Privacy Policy
Last Updated: August 22, 2026
INDUSTRIAL-GRADE PRIVACY
This policy explains what data Agentiff.AI collects, how we use it, and how users can control connected accounts and workflow data.
1. INFORMATION WE COLLECT
1.1 Direct Information
- Account Data: Email and encrypted credentials (scram-sha-256).
- Workflow Context: Data snippets required for human-in-the-loop approval decisions.
- Payment Data: Handled exclusively by Stripe (PCI-DSS compliant).
1.2 Free Resources, Forms, and Marketing
When you request a free resource, such as a skills bundle, workflow audit, or Knowledge Base guide, we collect the information you submit so we can deliver it and understand which resources are useful. This may include your email address, optional name and phone number, country or region, the resource requested, referring page or campaign, and a record of any consent you gave, including the wording, version, and time.
- Resource delivery does not require consent to receive marketing emails. If you do not opt in, we will still deliver the resource but will not send you marketing emails.
- Marketing email is sent only where you have separately opted in. You can unsubscribe at any time using the link in an email or by contacting [email protected].
- Request records may be kept in our customer database and synchronised to HubSpot. If you opt in to marketing email, your contact details may also be synchronised to Mailchimp.
- We may send a hashed lead event to Meta for campaign measurement only when you have accepted optional marketing cookies. We do not sell lead data.
- Some qualification forms may be provided by Typeform. The form will identify when that service is being used and its handling is subject to its own privacy terms.
1.3 AI & Execution Metadata
To provide deterministic AI orchestration, we log:
- LLM Decision Paths: Model used, token consumption, and reasoning context.
- Tool Call History: Which internal tools were triggered by an agent.
- Approval Records: Timestamps and identities of human approvers.
1.4 System Observability & Diagnostics
To maintain platform stability and debug workflow failures, we collect system telemetry and server logs via self-hosted observability tools (Grafana and Loki). These logs are stored on our private infrastructure, are never shared with third-party logging vendors, and are automatically purged after 90 days.
2. DATA PROTECTION & SOVEREIGNTY
2.1 Cookies and Similar Technologies
We use essential cookies and similar storage technologies to operate the site, remember security and consent choices, and provide requested forms and downloads. Optional marketing technologies, including HubSpot and Meta measurement, are loaded only after you accept the marketing category in the cookie controls. You can change that choice at any time using the Cookie Preferences link in the footer. Rejecting optional cookies does not prevent resource downloads, lead forms, or account use.
2.2 Local-First Security
For n8n-hosted workflows, your n8n API keys and third-party credentials are stored locally on your device via the Agentiff.AI application. These secrets are used to provision your host directly and are not transmitted to or stored on Agentiff.AI's central servers.
2.3 Credential Isolation
Your integration credentials (Google, Slack, etc.) are encrypted at rest in our vault using AES-256-GCM and decrypted only at sync time when provisioning your n8n instance. Credentials are never stored in workflow execution history or exposed to AI agents.
2.4 Infrastructure Security
- Network Security: Application traffic is protected in transit using TLS and other network-layer safeguards that may change as our infrastructure evolves.
- PII Protection: Automated pattern-based PII scanning is active for all AI inputs. No customer PII is stored in long-term vector memory.
- Local Encryption: Secrets on your device are protected by AES-256-GCM encryption using a device-derived key.
3. DATA RETENTION
- Approval Context: Deleted within 24 hours of decision.
- Diagnostic & Audit Logs: Retained for up to 90 days for security, troubleshooting, and operational monitoring.
- Backups: Encrypted offsite backups are maintained for 7 days.
4. THIRD-PARTY DATA HANDLING
- OpenAI/Anthropic: Context is sent for real-time processing only. We opt-out of training on your data via API enterprise controls.
- Infrastructure: Data is processed across a hybrid-cloud environment utilising DigitalOcean and Hetzner bare-metal servers. SSL/TLS encryption is enforced for all data in transit.
- Marketing and CRM: HubSpot, Mailchimp, Meta, and Typeform may process the limited lead, consent, or form data described above when their feature is enabled. Contact [email protected] for the current subprocessor list or a data-processing agreement.
