Agentic Fabriq, Inc. (“Agentic Fabriq,” “we,” “us,” or “our”) respects the privacy of our users (“user” or “you”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our identity and permissioning platform for AI agents (the “Services”) or visit agenticfabriq.com.
If you have any questions or concerns about this policy or our practices, contact us at support@agenticfabriq.com.
1. Our Role in Handling Your Data
Our responsibilities differ depending on the data:
- For website visitors, account holders, billing, and platform security — we act as the controller (or “business”).
- For data from services our customers connect (such as Google Workspace, Slack, or Notion) — we act as a processor (or “service provider”) on the customer’s behalf and under their instructions.
- For security, abuse prevention, and legal compliance — we act as an independent controller for those limited purposes.
If you use Agentic Fabriq through your employer, your employer controls its workspace and the data connected to it. Requests about workspace data may need to go to your workspace administrator; we support our customers in responding to them.
2. Collection of Your Information
Personal Data
Name, work email, organization and team membership, roles, and settings you provide when you create an account or use the Services — plus messages you send us through support, demo requests, and billing records handled by our payment processor.
Derivative Data
Information our servers collect automatically: IP address, browser type, device information, and usage data, plus the website data described in Section 6.
Platform Data
- Connection metadata: which providers are connected, the scopes granted, connection status, and timestamps.
- Credentials: OAuth access and refresh tokens and API credentials for connected services, held in an encrypted secrets vault (Section 7).
- Audit records: metadata about each agent action — who asked, which agent acted, the tool and action, the policy decision, timestamp, IP address, and user agent. Audit records do not include message or document bodies.
- Assistant conversations: if you use the in-product assistant, the messages you type to it and its replies.
Connected-Service Data
When you or your workspace administrator authorizes a connection and an authorized agent or user makes a request, we process the content needed to serve that request — for example a Gmail message, a Slack conversation, a Notion page, or a Drive file — within the scopes that were granted. We process this content transiently and do not keep copies of it (Section 7).
3. Use of Your Information
We use information strictly to provide and improve the Services. Specifically, to:
- Broker authorized agent actions, enforce permission policies, and maintain the audit trail (contract performance).
- Create and manage your account, respond to support requests, and handle billing (contract performance).
- Secure and operate the platform — authentication, token management, fraud and abuse prevention, reliability (contract performance; our legitimate interest in securing the Services).
- Understand and market our website, as described in Section 6 (legitimate interests; consent where local law requires it).
- Comply with legal obligations and enforce our terms (legal obligation; legitimate interests).
We do not:
- Sell customer content or connected-service data.
- Use customer content or connected-service data for advertising.
- Use customer content or connected-service data to train AI or machine-learning models.
Website visit data is handled separately (Section 6). Where we rely on consent, you may withdraw it at any time; where we rely on legitimate interests, you may object as described in Section 9.
4. Disclosure of Your Information
We disclose personal information only to these categories of recipients:
- Cloud infrastructure and hosting providers — our platform runs on Google Cloud; our website is hosted on Heroku.
- AI model providers — for the limited product features described in Section 5.
- Email, communications, and payment providers — for transactional email and billing.
- Website analytics and advertising vendors — as described in Section 6.
- Professional advisers — lawyers, accountants, and insurers, where necessary.
- Authorities and successors — where required by law, to protect rights and safety, or in a corporate transaction with the same protections continuing.
Sub-processors that handle customer data are bound by contractual and security safeguards. A current list is available on request at support@agenticfabriq.com.
5. AI and Model Providers
Two paths matter here, and they behave differently:
- Your agents calling models: Agentic Fabriq is infrastructure between your agents and your tools. When your agent uses a language model, that is your (or your vendor’s) model relationship — we broker the agent’s tool calls and do not route your connected-service content through model providers of our own.
- Our product features that use models: the in-product assistant and configuration suggestions send data to third-party model providers (currently Google and OpenAI) under our agreements with them. That data is platform metadata (agent names, tool names, connection status, usage counts) and the text you type to the assistant.
We do not:
- Send connected-service content (your emails, messages, documents) or stored credentials to model providers.
- Use customer content or connected-service data to develop, train, or improve AI or ML models.
- Permit our model providers to train on this data under our configurations.
6. Cookies and Website Tracking
Our website (not the product) uses three third-party services:
- Google Analytics 4 — aggregate site traffic (pages visited, referral sources, approximate region).
- Reddit Pixel — measuring the effectiveness of our advertising on Reddit.
- RB2B — a business visitor-identification service that may associate a visit with business contact information (such as a work email) that RB2B or its partners already hold, so we can follow up with companies that show interest.
These services set cookies and receive standard technical data such as IP address, browser type, and pages viewed. Depending on applicable law, some disclosures through these technologies may be considered a “sale,” “sharing,” or targeted advertising; you can exercise the opt-out rights below and in Section 9.
Opt-outs
- Global Privacy Control: we honor the GPC browser signal — if your browser sends it, none of these services is loaded at all.
- Block cookies with browser settings or a tracker blocker.
- Google Analytics: the opt-out add-on.
- Reddit: your Reddit privacy settings.
- RB2B: app.retention.com/optout (EU/UK: rb2b.com/rb2b-gdpr-opt-out).
7. Data Protection and Security
- Credentials: OAuth access and refresh tokens live in a dedicated encrypted secrets vault, separate from application data. Credentials are injected server-side at call time — agents do not hold them by default.
- Connected-service content: processed transiently to serve authorized requests. We do not maintain copies, search indexes, embeddings, or derived stores of your content.
