Skip to content

Privacy Policy

Last updated August 25, 2026

AgentMail, Inc. (“AgentMail,” “we,” “us,” or “our”) operates AgentID. This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you when you use AgentID.

By using AgentID, you acknowledge the practices described in this policy. If you do not agree, do not use AgentID.

01Scope

This policy applies to AgentID’s public website, authorization service, developer console, APIs, and related domains (collectively, “AgentID”). AgentID is an AgentMail product. Your use of an AgentMail account, inbox, API, or other AgentMail service is also covered by the AgentMail Privacy Policy.

This policy does not govern an application you sign in to with AgentID. That application controls how it uses information it receives and should provide its own privacy policy.

02Information we collect

Depending on how you use AgentID, we collect:

  • Account and organization information: your name, email address, account and organization identifiers, session information, and the AgentMail organization and inboxes connected to your use of AgentID.
  • Agent identity information: an agent’s stable subject identifier, inbox address, display name, organization information, and, when authorized, the owner’s name or email address.
  • Sign-in information: the application requesting a sign-in, redirect URI, requested and granted scopes, authorization decisions, transaction and token identifiers, timestamps, and sign-in activity.
  • Developer information: application names, redirect URIs, authentication settings, contact information, policy and terms URLs, logos, descriptions, and credentials associated with registered applications.
  • Usage and device information: IP address, browser and device type, pages and features used, referring pages, approximate location derived from IP address, diagnostics, and security logs.
  • Communications: information you include when you contact us for support or otherwise communicate with us.

03Where information comes from

We receive information directly from you and developers, automatically from browsers and devices, from AgentMail when an inbox or organization is used with AgentID, from our authentication provider, and from applications that initiate AgentID sign-ins.

04How we use information

We use information to:

  • provide, authenticate, and complete AgentID sign-ins;
  • create and manage developer accounts and registered applications;
  • issue, verify, scope, revoke, and audit credentials, authorization codes, and tokens;
  • operate, secure, troubleshoot, analyze, and improve AgentID;
  • prevent fraud, abuse, impersonation, and unauthorized access;
  • communicate about the service and respond to support requests; and
  • comply with law and enforce our agreements.

05Information shared with applications

AgentID always provides an application with a stable identifier for the signing-in agent. Other information is shared only when the corresponding scope is granted. Depending on the scopes, this may include the agent’s inbox address and display name or the owner’s name and email address.

The authorization screen identifies the application and the categories of information it will receive. After information is provided to an application, that application’s terms and privacy policy govern its use. You can revoke an agent’s credential or access, but revocation cannot make an application delete information it previously received.

06Cookies and browser storage

AgentID uses cookies and similar storage that are necessary for account sessions, security, and short-lived authorization transactions. These technologies bind a browser to the sign-in it started, remember limited preferences, and help prevent cross-site attacks.

If browser-based agent authentication is offered and you choose to enroll a browser, AgentID stores a non-exportable private signing key and related inbox metadata in that browser’s local database. The private key remains in the browser and is not sent to AgentID. Clearing site data removes this local credential from that browser.

07Analytics and advertising measurement

The public AgentID website uses Google Tag Manager, which may load analytics or advertising measurement technologies configured by us. Those technologies may collect page views, referral information, device information, and interactions with the site. You can use browser settings and provider controls to limit non-essential cookies and similar technologies.

The credential-bearing authorization pages at auth.agentid.com do not include marketing analytics or third-party advertising scripts.

08How we share information

We may share information:

  • with an application when an AgentID sign-in authorizes the relevant scopes;
  • with vendors that provide hosting, authentication, analytics, communications, security, and other services on our behalf;
  • with AgentMail affiliates and service teams that operate AgentID;
  • when required by law or reasonably necessary to protect rights, safety, and security;
  • as part of a merger, financing, acquisition, reorganization, or sale of assets; or
  • with your direction or consent.

We do not sell your personal information for money. A current list of infrastructure providers is available on AgentMail’s Subprocessors page.

Where applicable law requires a legal basis, we process information as needed to perform our contract with you, for our legitimate interests in providing and securing AgentID, with your consent, and to comply with legal obligations. You may withdraw consent where we rely on it, without affecting earlier processing.

10Retention

We keep personal information only as long as reasonably necessary for the purposes described here, including to provide the service, maintain security and audit records, comply with law, resolve disputes, and enforce agreements. Authorization transactions and their cookies are short lived. Account, application, grant, and sign-in records may remain while the relevant account or integration is active and for an appropriate period afterward. Backup copies and security logs may remain for a limited additional period under our retention schedules.

11Security

We use administrative, technical, and organizational safeguards designed to protect information. AgentID scopes tokens to the requesting application, uses short-lived and single-use authorization artifacts, and checks credential status before issuing tokens. No method of transmission or storage is completely secure. See our Security page for technical details.

12International transfers

AgentMail is based in the United States. We and our service providers may process information in the United States and other countries whose data protection laws differ from those where you live. Where required, we use appropriate safeguards for international transfers.

13Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; or appeal a decision about a request. You may also have the right to complain to a data protection authority.

To make a request, email support@agentmail.cc. We may need to verify your identity and may retain information where permitted or required by law. We will not discriminate against you for exercising a privacy right.

14Children

AgentID is not directed to children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can take appropriate action.

15Changes and contact

We may update this policy from time to time. We will post the updated version here and change the date above. If a change is material, we may also provide notice through the service or by email.

Questions and privacy requests may be sent to support@agentmail.cc. AgentMail, Inc., San Francisco, California, USA.