> PRIVACY POLICY
Who we are
Strange Attractor FZ-LLC, a company registered in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates, licence number 47033852 ("we", "us"), provides Subagency (the website, our Mac app and any future apps, the agency software and our online service). You can reach us at support@subagency.ai.
Strange Attractor FZ-LLC is the controller of the personal data this policy describes. For content on your own computer, and for what your bots send to your AI provider, you control it.
For account, billing, security and website data, we act as the controller. Where a business uses Subagency to process information on its instructions, we may act as its processor for that information, and further terms may apply.
What this covers
This policy covers our website, our Mac app and any future apps, the agency software you run on your own computer, and the online services we run to support them. It explains what personal data we collect, why, who we share it with, how long we keep it, and what choices you have.
The short version
- Subagency has two parts. The agency runs on your own computer. It holds your bots, their memory, your files and your approvals. We do not access or inspect that content as part of providing the service. The one exception is a cloud backup you switch on, where we hold the key (see "backups" below).
- The online service is the part we run. It looks after your account, your devices, your plan and, if you switch it on, your encrypted backups.
- Your bots may use an AI provider through an account or connection you choose; today that is your own account. We do not receive or inspect those requests as part of providing Subagency. Your AI provider receives and processes them under your agreement with it. We are not a party to that agreement.
- We do not sell your personal data. We do not use it for advertising.
- Subagency does not use your bot content to train AI models. That includes any support attachments and diagnostics you send us. When your bots send content to your AI provider, that provider's handling is governed by your own agreement and settings with it.
What we collect
We collect only what we need. It falls into these groups.
What you give us
- Account details, such as your email address. If you sign in with a provider such as Google, our sign-in service also receives the basic profile details that provider shares, which can include your name.
- Messages you send us, such as support requests, and any diagnostics you choose to attach.
- Answers on our forms, such as the sign-up or beta form.
- Payment and billing details, once paid plans start. Our payment provider handles these. We do not keep full card numbers.
What is created when you use Subagency
- Records of your devices: which are linked to your account, when each last connected, its type and its software version.
- Your plan and account status.
- Technical logs, which can include your IP address, times and error details, so we can run and protect the service.
- Backup records and, if you use backups, the backups themselves. See "backups" below.
What we collect on the website
- Sign-up details: your email address, your answers on the form, and the time and version of the wording you agreed to.
- Where relevant, which page or campaign brought you to us.
- Your approximate location, worked out from your network address. We never ask you for it. We do not keep your IP address with your sign-up.
- Usage statistics, collected without cookies. See "cookies and similar tools" below.
What we do not collect
- The content of your bots' conversations, memory, files, connected accounts and browsing sessions. These stay on your computer.
- Your AI provider sign-in or API key, and the passwords or sign-ins for services you connect to a bot.
If you choose cloud backup, an encrypted copy of some of your agency data is stored with us. See "backups" below for what that means.
Why we use your data
Where EU or UK data protection law applies, we rely on these legal bases.
- To provide the service (create your account, link devices, apply your plan, run backups, provide remote access): contract.
- To keep it secure and working (logs, abuse checks, fixing faults): legitimate interests.
- To give support: contract and legitimate interests.
- To tell you about Subagency (updates and beta invitations you asked for): your consent. You can withdraw it at any time.
- To understand how the website is used: legitimate interests.
- To take payment and keep records: contract and legal obligation.
- To follow the law: legal obligation.
Where UAE law applies, we process personal data on the bases the law allows, including consent where it is required.
We do not make decisions about you by automated means that have legal or similarly significant effects. Your bots act for you, under your instructions and approvals. Those are not decisions we make about you.
Who we share data with
- Service providers who help us run Subagency. They are listed under "service providers" below. They may use your data only to provide their service to us.
- Your AI provider, when your bots use it. This happens from your own computer under your own agreement. It is not a disclosure by us.
- Services you connect to a bot, such as email or calendar. Data flows between your computer and that service under your own account.
- Advisers and authorities, where the law requires it or where we need to protect our rights.
- A buyer or successor, if our business changes hands. The new owner would have to respect this policy.
We do not sell personal data. We do not share it for advertising.
Backups
Backups are optional. If you switch them on:
- Your agency encrypts an archive of your bots and their data on your computer, then uploads the encrypted archive to storage we run in the European Union.
