Privacy at Agentcy

We believe people should be able to embrace AI confidently without sacrificing visibility, oversight, or trust.

SafeAI is designed to analyze and redact prompt content locally in the browser while retaining current incident metadata for practical workspace oversight.

SafeAI operates where supported AI work happens.

SafeAI Prompt Guard is designed to run only on supported AI platforms and related SafeAI testing environments. It looks for supported prompt and chat input areas on those platforms and is not designed to monitor unrelated websites.

When connected to a workspace, Prompt Guard analyzes the current prompt locally in the browser to help identify sensitive information, policy-related events, and potential organizational risk.

Sensitive information is handled thoughtfully.

SafeAI includes built-in detection for common forms of sensitive information, such as email addresses, phone numbers, SSN-like patterns, and unusually large prompts. Organizations may also configure additional workspace rules, including keyword, pattern, and context-based detections.

When potential sensitive information is identified, Prompt Guard presents a warning and can create a corrected or redacted version locally. The user can apply the fix, review the warning and continue, ignore it, or dismiss it.

The dashboard shows useful context, not unnecessary detail.

Current incident records provide security and policy context through metadata such as timestamps, supported AI platform information, risk scores and severity, matched policy or detection rules, detected categories, sensitive-item counts, acknowledgement status, and guard actions. They do not include the original prompt, corrected prompt, or a prompt snippet.

Policy acknowledgement activity and extension status information help authorized workspace users understand whether SafeAI is connected and whether organization policies have been acknowledged.

Frequently Asked Privacy Questions

These services are operated by Agentcy LLC (“Agentcy,” “we,” “our,” or “us”).

SafeAI sends limited workspace, account, and incident metadata to the backend to support security, visibility, and organization policy features. Current incident requests may include an installation identifier, time, supported AI platform details, event type, risk score and severity, matched policy or detection rules, detected categories, acknowledgement status, guard action, and sensitive-item count. The service associates that activity with the paired workspace and user.

Current incident requests do not include the original prompt, corrected prompt, raw detected values, or a prompt snippet.

For account and workspace access, Agentcy uses authentication and organization information such as signed-in user identifiers, email addresses, names, organization membership, workspace roles, invitations, and account entitlement settings.

When you purchase a Visibility Audit or Monitoring, Stripe collects the billing identity and payment information needed to process the transaction. Agentcy receives purchase and subscription details, your name, email address, business name, website URL, and any discovery answers you provide, including what you want AI to recommend the business for and any audiences, locations, or competitors to consider.

Agentcy uses this information to verify the purchase, communicate about the order, prepare and deliver the audit, provide monitoring updates, support billing and cancellation requests, prevent fraud, and maintain appropriate business and tax records. Agentcy does not receive or store your full card number in the marketing application.

Current incident records store safety metadata such as the linked workspace, user and installation, timestamp, supported AI source, event type, risk score and severity, matched rules, detected categories, acknowledgement status, guard action, and sensitive-item count. They do not store the original prompt, corrected prompt, or a prompt snippet.

Policy acknowledgements store the linked user, workspace, source domain, timestamp, and policy version. Extension status records store the linked installation, user, status, and last-seen time so admins can see whether connected browsers are active.

Prompt Guard performs redaction locally in the browser. It can replace detected sensitive values with plain placeholders such as [EMAIL], [PHONE], [SSN], [SECRET], or a placeholder configured for a custom rule. The corrected version is offered to the user and is not included in the current incident request.

Some signals, such as a large prompt warning, do not have a specific value to replace. If only non-redactable signals are present, the automatic fix is unavailable; when the user chooses another action, SafeAI records the risk and action metadata rather than the prompt text.

Workspace information is designed to remain separated by organization, with dashboard visibility scoped according to the active workspace and user role.

Access to workspace activity and administrative features is role-based. Organization owners and administrators may have broader visibility into workspace activity, policies, extension health, and team management features, while standard users are limited to the information and actions appropriate for their assigned role.

SafeAI currently supports monitoring on the following web-based AI tools: ChatGPT, Claude, Gemini, Grok, Meta AI, and Perplexity.

No. SafeAI does not monitor browser activity outside of supported AI tool websites: chatgpt.com, claude.ai, gemini.google.com, grok.com, grok.x.com, meta.ai, and perplexity.ai.

Agentcy does not sell customer data.

Agentcy does not use SafeAI incident metadata, workspace rules, or policy activity for advertising.

SafeAI uses authenticated access controls, workspace roles, organization-scoped records, and secure extension-to-workspace linking to help protect customer data and limit access appropriately.

SafeAI is designed to maintain secure connections between browser extensions and authorized workspaces. When an extension is disconnected or unlinked, the associated connection is deactivated and browser check-ins are designed to stop after the local connection is removed.

SafeAI stores workspace-related records needed to support dashboard functionality, organization policies, extension management, incident visibility, and related workspace activity.

Purchase, subscription, billing, and fulfillment records may be retained as needed to provide the service and meet fraud-prevention, accounting, tax, dispute, and legal obligations. Customers may contact Agentcy with privacy, retention, or deletion questions, although some records cannot be deleted while a legal retention requirement applies.

Agentcy uses trusted third-party services to support account authentication, secure sign-in sessions, workspace invitations, payments, email delivery, and platform infrastructure. Stripe acts as the payment processor for online Visibility purchases and subscriptions and processes payment and billing information under its own privacy policy.

Agentcy may use Cloudflare Web Analytics to understand aggregate page visits, referring sites, page paths, and website performance.

The SafeAI dashboard communicates with backend services that support workspace functionality, organization management, incident visibility, and related platform features. Infrastructure and hosting providers may vary depending on the deployment environment used by your organization.

SafeAI warnings are advisory and do not hard-block submission. Users can apply the locally generated fix, open the warning details, continue after review, ignore the warning, or dismiss it. Completed actions such as Fixed all, Reviewed, Ignored, and Dismissed are logged as incident metadata; merely opening the review details does not create an incident. Users can also unlink the browser extension from its options page.

Owners and admins can manage workspace access, invite teammates, view extension connection status, and configure workspace detection rules and presets.