Agincy builds AI assistants and automations that work with your business systems. With your authorization, they can answer questions, retrieve records, send approved messages, and manage documents or appointments.
Connected Google workflows can use Gmail, Drive, Sheets, Calendar or YouTube, depending on the access you approve. You authorize access through Google and can revoke it at any time. Our Privacy Policy explains how information is used across Agincy’s services.
Agincy / Legal
Updated September 22, 2026
This Privacy Policy explains how Agincy collects, uses, shares and retains personal information across our website, consulting and development services, AI assistants, voice and chat services, business automation and connected applications. It includes warden, Agincy’s business assistant application, and its Agincy Connections features. The information we process depends on the services you use and the permissions you or your business authorize.
This policy covers website visitors, people who contact Agincy, our customers and their authorized workspace users, and people whose information is processed through an Agincy-powered service. References to Agincy, we, us and our refer to the provider of these services. You can contact us about privacy at agint@agincy.com.
When we manage our website, inquiries and customer relationships, Agincy determines how that information is used. When we operate an assistant or automation for a client, we process the client’s business and customer information under that client’s instructions and the applicable service agreement. The client’s own privacy notice also applies to its relationship with you.
Contact and business information: Information you provide through forms, consultations, email or other communications, such as your name, business, role, email address, phone number, project requirements and support requests. Customer administration can also involve service agreements, billing contacts and invoice or payment-status records.
Assistant and workflow content: Prompts, messages, uploaded files, documents, task instructions and generated results. Depending on the configured service, this can include customer inquiries, order and tracking details, appointments, business records and contact information needed to carry out the requested task.
Voice and messaging information: Phone numbers, call or message times, delivery and routing information, and conversation content. Voice services process audio to conduct a conversation. Recordings, transcripts and summaries may be retained where those features are configured by the business operating the assistant.
Connected accounts: Account identifiers, approved permissions, authorization credentials and the data needed from services you connect. Google data is described separately below. Other integrations may include business systems, messaging, scheduling, commerce or document services; their access depends on the integration and authorization provided.
Website and service activity: Our website, hosting and embedded service providers receive technical information such as IP address, browser and device details, pages requested, access times and error or security events. Cookies and similar technologies are described below.
We use information to respond to inquiries, scope and deliver projects, provide support, administer customer relationships and operate the services you request. For assistants and automations, this includes answering questions, retrieving authorized records, preparing or sending approved communications, managing requested documents or appointments, and returning results to the authorized business workspace.
We also use operational information to maintain connections, prevent duplicate actions, investigate errors and abuse, secure the service and meet applicable legal obligations. Access to a connected account is used for the authorized workflow; connecting an account does not authorize every possible action available through that account.
An AI-assisted task may send relevant instructions, conversation content, files or retrieved records to the configured AI or voice provider to produce an answer or complete the requested workflow. The content processed depends on the task, enabled tools and connected systems. Generated answers, summaries and task results can become part of the business workspace’s records.
The business operating an assistant selects its workflows, authorized users and communication settings. A call or chat with an assistant may therefore involve the business, Agincy and the providers needed to operate it. Recording or transcription settings and any required notices or consent must be addressed by the business operating that service.
Google data remains subject to the restrictions in the next section, including the prohibition on using that data to train generalized AI models. A service or project that uses other data in a materially different way requires an appropriate additional disclosure and any necessary authorization.
Account identity and authorization: Google provides your account identifier, email address, approved permissions and authorization tokens. We use this information to identify the connected account, authenticate requests and maintain the connection. Google handles the sign-in and consent process; the OAuth connection does not ask you to give Agincy your Google password.
Gmail sending: For an email-sending workflow, we process the recipient address, subject, message body, configured sender and reply address, and delivery identifiers returned by Google. This lets the assistant send the messages authorized by the business and avoid duplicate send requests. This sending-only connection requests Gmail send access, not access to read your inbox.
Gmail reading: Separate workflows with Gmail read permission can access messages, message metadata and attachments needed for the task you request, such as locating correspondence or preparing a response. A sending-only client connection does not receive this additional permission automatically.
Drive and Sheets: Where authorized, workflows can access file names, file contents, sharing information and spreadsheet data to find, read, create or update the documents and records requested by the user.
Calendar: Where authorized, workflows can access calendar and event details, including times, descriptions and attendees, to check availability and manage requested events.
YouTube: Where authorized, read access can retrieve account, channel, video and playlist information for requested research or reporting. Read-only permission does not authorize uploading or deleting videos.
