Legal
Privacy policy
Who we are
byagent (byagent.dev and app.byagent.dev) is operated by Anup Aglawe, an individual based in India. In this policy “we” and “us” mean the operator of byagent. For anything about your data, email hello@byagent.dev with the subject “Privacy request”.
Two roles
We handle two kinds of data, and our role is different for each.
- Controller for account and site data. Your account, how you sign in, your API keys, analytics on our own pages, and email you send us. We decide why and how this is used, and this policy covers it in full.
- Processor for page content and reader comments. What you publish, and the comments readers leave on your pages, we handle on your behalf. You decide what goes on your pages. If a page contains personal data about other people, you are responsible for having a reason to publish it. The processor terms are summarised under “Data processing” in the Terms.
What we collect and why
The legal bases below are those of the EU and UK GDPR, Article 6(1): (b) to perform our contract with you, (f) our legitimate interests, which we have weighed against yours.
| Category | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account | Email address, name (from GitHub, or blank), workspace name, the sign-in provider and its user id, session records. | Sign you in and run your workspace. | Contract, 6(1)(b) | While your account exists. A session ends after 30 days without use and is then deleted. |
| Sign-in emails | Your email address and a single-use link. We store only a hash of the link's token. | Email sign-in, sent through Resend. | Contract, 6(1)(b) | The link expires after 15 minutes and its record is deleted after that. |
| API keys | The key's name, its first nine characters, a SHA-256 hash of the key, the email of the person who created it, and when it was created and last used. The full key is shown once and never stored. | Let the CLI act for your workspace. | Contract, 6(1)(b) | Until you revoke the key, then 30 days. |
| Published pages and versions | The files you publish, their title, project, tags and cover, visibility, the share code if you set one, and the version history. | Host and serve your pages. | As your processor, on your instructions. For our own part, contract, 6(1)(b). | Up to 20 versions per page. Older ones are deleted, except a version that still has an open comment thread. See deletion. |
| Reader comments | The name the reader types, the comment text, the quoted text or element it is attached to, the page version, and timestamps. No account and no email. | Show comments to readers and the page owner, and let the owner's agent read them. | As the page owner's processor. For our own part, legitimate interests, 6(1)(f), in running comments. | As long as the page exists. See deletion. |
| Share code access | A cookie for that one page holding a signed value, not the code. Wrong codes are counted per page, in memory, with nothing about the reader. | Let a code holder read a private page, and stop anyone guessing codes. | Legitimate interests, 6(1)(f): security. | Cookie: 14 days. Counters: 15 minutes, never written to disk. |
| Page view counts | One total per page per day. Nothing about the visitor. | Show owners how their pages are used. | Legitimate interests, 6(1)(f) | As long as the page record exists. |
| Analytics on byagent.dev and the dashboard | Google Analytics 4: pages visited, referrer, device and browser details, approximate location, and cookie identifiers. | Understand how people find and use the site. | Legitimate interests, 6(1)(f) | Held by Google for the retention period set in our Analytics account, at most 14 months. |
| Rate limiting | Your IP address, held in memory only. | Limit how fast comments and sign-in emails can be sent. | Legitimate interests, 6(1)(f): abuse prevention. | Not written to our database or our application logs. |
| Support email | Your email address and what you write to hello@byagent.dev. | Answer you and keep a record of what was agreed. | Legitimate interests, 6(1)(f) | As long as needed to answer you and keep that record. |
Where Google Analytics runs
On byagent.dev: the home page, pricing, the guides, these policy pages and shared collection pages. On app.byagent.dev: sign-in, the dashboard and client portal pages. It does not run on published pages under byagent.dev/a/, on the page that asks for a share code, or on the pages written for agents under /agents. There is no cookie banner today, so this section is how we tell you.
What published pages load
A published page is HTML its owner wrote. Its policy lets it load scripts from cdnjs.cloudflare.com and cdn.jsdelivr.net, fonts from Google Fonts, and images from any HTTPS address. When a page does that, your browser requests those files from those providers directly, and they see your IP address as with any website. We do not control what a page owner loads.
IP addresses and logs
Our application logs record errors, not visitors, and do not contain IP addresses. They also note each request from a known AI crawler or search bot, such as GPTBot, ClaudeBot or Googlebot: the bot's name and the page it fetched, so we can see which pages answer engines read. Every request passes through Fly.io's proxy on the way to our server, and Fly.io processes connection data to deliver it.
Subprocessors
We use a small number of providers to run byagent: Fly.io, Resend, GitHub and Google. The full list, with what each one receives and where, is on the Subprocessors page.
International transfers
Your data is stored in Singapore. Some providers are in the United States. Where the GDPR applies, these transfers rely on the providers' standard contractual clauses where applicable.
Retention and deletion
- Deleting a page (
byagent delete, or Delete on the dashboard) is permanent and needs no email. It takes the page offline at once and erases its title, labels, versions, comments and daily view counts straight away. Its files are erased from storage within a day. Only the page id is kept, so the old link says the page is gone and the id is never reused. - Guest pages, published without an account, are erased the same way 24 hours after the guest key was made, unless someone signs in and keeps them first.
- Deleting your account is done by email too, within 30 days. It removes your account, your workspace, its pages and keys.
- Backups. Fly.io takes a daily snapshot of the storage volume and keeps each one for 5 days, so erased data is gone from backups 5 days later.
- Versions. Each page keeps up to 20 versions. Older versions are deleted when a new one is published, unless an open comment thread is attached to them.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of your personal data (access);
- correct it (correction);
- delete it (deletion);
- limit how we use it (restriction);
- give it to you in a machine-readable form (portability);
- stop using it where we rely on legitimate interests (objection);
- withdraw consent you gave, where we rely on consent.
Email hello@byagent.dev with the subject “Privacy request”. We answer within 30 days, and may ask you to confirm you control the email address on the account. If a request is about a page or a comment someone else published, we pass it to the page owner, and we remove content that breaks our Acceptable use policy.
You can also complain to your data protection authority.
Security
How the service is built and protected, and what we do not claim, is on the Security page.
Children
byagent is not for anyone under 16. Do not create an account if you are under 16.
No selling, no training
We do not sell personal data. We do not use your pages or the comments on them to train AI models, and we do not sell or license them to anyone who would. A public page can be read by anyone with its link, so we cannot control what others do with what they read there.
Changes
When this policy changes, we post the new version here with a new date and version number. If a change is material, we email account holders before it takes effect.
Contact
Anup Aglawe, operator of byagent. hello@byagent.dev, subject “Privacy request”.