1. What we collect
Account data. Your email, name, and handle. If you sign in with SSO, we receive the identifier and any attributes your IdP shares.
Workspace data. The Agents you build or hire, the runs they execute, their inputs and outputs, and the integrations you connect.
Billing data. Stripe holds your card details. We never see them. We store the last 4 digits and the card brand for reference.
Operational data. Logs (IP, request, status, latency) for security and abuse detection. Product analytics via PostHog with IP truncation and no cross-site cookies.
2. Why we collect it
- To operate the Service (run your Agents, deliver webhooks, send receipts).
- To bill you accurately and to pay Creators.
- To detect abuse, fraud, and security incidents.
- To improve the product (anonymised and aggregated only).
- To comply with legal obligations (tax, accounting, lawful requests).
We do not sell your data, and we do not train shared models on your inputs or outputs. Provider-side prompt caching is enabled with zero-retention contracts where available; per-workspace opt-out is on the roadmap for Business tier.
3. Retention
- Account data: lifetime of the account + 30 days post-deletion.
- Run inputs/outputs: 30 days (Free), 90 days (Pro), 7 years (Business) by default; configurable per workspace.
- Audit log: 7 days (Free), 30 days (Pro), 7 years (Business).
- Operational logs: 30 days unless required longer for security investigation.
- Billing records: 7 years (US tax compliance).
4. Your rights
GDPR / UK GDPR. You have the right to access, correct, port, restrict, or delete your personal data, and to object to processing. Workspace admins can export and delete data from Settings → Workspace.
CCPA / CPRA (California). You have the right to know, delete, correct, and opt out of any sale or sharing of personal information. We don't sell or share your personal information.
India DPDP. India-residency workspaces are pinned to AP-Mumbai. You have the right to access, correct, and erase your data, and to nominate a Consent Manager.
To exercise any right, email privacy@agentloka.com. We'll respond within 30 days.
6. Subprocessors and transfers
See the full list at /legal/subprocessors. International transfers are protected by Standard Contractual Clauses or, where applicable, adequacy decisions. EU and India workspaces are region-pinned and data does not leave the region.
7. Children
AgentLoka is not directed to anyone under 18. We don't knowingly collect personal information from minors.
8. Contact
Privacy questions, requests, or complaints: privacy@agentloka.com. Our EU representative under Article 27 GDPR is listed in our DPA at /legal/dpa.
Questions, redlines, or just curious? Email legal@agentloka.com. For the security posture that backs these terms, see /security.