Home/Privacy Policy

Privacy Policy

Last updated: July 18, 2026

This Privacy Policy explains how agorch.io (“we”, “us”, “the Service”) collects, uses, and protects personal data. We operate from France and process data in accordance with the GDPR (Regulation (EU) 2016/679) and French Law No. 78-17 of 6 January 1978 (Informatique et Libertés), as amended.

1. Data controller

The data controller (responsable de traitement) is Hurter Design Studio, publisher of agorch.io, identified in our Legal notice.

Privacy contact: [email protected].

2. Categories of personal data

Depending on how you use the Service, we may process:

  • Account data — name, email address, hashed password or authentication identifiers, role
  • Billing data — wallet balance, credit ledger entries, Stripe customer and payment method identifiers (card details are processed by Stripe and are not stored on our servers)
  • Service content — chat messages, agent configurations, MCP connection settings and tokens you provide, tool run inputs/outputs stored in your workspace
  • Technical data — IP address, browser/device information, security and application logs
  • Communication data — emails or support requests you send us
  • Billing data — if paid features apply (invoice details, payment status via payment providers)

We do not intentionally collect special categories of data (Art. 9 GDPR). Please avoid submitting sensitive personal data in chats unless necessary for your use case.

3. Purposes and legal bases

  • Create and manage your account, authenticate you, and provide orchestration, chat, and agent features — Art. 6(1)(b) GDPR (contract)
  • Operate, secure, and debug the Service (logs, abuse prevention, availability) — Art. 6(1)(f) GDPR (legitimate interests)
  • Comply with legal obligations (accounting, responding to lawful requests) — Art. 6(1)(c) GDPR
  • Non-essential cookies or optional marketing — Art. 6(1)(a) GDPR (consent), where required

4. Recipients and subprocessors

Data may be accessed by authorized staff of the controller and by technical subprocessors strictly necessary to run the Service, for example:

  • Hosting and edge delivery (e.g. Vercel)
  • Database and storage providers
  • Email delivery providers
  • AI model / inference providers used to generate responses
  • Payment processing (Stripe) for credit purchases and auto-refill

We do not sell personal data.

When you connect a third-party agent or MCP server, content you send may be transmitted to that provider under your instructions. Those providers act according to their own terms and privacy policies; we are not responsible for their independent processing.

5. International transfers

Some subprocessors may process data outside the European Economic Area (EEA). Where such transfers occur, we rely on appropriate safeguards under Chapter V of the GDPR, including the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, additional measures.

6. Retention

  • Account data — for the life of the account, then a limited period for security, dispute, or legal requirements
  • Chats and workspace content — until you delete them or close your account, unless longer retention is required by law
  • Security / technical logs — for a limited period proportionate to security and operational needs
  • Billing records — for the statutory retention periods under French commercial and tax law (when applicable)

7. Your rights

Under the GDPR, you may request:

  • Access to your personal data
  • Rectification of inaccurate data
  • Erasure (“right to be forgotten”), where applicable
  • Restriction of processing
  • Objection to processing based on legitimate interests
  • Data portability, where applicable
  • Withdrawal of consent at any time (without affecting prior lawful processing)

To exercise these rights, email [email protected]. We respond within the GDPR time limits (generally one month).

You may lodge a complaint with the CNIL: www.cnil.fr.

8. Security

We implement appropriate technical and organizational measures under Article 32 GDPR (access controls, encryption in transit where applicable, least-privilege access, and operational monitoring). No system is perfectly secure; you remain responsible for protecting your credentials and the sensitivity of data you submit.

9. Cookies and similar technologies

We use strictly necessary cookies or similar storage (for example session authentication) that do not require prior consent under French and EU ePrivacy rules. Non-essential cookies (analytics, advertising, or similar) are only used with your prior consent where required. You may withdraw consent at any time.

10. Minors

The Service is not directed at children under 15 (or the higher age of digital consent applicable in your EU Member State). If you believe a minor has provided us personal data, contact [email protected] so we can take appropriate action.

11. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest revision. Material changes may be communicated via the Service or by email when appropriate.

12. Related documents

Legal notice · Terms and Conditions