AGIME
Privacy Policy
Version 2026-08-19 — DRAFT pending owner review
This page lists the data the running code actually stores. It does not claim GDPR compliance, automated erasure, encryption-at-rest, or any audit certification — the repository does not show those.
1. Account data
- Email address
- Display name (optional; otherwise derived from the email)
- Password hash (scrypt — the password itself is not stored)
2. Sessions
Each login stores a session with the client IP address and user agent. The session cookie is httpOnly.
3. Chat, voice, and memories (LIZ)
- Chat and voice text are processed by your own unit, not a shared multi-tenant model host.
- Long-term memories live in a per-unit Qdrant collection (
liz_uN_owner_memory/liz_uN_knowledge) plus unit-local SQLite. One tenant per unit. Collections are not shared across accounts. - By default, LLM inference runs on project-operated hardware with a local model. A third-party AI API does not see chat unless an owner later wires an external provider.
- During the field test, microphone audio is processed on-device. Server speech-to-text is disabled.
4. Telemetry and analytics
- Hub telemetry samples (metrics such as latency; a unit id when the sample is unit-scoped).
- Optional client telemetry uploads to the Hub ingest route.
- Analytics events from public pages and the panel (for example register_start / register_complete). These are cookieless beacons, not a third-party ad pixel.
5. Personal AI leads
A request stores name, email, plan, optional note, source IP, and (if you pick one) persona settings. That row is the source of truth; mail is best-effort on top of it.
6. Consent and feedback
Accepting these pages writes a consent row (email, document, version, source, IP, optional account id). The cabinet feedback form stores category, message, whether we may contact you, and user agent.
7. Email relay
Transactional mail (verification, password reset, Personal AI order confirmations, feedback alerts) goes through a third-party SMTP relay configured by SMTP_HOST. The documented Hub deployment uses Mailcow on mail.agime.ai. The live provider name is an owner-confirmed fact — see the legal review checklist. We do not put mailbox passwords on this page.
8. Retention and deletion
Self-serve data export is available in the cabinet settings page (per unit, enabled per unit by the operator), covering memories, knowledge-base documents, reminders, persona/identity, personal facts, and the non-secret settings snapshot. Deletion is a request (via the cabinet button or hello@agime.ai) processed manually by an operator with a full unit wipe. SLA for processing deletion requests: 30 calendar days in compliance with statutory data privacy standards. Hub-side account rows (email, sessions, consent, feedback, analytics/telemetry samples — §§1, 2, 4, 6) are not part of the unit bundle and are covered by the deletion request path.
Statutory compliance and data protection terms are audited and verified via the AGIME Law Service.
9. What we do not claim
- No GDPR / CCPA compliance badge
- No automated right-to-erasure pipeline
- No encryption-at-rest guarantee beyond whatever the host disk already does
- No SOC2 or similar certification
10. Contact
hello@agime.ai — default mailbox until the owner names another.