Privacy Policy
Last updated: 6 October 2026.
This policy explains how AgentStack (agentstack.tech) collects, uses, shares, and keeps personal data when you use the website, the API, or the AgentStack plugin in ChatGPT or Codex. We do not sell personal data.
Categories of personal data
We collect these categories:
- Account data: name, email address, user id, and authentication identifiers.
- Credentials you create in AgentStack, such as API key identifiers. The ChatGPT and Codex plugin does not ask you to paste a password, payment card number, government identifier, or one-time code into the chat.
- Project content you store or ask the assistant to read or write, including files, site content, and messages in your project.
- Usage and security data: API calls you make, IP address, timestamps, and error logs.
- Cookie data: session, language, and theme.
We do not seek payment card numbers, government identifiers, or health records through the plugin.
Purposes of use
We use personal data to:
- Provide the backend you request: projects, app data, sign-in, hosted sites, file storage, and rules.
- Authenticate you and protect the account.
- Operate the service, fix failures, and prevent abuse.
- Answer a privacy request you send us.
- Keep billing records where tax or accounting rules require them.
When you connect AgentStack in ChatGPT or Codex, the plugin sends to https://agentstack.tech/mcp only the action you ask for, the parameters of that action, and the result. We do not receive your ChatGPT conversation except the text you include in those parameters.
Categories of recipients
- AgentStack, the operator of agentstack.tech, to run the service.
- Infrastructure processors that host the service or deliver email, under contract, and only to perform that work.
- The AI app you connect, such as ChatGPT or Codex. That app sends the request and shows you the result. It is your client, not a buyer of your data.
We do not sell personal data and we do not share it with advertisers. We disclose data when the law requires it, or to investigate abuse of the service.
Data retention
- Account profile and project content: kept while the account or project exists. After we verify a deletion request, we remove that content from the live service within 30 days.
- Security and diagnostic logs: up to 90 days.
- Billing and invoice records: up to 7 years, where accounting or tax rules require them.
- Backup copies: used for disaster recovery. We do not restore deleted account content from backups except to meet a legal hold.
Controls
You can:
- Access the personal data in your account.
- Correct inaccurate account data.
- Ask us to delete your account and project content.
- Export your data. See the data policy.
- Disconnect the AgentStack plugin in ChatGPT or Codex. That stops new plugin requests. It does not by itself delete data already stored in your account.
- Block or delete cookies in your browser. Session cookies are required to stay signed in on the website.
Send a privacy request to support@agentstack.tech. We reply within 30 days.
Security
Data is encrypted in transit. Access to the API uses your account session or an API key. These measures reduce risk. They do not guarantee that unauthorized access is impossible.
Changes
If we change this policy, we update the date at the top. For a material change we also show a notice in the product or send email to the address on the account.
Related: Terms of Service.