AgentPad ("we", "our", "us") is operated by FACTORÍA ELCANO, S.L. (NIF B13883186), with registered office at C/ Marqués de la Ensenada 2, 28004 Madrid, Spain. AgentPad is the agent-native collaborative markdown editor available at https://agentpad.cc. This Privacy Policy describes what data we collect, how we use it, and the rights you have over it.
We don't sell your data. We don't run advertising. We don't profile users for marketing. The data we collect is what we need to run the product — accounts, the documents you create, the comments you and your collaborators leave, and operational logs.
When you sign in we store your email address and an API key we generate for REST and MCP clients. Human web sign-in uses a short-lived one-time email link with a six-digit fallback code (no password). Agent, native, and connector clients retain the eight-digit email-code flow. We store only one-way verifiers for browser sign-in links and fallback codes. We store a one-way API-key verifier for authentication and an encrypted copy only so you can copy authenticated install commands or key-bearing connector URLs after signing in. The web app uses a separate revocable HttpOnly browser-session cookie and does not store the API key in browser storage. It also receives a short-lived HttpOnly human-control cookie for owner-only browser controls such as pausing or resuming agent edits. Treat sign-in links, codes, and API-key-bearing commands and URLs as secrets.
Markdown content of every document you create or edit, stored under a per-document key in our content store. We store the current revision plus a history of prior versions so you can restore.
Comments you (or invited collaborators or agents acting on your behalf) leave on documents, including the quoted text the comment anchors to, the comment text itself, the author identifier, replies, and resolution state.
Document ownership, tags you assign, presence (who is currently viewing a document, retained for ~30 seconds), recently-visited documents, and per-line edit attribution.
HTTP request paths, response codes, timing, and the originating IP for rate-limiting and abuse-prevention purposes. Sensitive URL segments (API keys in URLs, token query parameters) are redacted before logs are written. Logs are retained for up to 30 days.
We also keep an owner-visible security ledger when document content or content-derived data is returned or a known-document access attempt is denied. It records the document ID, actor account ID when authenticated, access method and role, action, outcome, server-generated request ID, timestamp, limited server-generated context, and an optional keyed hash of the source IP. It never stores caller-controlled headers, document content, titles, search queries or snippets, access tokens, email addresses, or raw IP addresses in the event context.
When an external service (such as ChatGPT) installs AgentPad as a connector, we store the registered client identifier, the granted scopes, and short-lived access/refresh tokens. We never store passwords or third-party API keys for those services.
We share your data only in these cases:
We use the following third parties to operate AgentPad. Each is bound by a contract that limits their use of your data to providing services to us.
| Provider | Purpose | Data they see |
|---|---|---|
| Cloudflare | Edge compute, KV storage, R2 object storage, DDoS protection | Document content, request logs |
| Neon | Managed PostgreSQL hosting | User accounts, document metadata, comments, version history |
| Resend | Transactional email delivery | Email address, one-time sign-in link and code |
| OpenAI | Optional: icon-slug suggestion on document creation | Document title (and optional content prefix) at creation time only |
We do not transfer your data to any other third party for any purpose other than the ones listed above.
We protect your data with:
No system is impenetrable. If you believe your account has been compromised, contact us immediately at security@agentpad.cc and rotate your API key from the AgentPad dashboard.
Depending on your jurisdiction (GDPR, CCPA, LGPD, etc.) you may have the right to:
To exercise any of these rights, email privacy@agentpad.cc. We will respond within 30 days.
You can delete your account yourself, from inside AgentPad. You do not need to email us, call us, or wait for us to act. There is no "deactivate" or "disable" option — deletion is permanent and cannot be undone.
DELETE /api/account — see the API reference.You are asked to type your email address and enter a fresh verification code sent to that address. The code protects permanent deletion if a long-lived app or API credential is compromised.
What is deleted: your email address, API key, browser sessions, OAuth connector grants, and every document you own — including its content, version history, comments, suggestions, review artifacts, and uploaded images. Collaborators lose access to those documents immediately, including access shared by link.
What is kept, with your identity removed: comments, versions, suggestions, review artifacts, edit records, and document-security events you left on documents owned by other people. Removing them would delete other people's content or security history along with yours, so the rows remain. The author is shown as "Deleted account" where applicable. Your identity is immediately hidden from document-security ledger responses, and bounded scheduled cleanup then physically removes the account ID from those ledger rows. Actor email addresses are never exposed by the security-ledger API.
Timing: your account and most structured fields identifying you are removed during the request itself. Security-ledger identity is hidden from product and API responses during the request, then physically scrubbed in bounded scheduled batches; backups retain earlier copies only until their normal expiry. Owned document rows, bodies, presence data, and uploaded images are normally erased in the same request. If cleanup is deferred because of its execution budget or a database, KV, or object-storage failure, the documents remain inaccessible and a bounded scheduled purge retries them. That purge normally runs hourly; large backlogs and provider outages can delay completion, with the 30-day deletion target stated in Section 5.
Signing in again with the same email address creates a new, empty account. Nothing from the deleted account can be recovered.
AgentPad is not intended for children under 13 (or under 16 in the EU/EEA). We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@agentpad.cc and we will delete it.
Our infrastructure runs on Cloudflare's global edge network and Neon's regional PostgreSQL clusters. Data may be processed in regions outside your country of residence. Where the destination region does not provide an adequacy decision under your jurisdiction's data-protection law (e.g., GDPR Article 45), we rely on standard contractual clauses (SCCs) with our service providers.
We may update this policy as the product evolves. The "Published" date identifies the notice version and the "Effective" date identifies when its changes take effect. For material changes that affect your rights or how we collect data, we will notify you by email at least 14 days before the change takes effect.
Account deletion does not require contacting us — see Deleting your account. For privacy questions or to exercise any of the other rights above: