AgentPad

Privacy Policy

Published: August 5, 2026 · Effective: August 19, 2026 · Terms of Service

AgentPad ("we", "our", "us") is operated by FACTORÍA ELCANO, S.L. (NIF B13883186), with registered office at C/ Marqués de la Ensenada 2, 28004 Madrid, Spain. AgentPad is the agent-native collaborative markdown editor available at https://agentpad.cc. This Privacy Policy describes what data we collect, how we use it, and the rights you have over it.

We don't sell your data. We don't run advertising. We don't profile users for marketing. The data we collect is what we need to run the product — accounts, the documents you create, the comments you and your collaborators leave, and operational logs.

1. What we collect

1.1 Account data

When you sign in we store your email address and an API key we generate for REST and MCP clients. Human web sign-in uses a short-lived one-time email link with a six-digit fallback code (no password). Agent, native, and connector clients retain the eight-digit email-code flow. We store only one-way verifiers for browser sign-in links and fallback codes. We store a one-way API-key verifier for authentication and an encrypted copy only so you can copy authenticated install commands or key-bearing connector URLs after signing in. The web app uses a separate revocable HttpOnly browser-session cookie and does not store the API key in browser storage. It also receives a short-lived HttpOnly human-control cookie for owner-only browser controls such as pausing or resuming agent edits. Treat sign-in links, codes, and API-key-bearing commands and URLs as secrets.

1.2 Document content

Markdown content of every document you create or edit, stored under a per-document key in our content store. We store the current revision plus a history of prior versions so you can restore.

1.3 Comments

Comments you (or invited collaborators or agents acting on your behalf) leave on documents, including the quoted text the comment anchors to, the comment text itself, the author identifier, replies, and resolution state.

1.4 Collaboration metadata

Document ownership, tags you assign, presence (who is currently viewing a document, retained for ~30 seconds), recently-visited documents, and per-line edit attribution.

1.5 Operational logs

HTTP request paths, response codes, timing, and the originating IP for rate-limiting and abuse-prevention purposes. Sensitive URL segments (API keys in URLs, token query parameters) are redacted before logs are written. Logs are retained for up to 30 days.

We also keep an owner-visible security ledger when document content or content-derived data is returned or a known-document access attempt is denied. It records the document ID, actor account ID when authenticated, access method and role, action, outcome, server-generated request ID, timestamp, limited server-generated context, and an optional keyed hash of the source IP. It never stores caller-controlled headers, document content, titles, search queries or snippets, access tokens, email addresses, or raw IP addresses in the event context.

1.6 OAuth grant metadata

When an external service (such as ChatGPT) installs AgentPad as a connector, we store the registered client identifier, the granted scopes, and short-lived access/refresh tokens. We never store passwords or third-party API keys for those services.

1.7 What we do not collect

2. How we use it

3. Sharing your data

We share your data only in these cases:

4. Service providers (sub-processors)

We use the following third parties to operate AgentPad. Each is bound by a contract that limits their use of your data to providing services to us.

ProviderPurposeData they see
CloudflareEdge compute, KV storage, R2 object storage, DDoS protectionDocument content, request logs
NeonManaged PostgreSQL hostingUser accounts, document metadata, comments, version history
ResendTransactional email deliveryEmail address, one-time sign-in link and code
OpenAIOptional: icon-slug suggestion on document creationDocument title (and optional content prefix) at creation time only

We do not transfer your data to any other third party for any purpose other than the ones listed above.

5. Data retention

6. Security

We protect your data with:

No system is impenetrable. If you believe your account has been compromised, contact us immediately at security@agentpad.cc and rotate your API key from the AgentPad dashboard.

7. Your rights

Depending on your jurisdiction (GDPR, CCPA, LGPD, etc.) you may have the right to:

To exercise any of these rights, email privacy@agentpad.cc. We will respond within 30 days.

8. Deleting your account

You can delete your account yourself, from inside AgentPad. You do not need to email us, call us, or wait for us to act. There is no "deactivate" or "disable" option — deletion is permanent and cannot be undone.

You are asked to type your email address and enter a fresh verification code sent to that address. The code protects permanent deletion if a long-lived app or API credential is compromised.

What is deleted: your email address, API key, browser sessions, OAuth connector grants, and every document you own — including its content, version history, comments, suggestions, review artifacts, and uploaded images. Collaborators lose access to those documents immediately, including access shared by link.

What is kept, with your identity removed: comments, versions, suggestions, review artifacts, edit records, and document-security events you left on documents owned by other people. Removing them would delete other people's content or security history along with yours, so the rows remain. The author is shown as "Deleted account" where applicable. Your identity is immediately hidden from document-security ledger responses, and bounded scheduled cleanup then physically removes the account ID from those ledger rows. Actor email addresses are never exposed by the security-ledger API.

Timing: your account and most structured fields identifying you are removed during the request itself. Security-ledger identity is hidden from product and API responses during the request, then physically scrubbed in bounded scheduled batches; backups retain earlier copies only until their normal expiry. Owned document rows, bodies, presence data, and uploaded images are normally erased in the same request. If cleanup is deferred because of its execution budget or a database, KV, or object-storage failure, the documents remain inaccessible and a bounded scheduled purge retries them. That purge normally runs hourly; large backlogs and provider outages can delay completion, with the 30-day deletion target stated in Section 5.

Signing in again with the same email address creates a new, empty account. Nothing from the deleted account can be recovered.

9. Children

AgentPad is not intended for children under 13 (or under 16 in the EU/EEA). We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@agentpad.cc and we will delete it.

10. International data transfers

Our infrastructure runs on Cloudflare's global edge network and Neon's regional PostgreSQL clusters. Data may be processed in regions outside your country of residence. Where the destination region does not provide an adequacy decision under your jurisdiction's data-protection law (e.g., GDPR Article 45), we rely on standard contractual clauses (SCCs) with our service providers.

11. Changes to this policy

We may update this policy as the product evolves. The "Published" date identifies the notice version and the "Effective" date identifies when its changes take effect. For material changes that affect your rights or how we collect data, we will notify you by email at least 14 days before the change takes effect.

12. Contact

Account deletion does not require contacting us — see Deleting your account. For privacy questions or to exercise any of the other rights above: