Legal
Privacy policy
How AgnCred handles personal data, and how the right to erasure works alongside records that have to stay verifiable for years. Effective 23 August 2026.
Who we are
AgnCred is operated by Slobal Ltd, registered in Ireland. Slobal Ltd is the data controller for personal data processed through agncred.com and the AgnCred service. Write to info@agncred.com for any question about this policy or about your data.
AgnCred issues portable, cryptographically verifiable work receipts for AI agents. An operator submits a receipt for completed work, an independent company reviewer attests it with a signature over an immutable record, and anyone can check that signature afterwards, including offline. The design of the service explains most of what follows: we hold proof of work, not the private work itself.
What we process
- Account data. Sign-in runs through the Slobal relay, so we hold the email address and display name it passes to us, plus your workspace membership records. Membership is where authority comes from: it decides which workspace you can see and what you may do in it.
- Receipt content and evidence hashes. A receipt carries work metadata, a task summary, timestamps, runtime details and outcome claims. Evidence is committed by content hash, so the raw work product (documents, source code, prompts, customer data) never reaches AgnCred. Private evidence references such as ticket identifiers or run links are held separately from the signed record and can be deleted.
- Reviewer data. Reviewer identity, the review decision, and the independence declaration made at review time. The declaration is recorded inside the signed attestation, which is what makes it non-repudiable. Private reviewer notes are stored in erasable form and never published.
- Invitations. When an operator names a reviewer, we process that reviewer's email address and any personal message. Invitations are single use, expire after seven days, and the email address and message are stripped on expiry.
- Operational logs. Request identifiers, timestamps, route, and response status. Authorisation headers and cookies are redacted before anything is written, so no session tokens or cookie values reach the logs.
We do not ask for payment details on this site, and we do not seek special category data. Receipts are for privacy-safe summaries and metadata only.
Signed records, erasure and redaction
Two promises meet here: an attested receipt must stay checkable indefinitely, and you must be able to have your personal data erased. We keep both by splitting the data at the schema level.
The immutable side holds receipt versions, attestations and hash-chained event records. These carry pseudonymous identifiers and approved metadata only. The erasable side holds names, email addresses, private evidence references, reviewer notes, invitation contents and outgoing mail bodies.
An erasure request is self-service for a workspace owner and needs an explicit confirmation. It deletes private evidence, strips invitation emails and messages, revokes agent API keys, clears private reviewer notes, destroys private signing key material, and pseudonymises the operator or company record. It never rewrites a signed payload, an attestation or an event chain. Past signatures therefore keep verifying against the retained public keys, and erasure cannot be turned into a tool for destroying inconvenient proof. A verification report states the erasure as a separate fact rather than hiding it.
In plain language: after erasure what remains is a run of hashes, identifiers and signatures whose meaning as personal data has been removed, because the mapping that connected those identifiers to a named person no longer exists on our side. The record still proves that a piece of work was attested by a company on a date, which is the point of the service, without saying who you are.
Content redaction is a first-class state, not an afterthought. A reviewer can accept a receipt while approving only some fields for publication, and content can be redacted later, with the cryptographic record staying checkable throughout.
One honest limitation: personal data that a user types directly into a free-text field of a receipt becomes part of the signed record and cannot be taken back out of it. Our guides ask users never to do this, and receipts should describe work, not people.
Legal bases
- Performance of a contract. Running your account and workspace, accepting receipts, routing them to reviewers, publishing attested results, and sending the service email that makes the loop work.
- Legitimate interests. Keeping verification records intact and checkable for third parties, preventing abuse of the service, security logging, and defending legal claims. We keep the retained data pseudonymous so this interest does not override your rights.
- Consent. Where we ask for it, for anything optional. You can withdraw consent at any time, and withdrawal does not affect processing already carried out.
- Legal obligation. Where Irish or EU law requires us to retain or disclose something.
Retention
- Account data and workspace memberships: for as long as the account is active, then deleted or pseudonymised on erasure.
- Sign-in links: 15 minutes, single use. Browser sessions: 24 hours. Both are stored as hashes.
- Invitations: 7 days, after which the email address and message are stripped.
- Transactional email: message bodies are deleted as soon as the message is sent, delivery metadata after 30 days.
- Operational logs: short-lived, per the hosting configuration, and never a place where tokens appear.
- Signed records (receipt versions, attestations, event chains and public signing keys): retained indefinitely in pseudonymous form, because indefinite verifiability is what the service promises to the third party reading a receipt.
Third parties and processors
Application hosting and the database run on infrastructure located in the European Union. Transactional email for invitations, sign-in links and notifications is delivered by Resend, which handles the recipient address and the message at the moment of delivery.
There is no analytics service, no advertising, no tracking cookie and no third-party script. The public pages of this site make zero third-party requests: the fonts are self-hosted alongside the rest of the site. We do not sell personal data and we do not share it for advertising.
The cookies the service does set are strictly necessary: a session cookie and its cross-site request forgery companion, both HttpOnly where the browser must not read them, both same-origin, and neither used to follow you anywhere.
Your rights
Under the GDPR you have the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object to processing based on legitimate interests. Portability is self-service: a signed-in member can export their workspace as JSON, public signing keys included and private key material never. Erasure works as described above, with the pseudonymous record surviving in a form that no longer identifies you.
Ask us at info@agncred.com and we will answer within one month. If you are not satisfied, you can complain to the Irish supervisory authority, the Data Protection Commission (dataprotection.ie), or to the authority where you live or work.
Changes and contact
If this policy changes, the effective date at the top changes with it and the current version always lives at this address. Questions, requests and complaints: info@agncred.com, Slobal Ltd, registered in Ireland.
Effective 23 August 2026.