Privacy Policy
What Delagents collects on the website and in the preview app, why, how long it is kept, who processes it, and the rights you have over it.
Effective 17 September 2026
Delagents is in preview. The website is live, the workspace app runs on demo data, and the backend that will process customer data is being built. Sections marked 'when the app launches' describe processing that has not started. We will update this policy before it does.
1. Who we are and what this policy covers
Delagents (the operator, 'we') runs the website at delagents.com and the Delagents workspace app. This policy explains what personal data we collect when you visit the website, write to us or use the preview app, how we use it, and the choices you have. It applies to visitors, to people who contact us and, when the app launches, to account holders.
When a customer uses Delagents to process data about their own customers, contacts or candidates, the customer is the controller of that data and we act on their instructions as a processor. That relationship is described in our Data Processing Addendum. This policy covers the data we handle as a controller.
2. What we collect
On the website
- Contact form and email: your name, email address, the message you send and, if you include it, your company name. We collect this when you write to us through the form or at hello@delagents.com.
- Server and security logs: IP address, browser type, requested pages and timestamps, recorded by Cloudflare, which hosts and protects the website. These logs keep the site running and block abuse.
- Analytics: we do not currently run analytics scripts on the website. If we add measurement, we will prefer aggregated, cookie-free methods and update this section before it goes live.
In the preview app
The preview app runs on demo data. It does not create accounts and does not connect to your tools. If you ask for early access, we collect the email address and name you give us so that we can write back.
When the app launches
- Account data: name, email address, workspace name, role, and sign-in identifiers handled by our sign-in provider.
- Billing data: plan, invoices and payment status. Card details are entered directly with our billing provider and are never stored on our systems.
- Customer content: briefs, attachments, transcripts of agent runs, deliverables, and data read from the tools you connect, within the scopes you grant.
- Integration tokens: the credentials that let an agent act in a connected tool, kept in an encrypted vault and used only inside the tool call.
- Activity and usage records: the append-only log of tool calls, approvals and policy changes, and the usage records that make up your bill.
3. How we use it
- To answer your message and follow up on it.
- To run, secure and improve the website and the service.
- To operate your workspace: run delegations, show progress, file approvals, deliver results and keep the audit log.
- To bill you, and to send receipts, notices about your account and changes to these documents.
- To meet legal obligations and to establish or defend legal claims.
We do not sell personal data, and we do not use customer content to train models, whether our own or a provider's.
4. Legal bases for visitors in the EU, EEA, UK and Switzerland
| Purpose | Legal basis |
|---|---|
| Answering your message | Legitimate interest in responding to people who write to us, or your consent when you ask to be contacted |
| Security and server logs | Legitimate interest in keeping the website available and safe |
| Providing the service to account holders | Performance of the contract with you |
| Billing, tax and accounting | Legal obligation, and performance of the contract |
| Product notices and changes to these documents | Performance of the contract; legitimate interest |
| Marketing email, if we ever send it | Consent, which you can withdraw at any time |
5. Cookies
The website sets no marketing or tracking cookies. Cloudflare may set cookies that are strictly necessary for security and load balancing. When the app launches it will use a session cookie to keep you signed in, and nothing else without asking you first.
6. How long we keep it
- Contact messages: up to 24 months after our last exchange, unless the conversation leads to a contract, in which case they are kept with the account.
- Security logs: for the short period Cloudflare retains them, typically days rather than months.
- Account data: for the life of the account and up to 30 days after it is closed, then deleted.
- Customer content: for the retention period shown on your plan, then removed by a nightly purge that deletes transcript content and files while keeping the audit skeleton (which step ran, when, and who approved it) for the plan's audit retention period.
- Billing records: for the period required by tax and accounting law.
- Model provider: Anthropic retains data sent to its API for up to 30 days, after which it is deleted on their side.
7. Who processes data for us
We use a small number of providers to run the website and the service. Each processes data only on our instructions, under a written agreement, for the purpose listed.
| Provider | Purpose | Status |
|---|---|---|
| Cloudflare | Hosting, content delivery, security and edge services for the website and app | In use now |
| Anthropic | Model inference for delegations; API data retained up to 30 days; not used for training | When the app launches |
| Clerk | Sign-in, sessions and identity | Planned |
| Stripe | Billing, invoices and payment processing | Planned |
| Neon | Managed Postgres database | Planned |
We update this list before a new provider begins processing personal data. Account holders are notified of changes as described in the Data Processing Addendum.
8. International transfers
Our providers may process data outside the country you live in, including in the United States. Where data leaves the EU, EEA, UK or Switzerland, we rely on the European Commission's standard contractual clauses or an equivalent lawful safeguard, together with the security measures described on our security page. Regional hosting is on our roadmap and is not available in the preview.
9. Your rights
Depending on where you live, you have some or all of the following rights over your personal data. We honor them for everyone, wherever you are.
- Access: ask what data we hold about you and receive a copy.
- Correction: have inaccurate data fixed.
- Deletion: ask us to delete your data, subject to records we must keep by law.
- Portability: receive your data in a common, machine-readable format.
- Restriction and objection: ask us to limit or stop processing that is based on legitimate interests.
- Withdrawal of consent: at any time, where consent is the basis.
- Complaint: to your local data protection authority, if you believe we have handled your data unlawfully.
To exercise a right, email hello@delagents.com from the address concerned. We reply within 30 days. When the app launches, account data and customer content will also be exportable and deletable from the workspace settings.
10. Security
Data is encrypted in transit and at rest. Access to connected tools is granted per agent and scoped to what was approved. Integration tokens are held in an envelope-encrypted vault and never appear in prompts or logs. The activity log is append-only. Our security page describes these measures in more detail. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you without undue delay.
11. Children
Delagents is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
12. Changes to this policy
When we change this policy we publish the new version here with a new effective date. For material changes affecting account holders we also send an email before the change takes effect. The effective date at the top of the page is the date of the current version.
13. Contact
Questions, requests and complaints go to hello@delagents.com. A person reads and answers them.