This page is informational and describes how security works when you use the Site and the Product. The binding conditions are set out in the Terms of use and the Privacy policy.

Where your data lives

The workspace structure, the rules and every file the Agent works with sit on your own equipment and your own server.

The Provider receives no copies of your files, has no access to your conversations or documents, and does not connect to the services you have connected to the Agent. This architecture means the Provider has no technical route to that data, not merely a contractual promise not to look.

Access keys

You give the Model key and the credentials for connected services to the Agent yourself, and they stay on your side. They are never transmitted to the Provider.

The reverse follows: if a key is compromised, you are the only person who can revoke it. Grant the Agent the minimum permissions its tasks require, and connect services as the need arises rather than all at once.

What the Provider can see

Only what you entered in the form on the Site: name, email address and, at your discretion, phone number and Telegram username. Anonymised visit analytics are processed in addition.

The full list of data, purposes and retention periods is in the Privacy policy.

How the Site is protected

  • data is transmitted over HTTPS only;
  • a strict content security policy is applied;
  • embedding the Site in third-party frames is blocked;
  • the form is protected by Cloudflare Turnstile and an origin check;
  • hosting and DNS are provided by Cloudflare.

What is worth doing on your side

Keep backups of your working files. Check the Agent’s output before you use it, send it to anyone or make decisions on the strength of it. Grant access one service at a time, as you need it.

Reporting a vulnerability

If you find a vulnerability, send a description and steps to reproduce to [email protected]. We will acknowledge it and fix it.

Please do not disclose the details publicly until it has been resolved.