Last updated 24 July 2026

Privacy Notice

This notice explains how AgentsHub collects, uses, and protects personal information when you use AgentsHub.

AgentsHub · 677P, Sector 42, Gurugram, Haryana -122002, India · support@agentshub.ai

Introduction

AgentsHub ("AgentsHub," "we," "our," or "us") values your privacy. This Privacy Notice ("Notice") describes how AgentsHub collects, uses, discloses, and otherwise processes personal information when you use our website at https://agentshub.ai, related subdomains such as connect.agentshub.ai, and our AI agent platform, marketplace, and related services (collectively, the "Services").

In this Notice, "personal information" (or "personal data") means information that identifies you or can reasonably be linked to you. This Notice applies whenever we process your personal information in connection with the Services described in Section 1.

For information about your choices, see Section 7. Your Privacy Choices. For EU/UK and Australian residents, additional rights are described in Sections 13 and 14.

1. Scope

This Notice applies to our online processing activities relating to individuals who:

  • Visit our website or use the AgentsHub application;
  • Create or use a AgentsHub account;
  • Build, run, publish, or acquire AI agents, skills, or workforces on our platform;
  • Participate in team workspaces or accept team invitations;
  • Connect third-party applications or services to AgentsHub;
  • Use our Agent-to-Agent (A2A) connectivity features;
  • Purchase subscriptions or credit packs;
  • Contact us for support or submit bug reports.

Additional notices. If we provide a supplemental notice for a specific feature (for example, a marketplace listing or team workspace), that notice applies to the extent it conflicts with this Notice for that processing activity.

Team and business customers. When you use AgentsHub through a team or organization account, your organization may administer your access. Your organization's policies may also apply to how it uses information processed through the Services.

This Notice does not apply to personal information we process about job applicants, employees, or contractors in the context of our working relationship with them, which is covered by separate notices.

2. Personal Information We Collect

We collect personal information directly from you, automatically when you use the Services, and from third parties where you connect integrations or sign in with a third-party account.

Information you provide directly

  • Account and profile information: email address, display name, password (stored as a secure hash for password-based accounts), profile photo (when provided via sign-in), first and last name, job title, company name, and stated use case collected during onboarding.
  • Authentication data: one-time passcodes sent to your email for sign-in or verification; we store hashed codes and related challenge metadata for a limited time.
  • User-generated platform content: agent and skill configurations, prompts, workflows, knowledge base documents and uploads (including files up to 25 MB), chat messages with our Hub Assistant and builder tools, run inputs and outputs, memories and user facts you or your agents store, team names and membership details, marketplace listings, and bug report descriptions (including optional screenshots).
  • Integration and credential data: when you connect third-party apps, MCP servers, or store API keys, we process connection metadata and encrypt credential values at rest using application-level encryption.
  • Team collaboration data: team names, slugs, logos, member roles, invitation email addresses, and leave requests.
  • Billing-related identifiers: Stripe customer and subscription identifiers and transaction records. Payment card details are collected and processed by Stripe during checkout; we do not store full payment card numbers on our servers.
  • Communications with us: information you include in support requests, bug reports, or emails to us.

Information from third-party sign-in

  • Google sign-in: email address, display name, and profile photo, based on the profile and email scopes you authorize.
  • LinkedIn sign-in: email address, name, and profile picture, based on the OpenID profile and email scopes you authorize.

Information from connected integrations (at your direction)

  • When you authorize integrations through our integration partners (such as Composio) or legacy connection paths, we and our subprocessors may process data from those services as needed to run the actions and triggers you configure—for example, email content, calendar events, Slack messages, or social media account data. We do not collect this data unless you connect the integration and configure an agent or workflow to use it.
  • Inbound webhooks from connected integrations may deliver event payloads that are processed to execute your configured automations.

Information collected automatically

  • Authentication cookies: httpOnly session cookies (`ah_access`, `ah_refresh`) used to keep you signed in.
  • Usage and operational data: feature usage, agent run metadata, token and credit consumption records, API request logs (method, path, status, duration), and similar technical logs used to operate and secure the Services.
  • Device and browser information: browser type, operating system, language, and general location derived from IP address where available in server logs or security tooling.
  • Product analytics (optional): if you enable Analytics cookies, Google Tag Manager and related measurement tags may collect page views, events, device/browser information, and similar usage data to help us understand how the Services are used.
  • Error and diagnostic data: when enabled, error reports and related diagnostic information sent to our monitoring providers, with sensitive authentication data scrubbed before transmission.

Information we do not intentionally collect

  • We do not require a phone number to create an account.
  • We do not operate marketing newsletters or promotional email programs within the application.
  • We do not knowingly collect personal information from children under 16.

If you do not provide required personal information, we may be unable to create your account, authenticate you, or provide all features of the Services.

3. Purposes for Collecting and Processing

We process personal information for the following purposes:

  • Providing and operating the Services, including account registration, authentication, agent execution, workflow orchestration, knowledge retrieval, team workspaces, marketplace features, and A2A connectivity.
  • Processing payments and managing subscriptions, credits, and billing records through Stripe.
  • Sending transactional communications, such as sign-in codes, team invitations, human-in-the-loop approval requests, and service-related notices, via our email delivery provider.
  • Enabling third-party integrations and MCP connections that you authorize.
  • Running AI features by sending prompts, messages, knowledge excerpts, and tool outputs to AI model providers when you use those features.
  • Personalizing your experience, including onboarding, assistant memories, and optional user profile or "brain" features.
  • Monitoring usage (including optional product analytics via Google Tag Manager when Analytics cookies are enabled), calculating credits and costs, improving reliability, and developing new features.
  • Providing customer support, investigating bug reports, and—where necessary—administrative account access by authorized support personnel to resolve issues you report.
  • Protecting the Services and our users, including fraud prevention, rate limiting, access controls, encrypted credential storage, and abuse detection.
  • Complying with legal obligations and responding to lawful requests from regulators, courts, or law enforcement.
  • Managing corporate transactions such as mergers, financing, or reorganizations, subject to applicable law.

4. AI Processing and Automated Features

AgentsHub is an AI agent platform. When you create, run, or interact with agents, skills, workforces, or assistants, we process the content you submit and generate outputs using third-party AI and automation providers (such as OpenRouter and, where configured, direct model providers, Replicate, Apify, and similar services).

Outputs may be inaccurate or incomplete. You are responsible for reviewing outputs before relying on them, especially where they affect third parties or regulated activities.

When you connect integrations, agents may take actions in external systems on your behalf according to the permissions and workflows you configure. You control which integrations are connected and which automations are enabled.

We do not use your private workspace content to train public foundation models unless a specific feature clearly states otherwise and you opt in. AI providers may process data according to their own terms when you use AI features.

5. Disclosures of Personal Information

We may disclose personal information to the following categories of recipients for the purposes described in this Notice:

  • Service providers and subprocessors that help us operate the Services, including hosting and database providers, Redis/cache providers, workflow infrastructure, email delivery (Plunk), payment processing (Stripe), integration platforms (Composio), AI routing and model providers (OpenRouter and related model hosts), optional media generation (Replicate), web scraping actors (Apify), optional object storage (AWS S3), optional product analytics / tag management (Google Tag Manager and related Google measurement products, only when Analytics cookies are enabled), optional error monitoring (Sentry), optional log aggregation (Axiom), optional LLM tracing (LangSmith), optional graph database services (Memgraph), code sandbox infrastructure (Cloudflare Workers), and issue tracking for bug reports (Atlassian Jira).
  • Other users, when you publish content to the marketplace, share team workspace resources, or use features that expose information to collaborators.
  • OAuth and identity providers (Google, LinkedIn) when you choose to sign in with those services.
  • Professional advisers, auditors, lenders, or acquirers where reasonably necessary for corporate, legal, or compliance purposes.
  • Law enforcement, regulators, courts, or other parties when required by law or when we believe disclosure is necessary to protect rights, safety, or security.

