1. Who is responsible
IaGenify LLC, a limited liability company in Wyoming, United States, is the controller of the personal data described here. Write to contact@iagenify.com for anything in this policy, including a request about your data.
Where you use IaGenify to process personal data belonging to other people — the contents of a database you connect, a mailbox you run, a site you publish — you are the controller of that data and we act as your processor, under these terms.
2. What we collect
- Account
- Your email address, your display name and picture if you provide one or sign in with a third-party account, your plan, and your credit balance.
- Authentication
- Sign-in events, verification codes, and session records. A session records the device characteristics the SDK reports — runtime, machine identifier, host name — so a session can be identified and revoked.
- Usage and billing
- Model calls with their token counts and cost, credit transactions, orders and payment records. Payment card details are handled by our payment processor; we do not receive or store them.
- Agent run records
- For each tool call: the tool, a short target such as a path or a query, whether it succeeded, what it cost and how long it took. Conversation messages are kept when you create a session with memory enabled.
- Content you connect
- Files you upload, documents you index, the contents of storages we host for you, mailbox contents and attachments, and anything you deploy. We process this to provide the service you asked for.
- Technical
- IP address and request metadata, used for security, abuse prevention and rate limiting.
3. What we do not collect
The contents returned by an agent's tools — what a file contained, what a command printed, what a database query returned, what a page said — are not stored by the platform. They remain on the device where the agent ran. The record we keep is an activity trace, not an archive of your work.
We do not use your content to train models, and we do not sell personal data.
This site uses no analytics and no advertising cookies. See the Cookie Policy.
4. Why we use it, and on what basis
If the GDPR or the UK GDPR applies to you, the legal basis for each use is below.
- To provide the service
- Performance of our contract with you. This covers running model calls, operating storages, delivering mail, serving what you deploy, and keeping your account working.
- To bill you
- Performance of our contract, and compliance with a legal obligation for tax and accounting records.
- To keep the platform secure
- Our legitimate interest in preventing abuse, fraud and unauthorized access, and in protecting other customers.
- To support you
- Performance of our contract, and our legitimate interest in answering what you ask us.
- To improve the service
- Our legitimate interest in understanding operational behaviour — error rates, cost, latency — using operational records rather than the contents of your work.
- To comply with the law
- Compliance with a legal obligation, where we are required to retain or disclose something.
5. Who else processes it
We use a small number of service providers to operate the platform. They act on our instructions, are bound by contract, and receive only what their function requires.
- Cloud infrastructure
- Hosting of the platform, its databases and object storage.
- Model providers
- The provider of whichever model you select receives the prompt and attachments for that call, and processes them under its own terms.
- Payment processing
- Taking payment and holding card details, which we never receive.
- Email delivery
- Sending platform messages and the mail you send from your mailboxes.
- Network and DNS
- Serving this site, the hosting product, and the DNS zones of attached domains.
We will name the specific providers behind these categories on request — write to contact@iagenify.com. We will also give notice before adding a category of processor that materially changes how your data is handled.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
6. International transfers
We are established in United States, and our providers may process data in other countries. Where personal data protected by the GDPR or the UK GDPR is transferred outside the EEA or the UK, we rely on an appropriate safeguard — in most cases the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable.
You can ask us for details of the safeguard that applies to a given transfer at contact@iagenify.com.
7. How long we keep it
- Account data
- While your account exists, and for a reasonable period afterwards to resolve disputes and meet legal obligations.
- Billing records
- As long as tax and accounting law requires, which is longer than the life of the account.
- Agent sessions and run records
- Until you delete the session, or your account is closed. Deleting a session removes the account's copy, the device journal and its checkpoints.
- Content in your storages
- Until you delete it, or your account is closed.
- Mailbox contents
- Until you delete the message or the mailbox. Deleting a message from the trash removes it permanently, along with its attachments.
- Security and abuse records
- For as long as needed for the purpose, and no longer than necessary.
Deletion is not always instantaneous: backups and logs roll over on their own schedule, and a copy may persist briefly in them before it is overwritten.
8. Your rights
If the GDPR or the UK GDPR applies to you, you have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to its processing, to receive a copy in a portable format, and to withdraw consent where we relied on it. You also have the right to complain to your supervisory authority.
Write to contact@iagenify.com and include enough detail for us to identify your account safely. We answer within one month, and will tell you if we need longer because a request is complex.
We do not charge for a request unless it is manifestly unfounded or excessive, in which case we will say so before doing anything.
9. California residents
If you are a California resident, the CCPA as amended by the CPRA gives you specific rights: to know what personal information we collect and why, to access it, to delete it, to correct it, and not to be discriminated against for exercising them.
In the twelve months before the date of this policy, the categories we collect are identifiers (such as your email address), commercial information (your plan and transactions), internet or network activity (request metadata), and the content you choose to give us. We collect them for the business purposes described in section 4.
We do not sell personal information and we do not share it for cross-context behavioural advertising. To exercise a right, write to contact@iagenify.com. You may use an authorized agent, and we will ask for proof of their authority.
10. Children
The service is not for people under 18, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, write to us and we will delete it.
11. Security
API keys are exchanged for short-lived signed sessions. Credentials you give us for a connected system are encrypted at rest. Outbound requests the platform makes on your behalf are checked against private and internal addresses before they are sent, and redirects are re-checked rather than followed blindly.
No system is perfectly secure. If a breach affects your personal data and the law requires it, we will notify you and the relevant authority within the required time.
12. Changes
We may update this policy. The date at the top is the version in force. For a material change we will give notice before it takes effect.
The English version of this policy governs; a translation is provided for convenience only.
These documents are written in English, and the English version governs. Questions about any of these reach contact@iagenify.com.
Jurídico