Legal

Partner Privacy Policy

How AgentOnboard handles your data as an API provider — and how we keep your users' data out of our path. Last updated August 2026.

1. What we collect from providers

When you create a partner account, we collect your name, email address, and password (stored securely). We also issue a partner key that your API uses to make verification calls — the key itself is never stored in plain text, and you can rotate it anytime from your dashboard.

2. What we see in the verify flow

When your API verifies a session token, we process the token and return the identity of the user the agent represents — their AgentOnboard email. We log verification attempts for security and abuse prevention. We do not see, log, or store the contents of your API requests or responses.

3. What we never collect

We never see your users' data, your API payloads, or any credentials your users hold for your service. AgentOnboard verifies identity; it does not proxy traffic, so your users' data never passes through us.

4. Session tokens

Session tokens are short-lived by design and expire in minutes. We store only what is needed to verify a token's validity, and tokens are not readable after expiry. Your integration should not store session tokens beyond what is needed to complete a verification.

5. Data sharing

We do not sell your data. We share data only with service providers who help us operate the Service (such as hosting and email delivery), and only to the extent needed to provide it. We may disclose data where required by law.

6. Retention and deletion

We keep account data for as long as your account is active, and verification logs for a limited period to support security and your analytics. If you close your account, we delete your account data and revoke your partner key. You can request deletion of your data at any time.

7. Contact

For privacy questions or data requests, contact us through our GitHub repository or at the support email listed on the partners dashboard.