Skip to content
AgentDock

Privacy Policy

Effective date: 8 September 2026 · Version 1.0

This Privacy Policy explains how AgentDock (“AgentDock”, “we”, “us” or “our”) collects, uses, stores and discloses personal information when you use AgentDock websites, account services, paid plans and AgentDock-branded software or services that link to this policy.

AgentDock is designed around a local-first desktop architecture. The website and account system do process some personal information remotely, but your local projects and third-party agent traffic are treated differently, as explained below.

1. Scope and local-first design

AgentDock’s desktop application launches and coordinates AI agent software that you install and authenticate on your own device.

By default:

  • agent processes run on your device;
  • project files, workspace data and desktop session data remain on your device;
  • provider credentials are managed by the provider tools you install, not by AgentDock;
  • network requests from provider CLIs such as Claude Code, Codex and Antigravity go from your device to the relevant provider rather than being proxied through AgentDock servers; and
  • AgentDock does not receive or centrally store your source code, local prompts or agent outputs merely because you use the desktop application.

Separate online functions, such as account authentication, subscription billing, website analytics, email verification, support and any future cloud-connected feature, may process data remotely as described in this policy.

2. Personal information we collect

Depending on how you use AgentDock, we may collect:

Account and profile information

  • email address;
  • display name or profile name;
  • account identifiers;
  • email verification status;
  • authentication records and security-related account state.

Passwords are stored as password hashes rather than readable passwords.

Google sign-in information

If Google sign-in is available and you choose to use it, we may receive basic account information made available through the OAuth flow, such as your Google account identifier, email address, name and verification status, subject to the permissions shown during sign-in.

Subscription and billing information

We may store:

  • Stripe customer and subscription identifiers;
  • plan, entitlement and subscription status;
  • billing period, cancellation and renewal status; and
  • transaction-related records needed to administer subscriptions.

Payment card details are handled by Stripe. AgentDock does not store full payment card numbers on its own servers.

Website analytics

The AgentDock website currently uses first-party analytics to understand site usage. This may include:

  • a randomly generated session identifier;
  • pages viewed;
  • selected buttons or links;
  • download platform selections;
  • event names;
  • basic platform information; and
  • limited event metadata associated with those actions.

The current analytics session identifier is stored in browser session storage and is designed to expire with the browser session rather than act as a long-term advertising identifier.

Security and technical information

We may process information needed to protect the Services, including:

  • session and authentication tokens or token hashes;
  • login attempts, rate-limit records and security events;
  • request, network or device information that may be available in ordinary hosting or security logs, such as IP address, browser or user-agent information, timestamps and request paths.

Communications and support

If you contact us, we collect the information you provide, such as your email address, message contents and information needed to investigate or respond.

Legacy waitlist or product-interest information

If you previously submitted a waitlist or product-interest form, we may retain information you provided such as name, email address, use case, source page and associated session identifier until it is no longer reasonably needed.

3. Information AgentDock does not normally collect from local desktop use

Merely using the local desktop application does not cause AgentDock to centrally receive:

  • your repository contents or project files;
  • provider API keys or provider login credentials;
  • the full contents of prompts sent through locally installed provider CLIs;
  • the full outputs returned by those CLIs; or
  • the ordinary network traffic between a provider CLI and that provider.

If you intentionally send these materials to AgentDock through support, a cloud-connected feature or another online submission, they may then be processed for that specific purpose.

4. How we collect personal information

We collect personal information:

  • directly from you when you create or update an account, subscribe, contact us or submit a form;
  • automatically when you use our website or online account services;
  • from payment and infrastructure providers where necessary to operate billing, security and account functions;
  • from Google if you choose Google OAuth sign-in; and
  • from your device only where an AgentDock feature expressly sends information to an AgentDock-operated online service.

Where lawful and practical, you may browse public website content without creating an account.

5. Why we use personal information

We may use personal information to:

  • create, authenticate and secure accounts;
  • provide desktop account authorisation and paid entitlements;
  • process subscriptions, cancellations and billing administration;
  • provide password resets, email verification and service messages;
  • operate and improve the website and Services;
  • understand aggregate product and website usage;
  • prevent abuse, fraud and security incidents;
  • diagnose service problems;
  • provide customer support;
  • comply with legal obligations and enforce our agreements; and
  • communicate material service, security, legal or billing updates.

If we use information for marketing communications in the future, we will do so in accordance with applicable law and provide required opt-out mechanisms.

6. Legal bases and lawful processing

Where a jurisdiction requires a stated legal basis for processing, we generally process personal information because:

  • it is necessary to provide a Service or perform a contract with you;
  • it is necessary for our legitimate interests in operating, securing and improving the Services, where those interests are not overridden by your rights;
  • you have given consent; or
  • processing is necessary to comply with law.

The specific basis may depend on the information and your jurisdiction.

7. When we disclose personal information

We do not sell personal information to advertisers.

