Legal
Privacy Policy
Last updated: 10 October 2026 · Version: draft
1. Who we are
This policy describes how agentstools (“we”) processes personal data when you use agentstools.com, app.agentstools.com, the proxy, or the ingest API.
Controller (draft): the operator of agentstools, a natural person / business based in Türkiye. [Legal name, address, and if appointed, KVKK VERBIS number — draft]. Contact: support@agentstools.com.
We intend this policy to meet the EU/UK General Data Protection Regulation (GDPR) and Türkiye’s Kişisel Verilerin Korunması Kanunu (KVKK, Law No. 6698). If those texts conflict for a specific person, we will apply the rule that gives that person more protection, unless a mandatory law says otherwise.
2. Data we collect
- Account data: email address, name if you give one, hashed authentication secrets, session identifiers.
- Project configuration: project name, upstream MCP URL, proxy token identifiers, plan, alert destinations (for example a Slack webhook URL you paste).
- Tool-call metadata: tool name, latency, status, truncated error, optional token cost, timestamps, project id. This is the default.
- Optional payloads: only if you enable payload storage on a project. Treat that as potentially sensitive.
- Billing identifiers: Paddle customer and subscription ids, plan, and payment status. We do not receive or store full card numbers. Paddle is the merchant of record.
- Support mail: whatever you send to support@agentstools.com.
- Security signals: Cloudflare Turnstile tokens (verified server-side), IP address and user agent as seen by Cloudflare for abuse prevention.
We do not intend to collect special-category data. Please do not send it through the proxy or in support mail.
3. Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c): create the account, run the proxy, show the dashboard, apply plan limits.
- Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5/2-f): secure the Service, debug outages, prevent abuse, understand aggregate product usage. You may object.
- Legal obligation: tax and accounting records related to Paddle transactions, and responses to lawful requests.
- Consent: optional payload storage; non-essential cookies if we ever add them (we do not use marketing cookies today).
4. Processors and transfers
We use:
- Cloudflare, Inc. — hosting (Workers, Pages, D1, Queues), CDN, Turnstile. Data may be processed on Cloudflare’s global network.
- Paddle.com Market Ltd and affiliates — payments, invoices, tax. Paddle is an independent controller for the checkout transaction. See Paddle’s privacy policy.
- Resend — transactional email (magic links, alerts). Sent from a sending subdomain such as send.agentstools.com.
These providers may process data outside Türkiye and the EEA. Where required we rely on adequacy decisions and/or standard contractual clauses (and KVKK-permitted transfer mechanisms). D1 jurisdiction (for example EU) is an open product decision; see PLAN.md.
5. Retention
Tool-call metadata is kept for the retention window of your plan (7 / 30 / 90 days on the current draft plans) and then deleted. Account and billing identifiers are kept for the life of the account and for the minimum period required for tax. Support mail is kept as long as needed to resolve the request. You can ask us to delete an account.
6. Your rights
Subject to the law that applies to you, you may request access, correction, deletion, restriction, portability, and to object to processing based on legitimate interests. You may withdraw consent where consent is the basis (for example payload storage).
GDPR: you may complain to your EU/EEA/UK supervisory authority. KVKK: you may apply to us first and then to the Kişisel Verileri Koruma Kurulu (KVKK Board) in Türkiye.
Requests: support@agentstools.com. We may need to verify the account email.
7. Cookies and similar tech
The marketing site is static and does not set advertising cookies. The dashboard will use a session cookie for sign-in and Cloudflare Turnstile on auth forms. Turnstile may set cookies as described in Cloudflare’s documentation. We do not sell personal data.
8. Children
The Service is not directed at children under 16 (or a higher age required where you live). We do not knowingly create accounts for them.
9. Changes
We will post updates on this page and change the date above. Material changes will also go to the account email when practical.