- We create and look after one key per account to protect your backups. It is stored encrypted in our service. The service is designed to release the backup key only to an authenticated, linked agency device. No ordinary Subagency admin tool can retrieve or use it. Someone with deep access to our underlying infrastructure could, in principle, reach the protected key material, subject to our security controls. Each time our service hands out a backup key, we record which account and device asked and when, but never the key itself. We keep these records for 90 days. That lets you restore on a new computer without a recovery phrase. It also means we are technically able to decrypt a backup. We do not do this as part of running the service. You should decide whether that is acceptable for what you back up.
- Backups leave out credentials such as AI sign-ins, connector logins and browser sign-ins.
- Backups can otherwise contain personal data, including your bots' memory, conversations and files. You choose what your bots handle, so you are responsible for having a lawful reason to back that data up.
- We keep a limited number of recent backups and delete older ones automatically.
- After your account is closed, we delete your backups after 30 days. You can also ask us to delete them sooner (see "your rights and choices").
How long we keep data
- Account and plan records: while your account is open. After your account is closed, we delete them after 12 months.
- Device records: while the device is linked. When you remove a device, we keep a revoked record for security.
- Technical logs: we delete server logs after 90 days.
- Backup key-access records: 90 days.
- Backups: until a newer backup replaces them under our automatic clean-up. After your account is closed, we delete your backups after 30 days.
- Support messages and the diagnostics you attach: about 90 days, then they are deleted automatically.
- Website sign-up list: until you unsubscribe. After you unsubscribe, we keep your address on a do-not-email list so that we do not email you again, and we delete it 12 months after you unsubscribe.
- Payment and tax records: as long as the law requires.
We keep any other personal data only as long as we need it for the purpose we collected it, then delete it. Our providers keep their own operational records for limited periods under their terms.
We may keep data for longer where we need it for a legal claim or legal duty. Data on your own computer is yours. You decide how long it stays there.
Cookies and similar tools
- Our website analytics are configured not to use cookies or persistent browser identifiers. They may still process technical request data, such as your IP address, browser type, the time and the pages viewed. We use PostHog (EU cloud) for this, and our hosting provider, Cloudflare, keeps its own standard traffic records.
- We use a bot-protection check on our forms (Cloudflare Turnstile). It runs a short test in your browser to tell people from automated traffic, and it receives technical signals such as your IP address to do that.
- If we ever add cookies that are not essential, we will ask you first and list them here.
- We do not respond to "do not track" browser signals, because we do not track you across other sites.
Sign in with Google
If you sign in with Google, we ask only for your name and email. We use what Google shares only to create and secure your account and to sign you in. We do not use it for advertising, we do not sell it, and we do not use it to train AI models. We do not read your Gmail, Calendar or Drive through the sign-in. You can stop at any time by removing Subagency's access in your Google account settings and asking us to delete your account. Removing our access in your Google account stops Google sign-in but does not delete your Subagency account. To delete it, contact us.
Where and how your data is processed and stored
Our own service and your cloud backups are hosted in the European Union. Some of the providers we use, such as sign-in and email, are based in the United States.
This is every place your data lives or passes through, what is there, and who can see it.
- Your computer: your bots, their memory, conversations, files and connector logins stay on your own machine. We do not access or inspect them as part of providing the service.
- Your AI provider (for example Anthropic or OpenAI): is usually based in the United States. Your bots may use it through an account or connection you choose; today that is your own account. We do not receive or inspect those requests as part of providing Subagency. Your AI provider receives and processes them under your agreement with it.
- Our online service: holds your account and plan records, device links, support messages and server logs. We can see this data. It runs with a hosting provider (Railway) and is hosted in the European Union (the Netherlands).
- Sign-in: Clerk may store sign-in data wherever Clerk and its providers operate, mainly the United States. It handles sign-in and holds your email address and sign-in records, together with any details a social sign-in you choose (such as Google) shares. Clerk and we can see them.
- Cloud backups: if you switch them on, encrypted backups are stored with Cloudflare R2 in the European Union. There is one key per account, stored encrypted in our service. The service is designed to release it only to an authenticated, linked agency device, and no ordinary Subagency admin tool can retrieve or use it. Because we hold the key, we are technically able to decrypt a backup. We do not do this as part of running the service.
