Privacy Policy

Last updated July 2026

1. What we collect

Account data: your email address and authentication details (handled through our auth provider), timezone and profile settings, and your budget and plan configuration.

Content you provide: the goals, prompts, and files you send an agent, any brand or product images you upload, and messages sent through connected channels (Telegram, Slack, WhatsApp, SMS, email).

Run data: the full step trace of what an agent did on your behalf — tool calls, intermediate results, and generated artifacts — so you can inspect and replay any run.

Billing data: subscription and payment details are handled by Stripe; we store your plan tier and usage totals, not your raw card number.

Operational data: request logs tagged with a correlation ID for debugging, and aggregate error/usage metrics used to keep the platform running.

2. How your password is checked

When you set a password, we check it against known-breach databases using k-anonymity — only a partial hash prefix ever leaves our servers, never your actual password or a hash that could be reversed to it. This lets us warn you if a password has already been exposed elsewhere without exposing your password to a third party ourselves.

3. How we use it

  • To run the agent platform: executing your goals, remembering context you’ve asked it to keep, and returning results.
  • To operate connected channels you set up (Telegram, Slack, WhatsApp, SMS, email).
  • To bill your plan and enforce the budget cap you’ve set.
  • To detect abuse, rate-limit runaway usage, and keep the platform stable and secure.
  • To send you transactional email (password resets, run failures, budget alerts) — never marketing email without your opt-in.

We don’t sell your data. We don’t use your prompts or files to train models.

4. Third parties we rely on

Running an agent means calling out to the services it needs to do the job: Anthropic and OpenAI for model inference, Composio for third-party account linking, Resend for transactional email, Twilio for SMS, and the messaging platforms (Telegram, Slack, Meta/WhatsApp) for any channel you connect. Files and generated artifacts are stored in our object storage; database backups are encrypted at rest. Each of these only receives the data needed to do its part of the job.

5. Text message (SMS) opt-in

Actus sends promotional/marketing SMS only to people who opt in below. Message frequency varies; message and data rates may apply. Reply HELP for help or STOP to unsubscribe at any time. Carriers are not liable for delayed or undelivered messages. This consent is not a condition of any purchase.

Actus may send you text messages related to your account and, if you opt in below, promotional offers. Standard message and data rates may apply. You may opt out at any time by replying STOP to any message, or reply HELP for assistance.

SMS Terms of Service: By opting into SMS messaging from Actus, you consent to receive text messages at the phone number provided. Consent is not a condition of any purchase. Message frequency varies. Standard message and data rates may apply based on your carrier plan. To opt out at any time, reply STOP to any message. For support, reply HELP or contact support@actusagent.cc. We do not share or sell your SMS opt-in data to third parties. Carriers are not liable for delayed or undelivered messages.

6. Your rights

From Settings, you can export a full copy of your account data at any time, and you can delete your account outright — this removes your stored content, run history, and memory. Some records (like billing history required for tax/accounting purposes) may be retained as required by law after deletion.

If you’re in the EU/UK, these are your GDPR rights to access, export, and erase your data; we honor equivalent requests regardless of where you’re located.

7. Data retention

Run history and step traces are kept so you can review and replay past work, until you clear them from Settings or delete your account. Request logs used for debugging and abuse detection are retained for a limited operational window, not indefinitely.

8. Security

Sensitive credentials (connected-account tokens, per-user API keys) are encrypted at rest. Sensitive agent actions can be gated behind an approval step you control. Database backups run on a schedule and are encrypted. No system is perfectly secure — if you discover a vulnerability, please report it to support@actusagent.cc.

9. Changes to this policy

We’ll update this page when our practices change and update the “last updated” date above.

10. Contact

Questions about this policy or a data request: support@actusagent.cc