5. GOOGLE API SERVICES USER DATA
Agentiff.AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.1 What Google User Data We Access
If you choose to connect a Google account, Agentiff.AI only requests the Google user data needed for the workflow feature you explicitly enable. This may include:
openid,email, andprofile— to authenticate your account with Google Sign-In and receive your basic Google account profile, such as name, email address, and Google account ID.https://www.googleapis.com/auth/spreadsheets— to read rows from Google Sheets you choose and write workflow outputs, drafts, enrichment data, or status updates back to those sheets.
We do not request permission to send, modify, delete, or permanently manage your Gmail messages, mailbox settings, Google Drive files, Google Calendar events, or other Google data unless a separate Google scope is clearly presented and approved by you for a specific feature.
5.2 How We Use Google User Data
We use Google user data only to provide and improve the user-facing feature you requested, such as reading selected Google Sheet rows, generating workflow output, and writing that output back to your selected sheet. We do not use Google user data for advertising, marketing profiling, sale to third parties, or any unrelated purpose.
Google user data is not used to train generalized AI or machine learning models. We do not allow humans to read your Google user data except when necessary to provide support, investigate abuse, comply with applicable law, or with your explicit consent.
5.3 Storage, Retention, and Security
Agentiff.AI stores Google OAuth tokens only as needed to maintain your authorized connection. Google Sheets data accessed through Google APIs is processed only for the requested workflow run and is not stored as a permanent copy on Agentiff.AI servers unless you explicitly configure a workflow destination that saves the result under your control.
Any retained Google-connected credentials are encrypted at rest and protected by our access controls. Workflow content and diagnostic data are retained only as described in the retention section of this policy.
5.4 Sharing and Disclosure
We do not sell Google user data. We do not share Google user data with third parties except:
- to provide the feature you requested within your configured workflow,
- to service providers acting on our behalf under confidentiality obligations,
- for security, fraud prevention, or legal compliance, or
- with your explicit direction or consent.
5.5 Revoking Access and Deletion
You can revoke Agentiff.AI's access to your Google account at any time via your Google Account permissions page. You can also disconnect the Google integration from within Agentiff.AI. Once access is revoked, Agentiff.AI will no longer be able to access new Google user data from that account. You may also request deletion of stored Google-connected account data by contacting us at [email protected].
6. KNOWLEDGE BASE CONTENT
If you use Agentiff's Knowledge Base feature, you can upload documents or point us at web pages to crawl. Here's exactly what happens to that content:
- What we store. The files or pages you add, plus a mathematical representation of that content ("embeddings") that lets our AI search and answer questions about it.
- Where it's stored. Your Knowledge Base content is stored on servers in Frankfurt, Germany, operated by Hetzner Online GmbH. Backups are stored encrypted with Bunny (BunnyWay d.o.o.), also in the EU.
- Who else touches it. To generate embeddings and answer your questions, your content is sent to OpenAI and/or Anthropic's commercial APIs. Both currently commit contractually not to train their models on your data by default. We also use Stripe for payments and Cloudflare for security/network delivery — neither sees your Knowledge Base content.
- How long we keep it. We retain your Knowledge Base content until you delete it, or until you close your account, whichever comes first. Deleting a document removes the document, its embeddings, and any cached answers derived from it.
- Who owns it. You do. You're uploading your own content, and we process it on your behalf and instruction — we don't use it for anything except providing the Knowledge Base feature back to you.
- What you shouldn't upload. Please don't upload sensitive personal information — health records, government ID numbers, biometric data, or similar — to the Knowledge Base. See our Terms of Service for the full policy.
- Deleting your data. You can delete individual documents or your entire Knowledge Base at any time from your workspace settings. To delete your account and all associated data, email [email protected]. We'll complete account-deletion requests sent to that address within 30 days.
Availability. Agentiff.AI is currently offered to customers outside the European Union and United Kingdom, with the initial launch focused on New Zealand, Australia, and the United States. If you're located in the EU or UK, the product and lead-magnet offers aren't available to your account yet.
7. YOUR CHOICES AND COMPLAINTS
You can ask us to access, correct, delete, or explain our use of your personal information by contacting [email protected]. Marketing emails include an unsubscribe link, and withdrawing marketing consent does not withdraw your consent to essential service communications. We will handle privacy complaints through the same address and explain the outcome. New Zealand users may also contact the Office of the Privacy Commissioner if they remain dissatisfied.
Questions? Contact our privacy team at [email protected]