AgentPad

Privacy Policy

Published: August 5, 2026 · Effective: August 19, 2026 · Updated: September 7, 2026 · Terms of Service

AgentPad ("we", "our", "us") is operated by FACTORÍA ELCANO, S.L. (NIF B13883186), with registered office at C/ Marqués de la Ensenada 2, 28004 Madrid, Spain. AgentPad is the agent-native collaborative markdown editor available at https://agentpad.cc. This Privacy Policy describes what data we collect, how we use it, and the rights you have over it.

We don't sell your data. We don't run advertising. We don't profile users for marketing. The data we collect is what we need to run the product — accounts, the documents you create, the comments you and your collaborators leave, and operational logs.

1. What we collect

1.1 Account data

When you sign in we store your email address and an API key we generate for REST and MCP clients. Human web sign-in uses a short-lived one-time email link with a six-digit fallback code (no password), Google Sign-In, or Sign in with Apple. Agent, native, and connector clients retain the eight-digit email-code flow. For Google and Apple, we store the provider name and the stable account identifier supplied by that provider so later sign-ins return to the same AgentPad account. We use the verified email claim to link an existing account only when it is authoritative; otherwise we ask you to prove the AgentPad account email with a fresh code. We do not store Google ID tokens. For Apple, we retain an encrypted revocation credential only when required to revoke the Apple authorization if you delete your AgentPad account. We store only one-way verifiers for browser sign-in links, fallback codes, and provider sign-in attempts. We store a one-way API-key verifier for authentication and an encrypted copy only so you can copy authenticated install commands or key-bearing connector URLs after signing in. The web app uses a separate revocable HttpOnly browser-session cookie and does not store the API key in browser storage. It also receives a short-lived HttpOnly human-control cookie for owner-only browser controls such as pausing or resuming agent edits. Treat sign-in links, codes, and API-key-bearing commands and URLs as secrets.

1.2 Document content

Markdown content of every document you create or edit, stored under a per-document key in our content store. We store the current revision plus a history of prior versions so you can restore.

Anonymous scratchpads are different. An account-free /new scratchpad is encrypted in your browser or local AgentPad skill before it is sent to us. We store its encrypted envelope, a one-way verifier derived from the private edit key, revision and expiry timestamps, and normal operational logs. We do not receive the root edit key from the URL fragment or the plaintext Markdown. The browser stores a separate recovery copy, including the private edit key and plaintext, in that browser's site data.

1.3 Comments

Comments you (or invited collaborators or agents acting on your behalf) leave on documents, including the quoted text the comment anchors to, the comment text itself, the author identifier, replies, and resolution state.

1.4 Collaboration metadata

Document ownership, tags you assign, presence (who is currently viewing a document, retained for ~30 seconds), recently-visited documents, and per-line edit attribution.

1.5 Operational logs

HTTP request paths, response codes, timing, and the originating IP for rate-limiting and abuse-prevention purposes. Sensitive URL segments (API keys in URLs, token query parameters) are redacted before logs are written. Logs are retained for up to 30 days.

We also keep an owner-visible security ledger when document content or content-derived data is returned or a known-document access attempt is denied. It records the document ID, actor account ID when authenticated, access method and role, action, outcome, server-generated request ID, timestamp, limited server-generated context, and an optional keyed hash of the source IP. It never stores caller-controlled headers, document content, titles, search queries or snippets, access tokens, email addresses, or raw IP addresses in the event context.

1.6 OAuth grant metadata

When an external service (such as ChatGPT) installs AgentPad as a connector, we store the registered client identifier, the granted scopes, and short-lived access/refresh tokens. We never store passwords or third-party API keys for those services.

1.7 What we do not collect

2. How we use it

3. Sharing your data

We share your data only in these cases:

4. Service providers (sub-processors)

We use the following third parties to operate AgentPad. Each is bound by a contract that limits their use of your data to providing services to us.

ProviderPurposeData they see
CloudflareEdge compute, KV storage, R2 object storage, DDoS protectionDocument content, request logs
NeonManaged PostgreSQL hostingUser accounts, document metadata, comments, version history
ResendTransactional email deliveryEmail address, one-time sign-in link and code
GoogleOptional Google account sign-inThe sign-in request and the Google account you choose; Google returns a stable account identifier, verified email, and basic profile claims to AgentPad
AppleOptional Apple Account sign-inThe sign-in request and the Apple Account you choose; Apple returns a stable account identifier and an email or private relay address to AgentPad
OpenAIOptional: icon-slug suggestion on document creationDocument title (and optional content prefix) at creation time only

We do not transfer your data to any other third party for any purpose other than the ones listed above.

5. Data retention

6. Security

We protect your data with:

No system is impenetrable. If you believe your account has been compromised, contact us immediately at security@agentpad.cc and rotate your API key from the AgentPad dashboard.

7. Your rights

Depending on your jurisdiction (GDPR, CCPA, LGPD, etc.) you may have the right to:

To exercise any of these rights, email privacy@agentpad.cc. We will respond within 30 days.

8. Deleting your account

You can delete your account yourself, from inside AgentPad. You do not need to email us, call us, or wait for us to act. There is no "deactivate" or "disable" option — deletion is permanent and cannot be undone.

You are asked to type your email address and enter a fresh verification code sent to that address. The code protects permanent deletion if a long-lived app or API credential is compromised.

What is deleted: your email address, Google or Apple identity link, API key, browser sessions, OAuth connector grants, and every document you own — including its content, version history, comments, suggestions, review artifacts, and uploaded images. When applicable, AgentPad also asks Apple to revoke its authorization before the encrypted revocation credential is removed. Collaborators lose access to those documents immediately, including access shared by link.

What is kept, with your identity removed: comments, versions, suggestions, review artifacts, edit records, and document-security events you left on documents owned by other people. Removing them would delete other people's content or security history along with yours, so the rows remain. The author is shown as "Deleted account" where applicable. Your identity is immediately hidden from document-security ledger responses, and bounded scheduled cleanup then physically removes the account ID from those ledger rows. Actor email addresses are never exposed by the security-ledger API.

Timing: your account and most structured fields identifying you are removed during the request itself. Security-ledger identity is hidden from product and API responses during the request, then physically scrubbed in bounded scheduled batches; backups retain earlier copies only until their normal expiry. Owned document rows, bodies, presence data, and uploaded images are normally erased in the same request. If cleanup is deferred because of its execution budget or a database, KV, or object-storage failure, the documents remain inaccessible and a bounded scheduled purge retries them. That purge normally runs hourly; large backlogs and provider outages can delay completion, with the 30-day deletion target stated in Section 5.

Signing in again with the same email address creates a new, empty account. Nothing from the deleted account can be recovered.

9. Children

AgentPad is not intended for children under 13 (or under 16 in the EU/EEA). We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@agentpad.cc and we will delete it.

10. International data transfers

Our infrastructure runs on Cloudflare's global edge network and Neon's regional PostgreSQL clusters. Data may be processed in regions outside your country of residence. Where the destination region does not provide an adequacy decision under your jurisdiction's data-protection law (e.g., GDPR Article 45), we rely on standard contractual clauses (SCCs) with our service providers.

11. Changes to this policy

We may update this policy as the product evolves. The "Published" date identifies the notice version and the "Effective" date identifies when its changes take effect. For material changes that affect your rights or how we collect data, we will notify you by email at least 14 days before the change takes effect.

12. Contact

Account deletion does not require contacting us — see Deleting your account. For privacy questions or to exercise any of the other rights above: