Legal

Privacy Policy

Last updated: August 12, 2026

What this covers

This policy explains what data AgentGate ("we", "us") collects when you use our approval-queue service (the "Service"), why we collect it, and what we do — and don't do — with it.

What we collect

DataWhy we collect it
Organization name, email (optional)Account identification and, if provided, contacting you about your account
API keyStored as a one-way hash only — we cannot recover your raw key, and neither can anyone with database access
Slack/Teams tokens or webhook URLsEncrypted at rest, used only to post approval requests to your connected workspace
Approval requests & contextWhatever your agents send when requesting approval — action name, description, and any context fields you include — stored so the request can be reviewed and audited
Audit log entriesWho approved/rejected what, and when — this is the product's core function, not optional telemetry
Billing identifiers (Paddle customer/subscription IDs)Links your account to your subscription. We never see or store your card details — that's handled entirely by Paddle

We do not use tracking cookies or third-party advertising trackers on the dashboard.

Who we share data with

  • Paddle.com Market Limited — our payment provider and Merchant of Record for paid plans. Paddle receives what's needed to process payment; see Paddle's Privacy Policy
  • Slack / Microsoft — only the approval-request content you configure is sent to your own connected Slack workspace or Teams channel, never to anyone else's
  • Infrastructure providers hosting the Service on our behalf (database and application hosting) — they process data as our processors, not as independent users of it

We do not sell your data. Ever.

Data retention

Approval requests and audit log entries are retained according to your plan — 7 days on the Free plan, indefinitely on Pro (see pricing). You can request deletion of your account and associated data at any time by emailing hello@useagentgate.com.

Security

API keys are hashed (never stored in plaintext), integration tokens are encrypted at rest, and all data is scoped per-organization — no organization can see another's data. No system is perfectly secure, but this is architected as a real constraint, not an afterthought.

Your rights

You can access, export (via the audit log CSV export), or request deletion of your data at any time. Email hello@useagentgate.com with any request and we'll act on it promptly.

Children's privacy

The Service is intended for business use and is not directed at, or knowingly used by, children under 16.

Changes to this policy

We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date.

Contact

Questions about this policy or your data? Email hello@useagentgate.com.