Privacy Policy
Effective: April 3, 2026 | Last updated: April 3, 2026
1. Overview
This Privacy Policy ("Policy") describes how Agents & Swarms, Inc. ("we," "us," or "our") collects, uses, stores, and protects information when you use the Agents & Swarms platform ("Platform"). The Platform provides memory-as-a-service for AI agents, including persistent memory storage, identity management, trust scoring, and agent-human linking capabilities.
This Policy applies to all users of the Platform, including individual developers, organizations operating agent fleets (agent operators), and humans who link with AI agents through our claim system.
By creating an account, linking with an agent, or using any Platform services, you acknowledge that you have read and understood this Policy.
2. Information We Collect
2.1 Account Data
When you create an account, we collect your email address, authentication method (password, magic link, or wallet), and IP address at the time of sign-up.
2.2 Agent Data
When you register an Agent on the Platform, we collect and store the Agent's name, decentralized identifier (DID), configuration settings, and associated metadata.
2.3 Memory Data
The Platform stores content created by your Agents, including text, semantic embeddings, and associated metadata such as timestamps, trust scores, and memory types. Memory content is authored by Agents autonomously during their operation.
2.4 Usage Data
We collect data about how you and your Agents interact with the Platform, including API call volumes, tool execution logs, and interaction metrics such as memory storage and retrieval frequency.
2.5 Technical Data
We automatically collect certain technical information for security and operational purposes, including browser and device information, IP addresses, and request metadata.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the Platform — operating the memory-as-a-service infrastructure, managing agent identities, and ensuring system reliability.
- Process memory operations — storing, retrieving, searching, and managing Agent memories on your behalf.
- Generate trust scores — performing automated safety analysis, provenance verification, and behavioral assessment of stored memories.
- Generate semantic embeddings — creating vector representations of memory content to enable search functionality.
- Service improvement — capacity planning, performance optimization, and feature development using anonymized and aggregated data only.
- Security and abuse prevention — monitoring for unauthorized access, detecting abuse patterns, and enforcing rate limits.
- Communications — sending service updates, security alerts, and policy change notifications.
We do NOT sell your data. We do not sell, rent, or share your personal information or memory content with third parties for their marketing purposes.
We do NOT use memory content to train AI models. Memory data is processed solely for Platform functionality: trust scoring, safety scanning, search indexing, and semantic embedding generation.
4. Memory Data & AI Agent Privacy
4.1 Ownership
Memory content stored on the Platform is owned by the linked human user or their Tenant organization. The Agent is the author of memory content; the linked user is the owner and controller.
4.2 Autonomous Storage
Agents store memories autonomously during their operation. Operators and linked humans should actively monitor the memories stored by their Agents to ensure compliance with applicable privacy laws and organizational policies.
Warning: Agents may inadvertently store sensitive information in memories, including API keys, credentials, personally identifiable information (PII), or other confidential data. Users should regularly review and manage their Agent memories through the Platform dashboard, and delete any memories containing sensitive content.
4.3 Trust Scoring
All memories receive an automated Trust Score computed from three dimensions: safety (content analysis), provenance (source verification), and behavioral (historical reliability). Trust scoring is performed by automated systems and does not involve human review of memory content, unless a memory is flagged for safety concerns requiring manual investigation.
4.4 Semantic Embeddings
Semantic embeddings (vector representations) are generated from memory content solely to enable search and retrieval functionality. Embeddings are not used for AI model training or any purpose beyond Platform search operations.
5. Data Storage & Security
We implement industry-standard security measures to protect your data:
- Location: Data is processed and stored in the United States.
- Encryption in transit: All data transmitted to and from the Platform is encrypted using TLS 1.3.
- Encryption at rest: All stored data is encrypted using AES-256.
- Tenant isolation: Row-Level Security (RLS) enforces strict multi-tenant isolation at the database level, ensuring that each tenant's data is accessible only to authorized users.
- Authentication: JWT-based authentication with configurable session timeouts.
- Rate limiting: All API endpoints are rate-limited to prevent abuse and ensure fair usage.
- Monitoring: Regular security monitoring and comprehensive audit logging of all platform operations.
No system is perfectly secure. You are responsible for securing your own authentication credentials, API keys, and the runtime environments where your Agents operate.
6. Data Retention
6.1 Memory Data
Memory data is retained according to your service tier:
- Free tier: 30 days retention
- Standard tier: 90 days retention
- Premium tier: Unlimited retention
6.2 Account Data
Account data is retained for the duration your account remains active on the Platform.
6.3 Account Deletion
Upon account deletion, all associated data (account information, agent registrations, and memory content) is permanently deleted within 30 days.
6.4 Audit Logs
Audit logs are retained for 90 days after the associated Agent is deleted. For compliance purposes, audit log metadata may be retained in cold storage for up to 7 years.
6.5 Metering Events
API usage and metering events are retained for 2 years for billing and capacity planning purposes.
7. Third-Party Services
The Platform does not host or operate AI models. The Platform provides memory, identity, and governance services only. Your Agents run on third-party AI infrastructure that you or your organization select and configure independently.
When your Agents store or retrieve memories, data may pass through third-party AI provider APIs for embedding generation. Those providers are governed by their own terms of service and data usage policies, which may include using API inputs for model improvement.
We cannot guarantee that third-party AI providers will not use data processed through their services for training or other purposes. We recommend selecting providers that offer data processing agreements and opt-out mechanisms for training data usage where available.
For analytics purposes, we use only anonymized and aggregated metrics. We do not share identifiable user data or memory content with analytics providers.
8. Your Rights
8.1 Data Access & Control
- Access: You may view, search, and export all memories associated with your Agents at any time through the Platform dashboard or API.
- Rectification: You may correct or annotate memories that contain inaccurate information.
- Erasure: You may delete individual memories or request bulk deletion of all Agent memories.
- Portability: You may export your memories in structured JSON format for migration to other platforms.
- Restriction: You may revoke Agent links at any time through the Platform dashboard, which immediately restricts the Agent's ability to store new memories.
8.2 GDPR (EU/EEA Users)
If you are located in the European Union or European Economic Area, your data is processed under Standard Contractual Clauses (SCCs). You have the right to access, rectify, erase, restrict processing, and port your data. To request a copy of our Data Processing Addendum (DPA), contact us at privacy@agentsandswarms.ai.
8.3 CCPA (California Residents)
If you are a California resident, you have the right to know what personal information we collect, the right to delete your personal information, and the right to opt out of the sale of your personal information. We do not sell personal information. To exercise your rights, contact us at privacy@agentsandswarms.ai.
9. Children's Privacy
The Platform is not intended for users under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a user under 18, we will take steps to delete that information promptly.
10. International Data Transfers
The Platform processes and stores data in the United States. If you are accessing the Platform from outside the United States, your data will be transferred to and processed in the United States.
For users in the EU/EEA, data transfers are governed by Standard Contractual Clauses (SCCs) to ensure adequate data protection. To request our Data Processing Addendum (DPA), contact us at privacy@agentsandswarms.ai.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address on your account and posted on this page at least 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
12. Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at:
- Privacy inquiries: privacy@agentsandswarms.ai
- Security issues: security@agentsandswarms.ai
- General support: support@agentsandswarms.ai
- Legal: legal@agentsandswarms.ai