Privacy Policy
Last updated July 24, 2026
This document is in force for our closed beta and is pending review by counsel. Questions? erikbigelow@gmail.com
How Agents & Operatives collects, uses, stores, and shares personal data — both yours as an account holder and your contacts' data held in your account.
Contents
Who we are
Agents & Operatives is a marketing platform. You use it to plan campaigns, write and send email and SMS, publish social posts, and keep what your business knows about its brand, products, and audience in one place. Much of that work is done by AI models run by third parties, which means your content is sent to those providers. They are all named below.
The service is in closed beta. It is not open to the public, and every new account is reviewed and approved by hand before it is activated.
This policy covers two different kinds of personal data: information about you, the account holder, and information about your contacts that you upload or collect through the product. They are stored and handled differently, so they get separate sections.
"We" means the people who operate Agents & Operatives. We have not yet published a registered legal entity for the service; this document will name it before public launch. For anything in this policy, write to erikbigelow@gmail.com.
Data we collect
When you create an account we store your email address, your name, and your codename (the display name shown inside the product). All three are stored in plain text. See "How we protect it" for what that means.
Your password is hashed by our authentication library before it is stored. This application never receives, sees, or keeps your password in plain text.
Each time you sign in we create a session record holding a session token, the IP address the request came from, and your browser’s user-agent string.
If you set up billing we store the Stripe customer ID that links your account to its record at Stripe. Card numbers are handled by Stripe in your browser and never reach our servers.
Everything you build in the product — campaigns, briefs, brand knowledge, products, contacts, uploaded files — is stored in our database and, for files, in our object storage. Both are run by providers named under "Service providers".
Data you upload about your contacts
The product is built to hold data about other people: your customers, subscribers, donors, and leads. That data is yours. We hold it on your behalf and process it to do what you ask the product to do.
Contact email addresses and phone numbers are stored two ways at once. The value itself is encrypted at rest, and a one-way hash of it is stored alongside so the product can find a contact without decrypting anything.
One path does not follow that rule, and we would rather tell you than make a blanket claim. When you import contacts from a CSV file, the columns you map — including the email column, which the importer requires — are also written into that contact’s profile traits in plain text. First and last names and consent metadata are stored in profile traits in plain text as well. So a contact’s email address can exist in both an encrypted and an unencrypted form, depending on how that contact entered the system. We are tracking this as a gap to close.
Consent records are deliberately not encrypted. When a contact opts in to email or SMS, we store the channel or phone number, the status, where the consent came from, and the exact wording they agreed to. That record is the evidence the consent happened, and it has to stay readable to serve that purpose.
How we use it
We use your account data to create and authenticate your account, review your closed-beta application, bill you through Stripe, answer your support requests, and apply the rate limits that keep the service available.
We use your contacts’ data to do the things you build in the product: send the email and SMS campaigns you create, assemble and count audiences and segments, and record consent and delivery outcomes.
Content you write or upload — briefs, brand knowledge, product descriptions, chat messages, and images — is sent to third-party AI providers so they can generate drafts, analyze images, and produce the vector embeddings that make search inside the product work. Those providers are named in the next section.
We do not sell personal data, and we do not use your data or your contacts’ data for advertising. No advertising network and no data broker appears in the list of service providers below.
Service providers
We run on third-party infrastructure and use third-party services for specific jobs. The list below was derived from this application’s source code rather than from memory: it is the set of services the product actually sends data to.
AI models. Anthropic (Claude) receives the prompts our agents assemble from your business and campaign data, including chat messages and brief text. Google (Gemini and Imagen) receives prompts and images for image generation, image editing, and vision analysis of images you upload. Voyage AI receives text and images to convert into the vector embeddings used for search.
Research and web content. Exa receives search queries when an agent runs competitive or trend research. Firecrawl receives the URLs we crawl — your site or a competitor’s — and returns the scraped page content. Google Places receives business name and address queries for location lookup. Unsplash receives stock-photo search queries and nothing else.
Email and SMS. Resend receives recipient email addresses and the subject and body of every message we send, through two isolated accounts: one for transactional mail such as password resets and invites, one for marketing campaigns. AWS Pinpoint SMS and Voice and AWS SNS receive recipient phone numbers and SMS message bodies. AWS SQS carries SMS delivery-status events back to us.
