Privacy Policy
Last updated: September 20, 2026.
This policy describes how AgentAddress handles information when you use our website, API, HTTPS inboxes, and inbound email service.
Information we collect
We store address records, optional task identifiers, received HTTP event data and email content, message metadata, and acknowledgement records. Email attachments are represented by provider metadata; we do not store attachment files. Access credentials are stored as hashes.
We also process technical information, such as IP addresses, request information, and usage counts, to operate the service, enforce limits, and prevent abuse. Creating an address does not require an account.
How we use and share information
We use information to receive and deliver events, maintain the service, troubleshoot problems, and protect against misuse. Service providers process information on our behalf, including Render for hosting, MongoDB for storage, and Resend for inbound email. Information may be processed in countries other than your own.
We do not sell your personal information. We may disclose information when required by law or when necessary to protect the service, its users, or others.
Website analytics and cookies
Public website pages use Google Analytics to understand visits and navigation. Google Analytics may use cookies and collect browser, device, and usage information. We do not intentionally send message content, read tokens, ingress URLs, or recipients as analytics events. Browser analytics are separate from API and MCP activity.
You can restrict cookies in your browser or use the Google Analytics opt-out browser add-on. See Google's Privacy Policy for its data practices.
Retention and deletion
Events are retained for 30 days. Reading or acknowledging an event does not delete it. Addresses have no expiry by default, but you can set an expiry when creating one or delete an address and its events through the authenticated API. Aggregate operational usage counts can remain after deletion or expiry.
Infrastructure logs and provider-held copies may follow separate retention schedules. Do not use AgentAddress as your only archive.
Security and your choices
Protect your read token and secret-bearing inbox URL. Anyone with a read token can access and delete the associated address data. Lost credentials cannot be recovered. We use access controls and hashed credentials, but no service can guarantee absolute security.
Only submit information you are authorized to share. Depending on your location, you may have rights to access, correct, or delete personal information. For privacy questions or requests, contact the maintainer through the maintainer's GitHub profile. Do not post credentials or private message content in public issues.
Changes
We may update this policy by publishing a revised version here with an updated date.
See also our Terms of Service.