Privacy Policy
Agentiq reads your email in order to answer it. This page explains exactly what that means for your data.
Last updated
Agentiq (“we”, “us”) provides AI agents that read and reply to email on behalf of a customer. This policy covers both the personal data we hold about you as a customer and the email content we process on your behalf. Under the GDPR we are the controller for the former and your processor for the latter.
What we collect
Account data
- Your name and email address, from the identity provider you sign in with (Google or Microsoft) or from the magic link you request. We never receive your password from either provider.
- Your workspace name, plan, and billing status.
- Sign-in metadata — IP address and user agent — kept with the session so you can see and revoke active sessions.
- An audit log of administrative actions taken in your workspace.
Email content
Mail sent to a mailbox you connect is delivered to us, parsed, and stored so it can be shown to you and answered. That means message headers, subject, body text, attachment names, and the addresses of everyone on the thread — including people who are not our customers and who wrote to you, not to us. We process it only to run the service you asked for.
Contacts
Contacts you upload for outreach: email address, and any name, company, or custom fields you supply. You are responsible for having a lawful basis to contact them.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not train AI models on your email. Content is sent to a model provider only to generate the reply you asked for, and is not retained by us for training.
- We do not read your mail as a matter of routine. Staff access to customer content is limited to what a specific support request or a security incident requires.
Sub-processors
We use the following providers to run the service. Each processes customer data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (SES, S3) | Sending and receiving email, and storing raw messages | United States |
| Cloudflare | Application hosting, edge routing, object storage, and per-mailbox state | Global edge |
| Neon | Primary database (accounts, mailboxes, contacts, message metadata) | United States |
| Anthropic | Generating draft replies, when you use a model that runs there | United States |
| Polar | Subscription billing and payment processing | United States |
How long we keep things
- Email content is kept for the retention window on your plan, after which a scheduled job deletes it — message bodies, attachments, and the per-mailbox working copy alike. Shortening the window applies to mail already stored, not just new mail.
- Account and billing records are kept while your workspace exists, and afterwards only as long as tax and accounting law requires.
- Suppression records — addresses that unsubscribed, bounced, or complained — are kept indefinitely on purpose. Deleting them would let the same address be contacted again, which is the opposite of what the person asked for.
Your rights
If you are in the UK, EU, or a jurisdiction with comparable law, you can ask us to give you a copy of your personal data, correct it, delete it, or restrict how we use it, and you can object to processing. Write to privacy@agentiq.emailand we will respond within 30 days.
If you wrote to a mailbox that a customer of ours operates and you want that message removed, contact that business directly — they decide what happens to their mail. We will help them action it, but we cannot make that decision for them.
Unsubscribing
Outreach sent through Agentiq carries a one-click unsubscribe link and the matchingList-Unsubscribe header. Using either removes your address immediately and adds it to that sender's suppression list, so their later campaigns cannot reach you.
Security
- Data is encrypted in transit, and at rest by our infrastructure providers.
- Credentials you give us for third-party AI providers are encrypted with a separate key before being stored, and are never returned by the API once saved.
- API and agent keys are stored only as hashes; the key itself is shown once, at creation.
- Access to a workspace's data is scoped by membership and role on every request.
Changes
If we change this policy materially we will tell workspace owners by email before it takes effect. The date at the top always reflects the current version.
Contact
Privacy questions, data requests, and DPA requests:privacy@agentiq.email.
