Privacy Policy
What AgentMesh collects, what it does not, and what you can do about it.
1What this covers
This policy covers the AgentMesh web application at agent-mesh.app and the AgentMesh Android app. Where the two differ (and on location, they differ considerably) the difference is stated.
2Information you give us
Account details. Your email address and a hashed password. We never store your password itself.
Workflow content. The workflows you build, the configuration you enter into them, and the record of the runs they produce. Credentials you enter for third-party connectors are encrypted before storage.
Billing information. Records of credits purchased and consumed, and of on-chain payments made by your workflows.
3Location, in the Android app
This section exists because it is the part people most want a straight answer about.
The Android app can start a workflow when you cross the edge of a place you have chosen. To do that, Android must be allowed to check your location while the app is closed. This is entirely optional: everything else in the app works without it, and the feature stays off until you turn it on.
On your device. A crossing that happens with no signal is held on the phone until it can be sent, so it is not lost. Those pending readings do include your position. They never leave the device except to report that one crossing, and each is deleted as soon as it is sent, or within a day if it never can be.
Turning it off. Remove the zone in the app, or revoke location permission in Android settings. Removing the zone also clears the state described above.
4Notifications
If you allow notifications, your device is issued a registration token by Google’s Firebase Cloud Messaging, and we store that token so we can tell your device when one of your workflows finishes. It identifies the app installation, not you. Signing out removes it, and a token that stops working is deleted.
5What we do not do
We do not sell your personal information. We do not share it with third parties for their own advertising or marketing. We do not use your workflow content to train machine-learning models.
6Service providers
Running the product means some data passes through others: hosting and database providers, Google’s Firebase Cloud Messaging for notifications, payment and blockchain infrastructure for billing, and the AI model providers your workflows are configured to call. A workflow that calls an external model or tool sends that provider whatever the workflow gives it. You choose those connections, and their own privacy policies apply to them.
7Retention and deletion
Account and workflow data is kept while your account is open. Deleting a workflow deletes its configuration and its run history. To delete your account and the data associated with it, write to privacy@agent-mesh.app.
8Security
Traffic is encrypted in transit. Connector credentials are encrypted at rest, and on Android the session token is held in storage encrypted with a key kept in the device’s hardware keystore. No system is perfect, and we do not claim otherwise.
9Children
AgentMesh is not intended for children under 13, and we do not knowingly collect their information.
10Changes
If this policy changes materially, we will update the effective date above and notify account holders. Continuing to use AgentMesh after a change means you accept it.
11Contact
Questions, requests, or complaints: privacy@agent-mesh.app.