Legal

Privacy Policy

Effective August 3, 2026

AgentOS is a product of Devcore. It gives your business a shared workspace where people and AI agents work together: a CRM, a wiki, tasks, chats, and connections to the tools you already use. This policy explains what data we collect to run that workspace, how we use it, and the choices you have. The short version: your data is used to provide the product to your workspace, and for nothing else. We do not sell it and we do not use it for advertising.

What we collect

Account information. When you sign up we collect your name and email address through our sign-in provider, WorkOS.

Workspace content. The work you and your agents create in AgentOS: records, documents, tasks, chats, notes, files, and the activity around them. This content belongs to your workspace and is visible only to its members.

Connected app data. When you connect an external tool (email, calendar, Slack, GitHub, and others), we access the data that connection permits in order to bring it into your workspace. You choose what to connect, and you can disconnect at any time.

Usage and billing. We collect product usage analytics (via PostHog) to understand how AgentOS is used and improve it, and the billing details needed to administer paid plans.

Google user data

When you connect a Google account, AgentOS requests read-only access to Gmail (gmail.readonly) and Google Calendar (calendar.readonly), plus your account email for identification. We use this data solely to provide in-product features within your workspace: capturing email and meeting activity onto your CRM timeline and surfacing time-sensitive items to your team.

Limited Use. AgentOS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or sell this data, do not use it for advertising, and do not allow humans to read it except with your consent, for security purposes, to comply with law, or as part of internal operations on de-identified or aggregated data. Tokens are encrypted at rest; access is scoped to your workspace. You can disconnect at any time in Integrations, which revokes our access and deletes the stored tokens.

How we use your data

We use the data above to operate AgentOS for your workspace: storing and displaying your content, letting your agents work with it, connecting it to the tools you choose, and keeping the service reliable and secure. Content is sent to AI model providers (such as Anthropic and OpenAI) only to generate the responses and work products you ask for; we use their business APIs, which do not use your data to train their models.

Where your data lives

AgentOS runs on infrastructure providers who process data on our behalf: Fly.io (application hosting), Supabase (database), and Cloudflare (file storage and delivery). Sign-in is handled by WorkOS and analytics by PostHog. Data from tools you connect flows through the connection provider you chose when connecting. Each of these providers is bound by its own data processing terms.

Security

All traffic is encrypted in transit with TLS, and data is encrypted at rest. OAuth tokens for connected accounts are additionally encrypted at the application layer before storage. Application secrets live in a managed secrets store, not in code or configuration files. Every workspace's data is isolated: members of one workspace can never see another's content.

Retention and deletion

We keep your workspace content for as long as your workspace exists. Disconnecting an integration revokes our access and deletes its stored credentials. If you want your workspace's data exported or deleted, email us at hello@devvcore.com and we will handle it promptly.

Your choices

You control what gets connected to your workspace and can disconnect any integration at any time. You can ask us to correct, export, or delete your personal data. Analytics can be limited through your browser's tracking protections; the product works fine either way.

Changes to this policy

If we make material changes, we will update this page and note the new effective date above. Continued use of AgentOS after a change means the updated policy applies.

Contact

Questions about this policy or your data: hello@devvcore.com.