Privacy policy

Version / effective date: 2026-09-04

AgentBell

Product support and privacy contact: support@agentbell.top

1. Who processes your information

AgentBell is responsible for AgentBell account and product data. Send privacy requests to support@agentbell.top. Creem describes its processing of payment and billing data in its Privacy Policy.

2. Information collected and purposes

We process your sign-in email, irreversible verification-code hashes, account ID, desktop installation identifier, device name, and operating-system version for authentication, device management, and account security. Browser sessions use a random sign-in cookie whose raw value is not stored in the server database.

Event data includes agent type, event type, project name without its full path, session and task identifiers, and required timing data for notification, deduplication, and history. Completion and failure events also include the current user input and final agent response to produce a complete email; that email is not sent when either value is missing. Confirmed permission or input waits may include the current user input and visible agent progress when available; requests in one turn are grouped and are not delivered after fifteen minutes. Notification state, provider message ID, subscription state, order association, and purchase-consent records support delivery, billing, and dispute handling.

The service receives request IP addresses; rate-limit keys use a server-keyed digest. Hosting and security services may retain necessary access logs.

3. Input, output, and code content

The desktop extracts up to 1,500 characters each from the current user input, visible agent progress, or final agent response through official hooks, plugin events, or a local agent API and sends them to the cloud and email provider. The OpenCode adapter uses recent local API messages to isolate the current turn and forwards only the matching input and visible Assistant text; DeepSeek Harness uses structured user/message and assistant/message events from the current turn. These texts may contain code, secrets, or other sensitive information from the prompt or response.

Enabling “Hide input and output” prevents those texts from being uploaded. Completion and failure emails are still sent and contain task metadata only — never the input or output text — after AgentBell confirms the turn had a real input and reply; that check may read whether visible input and a final reply exist in the session transcript on this device, without uploading their text. Permission and input-wait alerts may also be sent without that work content. Matching text is removed from the local outgoing queue and from stored event records. Adapters do not read tool arguments, tool results, terminal output, source files, Git diffs, or reasoning. Delivered email cannot be recalled. Sensitive project names or session identifiers may still be processed as metadata. We do not sell personal information or use event data to train models.

4. Cookies and local storage

The website uses a necessary HttpOnly, SameSite sign-in cookie, with Secure enabled over HTTPS, for up to seven days. Signing out revokes it. A SameSite preference cookie containing no account information remembers the selected language for up to one year. The CSRF token remains only in page memory. Access and refresh tokens are not stored in browser localStorage, and the site uses no advertising cookies or third-party analytics scripts.

Desktop credentials are stored in the operating-system credential manager. Settings and queued events are stored locally. When input and output privacy is disabled, queued events temporarily contain those texts until delivery or queue expiry. Necessary cookies support the sign-in and language-selection features you request; the current site loads no advertising tracker requiring consent.

5. Providers and international processing

Account and entitlement services process paid status and email configuration. The email provider processes recipient addresses and verification or notification email. Creem and its payment partners process card subscriptions, taxes, orders, and billing information. JianPay and its payment channels process WeChat Pay and Alipay orders. Infrastructure providers may process hosting and security logs.

These providers may process data outside your location. We share only what is necessary to deliver and secure the service, meet obligations, or respond lawfully, and apply protections required by applicable law.

6. Retention and security

Completed notifications and event records older than 35 days are removed by default. Completion and failure items in the local outgoing queue remain valid for up to 23 hours; permission and input-wait items expire after fifteen minutes. Verification codes expire after ten minutes and expired records are normally removed during scheduled cleanup after another 24 hours; expired web sessions are removed during cleanup. Account and device information is retained while the service is provided. Purchase consent and required billing records remain for applicable tax, dispute, and security obligations.

We use HTTPS, operating-system secure storage, access controls, verification-code rate limits, and data minimization, but no system can promise absolute security.

7. Your choices and rights

You can disable agents, pause email, remove devices on the account page, or sign out of the website. Subject to applicable law, contact support@agentbell.top to request access, correction, export, or deletion of account data, or to object to or restrict processing. We verify control of the email and explain records we must retain. You may also complain to your local data-protection authority where applicable.

Deletion requests and subscription cancellation are handled separately. To prevent future charges, confirm cancellation on the AgentBell account page. The service is not directed to minors below the age at which they can validly enter a service contract in their location.