Privacy Policy

How Ageontic collects, uses, protects, and shares personal data.

Last updated: August 18, 2026

1. Introduction

This Privacy Policy explains how Ageontic (doing business as "Ageontic", "we", or "us") handles personal data when you use our website, customer portal, APIs, and hosted AI agent services (the "Services"). It applies to visitors, account holders, and — as described in Section 11 — people who chat with AI agents our customers deploy through the Services.

Ageontic is the controller of account, billing, website, and direct-support data. You can contact us at privacy@ageontic.com.

For account holders, Ageontic decides how account and billing data is processed. For content processed inside a customer's agent (such as chat conversations with that agent), the customer who operates the agent determines the purposes of processing, and we process that data on their behalf to provide the Services.

2. Information We Collect

  • Account data: your email address, login credentials, and optional security settings such as multi-factor authentication. If you sign in with Google, we receive your email address from Google.
  • Billing data: subscription status, plan, currency, billing history, and transaction references. Payment-card details are handled by our payment provider.
  • Agent content: the instructions, documents, website content, and API data you upload to or direct the Services to fetch for your agents.
  • Chat data and leads: conversations between visitors and hosted agents, and contact details a visitor chooses to share in chat (such as name, email, or phone number).
  • Integration data: if you connect a third-party service, we receive and store the information needed to provide the features you enable. For calendar integrations, this may include connection credentials, calendar details, availability, and event information.
  • Usage data: server logs needed to operate and secure the Services, and — only with your consent — website analytics as described in our Cookie Policy.

3. How We Use Information

  • Providing, operating, and improving the Services, including generating AI responses for your agents.
  • Sending transactional email such as account, billing, and — if you enable them — lead notification messages.
  • Processing payments, preventing fraud, and maintaining billing records.
  • Securing the Services, debugging, and providing support.
  • Complying with legal obligations.

We do not sell personal data, and we do not use your content or your visitors' conversations for advertising.

4. AI Processing

To generate agent responses, chat messages and relevant excerpts of the knowledge you configured are sent to our AI model provider (OpenAI) via its API. This processing is governed by the provider's API terms, under which submitted data is not used to train their models. We do not use your content or your visitors' conversations to train models of our own.

5. Legal Bases

  • Contract: creating and administering accounts, providing agents and integrations, processing subscriptions, and responding to service requests.
  • Legitimate interests: securing, maintaining, debugging, and improving the Services; preventing fraud and abuse; and understanding aggregate service performance. We balance these interests against the rights of affected people.
  • Consent: optional public-site analytics and any other processing for which we specifically request consent. You may withdraw consent at any time without affecting earlier lawful processing.
  • Legal obligation: tax, accounting, sanctions, regulatory, and lawful disclosure requirements.
  • Customer instructions: for agent conversations and leads, we generally act as the customer's processor or service provider rather than relying on our own purpose.

6. Sharing & Service Providers

We disclose personal data only as needed to provide, secure, and support the Services. The recipients may include:

  • AI model providers that generate responses and process knowledge for retrieval.
  • Cloud hosting, data-storage, security, and email-delivery providers.
  • Payment providers that process subscriptions and transactions.
  • Authentication and analytics providers, where you choose the relevant feature or give consent.
  • Integration providers that you choose to connect, such as calendar services.

Some providers process personal data on our behalf under contractual restrictions; others act independently under their own terms and privacy notices. Not every provider receives customer content. Business customers may request our current customer-content subprocessor list and enter into a Data Processing Addendum where required.

We may also disclose information where required by law or to protect the rights, safety, or security of Ageontic, our customers, or others.

7. Google User Data

Ageontic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section describes exactly what Google user data we access, how we use it, how it is shared, how it is stored and protected, and how long we keep it and how you can have it deleted.

7.1 Data we access

  • Sign in with Google (optional): if you choose to sign in with Google, we receive the email address of your Google Account, which we use as your account login identifier. We do not access any other Google data through sign-in.
  • Google Calendar connection (optional): if you connect a Google Calendar to one of your agents, we request only the following granular OAuth scopes:
    • calendar.calendarlist.readonly — a read-only list of your calendars (names, IDs, and timezones), used solely so you can pick which calendar the agent should use and so we can default the correct timezone.
    • calendar.freebusy — free/busy availability information for the calendar you selected, used solely to check open time slots when a visitor asks to book.
    • calendar.events — events on the calendar you selected, used solely to create, reschedule, or cancel appointments that you or your agent's visitors explicitly request.
  • We also receive the email address of the connected Google Account so you can identify the connection in your portal. We do not request or access Gmail, Google Drive, Contacts, or any other Google data.

