Last updated 17 July 2026

Privacy Notice

This notice explains how WareweAI Private Limited collects, uses, and protects personal information when you use Agentshub AI.

WareweAI Private Limited · 677P, Sector 42, Gurugram, Haryana -122002, India · support@agentshub.ai

Introduction

WareweAI Private Limited ("Agentshub AI," "we," "our," or "us") values your privacy. This Privacy Notice ("Notice") describes how Agentshub AI collects, uses, discloses, and otherwise processes personal information when you use our website at https://agentshub.ai, related subdomains such as connect.agentshub.ai, and our AI agent platform, marketplace, and related services (collectively, the "Services").

In this Notice, "personal information" (or "personal data") means information that identifies you or can reasonably be linked to you. This Notice applies whenever we process your personal information in connection with the Services described in Section 1.

For information about your choices, see Section 7. Your Privacy Choices. For EU/UK and Australian residents, additional rights are described in Sections 13 and 14.

1. Scope

This Notice applies to our online processing activities relating to individuals who:

  • Visit our website or use the Agentshub AI application;
  • Create or use a Agentshub AI account;
  • Build, run, publish, or acquire AI agents, skills, or workforces on our platform;
  • Participate in team workspaces or accept team invitations;
  • Connect third-party applications or services to Agentshub AI;
  • Use our Agent-to-Agent (A2A) connectivity features;
  • Purchase subscriptions or credit packs;
  • Contact us for support or submit bug reports.

Additional notices. If we provide a supplemental notice for a specific feature (for example, a marketplace listing or team workspace), that notice applies to the extent it conflicts with this Notice for that processing activity.

Team and business customers. When you use Agentshub AI through a team or organization account, your organization may administer your access. Your organization's policies may also apply to how it uses information processed through the Services.

This Notice does not apply to personal information we process about job applicants, employees, or contractors in the context of our working relationship with them, which is covered by separate notices.

2. Personal Information We Collect

We collect personal information directly from you, automatically when you use the Services, and from third parties where you connect integrations or sign in with a third-party account.

Information you provide directly

  • Account and profile information: email address, display name, password (stored as a secure hash for password-based accounts), profile photo (when provided via sign-in), first and last name, job title, company name, and stated use case collected during onboarding.
  • Authentication data: one-time passcodes sent to your email for sign-in or verification; we store hashed codes and related challenge metadata for a limited time.
  • User-generated platform content: agent and skill configurations, prompts, workflows, knowledge base documents and uploads (including files up to 25 MB), chat messages with our Hub Assistant and builder tools, run inputs and outputs, memories and user facts you or your agents store, team names and membership details, marketplace listings, and bug report descriptions (including optional screenshots).
  • Integration and credential data: when you connect third-party apps, MCP servers, or store API keys, we process connection metadata and encrypt credential values at rest using application-level encryption.
  • Team collaboration data: team names, slugs, logos, member roles, invitation email addresses, and leave requests.
  • Billing-related identifiers: Stripe customer and subscription identifiers and transaction records. Payment card details are collected and processed by Stripe during checkout; we do not store full payment card numbers on our servers.
  • Communications with us: information you include in support requests, bug reports, or emails to us.

Information from third-party sign-in

  • Google sign-in: email address, display name, and profile photo, based on the profile and email scopes you authorize.
  • LinkedIn sign-in: email address, name, and profile picture, based on the OpenID profile and email scopes you authorize.

Information from connected integrations (at your direction)

  • When you authorize integrations through our integration partners (such as Composio) or legacy connection paths, we and our subprocessors may process data from those services as needed to run the actions and triggers you configure—for example, email content, calendar events, Slack messages, or social media account data. We do not collect this data unless you connect the integration and configure an agent or workflow to use it.
  • Inbound webhooks from connected integrations may deliver event payloads that are processed to execute your configured automations.

Information collected automatically

  • Authentication cookies: httpOnly session cookies (`ah_access`, `ah_refresh`) used to keep you signed in.
  • Usage and operational data: feature usage, agent run metadata, token and credit consumption records, API request logs (method, path, status, duration), and similar technical logs used to operate and secure the Services.
  • Device and browser information: browser type, operating system, language, and general location derived from IP address where available in server logs or security tooling.
  • Error and diagnostic data: when enabled, error reports and related diagnostic information sent to our monitoring providers, with sensitive authentication data scrubbed before transmission.