The permissions requested depend on the workflow being connected. Some permissions grant broader technical access than a single task needs; we use that access to carry out authorized tasks. You can review the permissions in Google’s consent screen and in your Google Account connections.
We do not sell Google user data, use it for targeted advertising, or use it to develop, improve or train generalized AI or machine-learning models. Our handling and transfer of Google API data complies with the Google API Services User Data Policy and its Limited Use requirements. These restrictions also apply when a service provider processes Google data for us.
We share information with providers needed to operate the relevant service. These can include Wix for the website, Google for connected Google services, Cloudflare for hosting and the customer email connector, Supabase for business backends, ElevenLabs for voice assistants, Twilio for phone or messaging workflows, and the configured AI service provider for AI-assisted tasks. Not every provider receives information from every service; the information shared depends on the workflow.
Information is also shared with the people or systems selected in an authorized task, such as email or message recipients, document collaborators and calendar invitees. Task results and saved records are available to authorized users of the business workspace. One client’s connection is not made available to unrelated clients.
Agincy personnel may access information as needed for authorized service delivery or support, security investigations or applicable legal requirements. Human access to Google data follows Google’s Limited Use rules, including obtaining affirmative agreement to view specific data when required. We may disclose information when required by law or as necessary to address fraud, abuse or security threats, subject to applicable restrictions.
Our providers may process information in countries other than the one where you live. The providers and locations involved depend on the service configuration. Contact us with questions about the providers handling a particular service. External websites and services you use separately have their own privacy policies.
We use access controls and service-specific safeguards to protect information. The customer email connector encrypts stored authorization tokens, uses encrypted network connections, separates business connections and enforces a fixed sender policy. Credentials are excluded from that connector’s diagnostic logs. No storage or transmission method can eliminate every security risk.
We retain inquiry, customer administration and service records for as long as needed to provide the service, manage the relationship, resolve issues and meet applicable legal obligations. Retention depends on the type of record, the client’s configuration and instructions, and any applicable service agreement. There is no single retention period for every Agincy service.
Assistant tasks may retain inputs, outputs, uploaded files, transcripts, summaries and related records in a business workspace or its history. These records are managed through workspace administration or a verified deletion request, subject to applicable retention requirements. Provider logs and backup copies follow the relevant service’s retention processes and may not be erased immediately when an active record is removed.
For the customer email connector specifically, connection invitations expire after seven days, callback diagnostics after 24 hours, and delivery records used to prevent duplicate sends after up to 30 days. Its token vault does not store email message bodies. Authorization tokens and connection settings remain while the connection is configured, until removed by an authorized administrator. These connector periods do not describe the retention of all Agincy workspace content.
Revoking a connection stops future access once the revocation takes effect; it does not automatically delete prior task records or messages already delivered. Copies held by a client, Google, recipients or another service are also subject to that party’s settings and responsibilities.
Our website uses Wix and embedded services that may use cookies, local storage or similar technologies for security, session management, preferences and service functionality. Analytics or other optional technologies, where enabled, may collect information about site use. An embedded voice or scheduling service may receive technical information when it loads and additional information when you interact with it.
You can manage cookies in your browser and through site consent controls where provided. Blocking certain technologies may affect website features. A website cookie choice does not grant or revoke access to a connected Google account; those permissions are managed separately.
You can choose what information to submit and whether to authorize a connection. Features that need withheld information or permissions may not operate. Review or remove Google access at myaccount.google.com/connections. To disable an Agincy connection immediately, contact us; Google controls the expiration or invalidation of its existing access tokens. Changed permissions or invalidated authorization can require a new consent step.
Contact agint@agincy.com to ask about information held by Agincy or request access, correction, export or deletion. Depending on your location and the applicable law, you may also have rights to restrict or object to processing, withdraw consent or complain to a data protection authority. We assess requests under the applicable requirements and verify the requester’s authority before disclosing information or changing business records.
If you interacted with an assistant run for one of our clients, identify that business so we can coordinate your request with it. You can also contact the business directly. Please provide enough detail to locate the relevant account or interaction, but do not send passwords, authorization tokens or unnecessary sensitive information. Requests involving copies held independently by recipients or other services must also be directed to those parties.
Our services are intended for business use and are not directed to children. If you believe a child has provided personal information through our services, contact us so we can assess and address it.
We update this policy when our services or information practices change and revise the date shown above. Material changes will receive an appropriate notice, and we will obtain additional consent where required. New uses of Google data must be disclosed before they begin, with any authorization required by Google. For privacy questions or requests concerning Agincy’s services, email agint@agincy.com.