PRIVACY POLICY

Last updated March 26, 2026


This Privacy Notice for RaegentAI ('we', 'us', or 'our') describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you visit our website at raegentai.com, use RaegentAI, or engage with us in other related ways.


Questions or concerns? Contact us at hello@raegentai.com.


SUMMARY OF KEY POINTS

What personal information do we process? We may process email addresses, names, usernames, passwords, contact or authentication data, device data, and approximate location data depending on how you interact with our Services.


Do we process sensitive personal information? No. We do not process sensitive personal information.


Do we collect information from third parties? No. We do not collect any information from third parties.


How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.


How do we keep your information safe? We use AES-256-GCM encryption, SHA-256 token hashing, row-level security, Cloudflare DDoS protection, and automated security monitoring. No system is 100% secure, but we implement industry-standard measures.


What are your rights? Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data. Visit raegentai.com/contact to exercise your rights.


TABLE OF CONTENTS

  1. What Information Do We Collect?
  2. How Do We Process Your Information?
  3. What Legal Bases Do We Rely On?
  4. When And With Whom Do We Share Your Personal Information?
  5. Do We Offer Artificial Intelligence-Based Products?
  6. Is Your Information Transferred Internationally?
  7. How Long Do We Keep Your Information?
  8. How Do We Keep Your Information Safe?
  9. Do We Collect Information From Minors?
  10. What Are Your Privacy Rights?
  11. Controls For Do-Not-Track Features
  12. Do United States Residents Have Specific Privacy Rights?
  13. Proxy Infrastructure
  14. Provider Endpoint Protection
  15. Access Token Security
  16. Automated Security Monitoring And Decision-Making
  17. Data Minimisation
  18. Do We Make Updates To This Notice?
  19. How Can You Contact Us About This Notice?
  20. How Can You Review, Update, Or Delete The Data We Collect From You?
  21. Cookies And Tracking Technologies

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

We collect personal information that you provide to us.


We collect personal information that you voluntarily provide when you register on the Services, express an interest in obtaining information about us or our products, or otherwise contact us. The personal information we collect may include:

  • Email addresses
  • Names
  • Usernames
  • Passwords
  • Contact or authentication data

Sensitive Information. We do not process sensitive information.


Payment Data. We may collect data necessary to process your payment if you choose to make purchases. All payment data is handled and stored by Stripe. You may find their privacy notice at stripe.com/privacy.


All personal information you provide must be true, complete, and accurate. You must notify us of any changes.


Information automatically collected

Some information — such as your IP address and browser characteristics — is collected automatically when you visit our Services.


We automatically collect certain information when you visit, use, or navigate the Services. This may include device and usage information such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, and other technical information. The information we collect includes:

  • Log and Usage Data. IP address, device information, browser type, date/time stamps, pages viewed, searches, and other actions you take in the Services.
  • Device Data. Information about your computer, phone, tablet, or other device including IP address, device identification numbers, location, browser type, hardware model, and operating system.
  • Location Data. We collect approximate location data derived from your IP address at the server level. This occurs independently of your device's location settings and cannot be disabled by them. Use of a VPN or proxy may affect the location we derive from your IP.

2. HOW DO WE PROCESS YOUR INFORMATION?

We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.


We process your personal information for the following purposes:

  • To facilitate account creation and authentication and otherwise manage user accounts
  • To process API access token generation and usage tracking
  • To deliver and facilitate delivery of services to the user
  • To verify provider agent submissions
  • To respond to user enquiries and offer support
  • To send administrative information such as changes to our terms and policies
  • To fulfil and manage your orders including subscriptions and payments
  • To request feedback and contact you about your use of our Services
  • To send marketing and promotional communications (where permitted by law and you have not opted out)
  • To protect our Services by detecting and preventing fraud, abuse, and security threats
  • To store and display playground query results for your personal use via persistent results pages
  • To identify usage trends and analyse aggregated, anonymised data
  • To comply with our legal obligations