Information we do not intentionally collect

  • We do not require a phone number to create an account.
  • We do not operate marketing newsletters or promotional email programs within the application.
  • We do not use Google Analytics or similar advertising analytics on our Services.
  • We do not knowingly collect personal information from children under 16.

If you do not provide required personal information, we may be unable to create your account, authenticate you, or provide all features of the Services.

3. Purposes for Collecting and Processing

We process personal information for the following purposes:

  • Providing and operating the Services, including account registration, authentication, agent execution, workflow orchestration, knowledge retrieval, team workspaces, marketplace features, and A2A connectivity.
  • Processing payments and managing subscriptions, credits, and billing records through Stripe.
  • Sending transactional communications, such as sign-in codes, team invitations, human-in-the-loop approval requests, and service-related notices, via our email delivery provider.
  • Enabling third-party integrations and MCP connections that you authorize.
  • Running AI features by sending prompts, messages, knowledge excerpts, and tool outputs to AI model providers when you use those features.
  • Personalizing your experience, including onboarding, assistant memories, and optional user profile or "brain" features.
  • Monitoring usage, calculating credits and costs, improving reliability, and developing new features.
  • Providing customer support, investigating bug reports, and—where necessary—administrative account access by authorized support personnel to resolve issues you report.
  • Protecting the Services and our users, including fraud prevention, rate limiting, access controls, encrypted credential storage, and abuse detection.
  • Complying with legal obligations and responding to lawful requests from regulators, courts, or law enforcement.
  • Managing corporate transactions such as mergers, financing, or reorganizations, subject to applicable law.

4. AI Processing and Automated Features

Agentshub AI is an AI agent platform. When you create, run, or interact with agents, skills, workforces, or assistants, we process the content you submit and generate outputs using third-party AI and automation providers (such as OpenRouter and, where configured, direct model providers, Replicate, Apify, and similar services).

Outputs may be inaccurate or incomplete. You are responsible for reviewing outputs before relying on them, especially where they affect third parties or regulated activities.

When you connect integrations, agents may take actions in external systems on your behalf according to the permissions and workflows you configure. You control which integrations are connected and which automations are enabled.

We do not use your private workspace content to train public foundation models unless a specific feature clearly states otherwise and you opt in. AI providers may process data according to their own terms when you use AI features.

5. Disclosures of Personal Information

We may disclose personal information to the following categories of recipients for the purposes described in this Notice:

  • Service providers and subprocessors that help us operate the Services, including hosting and database providers, Redis/cache providers, workflow infrastructure, email delivery (Plunk), payment processing (Stripe), integration platforms (Composio), AI routing and model providers (OpenRouter and related model hosts), optional media generation (Replicate), web scraping actors (Apify), optional object storage (AWS S3), optional error monitoring (Sentry), optional log aggregation (Axiom), optional LLM tracing (LangSmith), optional graph database services (Memgraph), code sandbox infrastructure (Cloudflare Workers), and issue tracking for bug reports (Atlassian Jira).
  • Other users, when you publish content to the marketplace, share team workspace resources, or use features that expose information to collaborators.
  • OAuth and identity providers (Google, LinkedIn) when you choose to sign in with those services.
  • Professional advisers, auditors, lenders, or acquirers where reasonably necessary for corporate, legal, or compliance purposes.
  • Law enforcement, regulators, courts, or other parties when required by law or when we believe disclosure is necessary to protect rights, safety, or security.

International transfers. Our subprocessors may process personal information in countries other than your own, including the United States, the United Kingdom, the European Economic Area, Australia, and other regions where they operate. Where required by applicable law, we implement appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses or equivalent mechanisms. Contact us for more information about safeguards applicable to your region.

Aggregate and de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably be used to identify you for analytics, research, and service improvement.

6. Cookies and Similar Technologies

We use a limited set of cookies and similar technologies:

  • Strictly necessary authentication cookies (`ah_access`, `ah_refresh`): httpOnly cookies that maintain your signed-in session. Access tokens expire after approximately 15 minutes; refresh tokens expire after up to 30 days unless you sign out or we revoke them.
  • Payment scripts: when you use Stripe Checkout, Stripe may set cookies or use similar technologies subject to Stripe's privacy notice.
  • Error monitoring: if enabled in our environment, Sentry may use cookies or similar technologies to help diagnose errors, subject to Sentry's privacy notice.

