agnus.work

Legal

Privacy Policy

Effective date: 18 July 2026

1. Who we are

Agnus is a cloud-based AI coding studio operated by Jean Daniel Alexis ("we," "us"). You can reach us at support@agnus.work. We are the data controller for the personal data described in this policy.

2. What data we collect and why

Account data (GitHub OAuth)

When you sign in with GitHub we receive your GitHub username, display name, public email address, and profile photo URL. We use this to create and identify your account.

Project data

Code files, project names, and any other content you create or upload inside Agnus. This data lives in your account and is used to provide the service.

Conversation and agent-action data

Chat messages you send, agent responses, tool calls (file reads/writes, shell commands, database queries), and the decision ledger entries those actions produce. This data is used to maintain conversation memory, display the decision timeline, and generate compliance statements.

Integration credentials

OAuth tokens for GitHub, Railway, Supabase, and Vercel integrations, and any AI provider API keys you supply. All credentials are stored encrypted at rest (AES-256-GCM). We never store them in plaintext and never display them to you after they are saved.

Usage data

Token counts, API costs per agent, and job counts, used to show you the Settings → Usage panel and to enforce the budget caps you set.

Technical / diagnostic data

IP address, browser user-agent, and error reports (via Sentry, if our Sentry integration is enabled). Used for security monitoring and debugging.

3. Legal basis for processing (GDPR)

Contract performance (Article 6(1)(b)): Account data, project data, conversation data, integration credentials, and usage data are processed because they are necessary to provide the service you have agreed to use.

Legitimate interests (Article 6(1)(f)): Security logging, bot/abuse detection, and error monitoring are necessary to protect the service and its users. These interests do not override your rights and freedoms.

4. Who we share data with

We do not sell your data. We share it only with the sub-processors listed below, to deliver the service.

ProcessorPurposeLocation
NeonManaged Postgres — platform databaseUS
e2bSandboxed code execution per projectUS/EU
AnthropicClaude model inference (chat/code generation)US
DeepSeekDeepSeek model inference (Worker mode, Scribe)CN
OpenAIOpenAI model inference (Codex mode)US
GoogleGemini model inference (custom agent option)US
Mistral AIMistral model inference (custom agent option)EU
GitHubAuthentication; optional repo accessUS
RailwayAPI hosting; optional deploy integrationUS
VercelWeb hosting; optional deploy integrationUS
SupabaseOptional linked database integrationUS
SentryError monitoring (if DSN configured)US

Your chat messages and relevant file contents are sent to whichever AI provider handles the active mode or agent. We do not send data to providers for training purposes, but each provider's own data-use terms govern what they do with inference traffic.

5. International data transfers

Most of our sub-processors are based in the United States. Where we transfer personal data to countries outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) or, where applicable, adequacy decisions. You can request a copy of the relevant safeguards by contacting us.

6. How long we keep data

Account and project dataUntil you delete your account or the project.
Conversation and decision-ledger dataUntil you delete the project or session. Chained entries are not deleted individually — deleting the session removes the whole chain.
Compliance statements7 years from generation (regulatory record-keeping analogue).
Usage statements3 years from generation.
Integration credentialsUntil you disconnect the integration.
Error logs (Sentry)90 days, per Sentry's default retention.

7. Your rights under GDPR

If you are in the EEA or UK, you have the following rights:

Access (Art. 15)Request a copy of the personal data we hold about you.
Rectification (Art. 16)Ask us to correct inaccurate data.
Erasure (Art. 17)Ask us to delete your data (subject to our legal retention obligations).
Restriction (Art. 18)Ask us to pause processing while a dispute is resolved.
Portability (Art. 20)Receive your data in a machine-readable format where processing is based on contract or consent.
Objection (Art. 21)Object to processing based on legitimate interests.

To exercise any of these rights, contact us at support@agnus.work. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

8. Security

All credentials (API keys, OAuth tokens) are encrypted at rest with AES-256-GCM and decrypted only in memory at the moment of use. Sensitive tables have Row-Level Security enabled at the database level. Access to production infrastructure is restricted to the service operator. Full technical detail is available in our Security & Encryption document.

9. Cookies and tracking

Agnus uses a single session cookie set by Auth.js to maintain your signed-in state. We do not use advertising cookies, third-party analytics cookies, or tracking pixels.

10. Children

Agnus is not directed at children under 18 and we do not knowingly collect data from them. If you believe we have collected data from a child, contact us immediately.

11. Changes to this policy

We may update this policy. Material changes will be announced by updating the effective date above and, where practical, by in-app notification. Continued use of Agnus after a change constitutes acceptance.

12. Contact

For any privacy question or to exercise your rights, email support@agnus.work.