Privacy Policy
Last updated: August 3, 2026
1. Who we are
Agend LLC, a Wyoming limited liability company ("agend", "we", "us", "our"), operates the agend platform at agend.sh. This Privacy Policy describes how we collect, use, and protect your information when you use our service.
2. What we collect
2.1 Account data
- Email address (required for signup).
- Name (optional).
- GitHub OAuth profile — login, user ID, and avatar URL (if you sign up via GitHub).
- Hashed password (if you sign up via email — we never store plaintext passwords).
2.2 Environment data
- Files, code, packages, and processes inside your microVM.
- We do not inspect, access, or read the contents of your Environments. Your Environment is opaque to us.
- We store Environment metadata: state (running, sleeping, stopped), tier, creation timestamp, last active timestamp.
2.3 Usage data
- First successful MCP use — tool name, timestamp, and CLI version. This activation marker is recorded once per account. We do not collect the tool arguments or output.
- Environment lifecycle events — created, started, slept, woken, destroyed.
- CLI version associated with the first successful MCP use.
2.4 Payment data
- All payments are processed by Paddle.com Market Limited, our Merchant of Record.
- We store Paddle customer ID, subscription ID, plan tier, and subscription status.
- We never see, store, or process your credit card number, bank details, or full billing address. Paddle handles all payment data directly.
2.5 Website analytics
- We use cookieless Cloudflare Web Analytics to understand aggregate website traffic. Cloudflare processes ordinary request metadata as our infrastructure provider.
- Our first-party funnel telemetry records the event name, page path, CTA label, and a random per-tab session identifier. It does not include form values, passwords, MCP arguments, or MCP output.
- API access and security logs may include source IP addresses and are retained for 30 days.
3. How we use your data
- Service operation: Provision and manage your Environments, authenticate your CLI and MCP connections, enforce resource limits per your plan.
- Billing: Process subscriptions and communicate with Paddle for payment management.
- Transactional emails: Account verification, password reset, billing notifications, and service announcements. We will never send marketing emails without your explicit consent.
- Abuse prevention: Detect and prevent violations of our Acceptable Use Policy using metadata (not Environment contents).
- Service improvement: Aggregate, anonymized usage patterns (e.g., which MCP tools are most used) to improve the platform. Individual usage is never shared.
4. What we do NOT do
- We do not sell, rent, or share your personal data with third parties for advertising or marketing.
- We do not inspect the contents of your Environments.
- We do not log the arguments or output of MCP tool calls.
- We do not use advertising cookies or cross-site advertising trackers.
- We do not train AI models on your data.
5. Infrastructure and data location
| Component | Provider | Location | Purpose |
|---|---|---|---|
| Control plane | AWS | us-east-1 (Virginia) | API, authentication, billing, Environment orchestration |
| Compute (Environments) | Bare-metal servers | Variable (see plan details) | Firecracker microVMs running your Environments |
| DNS & tunnels | Cloudflare | Global edge | DNS resolution, secure tunnel transport |
| Payments | Paddle | UK / EU | Merchant of Record — invoicing, tax, refunds |
6. Data retention
- Active subscription: Account and Environment data is retained for the duration of your subscription.
- After cancellation: Environment data (files, packages, configurations) is retained for 30 days, then permanently and irrecoverably deleted.
- Account data: Account records (email, subscription history) are retained for 12 months after cancellation for legal and accounting purposes, then deleted.
- Usage records: First-use activation metadata and operational lifecycle logs are retained only as needed to operate and improve the service.
7. Data security
- Each Environment runs in its own Firecracker microVM with a dedicated kernel, providing hardware-level isolation between tenants.
- Network isolation via separate network namespaces and seccomp system call filtering.
- All data in transit is encrypted (TLS 1.2+).
- Authentication tokens are cryptographically signed and short-lived.
- Access to production infrastructure is limited to authorized personnel with multi-factor authentication.
8. Your rights
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Delete your account and all associated data at any time.
- Export: Export your Environment data using
shell_file_getor standard tools (git, scp, etc.) before cancellation. - Objection: Object to processing of your data for specific purposes.
To exercise these rights, contact hello@agend.sh. We will respond within 30 days.
9. Children's privacy
agend is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. International data transfers
Our infrastructure is primarily located in the United States. If you access agend from outside the US, your data may be transferred to and processed in the US. By using the service, you consent to this transfer. We rely on Paddle for EU payment data processing, which is handled under their own GDPR-compliant policies.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For questions about this Privacy Policy or data handling, contact us at:
hello@agend.sh
Agend LLC
Wyoming, United States