At Agent 37 Inc. ("Agent 37", "we", "our", or "us"), privacy is foundational to how we built our service. We provide managed hosting for AI agents, including OpenClaw and Hermes instances and the Agent 37 Cloud API. This Privacy Policy explains how we collect, use, store, and protect your data when you use our platform.
1. Data collection
We only collect information necessary to provide our managed hosting service:
- Account information. Email address and authentication data, stored securely via Firebase Auth.
- Billing information. Payment data processed securely through our payment processor, Stripe. We do not store your full credit card number.
- Instance configuration. Instance ID, size, status, and settings necessary to provision and manage your service.
- Usage and billing records. Instance runtime, resource usage, and balance transactions used to meter prepaid plans.
- Request and operational metadata. The routing, security, and metering records described in section 2.
2. What we collect from your instance, and what we do not
Your instance is yours. We run the infrastructure it sits on; we do not collect its contents into our own systems, and we never use your data to train AI models. Specifically, we do not collect, record, or review:
- Prompts and AI responses. Conversations stay on your instance. They are not copied into an Agent 37 database and not read by us.
- Tool calls, terminal output, and desktop or file browser sessions. These are relayed to your browser in real time and are not recorded.
- Integration payloads. Data your agent exchanges with apps you connect flows between your instance and that provider.
- Your API keys. Keys you configure inside your instance are stored only within your instance. The Agent 37 API keys and starter credentials we issue you are stored on our side only as one-way hashes; the plaintext is shown once and never kept.
Your files, agent memory, and configuration live on your instance's encrypted disk. So that we can restore an instance after a failure, we hold encrypted backups of that disk, which necessarily contain whatever your agent has written to it. We do not read, index, or analyze those backups; they exist to give your data back to you. Section 9 says how long we keep them.
Two categories we do record, because we cannot operate or bill the service without them:
- Request and operational metadata. Timestamps, instance identifiers, request paths, response codes, and resource usage, used for routing, security, troubleshooting, and metering. Not request or response bodies.
- Managed model usage metadata. If you use starter credentials we issue instead of your own provider keys, model requests route through our managed proxy so we can meter them. We record tokens, model, and cost. We do not record your prompts or the model's replies.
Your instance runs on managed infrastructure that we administer. While we do not access your instance data in the normal course of operations, we do maintain infrastructure-level access to the servers that host your instance for the purposes of provisioning, updates, security, and support.
3. How your data flows
When using Agent 37, data flows as follows:
- You send a message via your chosen platform (WhatsApp, Telegram, Discord, Slack, the instance's own chat, etc.).
- The platform sends the message directly to your instance.
- Your instance sends an API request to your LLM provider using your own API keys.
- The LLM provider responds directly to your instance.
- Your instance sends the response back to you via the messaging platform.
When you bring your own API keys, Agent 37 is not in the path of your conversations. We provide compute, networking, and uptime. If you use starter credentials we issue instead of your own keys, model requests route through our managed proxy so we can meter usage; we record usage metadata such as tokens, model, and cost, not your conversation content.
4. How we use your data
We use your collected data for the following purposes:
- Service provisioning. To create, configure, and manage your instances.
- Authentication. To verify your identity and provide secure access to your account.
- Payment processing. To process subscriptions, prepaid top-ups, and metered usage.
- Communication. To send service updates, billing notifications, and respond to support requests.
- Service improvement. To analyze usage patterns and improve reliability and performance.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Data storage and security
We protect your data with industry-standard security measures:
- Encryption in transit. All traffic between you, our edge, and your instance is encrypted with TLS 1.2 or better.
- Encryption at rest. Agent 37 Cloud instance storage is encrypted at the volume level (AES-256) on servers we operate. Instance backups, account data, and billing records are encrypted at rest (AES-256).
- Instance isolation. Each instance runs in its own sandboxed environment with enforced per-instance resource limits and a locked-down network.
- Database security. Account data is stored in Firebase's secure infrastructure.
- Private hosts. Agent 37 Cloud servers have no public hostname; their traffic enters through our authenticated edge.
- HTTPS everywhere. All instance URLs are served over HTTPS.
- Signed access tokens. Terminal, desktop, and file browser sessions use short-lived, cryptographically signed tokens.
6. Security certifications and compliance
Our SOC 2 Type I report and our SOC 2 readiness report are available to prospective and current business customers on request under NDA. Our SOC 2 Type II is in progress, and our controls are monitored continuously. The scope covers the Agent 37 Cloud API, managed agent hosting, our dashboard, and the infrastructure that runs them.
To request either report, email info@agent37.com or see our Trust Center.
7. Third-party services
We use the following third-party services:
- Firebase. Authentication and database hosting.
- Stripe. Payment processing.
- Cloudflare. Networking and routing of instance traffic, and encrypted object storage for instance backups.
- Vercel. Hosting for our website, dashboard, and API.
- GitHub. Source and container image hosting for the templates your instances run.
- Resend and Google Workspace. Transactional email and support correspondence.
- PostHog. Product analytics on our website and dashboard.
- Composio. App integrations (Gmail, Slack, GitHub, Notion, and 1000+ more), if you connect them.
- LLM and search providers. Model and web search requests made with starter credentials we issue are routed to providers such as OpenRouter, Fireworks, and Brave.
- Daytona. Throwaway sandboxes that run cloud template builds and image imports.
- Grafana Cloud. Infrastructure metrics and request logs.
- Cloud infrastructure providers. Instance hosting.
Each of these services has its own privacy policy and data handling practices.
8. Google API services and user data
Our application integrates with Google API Services for authentication. This section explains how we handle Google user data:
- Data we access. Email address and profile information used for account creation and sign-in.
- How we use it. Account management and authentication only.
- Storage. Google account information is stored securely in Firebase with encryption at rest.
- Sharing. We do not share your Google user data with third parties for marketing purposes. Data may be shared with Firebase (authentication) and Stripe (payment processing), or as required by law.
- Your control. You can revoke our application's access to your Google data at any time through your Google Account settings. Deleting your account with us removes your Google user data within 30 days.
9. Data retention and deletion
We keep each category of data only as long as we need it:
- Prompts, AI responses, tool calls, terminal output, and integration payloads. Not retained by us at all, because we do not collect them. They persist only where your agent writes them, on your own instance.
- Instance contents (files, agent memory, configuration) and their backups. Kept for as long as the instance exists. Deleting an Agent 37 Cloud instance keeps a recovery copy for 7 days and then purges it permanently. Deleting a dashboard hosting instance keeps its data so support can restore it; email us to have it removed sooner. Deleting your account removes instance data on the 30-day schedule below, whichever kind of instance it is.
- Account information. Kept while your account is active, then deleted within 30 days of an account deletion request.
- Instance configuration, usage, and managed model usage metadata. Kept while the instance exists, and retained afterwards as part of the usage and balance history behind your charges.
- Billing records. Kept for as long as legal, tax, and accounting rules require, typically seven years.
- Request and operational logs. Kept on a rolling window, currently up to 30 days, then deleted automatically.
- Website and dashboard analytics. Kept by our analytics provider in a form that is never linked to instance contents.
Upon account deletion request, all associated data, including your instances and any stored configuration, is permanently deleted within 30 days, except records we are required to keep for legal, tax, or accounting purposes.
You may request account deletion at any time by contacting info@agent37.com.
10. Your privacy rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data
11. Children's privacy
Our service is not intended for children under 13. We do not knowingly collect information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on this page with a revised "Last updated" date. Continued use of the service after changes are posted constitutes acceptance of the revised policy.
13. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at info@agent37.com.