Infrastructure. Vercel hosts the application, so all traffic passes through it. Neon runs the PostgreSQL database holding application data. Amazon S3 stores uploaded files, media assets, and the export archives we generate for you. Upstash Redis holds rate-limit counters keyed to IP addresses and user identifiers, plus cached values. Upstash QStash carries job payloads for background work such as campaign generation. AWS EventBridge Scheduler holds schedule metadata — business and campaign identifiers and send times, not message content — for sends you schedule ahead.
Billing. Stripe receives your billing contact information and plan selection, and tokenizes payment methods in your browser.
Error monitoring. Sentry receives stack traces and request context when an unhandled error occurs. Data that happened to be in scope at the moment of the error can be included in that report.
Accounts you connect. If you sign in with Google, or connect Google Business Profile, Meta (Facebook and Instagram), LinkedIn, Pinterest, or X, we exchange an authorization code with that provider and store the resulting access tokens so the product can act on your behalf. Google sign-in also returns your profile email and name. If you connect Google Ads, we send account and campaign identifiers to pull your own advertising metrics into the product’s analytics.
Services you plug in yourself. The product can connect to your own Cloudinary or Adobe Experience Manager account for digital asset management. There is no platform-wide account for either: you supply your own credentials in Settings, we store them encrypted, and your assets then move to and from that provider under your agreement with them rather than ours.
Product analytics, currently off. The code contains an optional path that would send product-analytics events — a user identifier, a business identifier, an event name, and event properties — to PostHog, Segment, or a configurable webhook. The PostHog and Segment client libraries are not installed in this application, so those integrations do not run. If we switch on any product-analytics destination, we will name it here first.
How long we keep it
While your account is open we keep your account data and your contacts’ data for as long as you keep them. Nothing you create expires on its own.
Sign-in sessions expire 24 hours after they are created in production, and are extended after six hours of activity. Email verification codes and one-time codes expire after 10 minutes.
Download links for data exports expire seven days after the export is generated. After that, request a fresh export.
Account deletion is scheduled rather than immediate: it runs after a 30-day grace period and can be cancelled during that window. Data belonging to a deleted organization is retained for 30 days by default before it is purged.
That purge is thorough but not total, and you should know what it leaves behind. It removes the organization, its businesses, their campaigns, and their email templates. It does not remove the sign-in accounts themselves: your account email, name, and codename are detached from the deleted organization rather than deleted, and files you uploaded are not removed by this process. If you want those gone as well, email us and we will do it by hand.
Your rights
You can export your account data at any time from Settings, under Data & Privacy. The export includes your contacts, campaigns, and account records, and is delivered as a download link that expires after seven days.
You can request deletion of your account and its data from the same page. Deletion is scheduled with a 30-day grace period, during which you can cancel it. At the end of that window your organization is marked deleted and access to it ends — but the data is not gone yet. It is purged after a further retention period, 30 days by default, which puts permanent removal roughly 60 days after you ask for it. What that purge does and does not reach is set out under “How long we keep it” above.
If you are a contact of one of our customers rather than an account holder, the business that uploaded your data decides what happens to it. Ask that business first. You can also write to us and we will pass the request to them.
For any other request concerning your personal data, email erikbigelow@gmail.com.
How we protect it
Contact email addresses and phone numbers are encrypted at rest. The lookup hash stored beside them means the product can search for a contact without decrypting the stored value.
That protection does not cover everything, and this is the part most policies gloss over. Contact email addresses that arrive through CSV import, contact names, and consent records are stored in plain text. So are your own account email, name, and codename: our database has columns for encrypted versions of those fields, but no code writes to them, so account-holder data is not encrypted at rest today.
Passwords are hashed by our authentication library and never stored in plain text. Payment card numbers never reach our servers. Credentials for services you connect yourself, such as a Cloudinary or Adobe account, are stored encrypted.
The service applies rate limits to sign-in and other sensitive endpoints, and accounts are approved by hand during the closed beta, which limits who can reach the product at all.
If you think you have found a security problem, email erikbigelow@gmail.com. We would rather hear about it early.
Changes to this policy
The date at the top of this page is the last time this document changed.
This policy is in force for the closed beta and has not yet been reviewed by counsel. It will be reviewed, and rewritten where necessary, before public launch.
If we make a change that materially affects how we handle your data, we will email the address on your account before it takes effect and update the date above. Smaller corrections — a service provider renamed, a clarification — are made in place.
Questions about this document
Email erikbigelow@gmail.com.