Privacy Policy

1. Introduction

AgentOS ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services, including our CRM platform.

2. Information We Collect

We may collect information about you in a variety of ways. The information we may collect on the Site includes:

  • Personal Data: Name, email address, phone number, and other contact information you provide directly
  • Contact Information: When you use our contact sync features, we collect and store contact data from Google Contacts and Microsoft Outlook
  • Account Data: Information related to your CRM account, including leads, deals, and business data you input
  • OAuth Data: When you authorize a Google or Microsoft integration, we receive authorization tokens and the account information needed for that integration. Optional Gmail reply protection uses the separate, limited authorization described below.
  • Usage Data: Pages visited, features used, time spent, IP address, browser type, and operating system
  • Payment Data: When processing payments through Stripe, we do not store credit card information directly

3. How We Use Your Information

We use the information we collect or receive for the following purposes:

  • To provide, maintain, and improve our CRM services
  • To sync and manage your contacts from Google Contacts and Microsoft Outlook
  • To process transactions and send related information
  • To email you regarding your account or request
  • To fulfill and manage your orders, payments, and refunds
  • To generate a personal profile about you to better understand and serve your needs
  • To improve our website and services based on feedback and usage analytics
  • To comply with legal obligations

4. Third-Party Services

Our service integrates with third-party providers:

  • Google: For OAuth authentication, contact synchronization via Google Contacts, and optional Gmail reply protection with your separate permission
  • Microsoft: For OAuth authentication and contact synchronization via Microsoft Outlook
  • Resend: For transactional, lead and campaign email delivery. The Gmail connection does not send email through Gmail or forward your inbox to Resend.
  • Stripe: For payment processing (Stripe does not store your credit card data with us)
  • Vercel: For hosting and analytics

These third-party providers have their own privacy policies and are not covered by this Privacy Policy.

Self-service lead email

When enabled, self-service sending uses your name via AgentOS and your verified account email as the reply-to address. We store your verification status and a hash of each one-time verification token, your business name and mailing address, and the recipient, subject, message content, sending request identifier and delivery status needed to send and safely reconcile your messages. The sending payload, including your client-facing footer, is shared with Resend for delivery. Verification does not connect or read your inbox.

Recipient opt-outs and unsafe-delivery markers are recorded per workspace to prevent further lead follow-up and campaign emails. Saved message and verification records are removed when the associated AgentOS user record is deleted; workspace opt-out records remain to prevent unwanted email from another member of that workspace. You may request access, correction or deletion through support@agentoscrm.com. Do not include unnecessary sensitive information in email drafts.

5. Optional Gmail Reply Protection

This optional feature is limited to invited pilot users while testing. If it is available to you, connecting Gmail requires your explicit consent. You choose reply protection separately for each new campaign plan. Connecting an inbox does not start or resume a campaign, and existing manual plans are unchanged.

What we access and why

We request Gmail metadata access to identify replies to known campaign emails and pause the related plans for your review. We check the connected account address, message times, labels, sender and recipient headers, and identifiers that link messages to an email thread. Headers that help identify automated replies are also checked. Headers from unrelated mail may be processed while finding a match, then discarded.

Message bodies and attachments are not requested or saved. This connection does not send, modify, mark as read, or delete Gmail messages. It is separate from your Calendar and Contacts connections and must match the primary email address of your signed-in AgentOS account. Nothing is forwarded to the AgentOS support inbox.

What we store and retain

We store an encrypted refresh credential, your connected email address, consent and connection status, and the synchronization position needed to check new messages. Access tokens are used during provider requests rather than saved in campaign history. One-time connection authorization requests expire after ten minutes. A bounded processing queue can temporarily contain message identifiers until processing completes or you disconnect.

For matched messages, campaign history retains a hashed message identifier, references to the known campaign and sent email, the message type, time received, and review status. We do not retain message subjects, bodies, attachments, or unrelated message headers. Reply markers do not classify a lead as having had a human conversation.

Disconnecting removes the saved refresh credential and pending processing queue, but does not delete existing campaign history or tasks. Connection and reply records are removed when the associated AgentOS user record is deleted. You may request deletion through support@agentoscrm.com.

Your controls and the feature's limits

Checks run periodically while a protected plan is running or paused. Replies without matching thread identifiers may not be recognized, and an email already being submitted cannot be recalled. Failed connections or missing history hold protected plans. You must review your inbox and explicitly resume a paused plan; reconnecting alone does not resume it.

You can disconnect in AgentOS or revoke access in your Google Account connections, including after your AgentOS trial expires. Disconnecting in AgentOS also attempts to revoke Google's grant; if that attempt fails, use the Google Account link to remove permission. During Google's Testing mode, authorization must normally be renewed after seven days.

Limited use of Google data

Gmail data is used only to provide this visible reply-protection feature. It is not sold, used to serve or target advertisements, used to build personal profiles, or used to train general-purpose AI models. Our hosting and database providers process the minimum data needed to operate the feature; unrelated messages are not copied into the CRM or sent to our email-delivery provider.

We limit human access to Google-derived data to your affirmative permission for specific data, necessary security investigations, or legal requirements. Our use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements. The general uses elsewhere in this policy do not expand these Gmail-specific limits.

6. Data Encryption and Security

We implement appropriate technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Saved authorization credentials for Gmail reply protection are encrypted before storage and are not returned to the browser or included in application logs.

7. Data Retention

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, or resolve disputes. You may request deletion of your data by contacting us.

8. Your Rights

Depending on your location, you may have the following rights:

  • Right to access your personal information
  • Right to correct inaccurate data
  • Right to request deletion of your data
  • Right to restrict processing of your data
  • Right to data portability
  • Right to object to processing

To exercise any of these rights, please contact us at support@agentoscrm.com

9. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Email: support@agentoscrm.com

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date of this Privacy Policy.

Last Updated: September 13, 2026