AgentHost

Privacy Policy

This policy describes the data AgentHost expects to process for its hosted agent infrastructure service.

Data We Process

Account identifiers, API-key metadata, organization records, usage events, VM/browser/inbox metadata, mail routing metadata, abuse-review metadata, and billing support records. Mail message bodies and browser artifacts are processed only to provide the requested product behavior.

Infrastructure

Customer execution runs on isolated cloud infrastructure. Billing and legal invoice handling uses Mollie Invoicing. Agent mail is stored for 7 days and delivered through Amazon SES.

Security

AgentHost uses scoped API keys, isolated runtime boundaries, short-lived browser live tokens, realtime event authorization, rate limits, risk scoring, and operational cleanup controls.

Privacy Export

Authenticated users can download a bounded, streamed NDJSON export containing account, entitlement, agent, API-key metadata, computer/session/command metadata, inbox and message content (including soft-deleted messages), artifact metadata, usage, and billing records. A manifest and completion record make interrupted or concurrently changed exports detectable. Credentials, live/signaling URLs, command bodies/results, provider routing, relay diagnostics, and object-store keys are excluded.

Account Deletion

Confirmed deletion blocks new account activity, destroys execution resources and artifact objects in bounded, retryable passes, and removes login, entitlement, API-key, agent, session, command, inbox, message, artifact, and computer rows. Cleanup failures are never reported as complete; ambiguous provider ownership and object-storage failures remain in the durable deletion workflow for retry.

Retention

Soft-deleted mail remains exportable and counts toward stored-message quotas until the configured retention worker physically purges it (30 days by default). After account deletion, the organization tombstone, usage ledger, billing account, and finalized statements remain for metering evidence, abuse review, accounting, disputes, and legal obligations under the operator's separate retention schedule.

Contact

For privacy requests, contact the operator of the AgentHost deployment.