LegalDraft

Privacy policy

Last updated: TODO {{EFFECTIVE_DATE}}

This policy covers agentmbx.com, the AgentMBX Cloud early-access list, the hosted relay at relay.agentmbx.com and, once it launches, AgentMBX Cloud. It is provided by TODO {{LEGAL_ENTITY}} ("we"). [REVIEW: legal entity, address and, if required, an EU/UK representative.]

The short version

  • The AgentMBX software runs on your machines. It sends us nothing and has no telemetry.
  • Message bodies never reach us. Through the relay they pass encrypted, and we cannot open them.
  • The website sets no cookies and loads no third-party scripts. [REVIEW: confirm at launch.]
  • The early-access list stores your email address, the plan you picked, when you agreed and to which wording, whether you confirmed, and how many confirmation emails we sent, plus a scrambled (hashed) copy of each confirmation link while it is valid. Nothing else.
  • We don't sell personal data.

1. The AgentMBX software

The software (the agentmbx CLI, daemon and MCP server) runs on your machines and stores your mail there. We do not receive your messages, contacts, agent names or usage.

  • No telemetry. The software contains no analytics or usage reporting.
  • Update check. Once a day, the daemon asks GitHub Releases whether a newer version exists. GitHub sees that request, including your IP address, under GitHub's privacy statement. Set MBX_NO_UPDATE_CHECK=1 to turn it off.
  • Your network. Paired machines talk directly to each other on your network. That traffic never passes through us.
  • Relays. The software uses a relay only if you configure one. A relay you run yourself is under your control, not ours.

2. agentmbx.com

The website is static. It sets no cookies, uses no tracking pixels and loads no third-party scripts or fonts.

Cloudflare serves the site. Like any web server, it processes your IP address and request details to deliver pages and stop abuse. We do not keep request logs for the site: the site's Worker records only its own short status messages (never an email address, a link or an IP address), with its per-request logs turned off, and we do not use Cloudflare Logpush for agentmbx.com. Cloudflare's own aggregate zone analytics (request counts by country and status, no JavaScript beacon) may be visible to us. See Cloudflare's privacy policy. [REVIEW: owner to confirm the zone-analytics choice (site-copy question 12) and that Logpush stays off.]

3. The early-access list

What we store: your email address, the plan you are interested in, the time you first agreed to be emailed, the version of the consent wording you agreed to, whether you have confirmed, and how many confirmation emails we have sent you (at most three). Until you confirm, we also keep a one-way hash of each confirmation link we emailed, with the time it was sent; the link itself is only in your email, and the hashes are deleted when you confirm or when the links expire. Unsubscribe links are not stored at all: they are signed, so we can check them without keeping them. We also count how many confirmation emails we send each day, without any addresses.

Why: to confirm your address and to email you when AgentMBX Cloud sign-up opens. We use it for nothing else. [REVIEW: if the owner wants to send other early-access updates, say so here and in the form's consent text.]

Legal basis: your consent, given on the form and confirmed through the link we email you. [REVIEW]

How long: an address that is not confirmed is deleted when its last confirmation link expires, after TODO {{CONFIRM_TTL_HOURS}} hours. A confirmed address is kept until you unsubscribe or until TODO {{LIST_RETENTION_END}}. [REVIEW: e.g. deleted 90 days after Cloud launch unless you create an account.]

Who processes it: TODO {{EMAIL_PROVIDER}} sends the emails, and TODO {{LIST_STORAGE_PROVIDER}} stores the list. [REVIEW: name each processor, its location and its data processing terms.]

Unsubscribing: every email has a one-click unsubscribe link. Unsubscribing deletes your address from the list.

To stop abuse, the form limits how often it can be submitted from one network. Your IP address is used for that check, held only by Cloudflare's rate limiter for about a minute, and is not stored with your signup or logged. One address gets at most three confirmation emails, at most one every 15 minutes.

4. The hosted relay (relay.agentmbx.com)

If you point your machines at the hosted relay, it stores mail waiting for delivery and forwards it to the receiving machine.

  • Message bodies: stored encrypted for the receiving machine. We cannot read them.
  • Envelope metadata, readable by the relay: sender and recipient addresses, subject, thread and reply references, references (paths or URLs), the project path and project key, mentions, tags and task references, plus message sizes and timing.
  • Enrolment data: each machine's name, public host key, public encryption key and owner-key fingerprint.
  • Network data: IP addresses, used for rate limits and abuse protection.
  • Retention: queued mail is kept for up to 14 days. If it is not delivered by then, the sending machine reports it as undelivered. [REVIEW: the relay's retention sweep and expiry notices are planned (T167); confirm they run before publishing. Once accounts launch, retention follows the plan: Pro 14 days, Team 30 days.] Backups are kept for 7 days. [REVIEW: confirm backups are running (T167).]

5. AgentMBX Cloud (when it launches)

[REVIEW: this section describes the planned service. Re-check every item against the shipped service before launch.]

  • Account: your email address, sign-in methods (passkey public keys, and your GitHub account ID if you sign in with GitHub) and sessions.
  • Linked machines and agents: machine and agent names, roles, project identifiers (repository names such as github.com/org/repo; other repositories as a hash), participants, message counts, delivery states and timing. Subjects are stored only as hashes keyed by a secret you hold. No message bodies, file paths or usernames.
  • Approvals: the public keys of passkeys you enroll as owner authenticators, and a record of console commands and their receipts.
  • Billing: handled by Stripe. We receive your billing status and invoices, never your full card number. [REVIEW: Stripe Tax or a merchant of record.]
  • Retention: history is kept for your plan's period (Pro 30 days, Team 1 year). Backups for 7 days. [REVIEW]

6. Sharing

We share personal data only with the processors named above, to run the service, or when the law requires it. We don't sell personal data or use it for advertising.

7. Your rights

You can ask us for a copy of your data, to correct it, or to delete it. Email TODO {{EMAIL_PRIVACY}}. [REVIEW: GDPR/UK GDPR/CCPA wording, response times, the right to complain to a supervisory authority.]

8. Security

See Security for how AgentMBX protects messages and what it does not protect.

9. Changes

We will post changes here and update the date above. If you are on the early-access list and a change affects how we use your address, we will email you first. [REVIEW]

Contact

TODO {{EMAIL_PRIVACY}} · TODO {{LEGAL_ENTITY_ADDRESS}}