Who is responsible
The data controller is AinsworthLloyd, Washington, DC, United States. For anything in this policy, including exercising your rights, write to privacy@ainsworthlloyd.com.
This website
ainsworthlloyd.com is a static site. It sets no cookies, runs no analytics or advertising scripts, embeds nothing from third parties, and serves its fonts and media itself. Our hosting provider receives your IP address to deliver the pages, as any web server must, and keeps it in ordinary server logs for a short period for security.
The Agents platform: what we collect
When you create an account and use Agents we process the following.
- Account details. Your name, email address, and a password, stored only as a salted argon2id hash. If you continue with Google we receive your Google account ID, name, email, and profile picture instead of a password.
- Sign-in security. The IP address and browser of each session and of security events such as sign-ins, failed sign-ins, exports, and deletions.
- What you bring to the work. Prompts, conversations, uploaded files, missions, and the results agents produce for you. If you connect an outside service (Google Drive, Gmail, GitHub, Slack, Notion, and similar) we hold its access token, encrypted, for the purpose you connected it.
- Billing. Credit purchases run through Stripe. We keep a Stripe customer reference and a ledger of credits bought and spent. Card numbers never reach our systems.
- Notifications. In-app notices and the transactional emails that go with them: email verification, invitations, and approvals. We send no marketing email.
Why we are allowed to
- To provide the service you signed up for (contract): account, workspace, running agents on your instructions, billing, and support.
- To keep the platform secure and honest (legitimate interests): session records, security events, rate limits, and fraud prevention. We balance this against your privacy by keeping only what a security investigation needs, for as long as it needs it.
- Because the law requires it (legal obligation): financial records of purchases.
- Because you asked (consent): connecting an outside service to your workspace. You can disconnect it at any time under Connectors.
Who processes data for us
We use these providers to run Agents. Each acts on our instructions under a data processing agreement. Most are based in the United States; where you are in the EU, UK, or Switzerland, we rely on the EU-US Data Privacy Framework where a provider is certified and on Standard Contractual Clauses otherwise.
- DigitalOcean, for hosting, the database, and file storage.
- Stripe, for payments.
- Resend, for transactional email.
- Google, for sign-in and for the Google services you choose to connect.
- AI model providers, to generate the work you request: Anthropic, OpenAI, Google, and models reached through OpenRouter, plus ElevenLabs for voice and BytePlus for video. Your prompts and files are sent to them only to produce your result and are not used to train their models under the terms we hold with them.
- Tavily and Brave, for the live web search some agents perform.
- GitHub, Slack, Notion, and other services, only when you connect them.
How long we keep it
- Your account, content, and workspaces: until you delete them or your account.
- Session records: 30 days after the session expires, then deleted automatically.
- Email verification links: 7 days after they expire, then deleted automatically.
- Security events: the IP address and browser are removed after 12 months; the event itself is kept so the history of the account stays complete.
- Billing records: as long as tax and accounting law requires, typically 7 years.
- Backups: deleted data leaves our backups as they rotate, within 30 days of deletion.
Your rights, and how to use them now
Wherever you live, you can see, correct, export, and delete your data. If you are in the EU, UK, or another jurisdiction with data protection law, you also have the rights to restrict or object to processing, to withdraw consent, and to complain to your supervisory authority.
- Export: Settings → Privacy and data → Export data gives you one JSON file with everything we hold about you.
- Delete: Settings → Delete account removes your account, your personal organization, and everything in it immediately.
- Correct: your name and email can be changed in Settings; anything else, write to us.
- Anything else: email privacy@ainsworthlloyd.com. We answer within 30 days and may ask you to confirm you control the account first.
Cookies
Agents uses one cookie to keep you signed in and one short-lived cookie, ten minutes at most, during Google sign-in to protect the sign-in from forgery. Both are strictly necessary for the service, so no consent banner is shown. Your light or dark theme choice is stored in your browser and never sent to us. There are no analytics, advertising, or tracking cookies on either site.
Security
All traffic is encrypted in transit. Passwords are hashed with argon2id. Tokens for connected services are encrypted at rest. Session cookies are HTTP-only and cannot be read by scripts. Access to production systems is limited to the people who operate them and is logged.
Children
Agents is for people aged 16 and over. We do not knowingly collect data from anyone younger.
If something goes wrong
If a security incident affects your personal data, we will tell the relevant authority within 72 hours of confirming it and tell you without undue delay if the risk to you is high.
Changes
When this policy changes we update the date at the top. If a change affects how we use data you have already given us, we will tell you inside Agents or by email before it takes effect.