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

We only process your personal information when we have a valid legal reason. Under UK/EU GDPR, we rely on the following legal bases:

  • Consent. We may process your information if you have given us permission for a specific purpose.
  • Performance of a contract. We process your information when necessary to fulfil our contractual obligations to you.
  • Legitimate interests. We may process your information for our legitimate business interests, such as security monitoring and fraud prevention, provided these do not override your rights.
  • Legal obligations. We may process your information where required to comply with applicable law.
  • Vital interests. We may process your information where necessary to protect your vital interests or those of a third party.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We share data only with the following third-party service providers to operate the platform:

  • Supabase — database and authentication
  • Vercel — hosting and deployment
  • Resend — transactional email delivery
  • Loops — marketing email and waitlist management
  • Cloudflare — DDoS protection, DNS, and analytics
  • Stripe — payment processing
  • Anthropic — AI model processing for playground queries and demo agents

All third-party processors listed above are bound by Data Processing Agreements (DPAs) and are contractually required to process your data only on our instructions and in accordance with UK GDPR. We will never sell your personal data to any third party. We may disclose information where required by law, to prevent fraud or security threats, or in connection with a business transfer or acquisition.


5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

RaegentAI is a marketplace for third-party AI agents. We do not build or operate the AI agents listed on the platform. We provide the infrastructure through which renters access those agents via secure tokens.


Direct API calls (via access token): Only metadata (agent ID, response time, HTTP status code) is logged. Request and response content from direct API calls is not stored by RaegentAI.


In-app playground (natural language mode): When you submit a query via the playground, your input, the translated query, and the agent's output are stored in your personal usage history. These records are scoped to your account, accessible only to you, and are used solely to provide persistent results pages. You may request deletion of your usage history at any time by contacting us at hello@raegentai.com. Inputs sent through the playground are also processed by Anthropic's API; see Anthropic's privacy policy for details on how they handle this data.


Third-party agent providers: When your query is forwarded to a third-party agent endpoint, that data is processed by the relevant provider. RaegentAI is not responsible for how providers handle data at their endpoints. Providers are contractually bound by our Data Processing Agreement (see Terms, §34), but you should review the documentation of any agent you use for details of the provider's own data practices.


6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

Our infrastructure providers (Supabase, Vercel, Cloudflare, Stripe) may process data in multiple countries. Anthropic, which processes playground query inputs, is based in the United States. When your information is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including standard contractual clauses (SCCs) and UK International Data Transfer Agreements (IDTAs) where required under UK GDPR. You may request details of the specific safeguards in place by contacting us at hello@raegentai.com.


7. HOW LONG DO WE KEEP YOUR INFORMATION?

We retain your personal information for as long as your account is active. Geolocation data is retained for 6 months. Playground usage history (query inputs and outputs) is retained for the duration of your account and may be deleted at any time upon request. Upon account termination, personal data is retained for up to 12 months to handle disputes, chargebacks, or legal requests, then permanently deleted. If we have no ongoing legitimate business need to process your information, we will delete or anonymise it.


8. HOW DO WE KEEP YOUR INFORMATION SAFE?

We implement the following security measures:

  • AES-256-GCM encryption for sensitive provider data at rest
  • SHA-256 hashing for all API access tokens
  • Row-level security policies on all database tables
  • Cloudflare DDoS protection and Web Application Firewall
  • Automated detection and blocking of malicious API activity
  • HTTPS enforced across all services

Despite our measures, no electronic transmission over the internet can be guaranteed to be 100% secure. We cannot promise that hackers or cybercriminals will never be able to defeat our security.


Data breach notification: In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, where feasible and where required by law. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.


9. DO WE COLLECT INFORMATION FROM MINORS?

No. We do not knowingly collect data from or market to children under 18 years of age. If you become aware of any data we may have collected from minors, please contact us at hello@raegentai.com.


10. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on your location, you may have the following rights regarding your personal data:

  • Right to access the personal data we hold about you
  • Right to correct inaccurate or incomplete data
  • Right to erasure ('right to be forgotten')
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local data protection authority

To exercise your rights, visit raegentai.com/contact or email hello@raegentai.com. We will respond to all valid requests within one calendar month.


UK residents may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113.


Withdrawing consent: If we are relying on your consent to process your personal information, you have the right to withdraw at any time. This will not affect the lawfulness of processing before withdrawal.


Opting out of marketing: You can unsubscribe from our marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.


11. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems include a Do-Not-Track ('DNT') feature. As no uniform technology standard for recognising and implementing DNT signals has been finalised, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.


12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

If you are a resident of California, Colorado, Connecticut, Utah, or Virginia, you may have specific rights under applicable state privacy laws, including the right to know what personal data we collect, the right to delete your data, the right to opt out of sale of personal data, and the right to non-discrimination. We do not sell personal data as defined under these laws. To exercise your rights, contact us at hello@raegentai.com.


13. PROXY INFRASTRUCTURE

RaegentAI operates a secure proxy layer between renters and providers. All API requests made by renters are routed through RaegentAI's infrastructure. For direct API calls made via access tokens, only metadata (timestamps, status codes, response times) is logged — request and response content is not stored. For queries made through the in-app playground, inputs and outputs are stored in your personal usage history to provide persistent results pages. See Section 5 for full details.


14. PROVIDER ENDPOINT PROTECTION

Provider API endpoint URLs and authentication credentials are encrypted at rest using AES-256-GCM encryption. These details are never disclosed to renters or any third party under any circumstances.


15. ACCESS TOKEN SECURITY

API access tokens issued to renters are hashed using SHA-256 before storage. The plaintext token is displayed only once upon issuance and is not recoverable by RaegentAI thereafter.


16. AUTOMATED SECURITY MONITORING AND DECISION-MAKING

RaegentAI employs automated systems to monitor API usage for malicious activity, abuse, and security threats. Accounts and tokens found to be engaged in abusive behaviour may be suspended or permanently banned without prior notice. Where an automated decision materially affects you, you have the right to request human review of that decision by contacting us at hello@raegentai.com.


17. DATA MINIMISATION

RaegentAI collects only the minimum personal data necessary to operate the platform. For direct API calls, only metadata is retained. Playground query inputs and outputs are stored in your personal usage history and are accessible only to you; we do not access or use your playground query content for any purpose other than displaying your results. You may request deletion of your usage history at any time.


18. DO WE MAKE UPDATES TO THIS NOTICE?

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated date at the top of this page. For material changes — such as new categories of data collected, new third-party processors, or changes to your rights — we will notify you by email to the address associated with your account at least 14 days before the change takes effect. Continued use of the Services after that date constitutes acceptance of the updated notice.


19. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, email us at hello@raegentai.com or write to us at:


RaegentAI

First Floor, Swan Buildings

20 Swan Street

Manchester, M4 5JW


20. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete it. To submit a request, visit raegentai.com/contact or email hello@raegentai.com. We will respond within one calendar month of receipt.


21. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to operate the Services. Under the UK Privacy and Electronic Communications Regulations (PECR), we are required to inform you of the cookies we use and obtain your consent where required.


The following cookies may be set when you use the Services:

  • Essential cookies — Required for the Services to function. These include session authentication cookies set by Supabase and security cookies set by Cloudflare. These cannot be disabled without impairing core functionality.
  • Analytics — We use Cloudflare Web Analytics, which is cookieless and does not track individual users or set any cookies. It collects only anonymised, aggregated data (page views, visit duration, referrer information) and does not require PECR consent.
  • Payment cookies — Stripe may set cookies during the payment flow to prevent fraud and ensure payment security. See stripe.com/privacy for details.

You can manage or disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from logging in or using core features of the Services. We do not use advertising or third-party tracking cookies.