AgentGatev1.1 Official Release
Privacy / Version: 2026-09-12

Privacy Policy

Established and effective: September 12, 2026 / Last updated: September 12, 2026

1. Account and Authentication Information

We process the Supabase Auth user ID, email address, account status, display language, onboarding status, SSO provider identifier, accepted Terms and Policy versions and timestamps, and session-revocation threshold. For registration confirmation and password-reset emails, Supabase sends the destination address and email content to the configured SMTP service, Brevo. Supabase Auth processes passwords; AgentGate does not store plaintext passwords in its application database.

2. Organization, Workspace, and Usage Data

We store organization or workspace IDs and names; member user IDs, email addresses, roles, and active status; agent names, descriptions, owners, status, environment, API-key prefix and irreversible hash, and last-used time; policies and versions; MCP server names, endpoints, secret-reference names, tool metadata, and connection status; authority, delegation, and data classifications; risk configuration, evaluations, and history; and lifecycle, model-routing, budget, compliance, SSO, and A2A configuration and change history. A plaintext API key is displayed once when issued or rotated and is not stored permanently.

3. Actions, Audits, Integrations, and Inquiry Data

We process operation and idempotency identifiers; target tools and resources; arguments or payloads; user-supplied goals and context; decisions, reasons, and risk evaluations; approval details, reviewer, and notes; execution results and errors; audit logs; Black Box evidence; and model inputs, outputs, usage, and cost estimates. For GitHub, we process App installation ID, account login, repository ID and full name, private status, default branch, and requests and results involving issues, pull requests, branches, and similar resources. For inquiries and feedback, we store the category, message, source page, request ID, agent ID, and optional contact address. We do not bulk-collect entire repositories, but request or response bodies, source, MCP arguments, prompts, and model outputs may be stored. Do not submit secrets.

4. IP Address, Browser Information, and Error Logs

Vercel receives communications data such as IP address, HTTP headers including User-Agent, requested URL, timestamp, and response status to process requests. AgentGate uses an IP address in an abuse-prevention rate-limit key and stores its SHA-256 hash in the database, but does not store raw IP addresses or User-Agent values in the analytics_events table. Application logs record sanitized information such as event names, request IDs, error types, and status codes and are processed by Vercel's logging infrastructure.

5. Purposes of Processing

We use the information for identity verification; account, organization, and contract administration; eligibility and authorization checks; pre-execution evaluation under policy, risk, and data rules; human approval; execution of GitHub, MCP, model, and similar requests; audit, evidence, replay, and incident response; usage and cost management; rate limiting and other security measures; troubleshooting; understanding feature usage and improving the product; and responding to inquiries.

6. Third-Party Services and External Transfers

We use Supabase for authentication and the Postgres database; Brevo for authentication email delivery; Vercel for hosting, Serverless Functions, logs, and AI Gateway; GitHub for repository integrations; and Stripe for payments and subscription administration. Public Astra Lab goals and enabled intent-analysis, policy-generation, or model.generate prompts, generation settings, model outputs, and usage are sent through Vercel AI Gateway to OpenAI, which is currently used, or to the model provider selected by the organization. AgentGate has no code path that stores public Astra Lab goals or results in its application database. A registered MCP server receives its endpoint, tool name, resource, arguments, and necessary credential. Depending on service availability, contracts, and settings, these providers may process data in locations outside the user's country. Destinations, data, and purposes are limited to the connected feature and this section.

7. Cookies, Analytics, and Advertising Measurement

We use authentication session cookies, a language-preference cookie lasting up to one year, and GitHub state or PKCE cookies lasting up to ten minutes. They use attributes including Secure in production, HTTP-only, and SameSite=Lax. On public pages, we store only a first-party landing_view, the path '/', and timestamp in Supabase without a user ID; we set no persistent visit identifier or analytics cookie. After login, we associate a user ID with events and paths for signup, setup, connections, agent creation, decisions, dashboard use, feedback submission, and limited aggregate properties. We currently use no Google Analytics, Google Ads, GTM, advertising cookies, advertising identifiers, or conversion tags, and have no consent banner for non-essential cookies. Before introducing Google Ads or other advertising identifiers or conversion tracking, we will update this Policy and, where applicable law requires, provide a consent UI before collection.

8. Billing and Card Information

We send Stripe the organization ID, selected plan, and checkout, portal, and subscription information linked to a Stripe customer ID. AgentGate stores the Stripe customer ID, subscription ID, price ID, plan, status, cancellation settings, contract period, and processed webhook event IDs. Card numbers, CVCs, and other card data are processed on Stripe-hosted pages and are not retained by AgentGate.

9. Requests for Access, Correction, Deletion, and Inquiries

Operator: [要設定: 販売業者名]

After verifying identity, we respond to requests for access, correction, suspension of use, deletion, and other inquiries under applicable law. Immediate deletion as requested may not be possible when information is needed for a contract, legal obligation, dispute, security, or protection of third-party rights. Disconnect GitHub in both AgentGate and GitHub, and revoke MCP or model credentials at both the destination and in AgentGate settings.

Contact: air0916.jp@gmail.com

10. Retention

Action requests, approvals, audit logs, Black Boxes, enterprise events, governance history, and intelligence history use the plan at recording: 7 days for Free, 30 for Starter, 90 for Team, 365 for Business, and the contractual setting for Enterprise (365 days by default), followed by periodic deletion. A plan change does not shorten existing deadlines. Records that are executing or referenced by a Black Box may remain until consistency is secured, and an Idempotency-Key and digest remain as a tombstone to prevent duplicate execution. Rate-limit hashes are cleanup candidates after their windows. No uniform automatic deletion deadline is implemented for accounts, organizations, agents and policies, connection settings, legal acceptances, billing state, usage aggregates, analytics, or feedback; they are therefore retained while an account, contract, or feature is active and as needed for the stated purpose, legal obligations, disputes, or security, with individual review upon a deletion request. Provider-side records follow each provider's contract, settings, and applicable law.

11. Security Measures

We use TLS communications, Supabase RLS and organization boundaries, authentication-session expiry and revocation checks, GitHub App permissions scoped by installation, server-side credential storage, API-key hashing, secret detection and masking, same-origin checks, rate limits, audit records, security headers, and stop controls. These measures reduce risk but do not guarantee complete security or that a breach can never occur.

12. Policy Changes and Effective Date

This Policy applies from September 12, 2026. We update it when our processing changes and announce material changes through the Service. When renewed consent is required, we ask users to accept the new version on their next use.