AgentKey
Overview Services Capabilities FAQ Pricing Blog
Login

Legal

Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how AgentKey collects, uses, and protects information when you use our API routing services. It also describes your rights and how to exercise them.

At a glance

  • We collect only what's needed — account details, hashed API keys, and usage metadata.
  • Your query and response content is relayed, not stored on our servers.
  • We never sell your data or use it to train AI models.
  • Payments go through Stripe — we never see your card number.
  • Product analytics are off until you opt in.
  • View, export, or delete your data anytime from your dashboard.

This summary is for convenience only and does not replace the full policy below.

01 Scope and definitions

This Policy applies to information processed by AgentKey when you use our website, console, CLI, REST API, or remote MCP endpoint (collectively, the "Service"). Capitalized terms not defined here have the meanings given in our Terms of Service.

  • "Personal data" means any information relating to an identified or identifiable natural person.
  • "Process" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • "Third-Party Provider" has the meaning given in the Terms of Service — independent API providers reachable through AgentKey's routing layer.

02 Information we collect

We collect only the information needed to operate and secure the Service. Specifically:

Account information. When you sign in, we collect your email address, profile image, and a unique identifier issued by our authentication provider. We do not store your password — authentication is handled by our identity provider (see §04).

API credentials. We store hashed representations of the API keys you create, along with the key name, prefix, and creation timestamp. The full key value is shown to you once at creation and is not retrievable thereafter.

Usage logs. For each API request routed through AgentKey, we record the timestamp, endpoint path, HTTP status, response latency, credit cost, and the API key that made the call. We do not log request bodies or response bodies in normal operation — the content of your queries and the data returned by third-party providers is relayed back to you and is not retained on our servers. We may temporarily process this content in memory only as needed to route the request and, in narrowly scoped incidents, enable short-lived diagnostic logging to investigate errors or abuse, which is disabled by default and purged on a short cycle.

Billing data. If you subscribe to a paid plan or purchase credits, our payment processor (see §04) handles card details. We receive only a customer reference, the amount paid, and the transaction status — never card numbers or CVCs.

Device and installation data. When you install our CLI or skill plugin, we may receive an anonymous installation identifier and basic telemetry (CLI version, install method) so we can deliver updates and measure adoption.

Marketing attribution data. When you arrive through a paid campaign, the URL may contain campaign identifiers, UTM parameters, and a platform click identifier (such as Google, Meta, or X click IDs). Those current-visit parameters may pass directly to the Console and be associated with a new account if you register during that visit. With analytics consent, we additionally remember the latest paid touch for up to 30 days so attribution can survive a later visit. We do not use this information for cross-site behavioral advertising.

Communications. If you contact us by email or community channel, we retain the content of that exchange to respond to and resolve your inquiry.

03 How we use information

We use the information described above to:

  • Authenticate you and authorize your access to the Service;
  • Route your API requests to the appropriate Third-Party Provider and return responses;
  • Meter and bill your usage of credits;
  • Detect, prevent, and investigate abuse, fraud, and security incidents;
  • Provide customer support and respond to your inquiries;
  • Maintain, debug, and improve the Service;
  • Measure the effectiveness of our own paid marketing campaigns;
  • Comply with our legal obligations and enforce our Terms of Service.

We do not sell personal data. We do not use your personal data to train machine learning models.

04 Third-party processors

We rely on a small set of established processors to operate the Service. Each handles a narrow function, processes data on our behalf under a data processing agreement, and applies its own additional privacy controls:

  • Authentication. Clerk (clerk.com) — sign-in, session management, and identity. We never see your password.
  • Payments. Stripe (stripe.com) — payment processing for subscriptions and credit purchases. Card details go directly to Stripe; we receive only transaction metadata.
  • Product analytics. PostHog (posthog.com) — pseudonymous event analytics so we can understand how the console is used and prioritize improvements. See §06.
  • Hosting and infrastructure. Cloud infrastructure providers used to run our servers and store data.

