AgentNet Privacy Policy
This policy explains what information the AgentNet portal collects, why we process it, who we share it with, and the choices you have.
- Version
- 2026-07-27-2
- Effective
- 2026-07-27
- Last updated
- 2026-07-27
- Published by
- AgentNet Inc.
1.Who we are and what this covers
AgentNet Inc.(“AgentNet”, “we”, “us”) provides the AgentNet portal. This policy covers information we process through the portal and the account, organization, usage, and billing features you reach from it.
It does not cover a separate AgentNet marketing site, or third-party sites and services you reach from links we provide, which have their own policies. Our registered mailing address is AgentNet Inc., 1367 N Chaucer Way, Eagle, Idaho 83616, United States.
2.Information you provide
- Your email address, which we store both as you entered it and in a normalized form used for lookup and uniqueness.
- A display name, which we derive from your email address at registration.
- Authentication data derived from your password. We store a one-way hash produced by a password-hashing function — never the password itself — and we cannot recover your password.
- Organization information you enter, such as the organization name and the URL slug we generate from it.
- Billing and subscription information you provide during checkout. Payment card details are entered with our payment processor, not with us; we receive and store subscription and customer references and status, not full card numbers.
- The content of support requests and other messages you send us.
- Which version of our Terms of Service and Privacy Policy you accepted, and when.
3.Information generated by your use of the portal
- Account identifiers, account status, the time you last signed in, and a session/security version we increment to invalidate old sessions after a password reset or a sign-out-everywhere.
- Organization memberships, roles, invitation records (including who invited whom and when an invitation was accepted, revoked, or expired), and membership audit records.
- Service credentials you create: a credential's public identifier, prefix, environment, scopes, restrictions, status, and timestamps. The credential secret is stored only as a one-way digest and is displayed to you once, at creation.
- Ant (AgentNet Token) usage events and period totals recorded against your organization, plus usage decision and audit records.
- Email verification and password-reset tokens, stored as one-way digests with an expiry and a status — never as usable tokens.
- Records of transactional emails we attempt to send you: purpose, recipient domain, provider response status, and delivery attempt history.
- Security audit records for events such as email verification, password change, session invalidation, and rate limiting.
- Rate-limit counters used to prevent abuse. These are keyed by a keyed one-way digest of the action and identifier, so the row itself contains no raw email address, user identifier, or IP address.
4.Technical information
Like any web service, our hosting and infrastructure providers process request metadata — including IP address, browser user-agent, and timestamps — in server and network logs in order to serve requests and protect the service. We do not maintain our own product analytics profile of you, and, as described above, our application-level rate-limit records do not store raw IP addresses.
We use cookies that are necessary for the service: a session cookie that keeps you signed in, the security tokens our authentication library uses to protect sign-in requests, and a cookie remembering which organization you last selected. We do not use advertising cookies. Server and network logs held by our providers are retained according to those providers’ own practices and our configuration, and for no longer than we need them to operate and secure the service.
5.Why we process information
- To create and operate your account and your organization, and to authenticate you.
- To verify that you control your email address, and to let you recover access to your account.
- To measure ant usage, apply plan allowances, and show you usage and reports.
- To take payment and manage subscriptions through our payment processor.
- To send transactional email you need — verification, password reset, and organization invitations.
- To respond to your support requests.
- To keep the service secure and available: detecting and preventing abuse, enforcing rate limits, investigating incidents, and maintaining audit records.
- To keep a record of which version of our Terms and Privacy Policy you accepted.
- To comply with law and to enforce our Terms.
We do not use your account or usage data to train models for others, and we do not use it for advertising.
6.Our basis for processing
We process this information because it is necessary to provide a service you have asked for and to perform our agreement with you, because we have a legitimate interest in operating the service securely and preventing abuse, and because some processing is required to meet legal obligations. Where a particular law requires consent for a specific activity, we will ask for it.
Which specific data-protection regimes apply depends on where you and your organization are located and on statutory thresholds; we do not claim a compliance certification or a formal adequacy determination.