We do not use advertising cookies, cross-site tracking pixels, or third-party marketing analytics on the Services.

Your browser may store local preferences (for example, UI state or drafts) in local storage. These are generally not used for authentication and can be cleared through your browser settings.

Because we rely on essential session cookies for sign-in, disabling them may prevent you from using authenticated features.

7. Your Privacy Choices

  • Account information: you can view and update certain profile information in Settings.
  • Integrations: you can disconnect third-party integrations, MCP servers, and stored credentials from the Connections area of the Services.
  • Memories and knowledge: you can delete assistant memories, user facts, and knowledge base items through the relevant product features.
  • Marketing communications: we send primarily transactional emails related to your account and use of the Services. We do not operate a general marketing newsletter within the product at this time.
  • Access, correction, deletion, and portability: you may request access to, correction of, deletion of, or a copy of your personal information by contacting us at the details in Section 15. We will respond in accordance with applicable law. Self-service account deletion is not currently available in the product; deletion requests are handled manually after identity verification.
  • Objection and restriction: where applicable law provides these rights, you may object to or request restriction of certain processing by contacting us.
  • Withdraw consent: where we rely on consent (for example, connecting an optional integration), you may withdraw consent by disconnecting the integration or contacting us.

9. User-Generated and Shared Content

If you publish agents, skills, or workforces to the marketplace, or use team or public-facing features, information you include may be visible to other users or the public according to the visibility settings you choose.

Do not submit sensitive personal information to prompts, knowledge bases, or public listings unless you intend for that information to be processed and, where applicable, disclosed according to your configuration.

10. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have collected information from a child in violation of applicable law, contact us using the details in Section 15 and we will take appropriate steps.

11. Security and Retention

We use technical and organizational measures designed to protect personal information, including encryption in transit (HTTPS), encryption of stored integration credentials, httpOnly authentication cookies, rate limiting, and access controls. No method of transmission or storage is completely secure.

We retain personal information for as long as necessary to provide the Services, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements. Examples include:

  • One-time sign-in codes: approximately 10 minutes.
  • Refresh tokens: up to 30 days unless revoked earlier.
  • Team invitations: approximately 24 hours unless accepted or cancelled.
  • Account and workspace content: retained while your account is active and for a reasonable period thereafter where required for backup, legal, or security purposes.
  • Billing records: retained as needed for accounting, tax, and fraud prevention, consistent with applicable law and Stripe's records.
  • Operational cost and usage telemetry (provider spend and credit ledger events used for internal Cost Burn analytics): retained for approximately 90 days, then automatically deleted.

When an authorized administrator deletes a user account, we delete or cascade-delete associated runs, knowledge, credentials, skills, and related records from our primary systems, subject to backup and legal retention requirements.

12. Changes to this Notice

This Notice is current as of 17 July 2026. We may update this Notice from time to time. We will post updates on this page and, where required by law, provide additional notice such as by email or an in-product notice for material changes.

13. Australia-Specific Provisions

If you are in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles may apply to our handling of your personal information.

  • Access and correction: you may request access to or correction of personal information we hold about you, subject to exceptions under applicable law.
  • Complaints: if you have a complaint about our handling of your personal information, contact us first. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

14. EU and UK Specific Provisions

If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR may apply. Depending on the processing activity, our lawful bases include:

  • Performance of a contract: to provide the Services you request, manage your account, process payments, and deliver team or marketplace features.
  • Legitimate interests: to secure and improve the Services, prevent abuse, provide support (including limited administrative access where necessary), and understand product usage, balanced against your rights.
  • Consent: where you connect optional integrations or otherwise provide consent for a specific purpose.
  • Legal obligation: where we must comply with applicable law.

You may have the right to access, rectify, erase, restrict, or object to processing, and to data portability, where applicable. You may also lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concern.

For transfers outside the EEA/UK, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses where required. Contact us for more information.

15. Contact Us

If you have questions about this Notice or wish to exercise your privacy rights, contact us at:

WareweAI Private Limited 677P, Sector 42, Gurugram, Haryana -122002, India Email: support@agentshub.ai

Website: https://agentshub.ai

Questions about this notice?

Email support@agentshub.ai to exercise your privacy rights or ask a question. We verify identity before acting on requests and respond in line with applicable law.