We periodically review these processors for security and privacy posture. We will update this Policy if we add or replace a processor that meaningfully affects how your information is processed.

05 Third-party providers

AgentKey acts as a routing layer. When you call an endpoint backed by a Third-Party Provider, your request (and any data within it) is forwarded to that provider. The provider then returns a response, which we relay back to you.

Notice: Third-Party Providers operate under their own privacy policies and terms of service. AgentKey does not control how they collect, process, or retain data on their side. If your use case involves personal data, you should independently review the policies of any provider you call.

Where Third-Party Data retrieved through the Service contains personal data, you act as the data controller for that data under applicable law. AgentKey is not a controller in respect of personal data you obtain via Third-Party Providers.

06 Cookies and analytics

We use a small number of cookies and similar technologies (including browser localStorage). We group them into three categories:

  • Strictly necessary — required for the Service to function (security, signing you in, and remembering your cookie choices). These are always active and do not require consent.
  • Functional — support a feature you actively requested, such as remembering an invite link you deliberately followed so your sign-up can be attributed to the person who invited you. These are first-party, short-lived, and not used for advertising.
  • Analytics — PostHog product analytics and cross-visit browser storage of first-party paid-campaign attribution that help us understand usage, measure campaign results, and improve AgentKey. These analytics cookies are off by default and persist only after you grant consent. We do not use them for cross-site advertising, and we do not sell the data.
NamePurposeCategoryDurationSet by
agentkey_consentStores your cookie-consent choiceStrictly necessary180 daysAgentKey (first-party)
__session, __clientKeep you signed in to the ConsoleStrictly necessarySession / up to 1 yearClerk (auth provider)
agentkey_invite, agentkey_refRemember an invite (/@handle) you followed so your sign-up is attributed to the inviterFunctional24 hoursAgentKey (first-party)
agentkey_paid_touchRemember the latest Google, Meta, or X paid-campaign touch before registrationAnalytics (consent required)30 daysAgentKey (first-party)
ph_* / PostHogProduct analytics: pseudonymous usage, page views, feature interestAnalytics (consent required)Up to 12 monthsPostHog

You control analytics at any time through the "Cookie Settings" link in our footer (in some regions also labeled "Do Not Sell or Share My Personal Information"), which lets you grant or withdraw analytics consent. We also honor your browser's "Do Not Track" signal. You can clear cookies in your browser at any time; clearing the necessary cookies will sign you out of the console.

07 Data retention

We retain information only as long as needed for the purposes described in §03, or as required by law.

  • Account data is retained while your account is active.
  • API key hashes are retained until you revoke the key, plus a short window for audit.
  • Usage logs are retained for operational and billing reconciliation purposes, typically up to twelve (12) months, then aggregated or deleted.
  • Billing records are retained as required by applicable tax and accounting laws.
  • Paid-campaign attribution is stored in your browser for up to 30 days only after analytics consent and, if linked to a new account, retained with account analytics until deletion or anonymization.

When you delete your account, we delete or anonymize personal data within thirty (30) days, except where retention is required by law or necessary to resolve a dispute. Backups containing residual copies are overwritten on their normal rotation cycle, no later than ninety (90) days.

After deletion we retain a one-way cryptographic hash of your email address (from which the address cannot be recovered). We keep it solely to prevent abuse of our free tier — for example, repeatedly deleting and recreating an account to obtain new free credits — which is a legitimate interest. It is not used to contact you or to build a profile.

08 International transfers

AgentKey and its processors operate across multiple jurisdictions. When personal data is transferred outside your country of residence, we rely on appropriate legal mechanisms (such as Standard Contractual Clauses or equivalent safeguards) where required by applicable law.

Some third-party data sources are subject to regional data-residency restrictions. Where a source may only be provided from within a specific jurisdiction, we route those requests through infrastructure in that region and may make the source unavailable in deployments outside it, so that data is not transferred across borders in a manner inconsistent with local law.

