Skip to content

Legal

Privacy Policy

Last updated: June 26, 2026

This Privacy Policy describes how AgentBuild, Inc. (“AgentBuild,” “we,” “us”) collects, uses, shares, and protects personal data. It applies to:

  • Visitors to agentbuild.it and our marketing pages
  • AgentBuild customers (the humans who hold an account and connect AI agents)
  • End users of customer-published websites (when those sites submit data to AgentBuild — e.g. contact-form submissions)

For end-user data submitted through customer sites, AgentBuild acts as a processor on behalf of the customer (the controller); the data processing terms in Section 10 of our Customer Terms of Service govern that processing.

1. Information we collect

1.1 Information you give us.

  • Account data: email address, password (hashed), business name (optional), country
  • Payment data: processed by our payment provider (Stripe). We store the last four digits of the card and the billing address; we do not store full card numbers
  • Account contact details (optional): if you choose to save contact details to your account profile (name, postal address, phone), we store them on your AgentBuild account. AgentBuild does not register domains, so we do not transmit this data to ICANN or a domain registrar
  • Customer Content: content you (or an AI agent you authorize) submits through the Service to publish on your sites
  • Support communications: what you tell us when you contact support
  • Waitlist & referral data:if you join the waitlist, your email, name, what you’re interested in, the AI tool you use, and any referral code — plus a hashed IP address and user-agent we keep for anti-abuse. If you arrive through a referral link, our referral partner (Dub) shares your email and click data with us

1.2 Information collected automatically.

  • API and platform logs: API requests, response codes, IP addresses, timestamps, user-agent strings — used for security, debugging, and abuse prevention
  • Marketing-site analytics: PostHog in cookieless mode: aggregate pageviews and events tied to an in-memory identifier that resets on every page reload. No cookies. No session recording. No autocapture. No keystroke logging. No data shared with ad networks
  • Authentication cookies: when you sign in, we set a small number of strictly necessary cookies (session, CSRF) — these are exempt from cookie consent under EU/UK ePrivacy rules

1.3 Information from end users of your sites. If a visitor to a site you publish through AgentBuild submits a contact form (or uses other interactive features you’ve enabled), we receive and store their submitted data on your behalf in your isolated per-site database. We process this data as your processor; you are the controller. End users with privacy questions about a customer site should contact the customer who operates that site.

1.4 First-party visitor analytics on customer-published sites. We collect aggregate, cookieless analytics on customer-published sites so the customer’s AI agent can answer “how is my site doing” questions. AgentBuild acts as the customer’s processor for this collection; the customer is the controller and is responsible for disclosing the use of analytics in their own privacy policy. The Service collects:

  • Page path (sanitized — query strings beyond UTM keys are stripped, and segments that look like opaque tokens are redacted)
  • Referrer hostname only (the full referrer URL, including referrer paths, is never stored)
  • Country (Cloudflare edge geolocation, two-letter code)
  • Device class (mobile / tablet / desktop)
  • Browser bucket (Chrome / Safari / Firefox / Edge / Other)
  • UTM parameters when present
  • Timestamp

We do not collect or store: IP addresses, raw user-agent strings, full referrer URLs, query string parameters beyond the UTM keys, cookies, localStorage identifiers, browser fingerprints, or any cross-site identifier. There is no session recording, heatmap, scroll tracking (Wave 1), or click-path replay. Your IP address is used only for transient abuse-prevention rate limiting (60-second salted hashing) and is never stored or associated with your visit record.

Honoring opt-out signals.When a visitor’s browser sends Do Not Track set to 1, the analytics beacon is not transmitted at all. When a browser sends the Global Privacy Control (Sec-GPC) signal, the beacon reaches our endpoint but is dropped server-side — not recorded or stored. A site’s code can also suppress the beacon entirely by setting window.__AGENTBUILD_DISABLE_ANALYTICS__ = true before page load (a page-level code flag, not a dashboard setting).

1.5 Data returned to your connected AI client. You operate AgentBuild through an AI client you connect (for example, ChatGPT or Claude). When you ask it to perform a task, the Service returns the data that task needs back into your AI client, where the model reads it to act on your request. Depending on what you ask, this can include:

  • Contact-form submissionsyour published sites received — the visitor’s name, email, message, and any other fields your form collects (when you ask to review your messages)
  • Aggregate, cookieless site analytics — top pages, referrer hostnames, and country-level visitor location; never individual visitor identities or IP addresses (which are not stored retrievably — see Section 1.4)
  • Your account information — your contact details, subscription status, and the records of the explicit confirmations you gave your Agent before sensitive actions (which may include the verbatim text of your confirmation)
  • Your domain, DNS, email, and integration settings — including, when you attach a domain, a scan of that domain’s existing DNS records (which may reveal your other vendors and email host); the analytics or advertising IDs you configured; and the notification inbox address you set for form alerts
  • Screenshots of your live site when you ask the Agent to look at it — a rendered image that may contain anything published on the page (staff photos, contact details, testimonials)

The Service returns this data only in response to a request you make through your connected AI client, and only to that client. Your AI client and its provider are not AgentBuild subprocessors; once data is returned into your client, that provider’s own terms govern how it is handled — AgentBuild does not control retention or use inside your AI client. For visitor data specifically, AgentBuild processes and returns it solely on your documented instruction as your processor under the Data Processing Terms (Customer Terms Section 10); you are the controller.

