Privacy Policy
AgentLife is a browser extension with a living AI agent. This policy explains what data it handles, what stays on your device, and the control you have. The agent is built to know you, not to surveil you.
Who we are
AgentLife is operated by Vladislav Demianiuk, an individual based in Ukraine, acting as the data controller. For any privacy question, contact privacy@agentlifeapp.com; a mailing address is available on request.
The short version
- We collect only what the agent needs to know you and act for you.
- Page content and incognito windows are never read unless you explicitly ask.
- We do not sell your data or use it for advertising.
- Every fact the agent remembers is visible to you and can be deleted.
What we collect
- Account: your Google account email and name, used to sign you in and attach your agent's memory to your account. Signing in with Google also stores the sign-in tokens that keep you logged in. We never see or store your Google password.
- Conversations: messages you exchange with your agent, stored so she keeps context across sessions.
- Memory facts: distilled facts the agent learns (for example your name or interests). Every fact is visible in the memory panel and deletable there.
- Browsing signals: lightweight context only: domain, tab title, time on page, tab-switching frequency. Used so the agent understands your situation.
- Voice input (only when you use it): when you hold the character or press the microphone, your audio streams to our speech provider and comes back as text. We never store the audio — only the number of seconds, so the monthly voice allowance can be counted. The recognised text then travels the same path as anything you type.
- Web searches (only when you ask): when you ask her to search, the search words are sent to our search provider to fetch results. We store the fact that a search happened, for your monthly allowance.
- Billing: handled by Paddle, our merchant of record. We never see or store your card details.
- Technical: minimal logs (timestamps, error traces, coarse usage counts) needed to run and secure the service. Your IP address and browser identifier are recorded with your sign-in session and used to rate-limit abuse. We do not use them to locate you, and we do not collect GPS or any precise location.
What never leaves your device
- Page content. The extension does not read page bodies unless you explicitly ask the agent to look or select text for her. Even then, content is distilled locally and only a minimal excerpt is sent.
- Incognito windows. The agent does not run in incognito at all.
- Passwords, forms, payment fields. Never read, never stored.
- Your browsing history. We never receive the addresses you visit or reconstruct your history from them. What we do receive is listed above under browsing signals: the domain and title of the tab you are on and how long you stayed — never the full address, and never anything from an incognito window.
How we use data
Data is used for one purpose: making your agent work for you — signing you in, keeping conversation context, maintaining memory, understanding page context, delivering the actions you request, billing, and keeping the service secure and reliable. We do not sell data, share it with advertisers, or use it to build profiles for anyone else.
Legal bases (GDPR)
Where GDPR applies, we rely on:
- Contract: to provide the service you signed up for (account, chat, memory, actions).
- Legitimate interest: to secure the service, prevent abuse, and improve reliability, balanced against your rights.
- Consent: for anything beyond the above, such as reading a page when you explicitly ask. You can withdraw consent at any time.
AI processing
Your messages are sent to large language models to generate replies. Inference is routed through OpenRouter to third-party model providers, who process each request under their own data policies. We do not sell your data, and we have configured OpenRouter to exclude providers that train on user inputs; we prefer zero- or limited-retention providers where available. The agent never fabricates memories: if it does not have a fact, it says so.
Sub-processors
We rely on a small set of providers to run the service:
- Railway — hosting, database (Postgres) and vector store (Qdrant).
- OpenRouter and its routed model providers — AI inference.
- Deepgram — speech recognition, only while you are dictating. The audio is transcribed in transit and not retained by us.
- Tavily — web search, only when you ask her to look something up.
- Google — sign-in (OAuth).
- Paddle — payments and invoicing (merchant of record).
Each processes data only to perform its function, under its own terms. We update this list as it changes.
International transfers
Some providers above operate outside your country, including the United States. Where data is transferred internationally, it is done under appropriate safeguards such as Standard Contractual Clauses or an equivalent mechanism offered by the provider.
Data retention
- Account, conversations, memory: kept while your account is active, because memory is the point of the product. Deleted within 30 days of account deletion.
- Browsing signals: distilled quickly into memory or usage counts; raw signals are short-lived.
- Voice audio: never stored. It is transcribed in transit and discarded; only the duration is kept, and only to count your monthly allowance.
- Technical logs: retained for a limited period for security and debugging, then removed.
Your rights
Depending on where you live, you have rights over your data. Under the GDPR these include access, rectification, erasure, portability, restriction, and objection, and the right to lodge a complaint with your supervisory authority. Under the CCPA/CPRA you have the right to know, to delete, to correct, and to opt out of sale — and we do not sell data. You will not be treated differently for exercising any right.
You can delete individual facts in the memory panel yourself. For any other request, contact privacy@agentlifeapp.com.
Children
AgentLife is not intended for anyone under 16. We do not knowingly collect data from children under 16; if you believe a child has used the service, contact us and we will remove the data.
Security
Access is authenticated, data is isolated per user, and every stored record is scoped to its owner. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data and will notify affected users of a breach as required by law.
Changes
We may update this policy. Material changes will be announced in the product before they take effect, and the date above will change.
Contact
Questions about this policy or your data: privacy@agentlifeapp.com