- Secure link to your computer: this is optional and only on plans that include remote access. Your apps connect with their own device credential, and the link address alone does not grant access. Traffic is encrypted between your app and Cloudflare, and between Cloudflare and your computer. Cloudflare's network handles it in between and runs globally, so it can pass through many countries. We do not intentionally store or inspect the content of that traffic. Cloudflare processes connection data as part of running and protecting its network. We keep the link address and when your computer was last online. Removing a device in your account cuts its access straight away.
- Email: Resend sends our account and product emails from servers in the United States, so it sees your email address and the message.
- Payments: once paid plans start, Paddle acts as the seller (merchant of record) for payments and handles your billing data under its own privacy policy. It is not live yet. We do not keep full card numbers.
- Website: Cloudflare Pages hosts it. Your sign-up details are kept in our online service. Cloudflare Turnstile checks forms, and PostHog (EU) counts visits without cookies.
We are based in the UAE, and our providers work in several countries. Your data may be handled outside the country where you live, including outside the UAE, the EU and the UK. Where required, we rely on an adequacy decision, standard contractual clauses, the UK International Data Transfer Addendum or another recognised mechanism, depending on the provider and destination.
Our providers keep their own operational logs for limited periods under their terms, and they delete our data within their stated periods after we stop using them.
Data about other people
Your bots may process information about people other than you, such as correspondents, customers, colleagues and attendees. You are responsible for having the authority, notices and lawful basis to connect those sources and use them with Subagency and your AI provider. If you use Subagency for work, your organisation may decide how that information is processed and may be its controller.
Security
We use encryption in transit and at rest, limit who can reach our systems, and store credentials in protected form. No service is perfectly secure. We assess security incidents and notify the relevant regulator and affected people where the law requires notification, within the legal timeframes.
AI agents carry their own risks. A bot can make mistakes. Text in an email or on a web page can try to trick it. That is why actions with real consequences wait for your approval. Keep that step switched on for anything sensitive. You are responsible for what you connect your bots to.
Your rights and choices
Depending on where you live, you may have the right to:
- ask what personal data we hold about you and get a copy;
- have wrong data corrected;
- have your data deleted;
- restrict or object to some uses of your data;
- take your data to another service;
- withdraw consent, for example by unsubscribing from emails;
- complain to a data protection authority: in the UAE, the UAE Data Office; in the EU or UK, the supervisory authority where you live, work, or where the issue arose.
The UAE Federal Decree-Law No. 45 of 2021 on the protection of personal data applies to us, together with other laws, such as the EU and UK GDPR and California law, where they apply to you. We offer them to everyone, wherever you live, as far as is practical.
To use a right, or to ask us to delete your account and data, email support@subagency.ai. We may need to confirm who you are. Where the law sets a deadline, we reply within it. Otherwise we aim to reply within one month. Rights apply subject to the conditions and exceptions the law allows. We will not treat you worse for using a right. Deletion is done by us on request. We will tell you when it is done.
You can also unsubscribe from any email using the link in it, and delete bots, clear memory or uninstall the agency on your own computer at any time.
Service providers
We keep this list current so that we can change it without changing the rest of this policy. We update it before we add a provider that handles personal data.
- Clerk: sign-in and account identity.
- Cloudflare: secure private links, encrypted backup storage in the EU, website hosting, and bot protection on forms.
- Railway: hosts our online service.
- Resend: sends our account and product emails.
- PostHog: cookieless website analytics, in the EU.
- Paddle: once paid plans start, acts as the seller (merchant of record) for payments. It is not yet live.
Your AI provider (currently Anthropic) and any service you connect to a bot are not our service providers. They act under your own agreement with them.
Children
Subagency is not directed at children, and we do not knowingly allow anyone under 18 to create an account. We do not knowingly collect children's data. If you think a child has given us data, tell us and we will delete it.
Links to other sites
Our website and apps may link to other sites and services. Their privacy practices are their own.
Changes to this policy
We will change this policy as Subagency changes. We will post the new version here with a new date. For material changes we will tell account holders by email, before the change takes effect where we can. You can ask us for earlier versions.
Contact
Email support@subagency.ai. Our terms are on the terms page.
← back