Legal
Privacy Policy
This policy explains what personal data TryAgent collects, how we use it, and the choices and rights you have.
Last updated June 23, 2026
1. Scope
This Privacy Policy describes how TryAgent inc. (“TryAgent,” “we,” “us”) handles personal data when you visit our websites, create an account, or use the Service. When we process personal data contained in Customer Data on behalf of a customer, we act as a processor and that processing is governed by our Data Processing Addendum.
2. Information we collect
- Account and workspace data — name, email, organization, role, workspace membership, authentication identifiers, and invite status.
- Billing data — plan, subscription status, billing contact, tax and invoice metadata, payment status, and limited payment metadata. Card details are collected and stored by Stripe, not by us.
- Usage, device, and analytics data — log data, IP address, browser and device type, pages viewed, referring pages, approximate location derived from IP address, event timestamps, cookie identifiers, and product analytics used to operate, secure, and improve the Service. Where optional analytics are enabled, we use Google Analytics and PostHog for website analytics, product observability, and frontend usage trends.
- Customer Data — escalation questions, evidence, choices, decisions, response values, metadata, policy keys, run IDs, reviewer records, audit records, and webhook delivery records you or your agents submit. This may contain personal data that you control; see our DPA.
- Integration and delivery data — Slack workspace and channel identifiers, email destinations, webhook endpoint metadata, delivery status, error responses, and contact methods you configure.
- Communications — messages you send to support and related metadata.
3. Sources of information
We collect information directly from you and your authorized users, from your agents and API calls, from customer-configured integrations, from service providers such as Auth0 and Stripe, and automatically from your browser or device when you use our websites or Service.
4. How we use information
- to provide, secure, and operate the Service;
- to route escalations and deliver notifications you configure;
- to generate learned recommendations, which are on by default and may involve sending escalation questions and evidence to an AI provider for embedding;
- to process payments and prevent fraud and abuse;
- to provide support, troubleshoot errors, send service-related communications, and maintain audit and delivery records;
- to analyze website and product usage, observe reliability and product friction, measure marketing effectiveness, and improve the Service; and
- to comply with legal obligations and enforce our terms.
5. Learned recommendations and AI providers
Learned recommendations are on by default when the Service is configured with the applicable AI provider credentials. TryAgent creates embeddings from escalation questions and evidence, stores the resulting vectors in a tenant-scoped database, and compares new escalations against prior reviewer decisions for the same tenant, policy, and workflow. We do not use Customer Data to train third-party foundation models for other customers unless you expressly agree otherwise in writing. Our current embeddings provider, OpenAI, states that API data is not used to train its models by default and may be retained for abuse monitoring for a limited period unless account-specific retention controls apply.
6. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies and TryAgent acts as a controller, we rely on the following legal bases. For Customer Data we process as a processor, the customer determines the legal basis for the underlying processing.
| Purpose | Categories | Legal basis |
|---|---|---|
| Provide, operate, and support the Service | Account, workspace, integration, delivery, and Customer Data | Contract; documented customer instructions for Customer Data |
| Route escalations and deliver notifications | Customer Data, reviewer records, contact methods, delivery data | Contract; documented customer instructions for Customer Data |
| Generate learned recommendations by default | Escalation questions, evidence, choices, and vectors | Contract and documented customer instructions |
| Process billing and prevent payment fraud | Billing, subscription, invoice, tax, and usage data | Contract, legal obligations, and legitimate interests |
| Secure the Service and prevent abuse | Account, device, log, audit, and security event data | Legitimate interests and legal obligations |
| Analyze optional website and product analytics | Usage, device, cookie, and page interaction data | Consent where required; legitimate interests where permitted |
| Comply with law and enforce agreements | Relevant account, billing, usage, and Customer Data | Legal obligations and legitimate interests |
7. How we share information
We share personal data with service providers and subprocessors that help us operate the Service, listed in our subprocessor list. We also share information with integrations and recipients you configure, such as Slack channels, email destinations, and webhook endpoints. We may disclose information to comply with law, to protect rights and safety, to enforce our terms, or in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal data for money. We do not knowingly share Customer Data for cross-context behavioral advertising. Where website analytics, product observability, or advertising-related identifiers are treated as a sale or sharing under applicable law, you may opt out as described below.
