted.
  • Email open and click records are retained for up to twelve (12) months, then deleted. Records that a message was sent and whether it was delivered are kept longer as a compliance record, and cease to identify you when your account is deleted (see §07).
  • Billing records are retained as required by applicable tax and accounting laws.
  • Paid-campaign attribution is stored in your browser for up to 30 days only after analytics consent and, if linked to a new account, retained with account analytics until deletion or anonymization.

When you delete your account, we delete or anonymize personal data within thirty (30) days, except where retention is required by law or necessary to resolve a dispute. Backups containing residual copies are overwritten on their normal rotation cycle, no later than ninety (90) days.

After deletion we retain a one-way cryptographic hash of your email address (from which the address cannot be recovered). We keep it solely to prevent abuse of our free tier — for example, repeatedly deleting and recreating an account to obtain new free credits — which is a legitimate interest. It is not used to contact you or to build a profile.

09 International transfers

AgentKey and its processors operate across multiple jurisdictions. When personal data is transferred outside your country of residence, we rely on appropriate legal mechanisms (such as Standard Contractual Clauses or equivalent safeguards) where required by applicable law.

Some third-party data sources are subject to regional data-residency restrictions. Where a source may only be provided from within a specific jurisdiction, we route those requests through infrastructure in that region and may make the source unavailable in deployments outside it, so that data is not transferred across borders in a manner inconsistent with local law.

10 Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete personal data;
  • Delete your personal data, subject to legal retention obligations;
  • Restrict or object to certain processing;
  • Receive a copy of your data in a portable format;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with your local data protection authority.

You can access and update your account information, view your usage logs, and delete your account and its associated personal data directly from your dashboard at any time. To exercise any other right, or if you cannot use the dashboard, contact us at support@agentkey.app (or the address in §14). We will respond within thirty (30) days, or sooner where required by applicable law, and will not discriminate against you for exercising these rights.

11 Security

We apply administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit, hashed API credentials, principle-of-least-privilege access controls, and routine review of our processors.

NO METHOD OF TRANSMISSION OR STORAGE IS PERFECTLY SECURE. WHILE WE WORK TO PROTECT YOUR INFORMATION, WE CANNOT GUARANTEE ABSOLUTE SECURITY. IF YOU BELIEVE YOUR ACCOUNT HAS BEEN COMPROMISED, CONTACT US IMMEDIATELY.

12 Children

AgentKey is not directed to children under the age of 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.

13 Region-specific disclosures

The following disclosures supplement the rest of this Policy for individuals in the regions named. Where a regional provision conflicts with the general text, the regional provision controls for residents of that region.

European Economic Area & United Kingdom (GDPR / UK GDPR)

Our legal bases for processing are: performance of a contract (operating the Service you sign up for), legitimate interests (securing the Service, preventing abuse, and basic product improvement), consent (analytics and advertising cookies — see §06 — each of which you may withdraw at any time), and legal obligation (tax, accounting, and lawful requests). You have the rights listed in §10, including the right to lodge a complaint with your supervisory authority. Analytics and advertising storage are enabled only after opt-in consent, in line with the ePrivacy Directive.

EU/UK representative. Where required under Article 27 GDPR, our appointed representative's contact details will be listed here. [To be completed once appointed — see internal compliance tracker.]

California (CCPA / CPRA)

In the past 12 months we collect the categories of personal information described in §02 (identifiers, commercial/billing information, internet activity, and account content) for the business purposes in §03. We do not sell your personal information for money. However, when you grant advertising consent, our Google Ads tag transmits online identifiers (such as cookie IDs and a click identifier) to Google for conversion measurement and remarketing — which is "sharing" for cross-context behavioral advertising as the CPRA defines it, and which some state laws also treat as a "sale." Advertising consent is off by default; if you grant it and later change your mind, withdraw it via the "Do Not Sell or Share My Personal Information" link in our footer, which turns the tag's storage back off. Our analytics cookies are used for our own product measurement and are not used to build advertising profiles. You have the right to know, delete, correct, and to non-discrimination for exercising these rights; exercise them as described in §10.

Mainland China (PIPL)

Where we process the personal information of individuals in mainland China, we do so on the legal bases permitted by the Personal Information Protection Law. Certain data sources are subject to data-residency restrictions and are not transferred out of their jurisdiction (see §09). Any cross-border transfer of personal information out of mainland China will be carried out only after completing a legally required mechanism (a security assessment, certification, or the standard contract, as applicable) and obtaining your separate consent where required. [Cross-border transfer mechanism pending legal sign-off — see internal compliance tracker.]

Brazil (LGPD)

If you are in Brazil, you have the rights afforded by the Lei Geral de Proteção de Dados, which mirror those in §10. You may contact us at the address in §14 to exercise them.

14 Changes and contact

We may update this Policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, provide additional notice through the Service or by email.

Questions about this Policy or requests to exercise your rights should be directed to:

Chainbase Technology Holdings Pte. Ltd.

33 Ubi Avenue 3, Vertex #08-43
Singapore 408868

For all inquiries: support@agentkey.app

On this page

  1. Scope and definitions
  2. Information we collect
  3. How we use information
  4. Third-party processors
  5. Third-party providers
  6. Cookies and analytics
  7. Email we send you
  8. Data retention
  9. International transfers
  10. Your rights
  11. Security
  12. Children
  13. Region-specific disclosures
  14. Changes and contact
AgentKey
© 2026 AgentKey
Fazier badge Featured on AI Agents Directory
Docs Privacy Terms Support Status About Your Privacy Choices