Privacy Policy
Last updated: June 28, 2026
This policy explains what personal data we handle, why, who we share it with, and the rights you have. AgentSpeed is metadata-first: we never store your prompts or model outputs.
1. Who we are and what this covers
This Privacy Policy explains how Vantlir LLC, a Delaware limited liability company, which operates the AgentSpeed service (“AgentSpeed,” “we,” or “us”), handles personal data in connection with our websites, applications, and APIs (the “Service”).
It sits alongside our metadata-first privacy explainer, which describes in detail how the ingest API is built so that prompt and output content can never be stored. This Policy is the formal document covering the personal data we do handle.
2. Controller and processor roles
For account, billing, and website data, we act as the data controller. For personal data that may be contained in the telemetry you send us, we act as your processor, handling it on your behalf and under your instructions; that processing is governed by our Data Processing Addendum. This Policy focuses on the data we control.
3. Information we collect
We collect the following categories of data:
- Account data: your email address (used for one-time sign-in links) and your organization name.
- Authentication data: a strictly necessary session cookie and short-lived, hashed sign-in tokens.
- Usage and log data: IP address, browser/user-agent, timestamps, and pages or endpoints accessed, used for security, rate limiting, and diagnostics.
- Telemetry metadata: the run metadata you send (status, timing, token counts, computed cost, model/agent/span/tool names, error type and a short error message). This is metadata only; see the enforcement explainer for how content is excluded.
- Billing data: handled by Stripe. We store your plan, subscription status, and a customer identifier; we do not store full payment-card numbers.
- Communications: messages you send us (for example, support requests).
4. How and why we use data
We use personal data to:
- provide, operate, secure, and maintain the Service;
- authenticate you and send transactional email (sign-in links, alerts, digests, and service notices);
- process payments and manage subscriptions;
- provide support and respond to your requests;
- understand usage in aggregate to improve the Service; and
- comply with legal obligations and enforce our terms.
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide the Service); our legitimate interests (to secure, maintain, and improve the Service and prevent abuse); your consent (where we ask for it); and compliance with legal obligations.
6. Cookies and tracking
We use a single, strictly necessary cookie to keep you signed in. We do not use advertising or analytics trackers, and we do not engage in cross-site tracking. Because the only cookie is essential to the Service, no cookie-consent banner is required to use AgentSpeed.
7. How we share data
We share personal data with vetted sub-processors that help us run the Service (for example, hosting, database, email, and payments). The current list, including what each one processes and where, is on our Sub-processors page.
We may also disclose data to comply with the law or a valid legal request, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice where required). We do not sell personal data, and we do not share it for cross-context behavioral advertising.
8. Data retention
We keep account data for as long as your account is active and for a reasonable period afterward to meet legal, accounting, and security needs. Telemetry is retained according to your plan (currently from 7 days on the free plan up to 180 days on higher plans) and is then automatically deleted. Logs are kept for a limited period for security and diagnostics. You can request deletion as described below.
9. International transfers
We and our sub-processors are based primarily in the United States, so your data may be processed there. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards such as the Standard Contractual Clauses.
10. Security
We protect data with encryption in transit, hashing of API keys and sign-in tokens, access controls, and a metadata-first design that minimizes the sensitive data we hold in the first place. No system is perfectly secure, but data minimization is our strongest safeguard.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the personal data we hold about you, and to object to certain processing. If you are in California, you have rights under the CCPA/CPRA to know, delete, and correct your data, to opt out of its “sale” or “sharing” (we do neither), and not to be discriminated against for exercising those rights.
To exercise any of these rights, email privacy@agentspeed.com. We will respond within the time required by law. If we process your data as a processor on a customer’s behalf, we will refer your request to that customer.
12. Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact us
Questions, requests, or complaints? Email privacy@agentspeed.com. If you are in the EEA or UK and believe we have not addressed your concern, you may also lodge a complaint with your local data-protection authority.