AgentLight

Legal

Privacy Policy

Last updated: July 14, 2026

AgentLight Inc. ("AgentLight," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.

1. Information We Collect

Account registration: email address, name and organization (optional), and a hashed password. Billing: card details processed via Stripe (we never see full card numbers), billing address, and tax ID for business customers.

Content you upload: source code files, documentation, GitHub repository data (if integrated), and test files. Usage data: which agents you use, API calls, processing time and output size, and error logs.

Device information: IP address, browser and OS, device type, and approximate location from IP. Cookies and tracking are described in full in our Cookie Policy.

2. How We Use Your Information

  • Service provision: creating and maintaining your account, running agents, responding to support requests
  • Improvement: anonymized usage patterns to improve AI models (never your raw code content)
  • Security & fraud prevention, and enforcement of our Terms of Service
  • Marketing communications, only with opt-in consent, always with an opt-out option
  • Legal compliance and responding to lawful requests

We do not sell your personal data, use your code for commercial purposes, share your code with other users, or train models directly on your private code.

3. Data Sharing & Disclosure

We share data only with vetted third-party processors, each under a Data Processing Agreement: Stripe (payments), AWS (hosting), GitHub (integration API, only when you authorize it), Google Analytics and Mixpanel (anonymized usage analytics), SendGrid (email), and Sentry (error logs).

We may disclose data if legally required (subpoena, court order, government request). Where possible, we notify you before disclosure. If AgentLight is acquired or merged, your data may transfer to the new entity, and we will notify you of any policy changes.

4. How We Protect Your Data

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Password hashing with bcrypt and salting
  • Role-based access control and mandatory MFA for admin accounts
  • SOC2 Type II certified infrastructure, quarterly security audits, annual penetration testing
  • 24/7 monitoring with anomaly detection and an on-call incident response team

No system is 100% secure. Use a strong, unique password, enable MFA, never commit secrets in code you send to us, and report suspicious activity immediately.

5. Data Retention

Data typeRetentionReason
Account infoWhile activeService provision
Billing / invoices7 yearsLegal / tax requirements
Support tickets3 yearsDispute resolution
Usage logs90 daysSecurity / debugging
Backups30 daysDisaster recovery

You can request deletion of your account and personal data at any time; deletion completes within 30 days of the request.

6. Your Privacy Rights

If you are in the EU, GDPR gives you the right to access, correct, and erase your data, to request data portability, to restrict processing, and to object to specific uses.

California residents have the right, under CCPA, to know what personal information is collected, to delete it, to opt out of any sale or sharing of it (we do not sell personal data), and to non-discrimination for exercising these rights.

To exercise any of these rights, email privacy@agentlight.io with your account email and the type of request. We respond within 10 business days and complete requests within 45 days.

7. Cookies & Tracking

We use essential, functional, analytics, and marketing cookies. A full breakdown of every cookie we set, its purpose and duration, is available in our dedicated Cookie Policy.

8. Children's Privacy

AgentLight is intended for users 18 years and older. We do not knowingly collect data from children under 13, and we delete any such data immediately upon discovery.

9. International Data Transfers

Your data is primarily stored on AWS in the United States. For EU users, we rely on Standard Contractual Clauses (SCCs) with our infrastructure providers to ensure adequate safeguards for cross-border transfers.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes are communicated via email and a notice on our website at least 30 days before they take effect.

11. Contact

Privacy inquiries: privacy@agentlight.io. EU Data Protection Officer: dpo@agentlight.io. If you believe we've violated your privacy rights, you may also lodge a complaint with your local data protection authority.