Skip to main content
Back to home

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains how Agencly("we", "us", or "our") collects, uses, and shares information when you use the Agencly website at agencly.app and the Agenclyplatform at app.agencly.app (collectively, the "Service").

Data controller

The data controller responsible for your personal data is Agencly. If you have questions about this policy or your data rights, contact us at contact@agencly.app.

Information we collect

We collect the following categories of information:

  • Account information: name, email address, and password (hashed). If you sign in with Google, we receive your Google ID, email, and profile photo.
  • Workspace data: everything you add to your workspace, including leads, contacts, projects, tasks, invoices, contracts, time entries, messages, files, forms, meetings, and team member information.
  • Client portal data: when you invite clients to their portal, we collect their name, email, and the data you choose to share with them (projects, invoices, documents, messages).
  • Usage data: pages viewed, features used, actions taken, session duration, browser type, device type, operating system, and IP address.
  • Cookies and similar technologies: we use cookies to keep you signed in, remember your preferences, and (with your consent) measure site usage. See the Cookies section below for details.
  • Google API data: if you connect Google Calendar, we access calendar events for scheduling. If you connect Google Drive, we access files you specifically select or create through Agencly. We do not access your full Google account or contacts.
  • Payment information: billing and subscription details are processed by Polar, our payment provider. Agenclydoes not collect, store, or handle credit card numbers directly. Polar's privacy policy applies to payment data.
  • Error and diagnostic data: error reports and performance data are processed by Sentry to monitor and improve reliability. Sentry is configured with send_default_pii=false and does not receive personally identifiable information.
  • Marketing site analytics: page views and interactions on our marketing website are tracked by Google Analytics 4. We use analytics cookies only with your consent via our cookie banner.

How we use information

We use your information for the following purposes:

  • To provide, maintain, and improve the Service.
  • To authenticate users and secure accounts.
  • To process subscriptions and send billing-related emails.
  • To send transactional emails (signup verification, password resets, team invites, client portal invites, meeting confirmations, contract notifications, and billing alerts).
  • To respond to support requests.
  • To monitor usage, prevent abuse, and diagnose technical issues.
  • To comply with legal obligations.

Legal basis for processing (GDPR)

If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data under the following legal bases:

  • Contract: processing is necessary to provide the Service you signed up for (account management, workspace functionality, billing).
  • Legitimate interests: improving the Service, preventing fraud, monitoring errors, and ensuring security.
  • Consent: analytics cookies on the marketing website are only set with your consent.
  • Legal obligation: retaining data as required by law (e.g., tax records, billing history).

How we share information

We share information only as described below:

  • Polar: for subscription billing and payment processing. Polar acts as a data processor on our behalf.
  • AWS (SES, EC2, RDS): for email delivery, compute, and database hosting. AWS acts as a data processor.
  • Cloudflare (R2): for file storage. Cloudflare acts as a data processor.
  • Sentry: for error monitoring and diagnostics. Sentry acts as a data processor with PII collection disabled.
  • Google Analytics 4: for aggregated, anonymized visitor statistics on our marketing website only. No personally identifiable information is sent to Google Analytics.
  • Cloudflare Turnstile: for CAPTCHA verification during signup to prevent automated abuse.
  • AI agent providers (MCP): when you connect an AI agent (such as Claude, ChatGPT, or Cursor) through the Model Context Protocol (MCP), the agent's provider may process the workspace data your API key is scoped to. This access is user-initiated, limited to the modules you grant, and revocable at any time. See "AI agent connections (MCP)" below for details.
  • Workspace members: data you share within your workspace is visible to members you invite, according to the role-based permissions you configure.
  • Clients: data you choose to share through client portals is visible only to the specific client you invite. Cross-client data is never shared.
  • Legal compliance: we may disclose information if required by law, court order, or to protect the rights and safety of users.

We do not sell your personal data. We do not share your data with advertisers. We do not use your data for targeted advertising.

Google user data

Agencly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Google Calendar: used solely to sync events for scheduling inside Agencly. We request read/write access to your calendar to create and manage events. We do not read or store calendar data beyond what is necessary for the scheduling feature.
  • Google Drive: we access only files you specifically create or select throughAgencly. We request limited file access (drive.file scope), which means we cannot see your existing Drive files.
  • Google Sign-In: we receive your Google ID and email for authentication. We do not access your Google contacts or any other Google data.

