Partner Privacy Policy
How AgentOnboard handles your data as an API provider — and how we keep your users' data out of our path. Last updated August 2026.
When you create a partner account, we collect your name, email address, and password (stored securely). We also issue a partner key that your API uses to make verification calls — the key itself is never stored in plain text, and you can rotate it anytime from your dashboard.
When your API verifies a session token, we process the token and return the identity of the user the agent represents — their AgentOnboard email. We log verification attempts for security and abuse prevention. We do not see, log, or store the contents of your API requests or responses.
We never see your users' data, your API payloads, or any credentials your users hold for your service. AgentOnboard verifies identity; it does not proxy traffic, so your users' data never passes through us.
Session tokens are short-lived by design and expire in minutes. We store only what is needed to verify a token's validity, and tokens are not readable after expiry. Your integration should not store session tokens beyond what is needed to complete a verification.
We do not sell your data. We share data only with service providers who help us operate the Service (such as hosting and email delivery), and only to the extent needed to provide it. We may disclose data where required by law.
We keep account data for as long as your account is active, and verification logs for a limited period to support security and your analytics. If you close your account, we delete your account data and revoke your partner key. You can request deletion of your data at any time.
For privacy questions or data requests, contact us through our GitHub repository or at the support email listed on the partners dashboard.