Legal

Privacy Policy

What we collect, what we do with it, and the controls you have over your data. Short and to the point.

Last updatedSeptember 27, 2026

What we collect

We collect the minimum data needed to operate the service. That breaks down into three categories:

  • Account data. Your email, name (optional), and authentication credentials. OAuth providers may provide an email and profile details. Connected GitHub App credentials may be stored encrypted in ACP's credential vault so the authorized integration can work.
  • Workspace data. Goals, prompts, ticket text, generated code, pull-request bodies, build logs, and any other content you put into ACP.
  • Operational data. IP addresses, browser type, timestamps, and aggregated usage metrics. We use these to keep the service fast, detect abuse, and fix bugs.

We do not sell your data. We do not share it with advertisers. We do not use your workspace data to train AI models.

How AI providers handle your data

When ACP dispatches an AI agent on your behalf, the prompt and any necessary code context are sent to the AI provider you have authorized. This usually means Anthropic, OpenAI, Google, or xAI.

Platform wallet. Free Solo does not collect a personal provider API key. Inference runs through ACP's platform wallet.

Optional keys. If an administrator later connects a provider API key, that traffic goes from ACP's servers to the provider under their relationship. We do not proxy or inspect the content beyond what's needed to deliver the request and record usage.

Provider policies apply. Each provider has its own current terms for retention and use of submitted data. Review the applicable provider terms before connecting a key or running a project with sensitive content.

Cookies and local storage

ACP uses first-party cookies for signed-in sessions and related application state. The session cookie is HTTP-only and signed with a server secret. We do not use third-party advertising cookies.

Pricing can use an approximate country lookup through ipwho.is. If you change the billing region manually, ACP stores your choice in a first-party amc_billing_region cookie for up to one year. The country lookup sends your IP address to that service as part of the request.

We also use localStorage to remember your theme preference (light, dark, or match your device) and your first goal so they survive a page refresh. If you are signed in, your theme choice is also stored on your account so it follows you across browsers. You can clear localStorage at any time; a signed-in preference stays on the account until you change it.

When we share data

We share your data only with the subprocessors needed to run the service:

  • Cloud hosting (compute, storage, CDN).
  • AI providers, only when an agent runs on your behalf.
  • Email delivery, for transactional messages (verification codes, billing alerts).
  • Analytics, in aggregated form, never with your workspace content.

We do not sell, rent, or trade personal data. We do not share data with law enforcement unless compelled by a valid legal process; if that happens, we will notify you before responding unless legally prohibited.

Public community

Community is public. If you claim a username or share an app, anyone on the internet can see your username, bio, shared prompts, and comments. Your email is not shown on Community, public profiles, or shared posts.

You can unpublish a share at any time. Unpublished posts leave the public feed and your profile. We may still retain copies as needed to operate the service, handle abuse reports, or comply with law.

Data retention

We keep your workspace data for as long as your account is active. On account deletion, we erase your workspace data within 30 days, except where retention is required by law (e.g. billing records).

Operational logs (access logs, error reports) are retained for up to 90 days and then aggregated or deleted.

Your rights

You can:

  • Export your projects at any time as a tarball of git repositories.
  • Request a copy of all personal data we hold about you.
  • Correct or delete your account information.
  • Opt out of optional product emails from your account settings.

Email admin@agentcontrolpanel.dev to exercise any of these rights. We respond within 30 days.

Security

Security is the foundation ACP is built on. Read the full Security page for the details, but the short version:

  • Some workflows separate changes into git worktrees.
  • Connected provider credentials are encrypted in the credential vault.
  • Ticket state and run output are recorded for inspection.
  • We disclose material security incidents within 72 hours.

Changes to this policy

When we make material changes, we will email account holders and show an in-product banner before the change takes effect. Non-material changes (clarifications, typo fixes) will be reflected in the "Last updated" date above.

Contact

Privacy questions? Email admin@agentcontrolpanel.dev or our Data Protection Officer at the same address.