Skip to content

Legal · version 2026-04-22

Privacy Policy

This Privacy Policy describes how Elements collects, uses, and protects your information. We believe in collecting the minimum data needed to operate the Service.

1. Information We Collect

Account data: email address, name you provide, hashed password, role, and timestamps.

Content data: pipelines you create, their configuration, execution logs, bug reports you submit, and chat session history from the Testing Playground.

Technical data: request IDs, rate-limit counters, audit logs of security-relevant actions, server-side error correlation IDs, approximate IP address for API-key calls.

Credentials: third-party API keys you store are encrypted at rest with AES-256-GCM. Raw keys are never written to logs.

2. What We Do Not Collect

  • Payment information (the Service is free during beta).
  • Social-network profiles.
  • Tracking data from advertising or analytics networks.
  • Device fingerprints or cross-site behavioral data.

3. How We Use Your Information

  • Operate, maintain, and improve the Service.
  • Authenticate you and secure your account.
  • Enforce rate limits and prevent abuse.
  • Respond to support requests and bug reports.
  • Send service-related emails (verification, password reset, critical alerts). We do not send marketing emails during beta.

4. Third-Party AI Providers

When you execute a pipeline that calls OpenAI, Anthropic, Google, Groq, OpenRouter, or any other model provider, your prompts and inputs are sent directly to that provider using the credentials you have configured. Those providers' handling of that data is governed by their own privacy policies, which you should review. We do not share your data with providers you have not configured.

5. Data Retention

  • Account data — retained until you delete your account.
  • Pipelines & credentials — retained until you delete them or your account.
  • Execution history — automatically deleted after 30 days.
  • Audit logs — retained for security investigations. Anonymized when you delete your account.

6. Your Rights

You can exercise these rights directly from Settings → Danger Zone:

  • Access & portability — export all your data as a ZIP file.
  • Correction — update your name and password from Settings → Profile.
  • Erasure — delete your account and associated data.

If you are in the EU (GDPR), UK (UK-GDPR), California (CCPA/CPRA), or India (DPDP Act), these rights are guaranteed under those laws. We respond to requests within 30 days.

7. Security

  • Passwords stored with bcrypt hashing.
  • Third-party credentials encrypted at rest with AES-256-GCM.
  • JWT tokens with refresh rotation and server-side revocation.
  • HTTPS enforced in production.
  • Rate limiting, audit logs, and security headers (CSP, HSTS-ready).

No system is perfectly secure. If you suspect unauthorized access, contact us immediately at support@agentstudiox.in.

8. Cookies

We use one technical token stored in your browser's localStorage to keep you logged in. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Children

The Service is not intended for users under 16. We do not knowingly collect data from children under 16.

10. Changes

Material changes to this policy will be notified in-app with a re-acceptance prompt.

11. Contact

Privacy questions or data-rights requests: support@agentstudiox.in.

Last updated: 2026-04-22 · Questions? support@agentstudiox.in