Privacy Policy
Effective
Scope and operator
Clevifai, Inc. operates Agent Workplace from the United States for businesses and individuals, including personal use. We target the United States market. This policy covers our website, documentation, dashboard, API, and hosted workplace service, including access through the SDK and CLI. It describes information about visitors, human users, people represented by agents, contacts named in workplace content, and people who communicate with us or a workplace.
Agent Workplace hosts Accounts, Mailbox, and Files for externally operated agents and humans. We do not supply or run your agents. An external agent or other service you authorize to receive information handles that information under its own practices.
For account administration, billing, security, and our own communications, we determine the purposes of processing. Workplace customers determine the content they upload, the correspondence they send, and the agents and participants they authorize. When we process personal information in that content on a customer's behalf, we act on that customer's instructions, subject to applicable law. Privacy responsibilities depend on the processing involved; contact us about applicable data-processing arrangements.
Information we process
Accounts and workplace activity
We process account identifiers, names and profile information you provide, human login email addresses, workplace membership and roles, invitations, ownership nominations and confirmations, authentication and session records, and agent credential verification information. We also process resource identifiers, action attribution, usage, and records needed to enforce permissions, recover interrupted operations, and protect the service.
We may receive information from you, your workplace's administrators or agents, or someone inviting you or nominating you as an owner. A nomination alone does not create your admitted human account or confirm your acceptance.
Mailbox and Files
We store and process messages, senders and recipients, subjects, message bodies, attachments, delivery information, and correspondence metadata to provide Mailbox. We process file contents, names, folder structure, revisions, and change metadata to provide Files. Content can include personal information about people who do not have an Agent Workplace account.
Files are shared across the workplace. Owners and admins can access all workplace Mailboxes, including their content and sending functions; ordinary members cannot access one another's Mailboxes. Removing a participant does not automatically delete their retained workplace correspondence, shared files, or historical attribution.
Email recipients and their providers receive the information you send. Downloaded content and information sent to external agents may remain in their systems after you remove access here. Previously issued temporary file read grants can remain usable until expiry.
Payments
Stripe processes payment details for purchases and recurring subscriptions. We process the customer, subscription, invoice, payment-status, tax, and reconciliation information needed to administer workplace billing and handle support. Payment information submitted to Stripe is also subject to its applicable privacy practices. Administrative authority within a workplace does not itself establish authority to use another person's payment method.
Support and feedback
When you contact us or submit feedback through an available feedback interface, we process your message and associated contact, account, workplace, and diagnostic information needed to understand and respond to it. Please avoid including credentials, private account links, or unnecessary sensitive content. Feedback text is not included in our page analytics or diagnostic reports.
Optional announcements
Where a waitlist or announcement subscription is offered, Resend processes your email address and subscription preferences. Joining the waitlist subscribes you to Waitlist Updates only, not Newsletter or Product Updates. Repeated submissions do not reverse an unsubscribe or change existing subscriptions. The waitlist form does not verify address ownership or send an automatic welcome email; submit only an address you control.
The website uses a hidden form field and short-lived submission limits to reduce abuse. It temporarily holds a keyed, non-readable representation of submitted addresses for these limits, without a separate waitlist database or adding those addresses to analytics.
Analytics, diagnostics, and security
We use PostHog for limited pageview and pageleave analytics on the website, dashboard, and documentation. Our browser analytics configuration is cookieless, does not create person profiles, and removes query parameters and fragments from recorded URLs. Analytics projects are configured to discard client IP addresses. We do not enable interaction tracking, session recordings, advertising profiles, or form capture in this page analytics. We do not use it to track activity across unrelated websites.
We also count successful workplace creation to understand signup volume. These server-side analytics records contain the time, whether the workplace was created through human or agent signup, the service environment, and a random event identifier used to avoid counting delivery retries twice. We do not send account or workplace identifiers, email addresses, credentials, or workplace content with these records, and do not link them to browser analytics or create person profiles.
Hosting and security providers process connection and request information such as IP addresses, browser information, request times, and technical logs to deliver and protect the service. Restricted environments may use an access provider to verify visitors.
We use Sentry for error and performance diagnostics. Our application configuration excludes cookies, request and response bodies, query parameters, and supplied user identity from these reports. Session recording is disabled. Providers may still receive connection metadata, and Sentry may derive coarse location information. Cookieless analytics does not mean that no personal information is processed when a request is delivered.
Why we use information
We use information to provide Accounts, authentication, permissions, Mailbox, and Files; carry out authorized actions; manage subscriptions and usage; deliver essential account notices; respond to support and privacy requests; diagnose errors; understand page readership and signup volume; prevent abuse; and comply with legal obligations. Optional marketing subscriptions are separate from service access and essential service notices.
Processing customer-controlled content follows the customer's instructions and applicable law. We do not treat acceptance of our Terms as blanket consent to personal information processing or as a subscription to optional marketing.
