Agor Agents
Privacy Policy
Effective June 24, 2026 · Agor AI
What Agor Agents is
Agor Agents (app.agor.me) lets a business configure and publish its own AI agent — for example a receptionist that answers questions from the business's documents and books appointments into the business's calendar. This policy covers what data we collect to provide that, and what we do with it.
Data we collect
- Account data: your email address and a password (credentials are held by our authentication provider, Supabase; we store your account id and email).
- Configuration data:the answers you give in the setup wizard (business name, hours, services) and any documents you upload as your agent's knowledge.
- Google user data (only if you connect a calendar): see the dedicated section below.
- Agent conversations: chats between your published agent and its visitors, including a sampled subset retained for quality monitoring (drift detection), with contact details redacted where feasible.
- Payment data: payments are processed by Stripe. We never see or store card numbers — only the checkout session reference needed to confirm your purchase.
Google user data (Calendar)
If you choose to connect a Google Calendar, you grant Agor Agents access via Google's OAuth consent. We request the narrowest scopes that support the feature: viewing free/busy availability and creating events. We use this access for exactly two things, both on your explicit instruction via your configured agent:
- checking availability so your agent can offer open time slots, and
- creating a booking event when a visitor schedules with your agent.
OAuth tokens are encrypted at rest (AES-256-GCM) and are never shared, sold, or used for advertising or training. We do not read, store, or analyze your calendar's event contents beyond the free/busy check described above. You can revoke access at any time from your Google Account security settings or by contacting support, after which we delete the stored token.
Agor Agents' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use data
Only to provide the service: building and running your agent, evaluating it before publication, monitoring it for quality drift, and support. We do not sell personal data, share it with data brokers, or use it for advertising.
Your agent is powered by third-party AI providers: Google Gemini (understanding and generating the agent's responses, plus knowledge retrieval) and, on phone agents, xAI Grok (real-time voice). Each AI call sends only the content needed to answer the conversation at hand. Your data — including any Google user data — is never used to train Google's, xAI's, or our own AI or machine-learning models.
Data security
We protect your data, including sensitive data, with layered safeguards:
- Encryption in transit: all traffic to and from app.agor.me is served exclusively over HTTPS/TLS.
- Encryption at rest: data is stored with our managed infrastructure providers (Supabase and Netlify), which encrypt data at rest; connected Google OAuth tokens are additionally encrypted with AES-256-GCM before storage.
- Access controls and tenant isolation:each customer's data is isolated per tenant, access is least-privilege, and stored credentials (including calendar tokens) cannot be loaded across tenants.
- Minimal collection and limited use: we request the narrowest Google scopes the feature needs and use Google user data only to provide the feature you enabled, in line with the Google API Services User Data Policy (Limited Use).
- Compliant providers: the voice model behind phone agents runs on xAI, which is independently SOC 2 Type 2 certified and offers HIPAA Business Associate Agreements (BAA) and GDPR/CCPA data-processing terms; card payments are handled by Stripe (PCI-DSS Level 1). These certifications belong to the respective providers — Agor Agents is not itself a certified medical-records system, so if you need a signed BAA for protected health information, contact support before going live.
Retention and deletion
Configuration, knowledge, and account data are retained while your agent is active. Contact support to delete your agent, your account, or any stored data — including connected-calendar tokens — and we will remove them.
Contact
Support is an AI, too: claude@agor.me · (775) 252-8333 · how that works →