Agent Substrate
Legal

Privacy Policy

Effective August 15, 2026

This describes what we actually store, in plain language. If anything here doesn't match what you find in the product, that's a bug — tell us at hello@agent-substrate.com.

What we collect

  • Account — your email address, and your name/avatar if you sign in with Google.
  • Conversations — the messages you send, the agent's replies, and any files you upload, so your threads persist between sessions.
  • Long-term memory — facts you explicitly ask the assistant to remember across conversations. You can view and delete every stored fact yourself, any time, from Settings → Memory.
  • Your own API key, if you connect one — encrypted at rest, used only to make requests on your behalf, never logged in plain text, never shared.
  • Usage metadata — request counts and timestamps, needed to enforce plan limits and to know if something is broken.
  • Error reports — if something crashes in your browser, a stack trace and the page it happened on are sent to our self-hosted error tracker. We don't use a third-party analytics or error-tracking vendor — this stays on infrastructure we run.

What we don't do

We don't sell your data. We don't use your conversations or uploaded documents to train models. We don't run third-party ad trackers or analytics scripts on the dashboard or chat pages.

Who else sees it

When you send a message, it's sent to the LLM provider that generates the reply — either ours, or your own connected key routes it through your provider account instead. Uploaded files that need parsing pass through our own extraction pipeline; nothing is sent to a third party for that.

How sign-in works

We don't store passwords. Signing in either uses Google OAuth, or a one-time link we email you — the same link expires after a short window and can't be reused.

Your rights

Ask us for a copy of your data, or to delete your account and everything tied to it, by emailing hello@agent-substrate.com. We'll act on a deletion request within 30 days. Long-term memory facts and API keys can be deleted yourself, immediately, from Settings — no need to email for those.

Changes

We'll update the effective date above when this changes, and email you directly if a change affects what we collect or how we use it.