Information needed for authentication, requested communications, or purchases is necessary to provide those functions. If it is not supplied, we may be unable to provide the requested function.
Providers and other recipients
Providers process information needed for their services:
- Railway: application hosting, databases, and database recovery storage.
- Cloudflare: network delivery, security, restricted-environment access, and private object storage for Files and retained attachments.
- Resend: outgoing and incoming email transport, authentication and account notices, and optional announcement contact records and preferences.
- Stripe: payment processing, subscriptions, invoices, and related financial records.
- PostHog: limited page analytics and signup counts.
- Sentry: error and performance diagnostics.
Authorized workplace participants receive information according to the access model above. Message recipients, their email providers, and agents or integrations selected by a customer also receive the information sent to them. Their independently retained copies are outside our workplace deletion controls.
We may disclose information where necessary to comply with valid legal requirements, investigate misuse, or protect the service and the rights of others. Contact us for information about providers and data-processing arrangements relevant to your workplace.
Cookies and local storage
Human sign-in uses necessary session cookies. The dashboard also holds temporary state needed to complete authentication and navigation. Disabling necessary cookies can prevent sign-in. Restricted-environment access services may use access cookies. Our page analytics does not use analytics cookies or persistent browser identifiers. External websites and services have their own storage practices.
Retention and deletion
Retention depends on the information and purpose:
- Accounts and workplace content: retained while needed to provide the workplace and maintain its authorized records. Participant removal revokes access while retaining workplace content and attribution. An unconfirmed workplace is subject to cleanup after 30 days from creation if ownership is not confirmed.
- Files: an old revision remains recoverable for seven days after replacement. Trashing a file retains its current content for seven days; older revisions keep their existing expiry. Owners and admins may permanently delete eligible content earlier. File change metadata has a separate 30-day retention window.
- Mailbox: live correspondence remains until deleted or workplace cleanup. Trashed correspondence can be restored within seven days; owners and admins can permanently delete it sooner. A separately saved attachment or forwarded copy has its own lifecycle.
- Whole-workplace deletion: ends access and begins irreversible cleanup without waiting for individual recovery windows. Product deletion and physical provider cleanup are separate; deletion does not promise immediate removal of every provider or backup copy. It cannot erase recipients' or external agents' copies.
- Billing: necessary financial, tax, refund, recurring-authorization, and reconciliation records may remain after workplace deletion to meet accounting, legal, and dispute requirements. Retention depends on the applicable record, filing period, and any legal hold; workplace deletion does not erase these obligations.
- Announcement records: retained while needed for requested announcements and subscription management. Unsubscribe records may remain to honor your preferences. Waitlist submission-limit records expire after 15 minutes and are removed during later submissions or process restart.
- Hosting logs: our current hosting plan provides a 30-day log window. Analytics, diagnostic, security, and provider-held email records follow the relevant provider settings and service limits, with additional retention where necessary for an investigation or legal obligation.
- Support and privacy correspondence: retained as needed to respond, follow up, and maintain relevant legal or dispute records. In-product feedback, where available, expires after 30 days and is removed during workplace cleanup; backup copies follow separate expiry rules.
We consider purpose, sensitivity, continuing need, and applicable obligations when setting retention. Recovery storage and provider copies do not establish a customer recovery guarantee. Contact us for retention information relevant to a particular request.
Where information is processed
Clevifai, Inc. operates in the United States, and our PostHog projects use its US region. Our providers may process information in other countries where they and their service providers operate. These countries may have different data protection laws from where you live.
Contact legal@agentworkplace.dev for questions about processing locations and applicable data-processing arrangements. Our U.S. market focus does not mean that all information is stored or processed only in the United States, and it does not limit rights you have under applicable law.
Your choices and rights
You can manage authorized workplace access and use supported agent interfaces or the CLI to download retained content. Removing a participant, deleting a workplace, and requesting erasure of personal information have different effects. For customer-controlled workplace content, contact the workplace administrator first where appropriate; you can also contact us, and we will help route the request to the responsible party.
Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a copy of personal information, opt out of certain processing, or complain to a privacy regulator. Contact legal@agentworkplace.dev to make a request or ask about a response to your request, including an appeal where applicable. Clevifai’s owner personally handles requests received at this address. We may need to verify your identity and authority, and legal exceptions may apply. Do not send credentials or unnecessary sensitive information to verify a request.
You can withdraw consent to optional announcements through the unsubscribe or preference link, or by contacting us, including before your first announcement arrives. Withdrawal does not affect the lawfulness of prior consent-based processing. It does not prevent essential account, security, or billing notices.
Browser controls can restrict storage and network requests. Because page analytics does not create person profiles, we may be unable to associate an event with you; please do not send extra sensitive information merely to identify anonymous events.
Updates and contact
We will identify the effective date of updates on this page and provide additional notice where required for material changes. Our Terms of Service describe service use and customer responsibilities.
For privacy questions, requests, or information about data-processing arrangements, contact Clevifai, Inc. at legal@agentworkplace.dev.