Legal

Privacy Policy

Last updated: March 10, 2026

Your privacy matters to us. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

We collect the following types of information: • **Account Information**: When you create an account, we collect your name, email address, and profile picture (provided by OAuth providers such as Google or GitHub). If you use email/password authentication, we store a securely hashed version of your password. • **Scan Data**: When you scan a website, we store the URL, domain, computed scores, recommendations, and any AI-generated analysis. If you are logged in, scans are associated with your account. • **Agent Submissions**: When you submit an AI agent to the directory, we store the information you provide, including agent name, description, category, and trust metrics. • **Reviews**: Ratings and comments you leave on agents are stored and publicly visible. • **Usage Data**: We collect basic usage analytics including pages visited, features used, and timestamps. We do not track your activity outside of AgentLayer.

2. How We Use Your Data

We use your data to: • Provide and improve the AgentLayer service • Compute Agent-Ready Scores and Trust Scores • Display your submitted agents and reviews in the directory • Manage your account and subscription • Send service-related communications (e.g., billing confirmations) • Generate aggregate statistics (no personal data is exposed) • Ensure security and prevent abuse

3. Cookies & Local Storage

We use essential cookies for: • **Authentication**: NextAuth session cookies to maintain your login state • **Security**: CSRF tokens to protect against cross-site request forgery We do not use advertising or tracking cookies. No third-party tracking scripts (Google Analytics, Facebook Pixel, etc.) are loaded on our site.

4. Third-Party Services

We share data with the following third-party services only as necessary: • **Stripe**: For payment processing. Stripe receives your email and payment information. See Stripe's Privacy Policy. • **OAuth Providers** (Google, GitHub): To authenticate your account. Only basic profile information is shared. • **Azure OpenAI**: Scan data (website content, not personal data) is sent for AI analysis. Azure's data processing terms apply. We do not sell, rent, or trade your personal information to any third parties.

5. Data Retention

• **Account data** is retained as long as your account is active. You can request deletion at any time. • **Scan results** are retained indefinitely for logged-in users or until account deletion. Anonymous scans are retained for 90 days. • **Agent submissions** are retained as long as the agent listing is active. • **Reviews** are retained as long as the associated agent listing exists. • **Payment records** are retained as required by applicable tax and financial regulations.

6. Your Rights (GDPR / CCPA)

You have the right to: • **Access**: Request a copy of the personal data we hold about you • **Rectification**: Correct inaccurate personal data • **Erasure**: Request deletion of your personal data ("Right to be Forgotten") • **Portability**: Receive your data in a structured, machine-readable format • **Objection**: Object to processing of your personal data • **Restriction**: Request restriction of processing To exercise any of these rights, please contact us at privacy@agentlayer.dev or through our Contact page. We will respond within 30 days.

7. Security

We implement appropriate technical and organizational measures to protect your personal data, including: • Passwords are hashed using bcrypt with a cost factor of 12 • All communications are encrypted via HTTPS/TLS • Database access is restricted and monitored • Regular security reviews and updates While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. Children's Privacy

AgentLayer is not directed to children under 16. We do not knowingly collect personal data from children. If we discover that we have collected data from a child under 16, we will promptly delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or a prominent notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.

10. Contact & DPO

For any privacy-related questions or concerns, contact our Data Protection Officer: • Email: privacy@agentlayer.dev • Contact form: /contact • Response time: Within 30 business days