- Encryption and access controls: data is encrypted in transit and at rest, with strict authentication and access controls.
- Human access: our personnel do not routinely access customer content. Access may occur only when reasonably necessary for customer-authorized support, investigating or remediating a security incident, maintaining service reliability, complying with law, or as otherwise authorized by the customer — limited to authorized personnel, logged, and access-controlled.
8. Data Retention and Deletion
- Account records: for the life of the account, then as needed for legal, tax, and dispute purposes.
- Credentials: until you disconnect the integration, the credential is replaced or expires, or the member or organization is removed — then our stored copy is deleted from the vault.
- Connected-service content: not retained (Section 7).
- Assistant conversations: until deleted with the account or on request.
- Audit and security records: retained for security, compliance, and customer-evidence purposes, independently of account deletion. They contain action metadata only.
- Database backups: automated backups are retained for 7 days.
- Support, sales, and marketing records: as long as needed for the relationship and as required by law.
- Website analytics: governed by the vendor retention settings in Section 6.
Disconnecting integrations
You can disconnect any integration at any time. Disconnecting causes us to delete the credentials we hold for that connection from our vault. You may also revoke access directly through the provider — for Google at myaccount.google.com/permissions, and for Slack and Notion in those products’ app-management settings. Because we do not persist connected-service content, there is no content store to purge on disconnection.
9. Your Rights and Control Over Your Data
Where applicable law grants them, you have the right to:
- Access your personal data and receive a copy of it.
- Request corrections to your data.
- Request deletion of your data.
- Port your data to another service.
- Opt out of “sale,” “sharing,” or targeted advertising (Section 6 — we honor GPC as an opt-out signal).
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Appeal a decision on your request, and complain to your local supervisory or enforcement authority.
To exercise any of these rights, contact support@agenticfabriq.com. We verify requests using information associated with your account (or, for website-only requests, your email), respond within the time required by applicable law, and never discriminate against you for exercising your rights. Authorized agents may submit requests with proof of authorization. If your data is controlled by your employer’s workspace, we may refer the request to them (Section 1).
10. International Transfers
We are based in the United States and process data there. If you access the Services from a region with data-transfer restrictions (such as the EU or UK), your information is transferred to the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses with our vendors.
11. Automated Decision-Making
Agentic Fabriq provides infrastructure through which customers configure and operate AI agents. We do not use personal information to make decisions about individuals that produce legal or similarly significant effects (such as employment, credit, housing, or healthcare decisions). Customers are responsible for how they configure their own agents and workflows, and for any notices or human review their use cases require.
12. Children
The Services and website are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post changes on this page with a new effective date, and for material changes affecting customers we will provide notice through the Services or by email.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at support@agenticfabriq.com.
Integration-Specific Addenda
Google Workspace Addendum
This section applies when you or your workspace administrator authorizes a connection between Google Workspace and Agentic Fabriq. Depending on the features your organization enables, the integration can access Gmail, Drive, Docs, Sheets, Slides, Calendar, Meet, Forms, Classroom, Contacts, Google Chat, and Tasks. The default connection requests read-only scopes; write scopes (for example, sending email or updating files) are requested only for features your organization enables, and the Google authorization screen identifies the specific permissions requested.
Limited Use of Google User Data
Agentic Fabriq’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve the user-facing features of the connection you authorized. We do not:
- Use or transfer Google user data for serving ads.
- Sell Google user data, or use it to build advertising profiles.
- Use Google user data to develop, train, or improve AI or machine-learning models — and our own product features do not send Google Workspace content to model providers (Section 5).
- Transfer Google user data except to provide or improve user-facing features, to comply with applicable law, or as part of a merger or acquisition with the same protections continuing.
- Allow human access beyond the access-control commitments in Section 7.
If any term in this Policy conflicts with the Limited Use commitments above, the more protective term applies to Google user data.
Slack Addendum
Agentic Fabriq requests only the Slack permissions required for the features your organization enables; the Slack authorization screen identifies the specific permissions requested for your installation. We do not request administrative scopes.
Data we receive from Slack
- OAuth tokens for the installation, including user tokens where those scopes are granted.
- Workspace and bot identifiers, and conversation metadata (IDs, names) accessible under the granted scopes.
- Message content accessible under the granted scopes. Where an installation grants user-token read scopes, an authorized agent acting for that user can read conversations that user is a member of — including direct messages and private channels — within those scopes. Content is processed to serve the authorized request and is not persisted (Section 7).
Write actions (such as sending a message) occur only where write scopes were granted and a feature your organization enabled uses them. We do not subscribe to Slack event streams; data is accessed when an authorized agent or user makes a request.
We handle Slack data in accordance with applicable Slack developer terms. If this addendum conflicts with the rest of this Policy, the more protective provision applies to Slack data.
Notion Addendum
Agentic Fabriq can access only the Notion content made available to the integration through the authorization and sharing controls provided by Notion, subject to the permissions granted to the integration.
Data we receive from Notion
- OAuth credentials: the integration access token, workspace ID, and basic workspace metadata.
- User and workspace information: where enabled during authorization, user names and avatars (and email, if you choose that option).
- Content shared with the integration: pages, databases, and blocks made available through Notion’s sharing controls, processed to serve authorized requests and not persisted (Section 7).
Where the authorization permits, agents can also create, update, and archive Notion pages and databases and append content — these write actions occur only through the permissions granted to the integration and the policies your organization sets in Agentic Fabriq.
If this addendum conflicts with the rest of this Policy, the more protective terms apply to Notion data.