8. Categories disclosed
In the last 12 months, we may have collected and disclosed the following categories of personal information for the business purposes described in this policy:
| Category | Examples | Recipients | Sold or shared |
|---|---|---|---|
| Identifiers | Name, email, IP address, account identifiers | Hosting, identity, email, analytics, and support providers | Not sold for money. Optional analytics identifiers may be treated as sharing under some laws. |
| Commercial information | Plan, subscription status, invoices, usage ledger | Billing and payment providers | No |
| Internet or network activity | Log data, browser data, pages viewed, cookie identifiers | Hosting, security, and analytics providers | Optional analytics may be treated as sharing under some laws; you can opt out. |
| Customer Data | Escalation questions, evidence, choices, decisions, metadata | Hosting providers, notification providers, AI providers for default embeddings, and integrations you configure | No |
| Sensitive personal information | Only if you include it in Customer Data, credentials, or support communications | Service providers needed to provide, secure, and support the Service | No |
We do not use or disclose sensitive personal information for purposes that require a separate right-to-limit mechanism unless we provide that mechanism.
9. Data retention
We retain personal data only as long as reasonably necessary for the disclosed purposes, subject to legal holds and security, tax, accounting, dispute, and compliance requirements.
| Category | Typical retention |
|---|---|
| Account and workspace data | For the account term, then as needed for support, audit, security, and legal purposes. |
| Billing and invoice data | For the subscription term and then as required for tax, accounting, chargeback, and legal records. |
| Customer Data | Per account configuration and the Agreement; generally exportable for 30 days after termination, deleted from active systems within 90 days, and deleted from backups in the ordinary backup cycle, typically within 180 days. |
| Audit, security, and delivery records | For the period needed to operate, secure, investigate, and evidence the Service, unless a longer period is required by law. |
| Optional analytics data | According to the analytics provider configuration and only after optional analytics are allowed for the browser. |
| Support communications | For the support relationship and then as needed for business, quality, legal, or dispute purposes. |
10. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, encryption of sensitive credentials at rest, tenant isolation, scoped access controls, audit logging, secret management, secure development practices, and incident response procedures. No method of transmission or storage is completely secure.
11. International transfers
We may process and store data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as the Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent UK mechanisms, Swiss transfer safeguards where applicable, and other lawful transfer mechanisms. You may request information about applicable transfer safeguards by emailing privacy@tryagent.ai.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. You may also have rights to opt out of sale, sharing, targeted advertising, certain profiling, or to limit the use of sensitive personal information. You may have the right to lodge a complaint with a supervisory authority or appeal a denied privacy request. To exercise these rights, contact privacy@tryagent.ai. If your data is processed on behalf of a customer, we will direct your request to that customer.
TryAgent is established in the United States and currently operates the Service from the United States. If a specific offering or processing activity requires an EU, UK, or Swiss representative, we will identify that representative in this policy or the applicable customer agreement before the relevant processing begins.
13. California and U.S. state privacy requests
California residents and residents of other U.S. states with applicable privacy laws may submit requests by emailing privacy@tryagent.ai. Because TryAgent operates as an online service, this email address is our designated request method unless we provide an additional method in the Service. You may use Your Privacy Choices to manage optional analytics for this browser. We may verify your request and, where permitted, ask you to use your account or provide information needed to confirm your identity. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising your privacy rights. Where technically detectable, we process opt-out preference signals such as Global Privacy Control in a frictionless manner for the browser or device sending the signal.
If legally required, we will respond to verified consumer requests within 45 days, unless an extension is permitted. If our use of optional website analytics or product observability is considered a sale or sharing under applicable law, you may opt out through Your Privacy Choices, by contacting us, or by using browser-based opt-out preference signals, such as Global Privacy Control, where we can detect them.
14. Cookies and analytics
We use strictly necessary cookies to operate the Service (for example, authentication and session management). Optional Google Analytics and PostHog analytics/observability are off unless you allow them for this browser, and they remain off when we detect a browser opt-out preference signal such as Global Privacy Control or Do Not Track. If enabled, PostHog processes manual page views, route changes, account/workspace identifiers, and related device data. We configure PostHog autocapture and session recording off to avoid collecting Customer Data content shown in the product UI. You can change this setting at Your Privacy Choices, control cookies through your browser settings, or use Google's browser add-on to opt out of Google Analytics at tools.google.com/dlpage/gaoptout. Disabling some cookies may affect functionality.
15. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
16. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by updating the date above and, where appropriate, by additional notice.
17. Contact
Questions or requests? Contact us at privacy@tryagent.ai, or by mail at our registered office: TryAgent inc., c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808.