AgentValet is operated by AIFirstPartner, a company incorporated in Australia ("we", "us", "our"). AgentValet provides an identity and governance layer that allows developers and organisations to register AI agents, manage their permissions, and securely proxy their calls to third-party platforms.
This Privacy Policy explains how we collect, use, store, and protect personal information when you use agentvalet.ai and app.agentvalet.ai (together, "the Service"). We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also aim to meet our obligations under the GDPR where applicable to users in the European Economic Area or the UK.
When you create an account we collect your email address and use it to send magic-link authentication emails. We do not store passwords.
When you register an AI agent we store:
When you connect a third-party platform (e.g. Stripe, GitHub, Slack) we store the resulting API keys or OAuth tokens in our encrypted credential vault. Credentials are encrypted using envelope encryption: a per-credential data-encryption key (DEK) is wrapped by a master key held in Azure Key Vault HSM. Plaintext credentials are never written to disk or logged - they are decrypted in memory only at the moment a proxied API call is made.
Every action an agent takes through the AgentValet proxy is recorded in an immutable audit log. Log entries include: agent ID, platform called, endpoint, HTTP status, timestamp, and whether human approval was required. Request and response bodies are never stored.
We collect standard server-side logs including IP addresses, browser user-agent strings, pages visited, and error events. This data is used for security monitoring, debugging, and service improvement.
We do not sell your personal information. We do not use your data to train AI models.
For users in the EEA or UK, the lawful basis for each processing activity is:
| Purpose | Lawful basis |
|---|---|
| Providing the Service (authentication, agent registration, proxying) | Performance of contract (Art. 6(1)(b)) |
| Security monitoring, circuit breakers, anomaly detection | Legitimate interests (Art. 6(1)(f)) - protecting the integrity of the Service |
| Transactional emails (magic links, approval notifications) | Performance of contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of contract (Art. 6(1)(b)) |
| Aggregated analytics for service improvement | Legitimate interests (Art. 6(1)(f)) - improving the Service |
We share data only with the following sub-processors, solely to deliver the Service:
We do not share your data with advertising networks or data brokers.
We implement the following controls to protect your data:
No system is completely secure. If you discover a vulnerability please contact us at [email protected].
Depending on your jurisdiction you may have the right to access, correct, delete, or export your personal data. You can:
If you are located in Australia, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you are not satisfied with our response. If you are in the EEA or UK, you may escalate to your local data protection authority.
The Service is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected such information please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we do we will update the "Last updated" date at the top of this page and, for material changes, notify you by email or via an in-app notice. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
For privacy questions or requests: