Skip to content
Draft for review — not effective. Contact-channel verification, retention schedules and legal approval are outstanding. This page does not activate payments or establish user acceptance.

Prepared October 8, 2026 · 2026-10-08-draft

Privacy Policy

What the hosted service handles, why it needs it and what happens when you connect an agent.

1. Scope and responsible operator

For privacy questions and requests concerning your personal information, contact Rishabh Mehan at support@simpleagentstore.com. Business mailing address: 32709 Amethyst Way, Union City, CA 94587, United States.

DRAFT — NOT EFFECTIVE. Simple Agent Store is operated by Rishabh Mehan, an individual based in California, United States. The effective date is awaiting confirmation. This draft describes the current application design and proposed privacy commitments. It needs owner and legal review before public use.

This notice covers the hosted Simple Agent Store service, not independent AI agents or self-hosted installations run by other people. The operator determines the purposes of account, security and service-administration processing. For stored personal data processed on a business customer's instructions, roles and obligations must be set out in an appropriate data processing agreement before that use is supported.

2. Information we handle

Account information: email address, display name, user ID, authentication/session information and profile information returned by a sign-in provider you choose. Google and GitHub are supported by the application wiring but require provider configuration before use. The app does not ask for access to your repositories, drive files or email inbox.

Stored content: object keys, kinds, labels/tags, JSON values, descriptions, searchable text, source-client identifiers, versions, timestamps and optional completion, due-date and expiry fields. Content can include personal information if you or an authorized agent put it there. We do not automatically collect whole conversations; the connected agent determines what it sends in a storage request.

Access and usage information: key names, key prefixes/last four characters, key digests, creation/revocation/last-use times, object counts and rate-limit counters. Raw API keys are shown on creation; the store keeps a digest and identifying metadata rather than the raw key. Your agent or device may separately retain the key.

Billing information: Paddle customer/subscription identifiers, plan/price identifiers, subscription status, billing-period and cancellation information, and event identifiers used to reconcile subscriptions. We send Paddle the account email and an internal account identifier to create and bind billing records. Payment details are entered into Paddle's checkout, not stored as full card numbers or security codes in our application database.

Technical and support information: requests and infrastructure providers can involve IP addresses, browser/device information, request timing, errors and security logs. We also receive information you choose to provide in a support request. Production logging scope, retention and support tooling need to be verified before launch; do not send secrets or unnecessary stored content in support requests.

3. How data is used

To sign you in, maintain sessions, store and retrieve your objects, enforce ownership and plan limits, connect agents you authorize, administer subscriptions, handle support, investigate errors and abuse, and comply with legal obligations. Search indexes and searchable text support deterministic retrieval, not a separate hidden memory or model-training system.

Proposed commitments for owner approval: we do not sell personal information, share it for cross-context behavioral advertising, or use your stored objects to train AI models. The current app has no model-training pipeline or advertising analytics integration. These commitments must also be verified against production providers and contracts before publication. They do not control how a third-party agent handles data you allow it to retrieve.

Where privacy law requires a legal basis, account/storage/subscription processing generally supports providing the requested service, security and operational processing may rely on legitimate interests subject to applicable balancing, legal retention may be required by law, and optional processing requiring consent must use a separate, withdrawable consent. Applicable bases and jurisdiction-specific disclosures need legal review; accepting service terms is not blanket privacy consent.

4. Connected agents and sharing you control

When you connect an agent using an API key, it can send, retrieve, change and delete stored objects within its permissions. Our current key grants read/write access across your account; it is not a per-object or read-only permission. Returned data leaves this service and may become part of the agent provider's conversation, logs or other systems under that provider's policies.

Only connect trusted clients and review their privacy and training settings. Revocation blocks future use of that key, but cannot remove previously retrieved content from another provider. Ask that provider separately to delete its copies. You control which agents receive your keys; we do not promise that only you can technically access hosted data.

5. Service providers and other disclosures

The selected hosted stack uses Vercel for application hosting/delivery and Supabase for authentication and PostgreSQL storage. Paddle handles checkout and billing as merchant of record under its own buyer terms and privacy notice. Google or GitHub receives sign-in requests when you choose that provider. These services process the information necessary for their functions under applicable contracts and their own notices where they act independently.

A production email delivery provider, support tooling and any monitoring providers have not yet been finalized. Their identities, purposes, regions and retention need to be added before launch. Stored object contents are not needed for Paddle billing and are not intentionally sent to Paddle by the app's billing integration.

We may disclose information where legally required, to protect rights and address fraud or security incidents, or in a business transfer subject to appropriate protections and required notice. Authorized personnel or providers may access hosted data when necessary for support, security, operations or legal obligations; access must be limited and governed by appropriate safeguards. We do not claim zero-knowledge or end-to-end encrypted storage.

6. Cookies and browser storage

Supabase uses cookies/session information to maintain sign-in and refresh authentication. The theme component uses browser storage for your appearance preference. Checkout and sign-in providers may use their own cookies or similar technologies when their services load.

The current application has no advertising or optional product-analytics integration. Verify hosting/provider cookie behavior before launch; add disclosures and consent controls before introducing non-essential tracking where legally required. Blocking essential session storage can prevent sign-in from working.

7. Retention and deletion

Active stored objects persist until deleted, subject to the service's account lifecycle. TTL/expiry can exclude an object from normal retrieval but is not currently a guaranteed physical-deletion job; expired rows still count toward storage until deleted. Object deletion through the app/API is separate from account closure and subscription cancellation.

Account-wide self-service deletion and export are not implemented yet. Before launch, the operator must establish a monitored identity-verified request process, cancellation-safe account removal, backup/log retention schedules and deletion verification. No fixed deletion deadline or backup-erasure promise is made by this draft. Legal response deadlines still apply where required.

Some billing, fraud-prevention, security or legal records may need to be retained after account closure. Deleted content can remain in provider backups until their documented retention expires; it must not be restored to normal use except for legitimate recovery or legal requirements, with deletion reapplied as appropriate. Connected agents and Paddle manage their own retained records.

8. Data location and security

US hosting is the intended primary configuration, but this is not a promise that every log, email, authentication, support or billing operation stays exclusively in the US. Production regions, subprocessors, international transfer mechanisms and any required data processing agreements must be confirmed before launch. Your connected agent may process retrieved data elsewhere.

The app uses authenticated sessions, owner-scoped database policies, API-key digests, signature verification for billing events, request bounds and plan/rate controls. These measures reduce risk but cannot guarantee absolute security. Production configuration, staff access, backups and incident-response procedures still need verification. Do not store highly sensitive data requiring protections or compliance agreements that we have not expressly provided.

9. Your choices and privacy rights

You can review, retrieve, edit and delete stored objects and revoke API keys in the product. Cancel billing separately through Paddle. Where applicable law provides rights to access, correct, delete or port personal information, object to processing, restrict processing, withdraw consent or appeal a decision, the operator must provide a monitored contact and identity-verification process before launch. Exceptions may apply for legal retention or other lawful reasons.

Depending on your location, you may complain to your competent privacy regulator. We must not discriminate against you for exercising applicable privacy rights. Any US state-specific disclosures, authorized-agent procedures, appeal rights, and EU/UK representative or transfer obligations must be assessed against actual launch markets and legal thresholds; this draft is not a blanket compliance certification.

10. Children, updates and contact

The service is intended for adults, not directed to children. If you believe a child provided personal information, contact the operator through the privacy channel that must be established before launch. The operator must finalize age eligibility and incident handling; this notice is not a claim that age verification is implemented.

Material privacy changes will require appropriate notice and any consent required by law before the changed use begins. The final notice will list its effective date and monitored privacy contact. Until contact-channel verification, operational commitments and legal review are complete, this page remains a draft.

Paddle payment documents