Privacy Policy
Last updated: August 11, 2026
What we collect
- Account data — name, email, and hashed password when you use email/password (plus short-lived reset tokens emailed to you); or third-party login data if Google sign-in is enabled.
- Billing data — managed by Stripe when you subscribe; we store plan status and Stripe customer/subscription ids needed to provide paid features (for example Pro).
- UI preferences — optional durable settings tied to your account when signed in (for example theme, workspace mode), and/or similar preferences in your browser local storage.
- Project files — files and chat you create while using the builder. Our product is designed so that durable project files live on your computer (Save to folder, Download ZIP, or open/link a folder in the desktop app). Temporary working copies may exist on the machine or host running Agentic Build while you work. We do not offer long-term cloud hosting of your full project trees as a core feature.
- AI keys (BYO models, optional) — if you enter your own LLM API keys, see “Bring-your-own API keys” below. These are secrets with monetary and security value; you choose to provide them.
- Technical data — basic server/logs needed to run and secure the service (for example IP, user agent, error logs).
Bring-your-own API keys (sensitive)
When you use Models → BYO models, you may paste an API key from a third-party AI provider (for example an OpenAI-compatible, Groq, OpenRouter, DeepSeek, or Anthropic key).
- Where stored — if you are signed in and the product is running with accounts and a database configured (typical cloud production), encrypted BYO profiles (API key material, model id, base URL, labels) may be stored in our database associated with your user account so settings can survive hosting redeploys and load balancing. On local/desktop open mode, keys may instead remain in an encrypted settings file on the machine running the app.
- How stored — keys are encrypted at rest (AES-256-GCM) using a secret derived from
AUTH_SECRETand/orAPP_BUILDER_SECRETS_KEY. Encryption is not a guarantee against every compromise: someone with access to both ciphertext and the decryption material, or with access to a logged-in session or bug that misuses your account, could cause your key to be used. We cannot promise zero risk for any secret you entrust to software. - How used — when you send agent requests, the server uses your key to call the AI provider you configured. We do not sell your keys. We do not use your BYO keys to train our own foundation models. Provider usage and billing happens on your account with that provider.
- What we show in the UI — after save, the product generally only indicates that a key is present; normal settings responses are not intended to re-display the full secret.
- Your responsibility — use keys you can revoke and monitor; protect your login; rotate keys after any suspected exposure; do not commit secrets to public repos; and review your AI provider’s privacy and data-use policies. Content you send (prompts, code, images) may be transmitted to that provider under their terms.
- No liability for keys or provider spend — by using BYO, you acknowledge that API keys are high-value secrets and that Agentic Build and its operators are not responsible or liable for unauthorized use of your keys, third-party API charges, loss of remaining credit/tokens, provider account actions, or damages resulting from storage or transmission of keys when you choose to use this feature. See our Terms of Service.
Subscriptions & plan status
If you subscribe, we process plan and payment status via Stripe and store the identifiers and plan fields needed to enable paid features (for example Pro platform AI when available). Plan detection is automated from those records and webhooks; it is separate from any BYO key you save. Failed payments may limit hosted AI while your own BYO key may still work if you configured one.
How we use data
- Provide login, builder, live preview, and export features.
- Run AI agents when you send messages (using your BYO key or, on Pro when configured, our platform AI capacity).
- Remember durable preferences you save to your account.
- Bill product subscriptions and prevent abuse.
- Respond to support requests you send us.
Sharing
We do not sell your personal information. We use subprocessors that help us operate the product (for example hosting, database, email delivery, payments, and LLM providers when you use Pro or your own keys). Content you send to an AI provider is processed under that provider’s terms. We are not responsible for how those providers store, use, or bill once data or requests leave Agentic Build.
Retention & your rights
You can export project files (Download ZIP / Save to folder). You may ask us to delete your account data via the contact form. Remove BYO keys in the product (clear the key field and save) when possible; after account deletion, associated encrypted key material is removed with your user record subject to backup retention. We retain billing records as required by law and fraud prevention.
Security
We use protections appropriate to a small online product (for example hashed passwords, HTTPS in production, session cookies, encrypted BYO keys at rest, and access controls on builder APIs when authentication is enabled). No method of storage or transmission is 100% secure. You accept residual risk when storing API keys or other secrets with any internet service, including this one. Report suspected security issues via the contact form.
Cookies & local storage
When you use Agentic Build in a browser, we may use cookies and similar local storage as follows:
- Necessary — session / authentication cookies (via Auth.js) so you can stay signed in and use protected features. These are required for the service to work when accounts are enabled.
- Preferences — optional local settings such as theme and layout preferences stored in your browser (localStorage). When you are signed in, some preferences may also sync to your account. You can turn optional local preference storage off in Cookie settings.
- Analytics — optional product measurement. We do not load analytics unless you opt in. We do not use third-party advertising cookies.
You can change your choices anytime via Cookie settings in the site footer, or by clearing site data in your browser. See also our cookie banner when you first visit.
Contact
Privacy questions: use the contact form. See also our Terms of Service.