Google user data is never used for advertising, is never sold to third parties, and is never used to train generalized AI or machine learning models.

AI agent connections (MCP)

Agencly supports the Model Context Protocol (MCP), which lets you connect AI agents (such as Claude, ChatGPT, or Cursor) directly to your workspace. When you create an MCP API key, you choose which modules the agent can access (for example, Projects, Invoices, Contacts, or Time Tracking) and whether it has read-only or read-and-write access.

Important points about MCP and your data:

  • Provider processing: when an agent connected via MCP reads or writes your workspace data, that data may be sent to and processed by the agent's provider (for example, Anthropic, OpenAI, or the tool you use). Their privacy policy and terms apply to that processing.
  • You stay in control: you decide what each key can access, and you can revoke or delete any key at any time from Settings. Revoking a key immediately cuts the agent's access.
  • Auditable: every action an agent takes through MCP is recorded in an audit log, so you can see what was accessed or changed and when.
  • No training on your data: we do not use your workspace data, including data accessed through MCP, to train generalized AI or machine learning models.

You are responsible for the agents you connect and the permissions you grant them. Only create MCP keys for agents and providers you trust.

Data retention

  • Account data: we keep your data for as long as your account is active.
  • After cancellation: when you cancel your subscription, your workspace data is retained for 90 days to allow reactivation. After 90 days, your data is permanently deleted from our production databases and file storage.
  • Backups: database backups are retained for 14 days. After that, they are permanently deleted.
  • Google Calendar data: retained only while the integration is connected. When you disconnect Google Calendar in Settings, calendar data is deleted.
  • Error logs: Sentry error data is retained per Sentry's default retention policy (typically 90 days).
  • Billing records: subscription and payment records are retained as required by tax and accounting law (typically 7 years).

Cookies

We use the following cookies:

  • Essential cookies (always active): ag_access, ag_refresh (HttpOnly, Secure, SameSite=Strict) for authentication and session management. ag_access_token for Next.js middleware route gating. These are required for the Service to function and cannot be disabled.
  • Preference cookies: agencly-accent (UI theme preference), agencly_active_workspace (last active workspace). These remember your preferences.
  • Analytics cookies (consent required): Google Analytics 4 cookies for measuring marketing site usage. Only set when you click "Accept" in our cookie banner.

You can change your cookie preferences at any time by clearing your browser cookies. Declining analytics cookies will not affect your ability to use the Service.

Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your personal data.
  • Restriction: request restriction of processing in certain circumstances.
  • Portability: request a copy of your data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent at any time where processing is based on consent.
  • Lodge a complaint: file a complaint with your local data protection authority.

To exercise any of these rights, email us at contact@agencly.app. We will respond within 30 days.

Account and data deletion

To request deletion of your account and all associated data, email us at contact@agencly.app with the subject line "Delete my account".

What gets deleted:

  • Your account credentials and profile.
  • All workspace data you own (projects, tasks, invoices, contracts, leads, messages, files, notes, time entries).
  • Client portal data and invited client accounts.
  • Calendar integrations and connected accounts.
  • All files stored in our systems.

What's retained (legal requirement):

  • Billing and subscription records (7 years, tax/accounting law).
  • Audit log entries (anonymized, no personal identifiers).

Timeline: Deletion is processed within 30 days of your request.

Google account: If you signed up via Google, disconnecting your Google account fromAgencly does not delete your data. You must email us to request full deletion.

Workspace owners: Deleting your account deletes the entire workspace and all data for its members.

International data transfers

Your data is processed on servers located in the United States (AWS us-east-1). If you are outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on Standard Contractual Clauses or equivalent safeguards where required by applicable law.

Security

We use industry-standard technical and organizational measures to protect your data, including TLS encryption in transit, AES-256 encryption at rest, role-based access control, automated backups, and audit logging. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your information.

For details on our security practices, see our Security page.

Children's privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will notify you of material changes by posting the updated policy with a new effective date and, where required, by email. Your continued use of the Service after changes take effect means you accept the updated policy.

Contact us

If you have questions about this policy or your data rights, email us at contact@agencly.app.