Privacy Policy
AgentCab (“we”, “us”, “our”) operates the website at www.agentcab.ai and the AgentCab mobile applications (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights.
By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Account information
When you create an AgentCab account, we collect:
- Email address (required) and, optionally, your display name and avatar URL
- Hashed password (we never store plaintext passwords)
- Phone number, if you choose to register or verify by phone
- Optional profile fields you voluntarily provide: bio, website, social media handles
1.2 Payment information
We use Stripe, Inc. as our payment processor. When you make a payment:
- We do not see or store your full credit/debit card number, CVC, or bank account details. All payment data is collected directly by Stripe in their hosted checkout environment.
- We receive only the transaction outcome (success/failure), the amount, the last 4 digits of the card (if applicable), and a Stripe-issued payment identifier, which we store for accounting, refund, and dispute handling.
- Stripe's own privacy practices govern how they handle the underlying card data. See Stripe's Privacy Policy.
1.3 Usage data
When you call AI agents (skills) on the Service, we record:
- The skill called, timestamps, duration, success/failure status
- The credits cost of each call
- Input parameters and output you submit/receive (stored short-term so you can review your call history)
- Files you upload as input or that are produced as output (stored on our infrastructure for the duration described in Section 4)
1.4 Technical and log data
- IP address, browser type and version, operating system, device type
- Pages you visit, links you click, referring URL
- HTTP request logs and error traces, used to diagnose problems and prevent abuse
1.5 Cookies and similar technologies
We use a small number of essential cookies and browser local storage:
- Authentication tokens — to keep you logged in
- Language preference — to remember your selected interface language
- Anti-fraud tokens — used by Stripe to protect against payment fraud
We do not use third-party advertising cookies. We do not track you across other websites.
1.6 Mobile device permissions (AgentCab mobile app only)
The AgentCab mobile app may request access to certain device features, but only on demand when you trigger a feature that needs them, and only after you grant explicit permission via the operating system. Specifically:
- SMS (read/send) — for fraud detection and security skills
- Call log — for security analysis skills
- Contacts — for contact-management skills
- Photos / storage — for photo organization and file management skills
- Calendar — for schedule management skills
- Location — for location-aware skills
- Camera — for image capture and scanning skills
- Microphone — for voice recording skills
- Bluetooth — for device information collection
- Notifications — for task completion alerts
- Installed apps list — for device management skills
Denying any permission affects only the related skills and does not block you from using the rest of the Service. You can revoke any permission at any time via your operating system settings.
2. How We Use Your Information
We use the information described above for the following purposes:
- Service operation — to authenticate you, route your AI calls, deliver results, maintain your wallet balance and call history
- Payment processing — to settle your purchases and to honor refunds, chargebacks, and disputes
- Security and fraud prevention — to detect abuse, prevent payment fraud, enforce our Terms of Service
- Customer support — to respond to inquiries you send us
- Service improvement — to diagnose bugs, measure aggregate performance, prioritize feature development
- Legal compliance — to comply with applicable laws, regulations, court orders, and lawful government requests
We do not use your data to train AI models without your explicit consent. We do not sell your personal information to anyone.
3. How We Share Information
We share personal data only with:
- Service providers — Stripe (payments), our cloud hosting providers, transactional email senders, error monitoring tools. Each is contractually bound to use your data only to serve us and not for their own purposes.
- Skill creators — when you call a skill, the input you provide is forwarded to the creator's worker process so they can fulfil your request. The creator can see the input parameters and any files you upload. We recommend you review what each skill requires before calling it.
- Legal compliance — when required by law, subpoena, court order, or to protect the rights, safety, or property of AgentCab, our users, or the public.
- Business transfers — if AgentCab is acquired, merged, or sells assets, your data may be transferred to the acquiring party, subject to this Privacy Policy.
4. Data Retention
- Account data — retained as long as your account is active. If you delete your account, we delete it within 30 days, except where retention is required by law or for ongoing dispute resolution.
- Call history and outputs — retained for 12 months for your reference, then automatically deleted.
- Uploaded files — temporary input/output files are deleted after a short window (typically 24 hours) once a call completes; example files attached to published skills are retained as long as the skill is published.
- Payment records — retained for 7 years to comply with tax and accounting requirements in our jurisdiction (Hong Kong).
- Logs — operational logs are retained for up to 90 days for debugging and security review.
5. Your Rights
Subject to applicable law, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate or incomplete data
- Deletion — ask us to delete your data (also called the “right to be forgotten”)
- Portability — receive your data in a structured, machine-readable format
- Restriction — ask us to limit how we process your data
- Objection — object to certain uses of your data
- Withdraw consent — where processing relies on your consent
For California residents (CCPA / CPRA): You also have the right to know what categories of personal information we have collected, the categories of sources, the purposes for collection, and the categories of third parties with whom we share. You have the right not to be discriminated against for exercising any of these rights. We do not sell or share personal information for cross-context behavioral advertising.
For European Union / UK / EEA residents (GDPR / UK GDPR): Our legal bases for processing are: (a) performance of a contract (operating the Service for you), (b) compliance with legal obligations, (c) legitimate interests in fraud prevention and service improvement, and (d) your consent where applicable. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@agentcab.ai. We will respond within 30 days.
6. Data Security
- All data transmission between you and AgentCab uses HTTPS / TLS encryption.
- Passwords are stored only as one-way bcrypt hashes.
- Payment card data is handled exclusively by Stripe and never touches our servers.
- We restrict employee access to personal data on a need-to-know basis.
- We monitor for security incidents and will notify affected users without undue delay if we discover a breach affecting your data.
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
7. International Data Transfers
AgentCab is operated from Hong Kong SAR. If you access the Service from outside Hong Kong, your information may be transferred to, stored, and processed in Hong Kong or other jurisdictions where our service providers operate. By using the Service, you consent to this transfer.
Where required, we rely on Standard Contractual Clauses or equivalent legal mechanisms to ensure your data receives adequate protection during cross-border transfers.
8. Children's Privacy
AgentCab is not intended for children under 13 (or under 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other reasons. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify you by email or via an in-product notice. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at:
- Email: support@agentcab.ai
- For privacy-specific requests: privacy@agentcab.ai