We may disclose or make personal information available to service providers that help us operate the Services, including:

Cloudflare

For website hosting, serverless functions, database services, content delivery, networking, security and related infrastructure.

Stripe

For payment processing, subscriptions, billing portals, fraud prevention and payment-related records.

Google

If you choose Google sign-in, for the operation of the OAuth authentication flow. Your use of Google services is also subject to Google’s own policies.

Email delivery providers

For sending account verification, password reset, security or other service emails. The specific delivery provider may change as our infrastructure changes.

Third-party AI providers you choose

The desktop application may launch provider CLIs such as Claude Code, Codex or Antigravity. Those tools communicate directly with their respective providers using your provider account. That traffic is governed by the provider’s own privacy practices and is not ordinarily routed through AgentDock.

Professional, legal and compliance recipients

We may disclose information where reasonably necessary to obtain professional advice, enforce rights, protect users or comply with a lawful request, court order or legal obligation.

Business transfers

If AgentDock is involved in a merger, acquisition, financing, reorganisation or sale of assets, information may be transferred as part of that transaction subject to applicable law and appropriate safeguards.

8. Overseas processing and disclosures

AgentDock uses global technology providers. Personal information may therefore be processed or stored outside Australia, including in the United States and other countries where Cloudflare, Stripe, Google or other service providers operate infrastructure or personnel.

Where Australian privacy law applies to an overseas disclosure, we will take reasonable steps required by law in relation to that disclosure.

Because cloud routing and provider locations can change, it may not always be practicable to identify every country in advance. We will keep this policy reasonably current as our service-provider arrangements change.

9. Cookies, local storage and similar technologies

AgentDock may use:

  • essential authentication cookies or similar mechanisms needed to keep you signed in and secure an account session;
  • browser session storage for a randomly generated first-party analytics session identifier; and
  • local browser storage where needed for preferences or user-interface state.

We do not currently use the first-party analytics session identifier as a cross-site advertising identifier.

Third-party services you open or interact with, including Stripe or Google, may use their own cookies or storage under their respective policies.

10. Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide an account, administer subscriptions, meet legal or accounting requirements, prevent fraud, resolve disputes and enforce agreements.

Retention periods vary by data type. For example:

  • active account and entitlement data may be retained while the account remains open;
  • billing and transaction-related records may be kept for periods required by tax, accounting, fraud-prevention or legal obligations;
  • authentication and security records may be retained for a reasonable period to maintain account security;
  • website analytics may be retained for product and operational analysis and may later be aggregated or de-identified;
  • support communications may be retained while an issue is active and for a reasonable period afterwards.

When personal information is no longer reasonably required, we will take reasonable steps to delete, de-identify or otherwise dispose of it, subject to technical, backup and legal constraints.

11. Security

We use reasonable technical and organisational safeguards designed to protect personal information. These include measures such as hashed passwords, protected session mechanisms, access controls and infrastructure security features.

No online service can guarantee absolute security. You are responsible for protecting your own device, provider credentials and AgentDock account credentials.

If you believe your AgentDock account or personal information has been compromised, contact support@agdc.dev.

12. Access, correction and deletion

Depending on applicable law, you may have rights to:

  • request access to personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • request deletion of information where applicable;
  • object to or restrict certain processing;
  • request portability of certain information; or
  • withdraw consent where processing is based on consent.

Some information may need to be retained where required by law or for legitimate security, fraud-prevention, billing or dispute-resolution purposes.

To make a privacy request, email support@agdc.dev. We may need to verify your identity before completing a request.

13. Privacy complaints

If you believe we have mishandled your personal information, contact support@agdc.dev with enough detail for us to investigate.

We will review the complaint and respond within a reasonable period. If Australian privacy law applies and you are not satisfied with our response, you may have the right to complain to the Office of the Australian Information Commissioner (OAIC).

14. Children and minors

The Services are primarily designed for developers and other users capable of understanding the permissions and risks associated with developer tools and AI agents.

If you are a minor, you should use the Services with the involvement of a parent or legal guardian where required by law. We do not knowingly seek to collect sensitive information about children through the website.

If you believe a child has provided personal information in circumstances that require parental consent and that consent was not obtained, contact support@agdc.dev.

15. Automated decisions

AgentDock does not currently use personal information in an AgentDock-operated online system to make solely automated decisions that we expect to significantly affect a person’s legal rights or similarly significant interests.

Third-party AI agents may automate tasks at your direction, but those local development actions are not decisions by AgentDock about your eligibility for services, employment, credit, insurance or similar rights.

If this changes, we will update this policy and provide any information required by applicable law.

16. Changes to this Privacy Policy

We may update this Privacy Policy as the Services, service providers or legal requirements change.

We will post the updated policy with a new effective date. If a change materially affects how we use personal information, we will provide additional notice where required by law.

17. Contact

Privacy, account and data enquiries can be sent to:

AgentDock
Email: support@agdc.dev
Website: https://agdc.dev