Last updated July 2026
Account data: your email address and authentication details (handled through our auth provider), timezone and profile settings, and your budget and plan configuration.
Content you provide: the goals, prompts, and files you send an agent, any brand or product images you upload, and messages sent through connected channels (Telegram, Slack, WhatsApp, SMS, email).
Run data: the full step trace of what an agent did on your behalf — tool calls, intermediate results, and generated artifacts — so you can inspect and replay any run.
Billing data: subscription and payment details are handled by Stripe; we store your plan tier and usage totals, not your raw card number.
Operational data: request logs tagged with a correlation ID for debugging, and aggregate error/usage metrics used to keep the platform running.
When you set a password, we check it against known-breach databases using k-anonymity — only a partial hash prefix ever leaves our servers, never your actual password or a hash that could be reversed to it. This lets us warn you if a password has already been exposed elsewhere without exposing your password to a third party ourselves.
We don’t sell your data. We don’t use your prompts or files to train models.
Running an agent means calling out to the services it needs to do the job: Anthropic and OpenAI for model inference, Composio for third-party account linking, Resend for transactional email, Twilio for SMS, and the messaging platforms (Telegram, Slack, Meta/WhatsApp) for any channel you connect. Files and generated artifacts are stored in our object storage; database backups are encrypted at rest. Each of these only receives the data needed to do its part of the job.
Actus sends promotional/marketing SMS only to people who opt in below. Message frequency varies; message and data rates may apply. Reply HELP for help or STOP to unsubscribe at any time. Carriers are not liable for delayed or undelivered messages. This consent is not a condition of any purchase.
From Settings, you can export a full copy of your account data at any time, and you can delete your account outright — this removes your stored content, run history, and memory. Some records (like billing history required for tax/accounting purposes) may be retained as required by law after deletion.
If you’re in the EU/UK, these are your GDPR rights to access, export, and erase your data; we honor equivalent requests regardless of where you’re located.
Run history and step traces are kept so you can review and replay past work, until you clear them from Settings or delete your account. Request logs used for debugging and abuse detection are retained for a limited operational window, not indefinitely.
Sensitive credentials (connected-account tokens, per-user API keys) are encrypted at rest. Sensitive agent actions can be gated behind an approval step you control. Database backups run on a schedule and are encrypted. No system is perfectly secure — if you discover a vulnerability, please report it to support@actusagent.cc.
We’ll update this page when our practices change and update the “last updated” date above.
Questions about this policy or a data request: support@actusagent.cc