Reactorby Agencer
Reactor Privacy Policy
Draft for legal review by Agencer Inc. Effective on the date it is published at reactor.agencer.ai/privacy.
1. Scope
This policy explains what Agencer Inc. ("Agencer", "we") collects when you use the Reactor API, its dashboard and its website (the "Service"), what we do with it, how long we keep it, and the choices you have. It is part of the Terms of Use.
Two kinds of data pass through the Service, and the rules differ. Account data is about you and your organization: we decide how it is handled and are its controller. Content is what your software sends through the API and what comes back: you decide what it contains, you are its controller, and we handle it on your instructions as your processor. Where the Content includes other people's personal data, you are responsible for having the right to send it.
2. What we collect
| Kind | What it is | Where it comes from |
|---|---|---|
| Account data | Name, email, organization name, billing email, password hash, sign-in times, IP addresses used to sign in | You, when you sign up and sign in |
| Payment data | Card brand, last four digits, expiry, billing address, purchase and charge history | Our payment processor; we never see or store the full card number |
| Provider credentials | The API keys for the model providers you configure | You, when you add a gear; stored encrypted |
| Content | The requests your software sends through the API and the responses returned, including any text, tool calls and files they contain | Your software, through your Reactor keys |
| Service records | For each request: time, key, label, run, step number, which gear answered, token counts, latency, status, and the prices used to compute your Savings | Produced by the Service as it runs |
| Dashboard use | Pages viewed, actions taken, browser type, approximate location from IP | Your browser, when you use the dashboard |
| Support | What you tell us when you write to us | You |
We do not collect data from third-party trackers or advertising networks, and we do not use cookies on the dashboard beyond the one that keeps you signed in and one that keeps your preferences.
3. How we use it
We use data for these purposes and no others:
To provide the Service. To receive your requests, decide which of your two gears answers each one, forward the request to that provider with your credentials, and return the response. Content is used only for this and for the purposes below.
To meter and bill. To count tokens, compute Savings, apply your plan, and produce your charges and invoices.
To keep the Service secure. To detect abuse, misuse of keys, and attacks on the Service, and to enforce rate limits and spend caps.
To support you. To answer your questions and investigate problems you report, including by looking at the specific requests you point us to.
To operate and improve reliability. To monitor latency, errors and capacity, using Service records rather than Content wherever that is enough.
To comply with the law and to establish or defend legal claims.
What we never do. We do not sell your data. We do not use your Content to train or improve any model, ours or anyone else's. We do not use your Content for advertising or profiling. We do not read your Content except as needed for the purposes above, and then only by staff who need to.
Legal bases (where they apply). Performance of our contract with you; our legitimate interests in running a secure and reliable service; compliance with legal obligations; and, for anything else, your consent, which you can withdraw.
4. How long we keep it
| Kind | Kept for | Then |
|---|---|---|
| Content | 30 days from the request, or less if you delete it sooner from Settings | Deleted from live systems; gone from backups within a further 30 days |
| Service records | While your account exists, plus the period tax and accounting law requires for the records behind a charge (up to 7 years) | Deleted |
| Provider credentials | Until you replace or remove them, or close your account | Deleted at once |
| Account and payment data | While your account exists, plus up to 7 years for billing records | Deleted |
| Dashboard use and sign-in logs | 12 months | Deleted |
| Support conversations | 3 years | Deleted |
Deleting Content yourself. Settings has a button that deletes all stored Content now. Runs remain as numbers; the words go.
Closing your account. When you close your account, Content is deleted within 30 days and credentials at once. Service records and billing data are kept only as long as the law requires, then deleted.
5. Who receives data
The model providers you configure. Every request the Service forwards goes to the provider you chose, with your credentials, under your agreement with that provider. Their handling of it is governed by their privacy terms, not ours. Which provider received which request is shown on your dashboard.
Our processors. Companies that host or run parts of the Service for us, under contracts that limit them to our instructions: cloud hosting (Amazon Web Services, United States), payment processing (Stripe), email delivery, and error and uptime monitoring. We keep the current list at agencer.ai/reactor/subprocessors and give notice before adding one.
Legal requests. We disclose data when the law requires it, to comply with a court order, subpoena or government request, or to protect the rights, safety or property of Agencer, our customers or the public. Where the law allows, we tell you first.
A change of ownership. If Agencer is acquired or merges, your data may transfer to the new owner under this policy; we tell you before it happens.
We do not share your data with anyone else, and we never sell it.
6. Security
All traffic to and from the Service is encrypted in transit. Provider credentials and stored Content are encrypted at rest, with keys held in a managed key service separate from the data. Reactor keys are stored as hashes; we cannot read a key back and show it to you only once, when it is minted. Access to production systems is limited to named staff, logged, and reviewed. We test the Service for security problems and fix what we find. No system is perfectly secure; if we learn of a breach affecting your data, we tell you without undue delay and in any case within the time the law requires, with what we know and what we are doing.
7. Your rights and choices
You can see and change your account data in Settings, export your Service records and charges, delete stored Content, replace or remove credentials, and close your account, all without asking us. For anything else, write to privacy@agencer.ai. Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive a copy in a portable form, and to complain to a supervisory authority. We answer within 30 days and never charge for a reasonable request. For personal data inside your Content, ask the organization that sent it; we will help them respond.
International transfers. The Service runs in the United States. If you use it from elsewhere, your data is transferred to and processed in the United States. Where the law requires safeguards for such transfers, we rely on standard contractual clauses or an equivalent mechanism, available on request.
Children. The Service is for businesses and developers and is not directed at children. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
Do Not Track and similar signals. The dashboard does not track you across other sites, so there is nothing for such a signal to change.
Changes to this policy. We may update this policy. For material changes we give at least 30 days' notice by email and on the dashboard, and we keep earlier versions available on request.
Contact. Agencer Inc. · privacy@agencer.ai · legal@agencer.ai. For security reports: security@agencer.ai.