Privacy Policy
This Privacy Policy explains what information VerityLabs LLC ("VerityLabs," "we," "us") collects through Agent Factory (the "Services"), how we use it, and the choices you have. It is part of, and should be read together with, our Terms of Service.
1. Information We Collect
Account information
When you create an account, we collect your email address, a hashed (never plaintext) password if you use one, and any display name you choose to provide.
Conversation content
We collect the messages you send to Agent Chat or the scoping conversation, the files you upload, and the responses generated in return. If you use the Services without an account, we still collect this content, tied to your browser session rather than an identity.
Payment information
Payments are processed by Stripe. We receive confirmation that a payment succeeded or failed, the amount, and billing metadata Stripe provides — we do not receive or store your full card number.
Credentials for connected services
If you connect a third-party service — for example a WordPress Application Password, a Google service account, or a similar credential — we store it encrypted at rest. It is decrypted only at the single point in our system where it is actually sent to that third-party service to carry out an action you requested; it is designed never to be displayed back to you, to the AI model, or to appear in the agent's own output.
Usage and log data
We collect technical data needed to operate and secure the Services: IP address, browser session identifiers, timestamps, which tools or actions were used, and error/debugging logs.
2. How We Use Information
- To provide the Services — running your conversation through the underlying AI model, carrying out approved actions, and remembering your conversation history;
- To process payments and administer your account, builds, and subscriptions;
- To secure the Services — detecting abuse, enforcing usage limits, and investigating security incidents;
- To communicate with you — transactional emails such as approval requests, receipts, payment-failure notices, and login links, and, where you've agreed to receive them, product updates;
- To improve the Services, including by reviewing aggregated or de-identified usage patterns; we do not sell your personal information.
3. Third-Party Service Providers (Subprocessors)
We share information with the following categories of service provider, only as needed to provide the Services:
We do not permit any of these providers to use your information for their own independent purposes beyond what they need to perform their service for us, except where an underlying model provider's own terms (such as Anthropic's) separately govern how they may use content processed through their API — see their published policies for that detail.
4. How Long We Keep Information
- Anonymous (no-account) conversations: stopped from being shown after 7 days of inactivity, and permanently deleted — along with anything uploaded — after 30 days, on an automated nightly job.
- Account data: kept for as long as your account is active, plus a reasonable period afterward for legal, billing, and dispute purposes, after which it is deleted or de-identified.
- Credentials for connected services: kept encrypted until you disconnect the integration or delete your account, at which point they are deleted. The encryption key itself is stored separately from routine backups.
- Backups: we run daily database backups for disaster recovery; backups age out on a rolling schedule and are not a way to keep data indefinitely after you've asked us to delete it.
5. Your Choices and Rights
You can access, correct, export, or request deletion of your personal information by contacting us at the address below. If you are located in the European Economic Area, the UK, or a U.S. state with its own privacy law (such as California), you may have additional rights under that law — including the right to know what we collect, to delete it, and to not be discriminated against for exercising these rights. [Which specific state/ international privacy statutes actually apply to VerityLabs's operations, and the exact mechanics of honoring rights under each, is a scoping question for counsel — this section states the general rights we intend to honor, not a jurisdiction-by-jurisdiction legal analysis.]
6. Data Security
We use encryption for credentials and sensitive data at rest, restrict internal access to what each part of the system needs, and run regular backups. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
7. Children's Privacy
The Services are not directed to, and we do not knowingly collect personal information from, anyone under 18.
8. International Data Transfers
We are based in the United States, and information you provide may be processed and stored in the United States or other countries where our service providers operate.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where required, notify you.
10. Contact
Questions about this Privacy Policy, or requests regarding your information, can be sent to veritytechsolutionsllc@gmail.com.