09 Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete personal data;
  • Delete your personal data, subject to legal retention obligations;
  • Restrict or object to certain processing;
  • Receive a copy of your data in a portable format;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with your local data protection authority.

You can access and update your account information, view your usage logs, and delete your account and its associated personal data directly from your dashboard at any time. To exercise any other right, or if you cannot use the dashboard, contact us at support@agentkey.app (or the address in §13). We will respond within thirty (30) days, or sooner where required by applicable law, and will not discriminate against you for exercising these rights.

10 Security

We apply administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit, hashed API credentials, principle-of-least-privilege access controls, and routine review of our processors.

NO METHOD OF TRANSMISSION OR STORAGE IS PERFECTLY SECURE. WHILE WE WORK TO PROTECT YOUR INFORMATION, WE CANNOT GUARANTEE ABSOLUTE SECURITY. IF YOU BELIEVE YOUR ACCOUNT HAS BEEN COMPROMISED, CONTACT US IMMEDIATELY.

11 Children

AgentKey is not directed to children under the age of 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.

12 Region-specific disclosures

The following disclosures supplement the rest of this Policy for individuals in the regions named. Where a regional provision conflicts with the general text, the regional provision controls for residents of that region.

European Economic Area & United Kingdom (GDPR / UK GDPR)

Our legal bases for processing are: performance of a contract (operating the Service you sign up for), legitimate interests (securing the Service, preventing abuse, and basic product improvement), consent (analytics cookies — see §06 — which you may withdraw at any time), and legal obligation (tax, accounting, and lawful requests). You have the rights listed in §09, including the right to lodge a complaint with your supervisory authority. Analytics are loaded only after opt-in consent, in line with the ePrivacy Directive.

EU/UK representative. Where required under Article 27 GDPR, our appointed representative's contact details will be listed here. [To be completed once appointed — see internal compliance tracker.]

California (CCPA / CPRA)

In the past 12 months we collect the categories of personal information described in §02 (identifiers, commercial/billing information, internet activity, and account content) for the business purposes in §03. We do not sell your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under the CPRA. To the extent our use of analytics cookies is deemed "sharing," you may opt out via the "Do Not Sell or Share My Personal Information" link in our footer. You have the right to know, delete, correct, and to non-discrimination for exercising these rights; exercise them as described in §09.

Mainland China (PIPL)

Where we process the personal information of individuals in mainland China, we do so on the legal bases permitted by the Personal Information Protection Law. Certain data sources are subject to data-residency restrictions and are not transferred out of their jurisdiction (see §08). Any cross-border transfer of personal information out of mainland China will be carried out only after completing a legally required mechanism (a security assessment, certification, or the standard contract, as applicable) and obtaining your separate consent where required. [Cross-border transfer mechanism pending legal sign-off — see internal compliance tracker.]

Brazil (LGPD)

If you are in Brazil, you have the rights afforded by the Lei Geral de Proteção de Dados, which mirror those in §09. You may contact us at the address in §13 to exercise them.

13 Changes and contact

We may update this Policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, provide additional notice through the Service or by email.

Questions about this Policy or requests to exercise your rights should be directed to:

Chainbase Technology Holdings Pte. Ltd.

33 Ubi Avenue 3, Vertex #08-43
Singapore 408868

For all inquiries: support@agentkey.app

On this page

  1. Scope and definitions
  2. Information we collect
  3. How we use information
  4. Third-party processors
  5. Third-party providers
  6. Cookies and analytics
  7. Data retention
  8. International transfers
  9. Your rights
  10. Security
  11. Children
  12. Region-specific disclosures
  13. Changes and contact
AgentKey
© 2026 AgentKey
Fazier badge Featured on AI Agents Directory
Docs Privacy Terms Support Status About Your Privacy Choices