7.Service providers we use
We rely on the following providers to run the portal. Each processes only what its function requires:
- Vercel — application hosting and delivery, including request handling and platform logs.
- Aiven — the managed MySQL database that stores the account, organization, usage, credential, and audit records described above.
- Google Workspace / Gmail — outbound transactional email delivery (verification, password reset, invitations).
- Stripe — payment processing and hosted checkout for paid plans. Stripe receives the payment details you enter and returns subscription and customer references to us.
If we add or change a significant provider we will update this policy.
8.When we disclose information
- Within your organization: other members can see organization data appropriate to their role, including membership and, for authorized roles, usage, credential metadata, and billing information.
- To the service providers listed above, for the purposes described.
- When required by law, or in response to a valid legal request.
- To protect the rights, safety, or property of AgentNet, our users, or the public.
- In connection with a merger, acquisition, or sale of assets, in which case we will give notice and the recipient will be bound by terms no less protective for information already collected.
9.Sale of information and advertising
We do not currently sell your personal information, and we do not currently share it for cross-context behavioral advertising or targeted advertising.
This describes our practice as of the effective date above rather than a perpetual promise. If we ever introduce a materially different practice, we will update this policy before doing so, and we will honor any rights — including any right to opt out — that applicable law gives you.
10.How long we keep information
We keep account, organization, usage, billing, and audit records for as long as your account is active and afterwards for as long as we need them to operate the service, resolve disputes, meet legal and accounting obligations, and maintain security records. Verification and password-reset tokens are short-lived by design and are marked used, superseded, or expired rather than remaining usable.
After an account is closed we retain records only for as long as reasonably necessary for security, fraud prevention, dispute resolution, legal and regulatory compliance, accounting, service integrity, and other legitimate business purposes — and then no longer.
How long any particular record is kept therefore depends on the type of record, the purpose it serves, the legal obligations that apply to it, and the practices of the provider that stores it. We have not published fixed retention periods, and we would rather say that plainly than state a schedule we do not yet enforce.
11.How we protect information
We take measures we consider appropriate for a service of this kind. In particular: passwords are stored only as one-way hashes; email verification, password-reset, and service-credential secrets are stored only as keyed one-way digests; database connections use TLS; authorization is re-checked against the database on every protected request; and abuse protection is applied to sensitive operations.
No service can promise perfect security, and we do not claim a security certification or a formal audit. If we become aware of a breach affecting your information we will act on it and give notice as required by applicable law.
12.Your choices
- You can review and update your account and organization information in the portal.
- You can change your password, and sign out of every device, from your account security settings.
- You can rotate or revoke service credentials at any time.
- You can ask us to delete your account by contacting support. Some records may be retained where we have a legal or security reason to keep them.
- Transactional email is part of the service and is not marketing; we do not currently send marketing email through the portal.
13.Regional privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, or to appeal a decision we make about such a request. Some of these rights apply only if a particular law covers you and, in some cases, only if the business meets statutory thresholds.
To make a request, contact us at support@agent-net.ai. We will verify the request against your account before acting on it and will not discriminate against you for making one.
14.International users
We operate from the United States and our providers may process and store information in the United States and in other countries where they operate. If you use the portal from outside the United States, you understand that information will be transferred to and processed in countries whose data-protection laws may differ from those where you live. We have not implemented data localisation, and we do not claim a specific transfer-mechanism certification.
15.Children
The portal is a business service intended for people aged 18 or over. It is not directed to children, we do not knowingly collect information from them, and we do not offer a children’s service. If you believe a child has given us information, contact us and we will delete it.
16.Changes to this policy
We may update this policy. Each version carries a version identifier and an effective date, shown at the top of this page, and we record which version you acknowledged when you created your account. If we make a material change we will give notice through the portal or by email.
17.Contact
For privacy questions or requests, contact support@agent-net.ai, which is our contact address for privacy and legal matters. Written requests may also be sent to AgentNet Inc., 1367 N Chaucer Way, Eagle, Idaho 83616, United States. Our Terms of Service govern your use of the portal.
AgentNet Inc. — version 2026-07-27-2, effective 2026-07-27.