Privacy Policy
Last updated: 26 September 2026
AgentFoundry is a demo chatbot-builder platform. The business persona you're chatting with (product names, pricing, and support details shown in this demo) is fictional; this policy covers data handled by the AgentFoundry application itself.
1. Who This Covers
This policy covers the AgentFoundry application: the demo chat, the Studio where businesses build a chatbot, the complaint tracker, and the bots and MCP servers published from it. The business persona in the demo is fictional. The controller of the personal data described here is AgentFoundry. You can reach us at expensemanagementvj@gmail.com.
When a business publishes a chatbot built with AgentFoundry, that business decides what its chatbot is for and is responsible to its own visitors for that use; AgentFoundry then processes the chat data on the business's behalf. If you are chatting with someone else's bot, please also read that business's privacy notice.
2. What We Collect
- Chat messages and replies. What you type and what the assistant answers, saved as a conversation.
- Complaint details you enter in the complaint tracker (your name, your email address and what you write), and tickets the assistant files when a message reads as very angry.
- An anonymous visitor ID and short memory notes — only if you choose “Yes, remember me” (see section 5).
- Usage events such as “a message was sent” with the detected mood label, and the pages visited, used to see how the product is doing.
- Your answer to “Did that solve your problem?” if you give one, saved on the conversation together with whether a human ticket was filed and, when the business is testing two versions of its bot, which version you saw. The business sees these only as totals — never your messages.
- Business setup content that a business enters in Studio: its name, products, FAQs and support details.
- Technical data. Your IP address is used to rate-limit requests and appears in our hosting provider's logs. If error monitoring is enabled, error reports are sent to Sentry.
We do not ask for your name or email to chat, and we don't want them: please don't type passwords, card numbers, health details or other sensitive information into the chat.
3. How We Use It, and Why We May
Under the GDPR and similar laws we need a legal basis for each use:
- To answer your questions using the business's knowledge base — our legitimate interest in running the service you asked for (and, for a business's own bot, that business's).
- To remember you between visits — your consent, which you can withdraw at any time with “Forget me”.
- To handle a complaint you file — to take steps you asked for, and our legitimate interest in resolving it.
- To keep the service secure and rate-limited, and to fix errors — legitimate interest.
- To tell a business how often its bot solves problems and which version does better (aggregated) — legitimate interest.
We don't sell personal data, we don't “share” it for cross-context advertising, and we don't use it to build advertising profiles.
4. AI and Automated Processing
Replies are written by an AI model and may be wrong; you are told you are talking to an AI. The assistant reads the tone of your message (for example, to reply more gently or to raise a ticket for a person to follow up when you sound angry). No decision with a legal or similarly significant effect on you is made automatically, and a person can always be asked for through the contact details in the chat or below.
5. Personal Details Hidden From the AI
Before your message reaches the AI model, the search step or storage, we replace personal details with placeholders such as <EMAIL_ADDRESS>. This covers names, email addresses, phone numbers, card, bank and government ID numbers, IP addresses, web addresses, exact dates such as birth dates, places smaller than a state or province, and religious, political or ethnic-group mentions. Countries, states, weekdays and language names are kept so questions like “Do you ship to Canada?” still work.
This is automatic and best-effort. Names in free English text are found by a separate service that can be unavailable, and it does not read other languages. In every language, emails, numbers, IDs and exact dates are hidden, and so is a name you introduce yourself with (“my name is…”, “me llamo…”) or sign with. A name mentioned in passing in a non-English message, or while the service is unavailable, may not be hidden. It is not a guarantee, so please keep sensitive details out of the chat.
6. Memory, Your Anonymous ID and Browser Storage
If a chatbot has memory turned on, it asks first. If you choose “Yes, remember me”, your browser creates a random ID (not derived from your name, email, IP address or device) and stores it in this browser's local storage, separately for each business. Short notes about what you ask are then saved under that ID so the assistant can recall them next time. If you choose “No thanks”, no ID is created and nothing is remembered.
Choose “Forget me” in the chat at any time to erase the notes, the conversations and the usage events saved under your ID, and to delete the ID from your browser. Clearing your browser's site data removes the ID from your device but not what is already saved on our side, so use “Forget me” first.
We use no advertising, analytics or cross-site tracking cookies. Your browser's local or session storage holds only: your theme choice; your memory choice and anonymous ID (above); the IDs of complaints you filed, so you can see them again; a note of which intro tips you dismissed; a timestamp used to avoid waking a service twice; for a bot's owner, the private key to that bot's insights page; and, for the site operator, a session token for the admin view.
8. International Transfers
These providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on the transfer safeguards they offer, such as the EU Standard Contractual Clauses or an adequacy decision, and the UK addendum.
9. How Long We Keep It
A daily job permanently deletes:
- Conversations and their messages — 30 days after the conversation started.
- Usage events — after 30 days.
- Remembered notes — each note 30 days after it was saved (or straight away with “Forget me”).
- Complaints — 30 days after they are resolved; a complaint nobody has resolved is deleted after 180 days at the latest.
You can delete a conversation earlier with “Clear” or “Forget me”. Copies in the providers' own backups and server logs are removed on their schedules, not ours.
10. Your Rights and How to Use Them
Depending on where you live (for example under the GDPR, UK GDPR, the California CCPA/CPRA or India's Digital Personal Data Protection Act) you may have the right to know what we hold about you, get a copy, correct it, delete it, restrict or object to its use, take it with you, and withdraw consent at any time — and to nominate someone to exercise these rights for you. Using them is free, and we will not treat you differently for doing so.
“Forget me” and “Clear” in the chat cover the data tied to your anonymous ID. For anything else — a complaint you filed, or if you can no longer use the chat — email expensemanagementvj@gmail.com from the address you used (for complaints) or say which conversation or ticket you mean. Because we don't know who an anonymous ID belongs to, we may ask you to show that you hold it or the ticket's reference before acting. We answer within one month (45 days at most where the law allows an extension) and tell you if we cannot act and why.
If you are not satisfied you may complain to your local data protection authority (for example your EU supervisory authority, the UK ICO, the California Attorney General, or India's Data Protection Board) — but we would like the chance to put it right first.
11. Security and Incidents
Connections use HTTPS. The database is closed to the public: it is only reachable through our server with restricted keys, requests are rate-limited, complaint details are visible only to the person who filed them and the support team, and our database provider encrypts data at rest. No system is perfectly secure. If a security incident affects your personal data we will tell you and the authorities as the law requires.
12. Children
AgentFoundry is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, email expensemanagementvj@gmail.com and we will delete it.
13. Changes, Contact and Grievances
We will update this page when our practices change and revise the date above; if a change matters to you (for example a new use of your data) we will say so in the chat or on this page before it takes effect.
Questions, requests and complaints about your data (including for India's grievance-redressal requirements): expensemanagementvj@gmail.com. We acknowledge within 7 days and aim to resolve within 30.