Privacy Policy

How Ageontic collects, uses, protects, and shares personal data.

Last updated: July 16, 2026

1. Introduction

This Privacy Policy explains how Ageontic ("we", "us") handles personal data when you use our website, customer portal, APIs, and hosted AI agent services (the "Services"). It applies to visitors of our website, holders of Ageontic accounts, and — as described in Section 10 — people who chat with AI agents that our customers deploy through the Services.

For account holders, Ageontic decides how account and billing data is processed. For content processed inside a customer's agent (such as chat conversations with that agent), the customer who operates the agent determines the purposes of processing, and we process that data on their behalf to provide the Services.

2. Information We Collect

  • Account data: your email address, a hashed password (we never store passwords in plain text), and optional security settings such as multi-factor authentication. If you sign in with Google, we receive your email address from Google.
  • Billing data: payments are processed by Stripe. We store subscription status, plan, currency, and billing history references; full card details never touch our servers.
  • Agent content: the instructions, documents, website content, and API data you upload to or direct the Services to fetch for your agents.
  • Chat data and leads: conversations between visitors and hosted agents, and contact details a visitor chooses to share in chat (such as name, email, or phone number). Captured contact details and calendar booking titles are encrypted at rest.
  • Calendar integration data: if you connect a calendar provider (such as Google Calendar or Calendly), we store the connection tokens encrypted and use them only to provide the calendar features you enable — checking availability and creating, rescheduling, or cancelling events as directed through your agent.
  • Usage data: server logs needed to operate and secure the Services, and — only with your consent — website analytics as described in our Cookie Policy.

3. How We Use Information

  • Providing, operating, and improving the Services, including generating AI responses for your agents.
  • Sending transactional email (via AWS SES) such as account, billing, and — if you enable them — lead notification messages.
  • Processing payments, preventing fraud, and maintaining billing records.
  • Securing the Services, debugging, and providing support.
  • Complying with legal obligations.

We do not sell personal data, and we do not use your content or your visitors' conversations for advertising.

4. AI Processing

To generate agent responses, chat messages and relevant excerpts of the knowledge you configured are sent to our AI model provider (OpenAI) via its API. This processing is governed by the provider's API terms, under which submitted data is not used to train their models. We do not use your content or your visitors' conversations to train models of our own.

5. Sharing & Service Providers

We share personal data only with service providers that help us run the Services, and only to the extent needed:

  • OpenAI — AI model responses and text embeddings.
  • Stripe — payment processing and subscription billing.
  • Amazon Web Services (SES) — transactional email delivery.
  • Google — sign-in with Google, Google Calendar integration (if you connect it), and consent-based analytics.
  • Calendly — calendar scheduling integration (if you connect it).
  • Hosting and infrastructure providers that run our servers.

We may also disclose information where required by law or to protect the rights, safety, or security of Ageontic, our customers, or others.

6. Google User Data

Ageontic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section describes exactly what Google user data we access, how we use it, how it is shared, how it is stored and protected, and how long we keep it and how you can have it deleted.

6.1 Data we access

  • Sign in with Google (optional): if you choose to sign in with Google, we receive the email address of your Google Account, which we use as your account login identifier. We do not access any other Google data through sign-in.
  • Google Calendar connection (optional): if you connect a Google Calendar to one of your agents, we request only the following granular OAuth scopes:
    • calendar.calendarlist.readonly — a read-only list of your calendars (names, IDs, and timezones), used solely so you can pick which calendar the agent should use and so we can default the correct timezone.
    • calendar.freebusy — free/busy availability information for the calendar you selected, used solely to check open time slots when a visitor asks to book.
    • calendar.events — events on the calendar you selected, used solely to create, reschedule, or cancel appointments that you or your agent's visitors explicitly request.
  • We also receive the email address of the connected Google Account so you can identify the connection in your portal. We do not request or access Gmail, Google Drive, Contacts, or any other Google data.

6.2 How we use it

Google Calendar data is used only to provide the user-facing calendar features you enable: showing you your calendar list during setup, checking availability, and creating, rescheduling, or cancelling events as directed through your agent, with every change confirmed before it is made. Limited event and availability details (such as offered time slots or a booked appointment's time) are processed by our AI model provider (OpenAI) solely to generate the agent's replies within that booking conversation — never for model training. We do not use Google user data for advertising, do not sell it, and do not use it to develop or train AI or machine-learning models.

6.3 How it is shared

We do not transfer Google user data to third parties except: (a) to Google itself, to carry out the calendar actions you request; (b) to our AI model provider as described above, strictly to generate the agent's responses in a booking conversation; (c) to the infrastructure providers that host our servers, who process it only on our behalf; (d) with your explicit consent; or (e) where required by law. When a booking is made, a summary (event title, time, and event link) is stored on the related conversation record and is visible only to you, the account holder. Humans at Ageontic do not read Google user data except with your explicit permission, where necessary for security or abuse investigation, or to comply with applicable law.

6.4 How it is stored and protected

Google OAuth access and refresh tokens are stored encrypted at rest in our database, in addition to TLS encryption for all data in transit. Tokens are held only in our backend systems and are never placed inside agent containers or exposed to the browser. Stored booking titles are encrypted at rest. Access to production systems is restricted to authorized personnel.

6.5 Retention and deletion

Free/busy availability data is used transiently to answer a booking request and is not stored. OAuth tokens and the connected account email are retained only while your calendar connection is active. You can stop our access at any time by:

  • disconnecting the calendar from your agent's Integrations panel in the portal;
  • revoking Ageontic's access in your Google Account permissions, which immediately invalidates our stored tokens; or
  • deleting your Ageontic account, which deletes stored calendar connections and their tokens.

You may also email info@ageontic.com at any time to request deletion of the Google user data we hold about you; we will complete such requests within 30 days.

7. Cookies

Our use of cookies and similar technologies — including the consent notice for analytics — is described in the Cookie Policy.

8. Security

Data is encrypted in transit (TLS). Sensitive fields — including captured visitor contact details and calendar connection tokens — are additionally encrypted at rest. Integration tokens are held only in our backend and are never placed inside agent containers. Access to production systems is restricted.

9. Data Retention

We keep personal data for as long as your account is active or as needed to provide the Services. When you delete an agent or your account, associated content is deleted or de-identified, except for records we must keep for legal, billing, or security purposes (for example, billing history is retained as required by tax and accounting law).

10. Visitors Who Chat With Customer Agents

If you chatted with an AI agent hosted by Ageontic on another business's website, that business controls the conversation data and any contact details you shared, and we process them on the business's behalf. Please direct privacy requests about such conversations to the business you interacted with; we will support them in fulfilling your request.

11. Your Rights

Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise these rights, contact us at info@ageontic.com. You may also have the right to lodge a complaint with your local data-protection authority.

12. Children

The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. International Transfers

Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as our providers' standard contractual clauses) for such transfers.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date.

15. Contact

Questions about this Privacy Policy or our data practices can be sent to info@ageontic.com.