International transfers. Our subprocessors may process personal information in countries other than your own, including the United States, the United Kingdom, the European Economic Area, Australia, and other regions where they operate. Where required by applicable law, we implement appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses or equivalent mechanisms. Contact us for more information about safeguards applicable to your region.

Aggregate and de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably be used to identify you for analytics, research, and service improvement.

6. Cookies and Similar Technologies

We use a limited set of cookies and similar technologies:

  • Strictly necessary authentication cookies (`ah_access`, `ah_refresh`): httpOnly cookies that maintain your signed-in session. Access tokens expire after approximately 15 minutes; refresh tokens expire after up to 30 days unless you sign out or we revoke them.
  • Optional product analytics: if you enable Analytics cookies (Accept All, or Analytics on in Manage Cookies), we load Google Tag Manager, which may set cookies or use similar technologies and may load measurement tags configured in our container. Processing by Google is subject to Google's privacy notice.
  • Optional marketing cookies: if you enable Marketing in Manage Cookies (or Accept All), we may use marketing cookies or similar technologies as described in our Cookie Policy.
  • Payment scripts: when you use Stripe Checkout, Stripe may set cookies or use similar technologies subject to Stripe's privacy notice.
  • Error monitoring: if enabled in our environment and Analytics cookies are enabled where required, Sentry may use cookies or similar technologies to help diagnose errors, subject to Sentry's privacy notice.

Optional Analytics technologies (including Google Tag Manager) and Marketing cookies load only when those categories are enabled via our cookie banner or Manage Cookies. If you Reject All or leave a category off, we do not load it for your browser.

Your browser may store local preferences (for example, UI state or drafts) in local storage. These are generally not used for authentication and can be cleared through your browser settings.

Because we rely on essential session cookies for sign-in, disabling them may prevent you from using authenticated features.

For a full list of cookies, categories, and how to Accept All, Reject All, or Manage Cookies, see our Cookie Policy at https://agentshub.ai/cookies.

7. Your Privacy Choices

  • Account information: you can view and update certain profile information in Settings.
  • Integrations: you can disconnect third-party integrations, MCP servers, and stored credentials from the Connections area of the Services.
  • Memories and knowledge: you can delete assistant memories, user facts, and knowledge base items through the relevant product features.
  • Cookies: you can Accept All, Reject All, or Manage Cookies (Analytics and Marketing toggles, including Google Tag Manager under Analytics) via the cookie banner, and change your mind anytime from the Cookie Policy page.
  • Marketing communications: we send primarily transactional emails related to your account and use of the Services. We do not operate a general marketing newsletter within the product at this time.
  • Access, correction, deletion, and portability: Self-service account deletion and a portable JSON data export are available in Settings → Profile. You may also contact us at the details in Section 15. Deletion starts a 16-day waiting period you can cancel; after that we erase your personal data from live systems. We keep an anonymous account ID so marketplace listings you published can stay online without your name, and we keep billing records where required for tax or legal obligations. Team workspace content you created for a team stays with that team. Active subscriptions must be cancelled and team ownership transferred or teams archived/deleted before deletion can be scheduled. You can download a copy of your primary personal data (excluding secrets such as passwords and encrypted credentials) via Download my data before deleting.
  • Objection and restriction: where applicable law provides these rights, you may object to or request restriction of certain processing by contacting us.
  • Withdraw consent: where we rely on consent (for example, Analytics/Marketing cookies or connecting an optional integration), you may withdraw consent by changing cookie preferences, disconnecting the integration, or contacting us.

9. User-Generated and Shared Content

If you publish agents, skills, or workforces to the marketplace, or use team or public-facing features, information you include may be visible to other users or the public according to the visibility settings you choose.

