Privacy Policy

Last updated: May 2026

1. Overview

AgencyAI ("we", "us", "our") operates the AgencyAI platform at agencyai.dev. This privacy policy explains how we collect, use, and protect your personal information when you use our service.

We are a Canadian business headquartered in Alberta, Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

2. Information We Collect

  • Account information: Name, email address, and Google OAuth profile data when you sign up.
  • Business information: Company name, bio, expertise areas, and storefront content you provide.
  • Assessment data: Intake form responses, generated reports, and product configurations you create.
  • Payment information: Stripe processes all payments. We store transaction records but never see your full credit card number.
  • Usage data: Browser type, device info, and interaction patterns for analytics and service improvement.

3. AI Processing

AgencyAI uses artificial intelligence to generate assessment reports and process intake data. Key points:

  • Your expertise data, frameworks, and assessment configurations are never used to train AI models.
  • AI processing occurs through third-party API providers (OpenAI, Anthropic, or equivalent) under their data processing agreements.
  • Customer intake responses are processed to generate reports and are stored in your workspace.
  • You retain full ownership of all content you create and all assessment outputs.

4. Data Storage

Your data is stored in Supabase (PostgreSQL) hosted on AWS infrastructure. Data centers are located in North America. We use industry-standard encryption at rest and in transit (TLS 1.3).

5. Third-Party Services

We integrate with the following third-party services:

  • Supabase — Database and authentication hosting
  • Stripe — Payment processing and billing
  • Google OAuth — Authentication provider
  • AI Providers — Report generation (OpenAI, Anthropic, or equivalent)

Each provider operates under their own privacy policy and data processing agreements.

6. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We share data only with service providers necessary to operate the platform (listed above) and when required by law.

7. Data Retention

We retain your data for as long as your account is active. You can request deletion of your account and all associated data at any time by contacting us. Upon account deletion, personal data is removed within 30 days.

8. Your Rights

Under Canadian privacy law, you have the right to:

  • Access your personal information
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent for data processing
  • Lodge a complaint with the Privacy Commissioner of Canada

9. Contact

For privacy inquiries or data requests, contact us at privacy@agencyai.dev.