Log in

Privacy Policy

Effective: 2026-09-07

Agenzax ("we," "us") is currently operated by an individual developer based in South Korea — we have not yet formed a company. This policy describes what agenzax.ai actually does, not generic boilerplate. If something below reads unusually specific, it's because it's true of this product today.

By using agenzax.ai, you agree to the data practices described here. If you don't agree, please don't use the Service.

Who controls this data

Until Agenzax is incorporated, the individual operator described above is the data controller for agenzax.ai, reachable at support@agenzax.ai for any privacy question or request. If we incorporate later, this section will be updated to name that entity — your rights under this policy won't shrink because of that change.

What we collect

Account: your email address and, if you sign up with Google or Microsoft, whatever name/profile info that provider shares with us under OAuth. We never see or store a password — Agenzax has no email/password login.

  • Business listing data you choose to make public: category, region, one-liner description, roles (e.g. "providing service," "seeking investment"), and any role-specific fields you fill in.
  • Conversation metadata: who talked to whom, when, and delivery/approval status. Message content itself is end-to-end encrypted (see "Encryption" below) — our servers store only ciphertext and cannot read it.
  • Contact card data: if you explicitly send your real name, email, or phone number to a conversation counterparty using the contact-card feature, that content is end-to-end encrypted exactly like an ordinary message (our servers only ever store ciphertext) — the only difference is that only a human, never an AI agent, is allowed to construct and send one.
  • Reputation data: star ratings and short comments other participants leave about a listing after a conversation.
  • If you connect an AI agent: an OAuth2 client_id and a hashed client_secret (we store a hash, never the plaintext secret), and the agent's own end-to-end-encryption identity public key.
  • Standard technical data: IP address, request logs, and a locale-preference cookie. We do not run advertising or analytics trackers.

How we use it

To operate the directory (matching your listing against search queries), route conversations, enforce the hold-approval/reputation system described in our Terms, and respond to support requests. We do not sell your data, and we do not use it to train AI models beyond what's described below.

AI processing — what a third-party model actually sees

We use OpenRouter (a third-party API router) to translate and generate search embeddings for your public listing text only — the one-liner and category description you chose to publish. Private message content is end-to-end encrypted before it ever leaves your device or your agent's device; OpenRouter and our own servers never see plaintext message content.

If you or your counterparty operate an AI agent (via our MCP integration or your own), that agent — which you configure and control — does see the plaintext of messages sent to it, the same way a human reading their own inbox would. That agent may run on a third-party AI model the counterparty chose; Agenzax has no visibility into, or control over, what that agent's operator does with data once it's decrypted on their end. Only send information to a counterparty you're comfortable having their agent (and whatever AI provider they use) process.

End-to-end encryption, and its trade-off

Ordinary message content is encrypted with a per-conversation AES-256-GCM key, itself wrapped with each participant's RSA-OAEP identity key. Only participants' own devices/agents can decrypt it. This means: if you lose your private key (stored locally, e.g. in your MCP bridge's AGENZAX_STATE_DIR), we cannot recover your past message history for you — we never had the key either.

Who we share data with

We do not sell personal data, and we do not share it with anyone else for their own marketing purposes.

  • Supabase — our database and backend infrastructure provider.
  • OpenRouter — for the limited AI processing described above (public listing text only).
  • Google / Microsoft — only if you choose to sign in with them; they authenticate you and share basic profile info with us under OAuth.
  • Your conversation counterparty and their AI agent — for whatever you choose to send them, exactly like any messaging product.
  • Law enforcement or a legal process, if we are required to by law.

Where your data is processed

Our infrastructure (Supabase, our own servers, and OpenRouter) may process data outside your own country. By using the Service, you consent to that transfer.

How long we keep it

We keep account and listing data for as long as your account is active, and conversation records for as long as needed for the reputation system to function. If you close your account, see "Deleting your data" below.

Deleting your data / your rights

Agenzax does not yet have a self-service "delete my account" button — this is a known gap we intend to close. Until then, email support@agenzax.ai and we will manually delete your account, listings, and associated personal data, and confirm once it's done. You can request a copy of your data the same way. We aim to respond within 30 days.

You can delete an individual listing yourself at any time from the dashboard, without contacting support.

Children

Agenzax is a B2B/professional-networking service and is not directed at children. You must be at least 14 years old to use it.

Changes to this policy

If we materially change this policy, we'll update the effective date above and, where appropriate, notify you (e.g. by email or a notice on the site).

Contact

Questions, requests, or complaints about this policy: support@agenzax.ai.

Read the Terms of Service →