Privacy Policy
Effective October 9, 2026
AgentGrid, Inc., a Delaware corporation, operates AgentGrid and agentgrid.sh. This policy explains how information is handled when you visit our website, use our desktop or mobile software, connect services, or contact us.
AgentGrid brings AI agents, terminals, browsers, and project context into a workspace. Some information stays on your device; other information is sent to AgentGrid services, connected devices, or the providers used by a feature. The destination depends on what you use and connect.
1. Accounts and communications
When you create or use an account, we process your email address, name, profile image if supplied, account identifiers, verification status, and sign-in information. Email/password sign-in stores a password hash. Connected sign-in services can supply profile information and account tokens.
Our hosted systems also process sessions, IP addresses, browser information, device registrations, access tokens, time zone, and account activity such as sign-ins and downloads. We use this information to authenticate you, manage access, connect devices, protect the service, and provide support.
We process messages you send us and use email services to deliver account verification, password resets, access updates, and other communications. Email delivery, opens, and bounces can be recorded. Use an unsubscribe link where provided or contact us about communication preferences.
2. Projects, agents, and connected providers
Your workspace can contain project paths, source code, prompts, conversations, terminal output, notes, screenshots, and other attachments. Desktop state, conversation journals, usage history, settings, and attachments are stored in local files or databases so work can be restored. Provider tools may maintain their own local histories and credentials.
Running an agent or using an integration can send prompts, relevant project files, conversation context, tool results, and attachments to the model provider or service handling that request. This may include personal or confidential information in those materials. Remote or hosted execution also processes information on the machine or service where you run it.
API keys, provider sessions, and other credentials enable the connections you configure. Storage and handling vary by provider and feature. Review your selected provider's privacy policy, retention settings, and terms before sharing information; its handling of submitted data is governed by its own policies and your agreement with it.
Choose project access and agent permissions carefully. Connecting a tool can let an agent read files, run commands, use browsers, or send information to other services. Only supply information you are authorized to use and share.
3. Mobile, remote access, and voice
Pairing a device stores connection details, a device identifier, and a pairing credential. Remote features transmit commands, workspace information, conversation content, and selected attachments between connected devices. Forgetting a desktop in the mobile app removes the saved pairing on that mobile device.
The mobile app requests camera or photo-library access for pairing and image attachments, and local-network access to connect to a desktop. Desktop features may require microphone, screen-recording, accessibility, or automation permissions. You can review or revoke operating-system permissions in your device settings; the corresponding features may then stop working.
Voice dictation can process audio locally with a configured local transcription backend or send it to Deepgram. Agent calls send audio and conversation context to OpenAI's Realtime service. Call transcripts and summaries can be saved locally and added to agent conversations. Starting a voice feature and selecting its provider determine where that information is processed.
4. Website cookies, analytics, and advertising
The website uses cookies and browser storage for sign-in, appearance preferences, measurement, and attribution. We use PostHog for website activity and product analysis, and Vercel analytics and performance measurement. When you are signed in, PostHog activity can be associated with your account ID, email, name, and profile image.
When configured, Google Analytics, Google Ads, X, and Reddit measurement receive visit, signup, or download events, browser and network information, and campaign or advertising identifiers. We use these tools to understand acquisition and measure advertising results. These providers can use cookies or similar technologies under their own policies.
Website measurement is not currently gated by an on-site cookie-consent choice. Browser controls can restrict cookies or tracking, though blocking cookies can affect sign-in and does not prevent every form of collection. The desktop telemetry setting described below does not control website measurement. Contact us about privacy choices or objections relating to this processing.
5. Desktop analytics and diagnostics
Desktop usage and error reporting is enabled by default and can be disabled in the app's settings. PostHog receives usage events, app and operating-system information, installation identifiers, and error information. After sign-in, activity can be linked to your account and email address.
Packaged desktop builds also use Sentry for diagnostic error reporting when configured and enabled. Diagnostics include technical events, version information, and sanitized error details. Local diagnostic journals can still be written when remote telemetry is disabled. If you send a diagnostic export or support attachment, we receive the information you choose to send.
If you enable observability exports, agent traces can include prompts, tool parameters, and results sent to your configured collector or observability service. Review the endpoint and content settings before enabling this feature.
6. Payments and service providers
Website subscriptions use Stripe-hosted checkout and billing management. Stripe processes the payment details you provide. AgentGrid stores customer and subscription identifiers, plan and payment status, billing-period information, and cancellation status to manage access and support billing.
Information is processed by services supporting hosting, databases, authentication, email delivery, payments, analytics, diagnostics, and the AI or other integrations you use. Examples in the features described here include Stripe, Resend, PostHog, Sentry, Vercel, Google, X, Reddit, OpenAI, and Deepgram. Not every service receives every category of information.
We may also disclose information when required by law or legal process, to address fraud or security incidents, protect rights and safety, or carry out a business transaction subject to applicable law.
7. Storage, retention, and deletion
Local workspace information remains in the app's files, project folders, or provider-managed storage until removed or replaced by the relevant app or tool. Removing a pane, signing out, or uninstalling the app does not necessarily remove all project files, journals, backups, or provider histories.
Hosted account, transaction, communication, and diagnostic records have different purposes and lifecycles. Retention depends on the feature, ongoing service needs, legal obligations, security needs, and resolution of disputes. Connected providers maintain their own retention rules. This policy does not specify a single retention period for all information.
Contact us to request account deletion or removal of information held by AgentGrid. Deleting an account does not by itself delete copies on your devices or with independent providers. Some records may need to be retained where permitted or required by law. Ask us about the scope of a deletion request before removing local copies you need.
8. Privacy requests and international use
Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of your personal information, restrict or object to processing, withdraw consent where processing relies on it, or complain to a privacy regulator. Contact us to exercise a right or ask about the information we hold. We may need to verify your identity and clarify the request.
AgentGrid and the services you connect may process information outside your country, including in the United States, where privacy laws can differ. Contact us for information about a particular service, processing location, or applicable safeguards. This policy does not replace any rights or protections required by the law that applies to you.
9. Changes and contact
We may update this policy as the service or our practices change. The effective date identifies the current version; additional notice will be provided where required by applicable law.
Use the contact details below for privacy questions or requests. Our Terms of Service describe the conditions for using AgentGrid.