See what's new →
Legal & Compliance

Privacy Policy

Last updated: October 1, 2026

1. Executive Summary & Commitment

At AgentFlow ("we", "our", or "us"), we operate on a clear and unyielding principle: your data belongs to you. We do not sell your personal information, nor do we use your proprietary customer data, agent prompts, knowledge base uploads, or conversation logs to train public artificial intelligence models.

2. Information We Collect

To provide and continuously improve our agent deployment platform, we collect information across three main categories:

  • Account and Profile Information: Name, business email, organization name, authentication credentials, and billing details provided during registration.
  • Agent Configuration Data: Agent instructions, system prompts, knowledge source documents (PDFs, URLs, text snippets), tool integration credentials (OAuth tokens, API keys encrypted with AES-256), and channel settings.
  • Runtime Telemetry & Logs: Session timestamps, task execution latencies, token consumption counts, and error stack traces necessary to monitor agent performance and uptime.

3. How We Use Your Information

We process your data strictly to:

  • Deploy, operate, and maintain your custom AI agents across your selected communication channels.
  • Execute tool integrations, API webhooks, and database queries configured by your administrators.
  • Generate real-time analytics, conversation transcripts, and lead qualification scores in your dashboard.
  • Facilitate customer billing, usage metering, and account authentication.
  • Investigate security incidents and enforce our terms of service.

4. Model Training & LLM Isolation

We partner with enterprise LLM inference providers under strict Zero Data Retention (ZDR) and Business Associate Agreements. Under no circumstances is your proprietary data submitted to general training corpuses:

Your prompts, uploaded knowledge embeddings, and agent outputs are NEVER shared with third parties to train foundation models.

5. Data Retention & Deletion

You maintain complete control over data retention policies within the AgentFlow settings panel. You can configure automatic log purging (e.g. delete conversation transcripts after 30, 60, or 90 days). When an organization account is closed, all associated knowledge vectors, credentials, and conversation logs are permanently erased within 14 calendar days.

6. Security & Encryption Standards

We implement industry-leading technical measures to safeguard customer information, including:

  • End-to-end encryption for data in transit via TLS 1.3.
  • AES-256 encryption at rest for all database volumes, vector indices, and backups.
  • Isolated multi-tenant container execution with role-based access control (RBAC).
  • Routine third-party penetration testing and vulnerability scans.

7. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you have the right to request access to, rectification of, or permanent erasure of your personal information. To exercise any of these rights, please submit a request to our Data Protection Officer at privacy@agentflow.ai.

8. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact our privacy and legal team at:

AgentFlow Legal Department

548 Market Street, Suite 92000

San Francisco, CA 94104

Email: privacy@agentflow.ai