Privacy Policy
How Agent WAN handles account, device, operation, and billing data.
Last updated: 2026-08-11
Scope
This policy describes data handled by Agent WAN when you create a workspace, register Agents, invite members, exchange an API key for an operation ticket, or purchase a plan.
Data We Store
- Account and workspace data: name, email address, workspace name, membership, and role.
- Device directory data: an internal device identifier, display name, platform, Agent version, online state, last-seen time, and the Agent WAN nodes currently carrying that Agent connection.
- Authorization records: API-key prefix, permitted scopes, status, expiry, and last-used time. Permanent API keys, node keys, invitation tokens, and operation tickets are stored only as cryptographic hashes after their one-time display.
- Security audit data: credential issuance and consumption, operation result, actor, target device record, scope, node region, and time. We do not intentionally place command contents, screen contents, file contents, typed text, raw credentials, or session cookies in these audit records.
- Chat permissions and audit: Workspace owners and admins configure one device-group and operation-scope policy. Chat uses the signed-in member identity and does not create an Agent credential. Audit records retain redacted metadata such as action type, scope, target, and outcome—not command, clipboard, or notification contents.
- Chat conversation data: The control plane stores the workspace Chat policy, conversation titles, message contents, the model actually used for each assistant response, and device-operation traces. A conversation does not store a fixed model, and model billing records do not contain message contents.
- Billing and support data: plan, quota, subscription, order, payment-provider references, and support messages. Payment providers process card or wallet credentials; we do not store full card numbers.
Remote Sessions
The selected Agent WAN node necessarily transports the encrypted remote-session traffic and can observe connection metadata needed to deliver the session. The SaaS application issues a short-lived, single-use ticket for one device and one scope. A ticket is valid only on its selected node and cannot be replayed after consumption.
The platform administration interface exposes tenant-level counts and node health, not a global device-control console. Workspace device names and operations are available only to active workspace members with the required role. This application-level boundary does not eliminate the underlying infrastructure trust boundary: personnel who control production code, database credentials, TLS termination, backups, or host systems could technically alter or access those systems. Such access must be restricted, audited, and used only for security, reliability, legal compliance, or support explicitly authorized by you.
How We Use Data
We use the data above to authenticate users and nodes, enforce workspace roles and plan limits, register Agents, select a healthy low-latency node, issue and consume operation tickets, investigate abuse, process billing, and respond to support requests. We do not sell personal data or device directories.
Service Providers and Disclosure
We may disclose the minimum necessary information to infrastructure, email, payment, monitoring, or support providers acting on our behalf; to comply with a valid legal obligation; or to protect users and the service from fraud or attacks. Their handling is governed by their contracts and policies.
Retention and Deletion
Retention depends on the active plan, security needs, payment law, and backup schedules. Revoked credentials remain non-recoverable hashes. You may request access, correction, export, or deletion of account and workspace data, subject to legal, fraud-prevention, and billing-record obligations.
Security
Controls include TLS, optional mandatory mutual TLS for node APIs, scoped roles, server-authoritative quotas, one-time credentials, transactional replay prevention, and audit events. No Internet service can guarantee absolute security. Protect exported keys and report suspected compromise immediately.
Changes and Contact
We may update this policy and will change the date above for material revisions. Contact us using the support channel shown in the service for privacy questions or data requests.