2. Lawful basis for processing (EU/UK)

If GDPR or UK GDPR applies to you, we rely on the following lawful bases:

ProcessingLawful basis
Operating your account, providing the ServiceContract (GDPR Art. 6(1)(b))
Charging your payment method, sending receiptsContract (Art. 6(1)(b))
Security, fraud prevention, abuse detection, platform logsLegitimate interests (Art. 6(1)(f)) — interest: protecting AgentBuild and its customers
Cookieless marketing-site analyticsLegitimate interests (Art. 6(1)(f)) — interest: understanding aggregate site usage; impact minimized by cookieless design
Marketing emailConsent (Art. 6(1)(a)) — opt-in only

The table above covers personal data AgentBuild processes as a controller. For data on customer-published sites that AgentBuild processes on the customer’s behalf — both visitor form submissions (Section 1.3) and first-party visitor analytics (Section 1.4) — AgentBuild acts as a processor and does not determine the lawful basis; the customer operating the site is the controller and is responsible for establishing the lawful basis under the Data Processing Terms in Section 10 of the Customer Terms of Service.

3. How we use information

  • To operate, maintain, and improve the Service
  • To connect and manage domains you own on your behalf
  • To send transactional email (account verification, receipts, subscription renewal reminders, security notices)
  • To prevent fraud and abuse, enforce our Terms, and respond to legal process
  • To respond to support requests
  • To send marketing email if and only if you opted in (you can unsubscribe at any time)

We do not use Customer Content to train AI or machine-learning models, and we do not provide Customer Content to third parties for that purpose. Separately, when you operate AgentBuild through a connected AI client, the Service returns your data — including the data described in Section 1.5 — into that client so it can carry out your requests; that return-for-operation is distinct from training and is described in Section 1.5.

4. How we share information

Aside from the customer-directed returns to your connected AI client described below, we share personal data only with the subprocessors listed at agentbuild.it/legal/subprocessors, each of whom processes data only as needed to provide their part of the Service and is bound by data-protection terms.

Your connected AI client. When you operate AgentBuild through an AI client you connect (for example, ChatGPT or Claude), the Service returns your data into that client at your request, as described in Section 1.5. That AI client and its provider receive your data, but they are your chosen tool — not an AgentBuild subprocessor — so they are not on the subprocessor list above; once data is returned into your client, that provider’s own terms govern how it is handled.

We may also disclose personal data if required by law, court order, or lawful government request; to enforce our Terms; or to protect AgentBuild, our customers, or the public from harm.

If AgentBuild is involved in a merger, acquisition, or sale of assets, personal data may be among the transferred assets; we will notify you and provide an opportunity to object where required by law.

We do not sell your personal data and we do not share it with third parties for their own marketing or advertising purposes.

5. Where data is stored and processed

AgentBuild’s primary database is hosted in Supabase us-east-2. Per-customer site databases (Cloudflare D1) and assets (Cloudflare R2) are distributed globally across Cloudflare’s edge for performance, with metadata residence in the United States. Personal data may be transferred to the United States and other countries.

Where required (transfers from the EEA, UK, or Switzerland), we rely on the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, and the Swiss equivalent. Each subprocessor’s agreement incorporates these clauses; AgentBuild is a downstream beneficiary.

6. How long we keep data

  • Account data: while your account is open, plus 90 days after deletion (for fraud and dispute resolution); some records (billing, tax) up to 7 years as required by law
  • API and platform logs: up to 90 days, then aggregated and de-identified
  • Customer Content: while your account is open; 30 days after termination, then deleted
  • Customer-site form submissions: the contact-form messages your published sites receive (visitor name, email, and message) are retained for up to 90 dayson a rolling basis and then automatically deleted; they are also deleted when you delete the site or your account. Export or forward anything you need to keep beyond 90 days. (Form-notification emails routed to the inbox you configured are governed by that inbox provider’s retention, not AgentBuild’s.)
  • Account contact details:any contact details you saved to your account profile are deleted with your account on our normal schedule. Because AgentBuild does not register domains, we do not transmit this data to ICANN or a registrar, so there is no registrar-side retention obligation to reconcile. If you registered a domain at a third-party registrar, that registrar’s own privacy policy and ICANN’s retention rules govern any data it holds — separately from AgentBuild
  • Marketing-site analytics: PostHog rolls events up into aggregates; raw events are deleted after 90 days
  • Customer-site visitor analytics:raw events retained for 30 days then deleted; daily aggregates retained for up to 2 years (or until the customer’s account is terminated, whichever comes first)
  • Waitlist & referral data: retained while the waitlist is active and until you are granted access or ask us to delete it (email privacy@agentbuild.it); referral events are kept only as long as needed to administer the referral program

7. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erasedata (“right to be forgotten”) — subject to retention obligations described in Section 6
  • Port your data to another service
  • Object to processing based on legitimate interests
  • Restrict processing while a dispute is resolved
  • Withdraw consent (where consent is the lawful basis) — withdrawal does not affect prior processing
  • Lodge a complaintwith your local data-protection authority (in the UK, the Information Commissioner’s Office at ico.org.uk; in the EU, your country’s supervisory authority)

To exercise these rights, email privacy@agentbuild.it. We will respond within 30 days. We do not charge for these requests except where they are manifestly unfounded or excessive (e.g. repetitive).

