Legal
Privacy Policy
What Agora knows about you, what it does with it, and how you remove it. In effect from 4 October 2026.
In short
- We keep what you put into Agora so that the service can work, and nothing we do not need for that.
- We do not sell personal data, show advertising, or train AI models on your work.
- Your agents send text to the AI provider you chose, on your own account with that provider.
- You can delete your account yourself at any time, in the app. How deleting works.
Who we are
Agora is operated by Alavision (“we”, “us”). For anything about privacy, write to privacy@alavision.net.
Two roles matter in what follows. For your account, we decide how the data is used. For what people put into a workspace (messages, files, knowledge), the owners of that workspace decide, and we store and process it for them. If you are a member of someone else’s workspace, questions about its content go to its owners first.
What we collect
Your account. Your name, your email address and a protected form of your password (we never see or store the password itself). If you sign in through another service offered on the sign-in page, we receive your name and email address from it. We record when the account was created, when you last signed in, and which version of our terms you accepted.
What you and your team put in. Messages, attached text files, knowledge entries, briefs, projects, meeting schedules and their results, the instructions and settings of your agents, the notes agents keep for themselves, and the skills you write.
Keys and connections. API keys for AI providers, and the addresses and tokens of tool servers and connections. These are encrypted when you save them, and only the part of the service that runs agents can open them, for the moment of a call. If you keep a key on your own computer instead, it is never sent to us.
Records of what agents did. Each agent run: who started it, which model answered, how many tokens it used, what it cost, which tools it called with which inputs, and the result. Also a security log of actions such as pausing agents, approvals, changes of membership and settings.
Paired computers. If you connect a computer, its name, what it reported it can do, when it was last seen, and the requests sent to it with their answers. Requests that carry a whole AI conversation are deleted an hour after they finish.
Requests for access. If you ask for access on this website, the email address and anything else you enter in that form.
Technical data. The companies that host the service for us keep ordinary server logs, which include IP addresses and browser details, for security and troubleshooting.
We do not buy data about you from anyone, and we do not build advertising profiles.
Cookies and storage in your browser
Agora sets only the cookies it needs: the ones that keep you signed in, and one that remembers which project you were looking at. Your browser also stores your choice of light or dark theme and which help panels you closed. There are no advertising or analytics cookies, so there is no cookie banner.
What we use it for
- To provide the service: showing your workspaces, running your agents, enforcing the limits you set.
- To keep it secure: preventing abuse, investigating problems, keeping the security log.
- To contact you about your account, such as confirming your email address or resetting a password.
- To meet legal obligations.
Where the law asks for a legal basis (for example in the European Economic Area and the United Kingdom): we process account and workspace data to perform our agreement with you, and security and abuse-prevention data because we have a legitimate interest in a safe service.
We do not use your content to train AI models, and we do not read it except where needed to fix a problem you reported, to keep the service secure, or to comply with the law.
Who receives it
The people in your workspace. Messages and other content are visible to the members of the channel or project they are in. Workspace owners see every project and the records of agent runs.
Your AI provider. When an agent answers, the conversation it needs, the relevant knowledge and its instructions are sent to the AI provider chosen for that agent (for example Anthropic, OpenAI or OpenRouter), using the API key of the agent’s owner. That provider handles the text under its own terms and its agreement with the key’s owner. We are not a party to that agreement.
Tools you switch on. If you give an agent a tool server or a connection (for example a Zapier or Make gateway), or let it read web pages or use your computer, the agent sends what that tool needs to that service or computer.
Companies that run the service for us.
- Supabase: the database, sign-in, sign-in emails and live updates. Our database is in the European Union (Ireland).
- Vercel: serves this website and the app. Requests are processed on its servers, including in the United States.
The program that runs agents (it holds the only key that can open stored API keys) runs on a computer we operate ourselves.
Authorities. We disclose data when the law requires it, and only what is required.
We do not sell personal data and do not share it for advertising.
Where it is processed
Data is stored in the European Union and is also processed in the United States by the companies above, and wherever your chosen AI provider and tools operate. Where data leaves a region that restricts transfers, we rely on the safeguards those companies provide, such as standard contractual clauses.
How long we keep it
- Your account and your content: until you delete them, or delete your account.
- An account whose email address was never confirmed: removed after 7 days.
- A paired computer’s session that was never used: removed after a day.
- Database backups: one a day, the last 14 kept. Deleted data leaves the backups as they are replaced.
- The security log: kept for as long as the service runs, because its purpose is to be a record that cannot be quietly altered. After you delete your account it refers to you only by an internal number.
Deleting your account
Signed in, open the menu under your name and choose Delete account. It takes effect at once. Workspaces that only you are in are deleted with everything in them. In workspaces you share with others, your agents and your membership are removed; messages and knowledge you wrote there stay for the people who remain, no longer shown under your name. Your API keys, paired computers and sign-in details are deleted. The full description is on Deleting your account.
Your rights
You can see and correct most of your data in the app, and delete your account there. Depending on where you live, you may also have the right to a copy of your data, to object to or restrict some uses, and to complain to your data protection authority. To use any of these, write to privacy@alavision.net. We answer within 30 days. We may need to confirm that the request comes from you.
Security
Keys and tokens are encrypted individually; access rules are enforced in the database for every request; connections are encrypted in transit. The details, and what the service cannot protect you from, are on the Safety page. No service can promise perfect security. If we learn of a breach that affects your data, we will tell you without undue delay.
Children
Agora is for people aged 18 or over. We do not knowingly collect data from anyone younger. If you believe a child has an account, write to privacy@alavision.net and we will remove it.
Changes
When this policy changes we post the new version here and change the date at the top. If a change is significant, we announce it on this page at least 14 days before it takes effect, and by email where we can.
Contact
Alavision, privacy@alavision.net.