Scope
This notice describes the information AgentCloud processes to provide its public website, account control panel, OAuth-enabled MCP server, managed iOS build service, hosted Simulator sessions, retained evidence, billing, support, and product analytics. It applies to visitors, account holders, workspace members, and people whose authorized test data appears in a run.
Information AgentCloud processes
Account and workspace data can include a name, email address, sign-in method, email-verification state, workspace membership, invitations, OAuth clients and grants, billing plan, subscription state, and usage totals.
Product evidence can include source or app upload metadata, build output, Simulator actions, typed values, screenshots, accessibility snapshots, application and Simulator logs, artifacts, deep links, tunnel metadata, and recording segments. Customers decide what their authorized agent uploads and does during a run.
Website and service telemetry can include request metadata, device and browser information, referrers, page events, error context, and advertising conversion events where configured. Support messages contain the contact details and technical context a requester chooses to send.
Why the information is used
AgentCloud uses information to authenticate users, authorize workspace access, complete MCP OAuth flows, schedule builds and Simulators, retain evidence, enforce allowances, process subscriptions, prevent abuse, diagnose reliability problems, answer support requests, and understand whether onboarding and product surfaces work. Subscription checkout is handled by the payment provider; customers should never send payment-card details to AgentCloud support.
Providers and disclosure
The current implementation uses providers for hosting, private object storage, identity, transactional email, billing, analytics, advertising measurement, and error diagnosis. These include Render, Cloudflare R2, Stripe, Resend, PostHog, and Google sign-in. AgentCloud can also disclose information when needed to comply with law, protect users and the service, investigate abuse, or complete a business transaction subject to appropriate safeguards.
Retention and security
Product evidence remains available for the plan's stated retention period unless an authorized workspace member deletes it sooner. Short-lived upload capabilities expire, and worker-local build and Simulator files are transient. Account, billing, security, and operational records may remain while needed to provide the service, resolve disputes, meet legal obligations, or protect the platform.
AgentCloud uses OAuth 2.1 with PKCE, workspace-scoped authorization, private object storage, short-lived upload and tunnel capabilities, and isolated worker boundaries. No Internet service can promise absolute security; customers should use test accounts and fixtures, avoid unnecessary production secrets, and limit workspace access.
Choices and requests
Workspace owners and admins can delete retained evidence from the control panel where that action is available. To ask about access, correction, export, deletion, or another privacy concern, email help@agentcloud.so and identify the message as a privacy request. AgentCloud may verify identity and workspace authority before acting. See Contact for safe request guidance and Terms for service responsibilities.