7A. California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the rights below for the personal information AgentBuild handles as a business (your account information). For personal information AgentBuild handles as a service provideron a customer’s behalf (data collected from or submitted by visitors to customer sites — see Sections 1.3 and 1.4), the customer operating the site is the business; direct those requests to them.

Categories of personal information we collect (as a business):

Category (Cal. Civ. Code §1798.140)ExamplesPurpose
IdentifiersAccount email, name, company name, phone, postal address, account ID; waitlist sign-up and referral data (Section 1.1)Operate your account, provide the Service, billing, support, and waitlist/referral administration
Commercial informationSubscription and billing records; the last four digits of your card and your billing address (full card data is held by Stripe, not by AgentBuild)Process your subscription
Internet/network activityAPI and platform logs (IP, timestamps, user-agent), product usage eventsSecurity, abuse prevention, debugging, analytics
Geolocation (coarse)Country-level only, from request metadataSecurity and aggregate analytics

We collect these from you, from your authorized Agent, and automatically as you use the Service. We do not collect government IDs, biometric information, or precise geolocation.

We do not sell or share your personal information (including no “sharing” for cross-context behavioral advertising, as the CPRA defines it), and have not in the preceding 12 months. There is therefore no sale or share for you to opt out of.

Sensitive personal information. The only sensitive personal information (Cal. Civ. Code §1798.140(ae)) we handle is your account log-in credentials and API credentials. We store your password only as a secure salted hash, and your API keys only as SHA-256 hashes (the plaintext key is shown once at creation and never persisted). We use these solely to authenticate you and operate the Service — never to infer characteristics about you — and we do not sell or share them. Because we already use sensitive personal information only for these authentication and Service purposes, the CPRA right to limit its use is already satisfied.

Disclosures to service providers. In the preceding 12 months we disclosed the categories above to the service providers listed at agentbuild.it/legal/subprocessors for the business purposes described in this Policy, under contracts that prohibit them from selling the information or using it outside those purposes. We retain each category as set out in Section 6.

Subject to verification, California residents may:

  • Know/access the categories and specific pieces of personal information we have collected
  • Delete personal information we collected from you, subject to the retention exceptions in Section 6
  • Correct inaccurate personal information
  • Be free from discrimination for exercising these rights

You may use an authorized agent to make a request. To exercise, email privacy@agentbuild.it; we will verify the request against your account and respond within the time the CCPA requires. This Section, together with Sections 1 and 6, serves as our Notice at Collection.

8. Security

We use appropriate technical and organizational measures to protect personal data, including:

  • TLS encryption in transit; encryption at rest for our primary databases
  • API keys stored as SHA-256 hashes; the plaintext key is shown once at creation and never persisted server-side
  • Per-customer site isolation: every customer site has its own Cloudflare D1 database, so site content and form submissions are not stored in a shared database and are not exposed to cross-tenant queries. Uploaded site assets (such as images) are stored in a single Cloudflare R2 bucket under per-site, path-scoped keys (sites/{your-site}/…) that scope each site’s assets to that site
  • Image metadata removal: photos uploaded to a site’s asset library are processed to remove embedded metadata — including EXIF location (GPS) data, device details, and XMP/IPTC blocks — before storage. Images in formats whose embedded metadata cannot be removed are declined at upload
  • Row-level security policies on platform tables
  • Access controls: AgentBuild personnel can access customer data only when needed for support, debugging, or security, and access is logged
  • Subprocessor due diligence and contractual data-protection terms (DPAs and SCCs)
  • Incident-response procedures with breach notification within 72 hours to affected customers and authorities where required

No system is perfectly secure; you should also protect your account by safeguarding your API keys and using a strong, unique password.

9. Children

AgentBuild is not directed to children. We do not knowingly collect personal data from anyone under 16 (in the EEA, UK, or Switzerland) or 13 (elsewhere). If you believe we have collected personal data from a child, contact privacy@agentbuild.it and we will delete it.

10. Changes to this policy

We may update this Privacy Policy. For material changes, we will notify active accounts at least 14 days before the change takes effect by email and by posting the updated policy with a new “Last updated” date.

11. Contacting us

Privacy questions, requests to exercise rights, or complaints:

AgentBuild, Inc. — Privacy
Email: privacy@agentbuild.it
Address: 600 N Broad Street, Suite 5 #3477, Middletown, Delaware 19709