Privacy Policy
What AgentMesh collects, what it does not, and what you can do about it.
1What this covers
This policy covers the AgentMesh web application at agent-mesh.app and the AgentMesh Android app. Where the two differ (and on location, they differ considerably) the difference is stated.
The Android app runs and monitors workflows; it does not build them. Creating or editing a workflow, and connecting or disconnecting the services it uses, is done in the AgentMesh desktop app at agent-mesh.app. So the workflow content and connected-account data described below are entered there, not on your phone.
2Information you give us
Account details. Your email address, the name you give us, and, if you give one, the name of your organisation. If you sign up with a password, we keep only a hash of it, never the password itself.
Signing in with Google or GitHub. We ask the provider only for your verified email address, and use it to find or create your account. We do not receive or store your Google or GitHub password.
Workflow content. The workflows you build, the configuration you enter into them, and the record of the runs they produce. Credentials you enter for third-party connectors are encrypted before storage.
Connected accounts. If you connect a service such as Google (Gmail sending, Sheets, Calendar), Slack, Notion or Jira so a workflow can use it, we store the access tokens that service issues, encrypted. They are used only to perform the actions your workflows are configured to take, such as sending an email or updating a spreadsheet, and only when those workflows run. We do not read your Gmail messages or access your Google Drive. You can disconnect at any time from the desktop app, and revoke access from the service’s own account settings. AgentMesh’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Billing information. Records of credits purchased and consumed, and of on-chain payments made by your workflows.
3Google user data
This section applies if you connect a Google account to a workflow. It covers data AgentMesh receives through Google APIs.
What we access. Only what the Google steps in your workflows need, using three permissions: sending email from your Gmail account (we cannot read, list or delete your mail), reading and adding rows in Google Sheets you specify, and listing and creating events in your Google Calendar. We also receive the email address of the Google account you connect, to show you which account a workflow uses. We do not access Google Drive.
How we use it. Only to carry out the step your workflow is configured to perform, when that workflow runs: for example sending the email it composes, appending its result to a sheet, or creating the event it describes.
Who we share it with. We do not sell Google user data or share it with third parties, except as needed to run the workflow you built: if your workflow passes the result of a Google step to an AI model or another connected service, that result is sent there because you configured it to be. We do not use Google user data for advertising, credit or lending decisions, or to train AI or machine-learning models, and no person at AgentMeshreads it unless you ask us to for support, or the law requires it.
How we protect it. Google access and refresh tokens are encrypted at rest and only used server-side to make the API calls your workflows request. All traffic is encrypted in transit.
Retention and deletion. Tokens are kept until you disconnect the Google account, at which point we delete them; you can also revoke access at any time from your Google Account’s security settings. Results of Google steps, such as rows read from a sheet, can appear in that workflow’s run history, which is deleted when you delete the workflow or your account.
AgentMesh’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4Location, in the Android app
This section exists because it is the part people most want a straight answer about.
The Android app can start a workflow when you cross the edge of a place you have chosen. To do that, Android must be allowed to check your location while the app is closed. This is entirely optional: everything else in the app works without it, and the feature stays off until you turn it on.
On your device. A crossing that happens with no signal is held on the phone until it can be sent, so it is not lost. Those pending readings do include your position. They never leave the device except to report that one crossing, and each is deleted as soon as it is sent, or within a day if it never can be.
Turning it off. Remove the zone in the app, or revoke location permission in Android settings. Removing the zone also clears the state described above.
5Notifications
If you allow notifications, your device is issued a registration token by Google’s Firebase Cloud Messaging, and we store that token so we can tell your device when one of your workflows finishes. It identifies the app installation, not you. Signing out removes it, and a token that stops working is deleted.
6What we do not do
We do not sell your personal information. We do not share it with third parties for their own advertising or marketing. We do not use your workflow content to train machine-learning models.
7Service providers
Running the product means some data passes through others: hosting and database providers, Google’s Firebase Cloud Messaging for notifications, payment and blockchain infrastructure for billing, and the AI model providers your workflows are configured to call. A workflow that calls an external model or tool sends that provider whatever the workflow gives it. You choose those connections, and their own privacy policies apply to them.
8Retention and deletion
Account and workflow data is kept while your account is open. Deleting a workflow deletes its configuration and its run history. To delete your account and associated application data, use the profile menu's Delete account control, or visit our account deletion page. It explains what is removed, prerequisites and the web deletion path. For help with deletion, including copies held by connected services, operational logs or backups, write to privacy@agent-mesh.app.
9Security
Traffic is encrypted in transit. Connector credentials are encrypted at rest, and on Android the session token is held in storage encrypted with a key kept in the device’s hardware keystore. No system is perfect, and we do not claim otherwise.
10Children
AgentMesh is not intended for children under 13, and we do not knowingly collect their information.
11Changes
If this policy changes materially, we will update the effective date above and notify account holders. Continuing to use AgentMesh after a change means you accept it.
12Contact
Questions, requests, or complaints: privacy@agent-mesh.app.