Do not submit sensitive personal information to prompts, knowledge bases, or public listings unless you intend for that information to be processed and, where applicable, disclosed according to your configuration.

10. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have collected information from a child in violation of applicable law, contact us using the details in Section 15 and we will take appropriate steps.

11. Security and Retention

We use technical and organizational measures designed to protect personal information, including encryption in transit (HTTPS), encryption of stored integration credentials, httpOnly authentication cookies, rate limiting, and access controls. No method of transmission or storage is completely secure.

We retain personal information for as long as necessary to provide the Services, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements. Examples include:

  • One-time sign-in codes: approximately 10 minutes.
  • Refresh tokens: up to 30 days unless revoked earlier.
  • Team invitations: approximately 24 hours unless accepted or cancelled.
  • Account and workspace content: retained while your account is active and for a reasonable period thereafter where required for backup, legal, or security purposes.
  • Billing records: retained as needed for accounting, tax, and fraud prevention, consistent with applicable law and Stripe's records.
  • Operational cost and usage telemetry (provider spend and credit ledger events used for internal Cost Burn analytics): retained for approximately 90 days, then automatically deleted.
  • System backups: after account deletion, live systems are wiped immediately; encrypted backups that may still contain pre-deletion snapshots expire within approximately 30 days (or the period configured for our hosting environment), after which they are not restored into production.

When you complete self-service account deletion (or an authorized administrator deletes an account), we erase associated runs, knowledge, credentials, and related personal records from our primary (live) systems. Live marketplace listings may remain attributed to a scrubbed deleted-account record; billing records may be retained as required for tax and fraud prevention. Backup copies are not used as an active profile and expire on the backup rotation schedule described above.

Account deletion and subprocessors. After the cooling-off period we also request deletion or anonymization from processors where their APIs allow it (for example, cancelling and deleting a Stripe customer record, deleting your Plunk email contact, disconnecting Composio accounts, and anonymizing open Jira bug reports that identify you by email). We do not promise instantaneous removal from every third-party system. Optional observability and tracing tools (such as Sentry, Axiom, and LangSmith), when enabled, retain diagnostic data according to their configured retention periods and stop receiving new identifiable account activity once your account is erased. Workflow execution histories (Temporal) are not restored into live product systems as personal profiles; they expire according to platform retention.

12. Changes to this Notice

This Notice is current as of 24 July 2026. We may update this Notice from time to time. We will post updates on this page and, where required by law, provide additional notice such as by email or an in-product notice for material changes.

13. Australia-Specific Provisions

If you are in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles may apply to our handling of your personal information.

  • Access and correction: you may request access to or correction of personal information we hold about you, subject to exceptions under applicable law.
  • Complaints: if you have a complaint about our handling of your personal information, contact us first. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

14. EU and UK Specific Provisions

If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR may apply. Depending on the processing activity, our lawful bases include:

  • Performance of a contract: to provide the Services you request, manage your account, process payments, and deliver team or marketplace features.
  • Legitimate interests: to secure and improve the Services, prevent abuse, provide support (including limited administrative access where necessary), and understand product usage, balanced against your rights.
  • Consent: where you connect optional integrations or otherwise provide consent for a specific purpose.
  • Legal obligation: where we must comply with applicable law.

You may have the right to access, rectify, erase, restrict, or object to processing, and to data portability, where applicable. You may also lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concern.

For transfers outside the EEA/UK, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses where required. Contact us for more information.

15. Contact Us

If you have questions about this Notice or wish to exercise your privacy rights, contact us at:

AgentsHub 677P, Sector 42, Gurugram, Haryana -122002, India Email: support@agentshub.ai

Website: https://agentshub.ai

Questions about this notice?

Email support@agentshub.ai to exercise your privacy rights or ask a question. We verify identity before acting on requests and respond in line with applicable law.