7.2 How we use it

Google Calendar data is used only to provide the user-facing calendar features you enable: showing you your calendar list during setup, checking availability, and creating, rescheduling, or cancelling events as directed through your agent, with every change confirmed before it is made. Limited event and availability details (such as offered time slots or a booked appointment's time) are processed by our AI model provider (OpenAI) solely to generate the agent's replies within that booking conversation — never for model training. We do not use Google user data for advertising, do not sell it, and do not use it to develop or train AI or machine-learning models.

7.3 How it is shared

We do not transfer Google user data to third parties except: (a) to Google itself, to carry out the calendar actions you request; (b) to our AI model provider as described above, strictly to generate the agent's responses in a booking conversation; (c) to service providers that process it on our behalf; (d) with your explicit consent; or (e) where required by law. When a booking is made, a summary such as the event title, time, and link may be stored with the related conversation. Authorized personnel may access Google user data only with your permission, where necessary for security or support, or to comply with law.

7.4 How it is stored and protected

We use technical and organizational safeguards designed to protect Google user data, including encryption in transit and at rest where appropriate and access restrictions for production systems.

7.5 Retention and deletion

Free/busy availability data is used transiently to answer a booking request and is not stored. OAuth tokens and the connected account email are retained only while your calendar connection is active. You can stop our access at any time by:

  • disconnecting the calendar from your agent's Integrations panel in the portal;
  • revoking Ageontic's access in your Google Account permissions, which immediately invalidates our stored tokens; or
  • deleting your Ageontic account, which deletes stored calendar connections and their tokens.

You may also email privacy@ageontic.com at any time to request deletion of the Google user data we hold about you; we will complete such requests within 30 days.

8. Cookies

Our use of cookies and similar technologies — including the consent notice for analytics — is described in the Cookie Policy.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. These include encryption where appropriate, access controls, and restrictions on access to production systems. No method of transmission or storage is completely secure.

10. Data Retention

We keep personal data only for as long as needed for the purpose described above. Because exact periods depend on account status, customer configuration, legal requirements, and security needs, we use these criteria:

  • Account and agent content: while the account or agent remains active, followed by the time reasonably required to complete deletion from active systems and routine backup rotation.
  • Conversations and leads: while retained by the customer through the Services, subject to deletion by the customer or account deletion.
  • Integration credentials: while the relevant connection is active; disconnecting the integration or deleting the account removes the stored connection as described in Section 7.
  • Security and operational logs: for the period reasonably needed to investigate incidents, prevent abuse, and maintain service reliability.
  • Billing and transaction records: for periods required by applicable tax, accounting, fraud-prevention, and financial laws.
  • Support and legal records: while needed to resolve the request or dispute and establish, exercise, or defend legal claims.

When retention is no longer necessary, we delete or de-identify the information. Data may remain in protected backups until those backups rotate out and may be retained longer where required by law or subject to a valid legal hold.

11. Visitors Who Chat With Customer Agents

If you chatted with an AI agent hosted by Ageontic on another business's website, that business controls the conversation data and any contact details you shared, and we process them on the business's behalf. Please direct privacy requests about such conversations to the business you interacted with; we will support them in fulfilling your request.

The same applies to voice or text-message interactions where a business enables those features. The data may include call audio, recordings, transcripts, phone numbers, dates, times, duration, outcome, and consent or opt-out records. The business decides whether a conversation is recorded or transcribed, how long it is retained, and is responsible for required notices and consent. Direct privacy and do-not-contact requests to that business; we will support it in responding.

12. Your Rights

Depending on where you live, you may have rights to know or access, correct, delete, or export personal data; restrict or object to processing; withdraw consent; and appeal a denied request. We do not sell personal data or share it for cross-context behavioural advertising. To exercise a right, contact privacy@ageontic.com. We may verify your identity and authority before acting, and you may use an authorized agent where local law permits. You may also complain to your local data-protection authority. We will not discriminate against you for exercising applicable privacy rights.

13. Children

The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

14. International Transfers

Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as our providers' standard contractual clauses) for such transfers.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date.

16. Contact

Questions, complaints, and privacy requests can be sent to privacy@ageontic.com.