Privacy Policy

Last updated: April 2026

1. Introduction

Mast Agents ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI agent orchestration platform (the "Service").

We process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable. By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign in via a third-party provider (e.g., Google), we receive basic profile information from that provider.

Agent Configurations

We store the agent configurations you create, including agent names, system prompts, tool configurations, integration settings, and operational parameters.

API Keys

When you provide API keys for third-party AI providers or integrations, we store them encrypted at rest using industry-standard encryption. API keys are only decrypted at the point of use to execute agent operations and are never logged in plaintext.

Usage Data

We collect data about how you interact with the Service, including agent execution logs, message history, tool invocation records, performance metrics, and error logs. This data helps us operate and improve the Service.

Technical Data

We automatically collect technical information such as your IP address, browser type, device information, and referring URLs when you access the Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including executing your AI agents and their integrations
  • Authenticate your identity and manage your account
  • Process and complete transactions, and send related information
  • Monitor and analyze usage patterns to improve the Service's performance and reliability
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities
  • Send administrative communications, including security alerts and service updates
  • Respond to your comments, questions, and support requests

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal data depends on the specific data and the context in which we collect it:

  • Contract performance: Processing necessary to provide the Service you have requested
  • Legitimate interests: Processing for our legitimate business interests, such as fraud prevention, security, and service improvement, where those interests are not overridden by your rights
  • Consent: Where you have given us specific consent to process your data for a particular purpose
  • Legal obligation: Processing necessary to comply with applicable laws

5. Third-Party Services

We use the following third-party services to operate the platform. Each may process certain data on our behalf:

  • Vercel — Application hosting and edge delivery. May process request metadata and IP addresses.
  • Fly.io — Compute infrastructure for running AI agent workloads. Agent execution data is processed on Fly.io servers.
  • PlanetScale — Database hosting. Stores account data, agent configurations, and operational records.
  • AI Providers (Anthropic, OpenAI, xAI) — Language model inference. Agent prompts and messages are sent to these providers via your API keys, subject to their respective privacy policies.
  • Integration Partners (Slack, Google, Telegram, etc.) — When you connect integrations, data flows between the Service and these platforms as needed for agent operations.

We require our service providers to protect your data consistent with this policy and applicable law. We do not sell your personal data to any third party.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention periods include:

  • Account data: Retained while your account is active and for up to 30 days after deletion request
  • Agent execution logs: Retained for 90 days, after which they are automatically purged
  • API keys: Deleted immediately upon removal from your account or account termination
  • Technical/analytics data: Retained in aggregated, anonymized form indefinitely for service improvement

We may retain certain data longer where required by law or for legitimate business purposes such as resolving disputes or enforcing our agreements.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data, subject to certain legal exceptions
  • Data portability: Request a copy of your data in a structured, machine-readable format
  • Restriction: Request that we restrict processing of your personal data under certain conditions
  • Objection: Object to processing of your personal data based on our legitimate interests
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time

To exercise any of these rights, please contact us at privacy@mastagents.com. We will respond to your request within 30 days.

8. Cookies and Tracking

We use cookies and similar technologies to operate the Service:

  • Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Analytics cookies: Help us understand how the Service is used so we can improve it. You may opt out of analytics cookies through your browser settings.

We do not use advertising cookies or trackers. We do not engage in cross-site tracking.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS) and sensitive data at rest (AES-256)
  • Access controls and authentication for all internal systems
  • Regular security reviews and monitoring
  • Incident response procedures for potential data breaches

No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. Where we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

11. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete such information.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through the Service at least 30 days before the changes take effect. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

If you are located in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.