LEGAL · PRIVACY
Privacy Policy
Effective August 31, 2026
AgentLodge is built around a local desktop workspace. This policy describes the narrower set of information that leaves your device when you use connected account, billing, reporting, or voice features.
1. Scope
This Privacy Policy explains how AgentLodge ("AgentLodge," "we," "us," or "our") collects, uses, discloses, and protects information when you use the AgentLodge website, account services, desktop application, and optional voice features (together, the "Services").
AgentLodge is a desktop terminal application for running coding agents. Terminal sessions, local files, workspace layouts, screenshots, and local diagnostic logs remain on your device unless you choose a feature that sends particular information to us or a service provider, such as account sign-in, billing, a report, or the voice feature. Coding-agent services that you run through the terminal have their own privacy practices and are not operated by AgentLodge.
2. Information we collect
We collect information you provide, information created through your use of the Services, and limited technical information needed to operate and secure them.
- Account and profile information: your email address, display name, account identifier, linked sign-in methods, account creation and update times, and the country or service region selected for your account.
- Authentication and device information: necessary session and security cookies, authorization and refresh-token records (tokens are hashed where applicable), a stable per-install device identifier, a user-readable operating-system label and version, registered-device timestamps, and security or abuse-prevention records.
- Subscription and transaction information: plan, subscription status and dates, currency and amounts, Stripe customer and event identifiers, invoice metadata, and voice-credit grants, balances, and debits. Stripe processes payment-card details; AgentLodge does not store your full card number.
- Voice information when you enable voice: microphone audio, your spoken request, generated answers, and the information needed to complete the request. AgentLodge does not store audio or transcripts. Section 4 explains voice handling in detail.
- Reports and support information: report type, title, description, optional client metadata, whether an image was attached, your account identifier, and a one-way hash of an IP address for abuse controls. An attached report image is received for processing but is not persisted in the report database.
- Usage, billing, and diagnostics metadata: timestamps; app, operating-system, provider, model, and language identifiers; token, character, and audio-duration counts; request or generation identifiers; outcomes; and pseudonymous account identifiers. We do not include terminal text, prompts, transcripts, audio, file paths, or API keys in voice-usage analytics logs.
- Website and network information: IP address, request headers, browser or device information, page and endpoint requests, and server logs generated by our hosting infrastructure. We use necessary session and CSRF cookies for sign-in and account security; we do not use advertising cookies.
3. How we use information
We use information to provide, maintain, secure, and improve the Services; authenticate accounts; enforce device and subscription limits; process purchases; deliver transactional email; operate optional voice features; meter voice usage; respond to reports and support requests; prevent fraud and abuse; diagnose failures; comply with law; and communicate material service or policy changes.
We do not sell personal information. We do not use personal information for targeted advertising, and we do not use microphone audio, voice transcripts, the session information sent with a voice request, or generated voice responses to train AgentLodge or third-party AI models.
4. Voice processing
Voice is off by default and begins only after you enable it and activate push-to-talk. When voice is active, your microphone audio is processed by a voice processing vendor to produce text, and text is processed by that vendor to generate the speech AgentLodge plays back. Access to that vendor uses short-lived credentials issued for your session. AgentLodge does not store audio or transcripts.
To answer a voice request, AgentLodge sends your spoken request and the information needed to answer it to an AI model provider. These requests use zero-data-retention routing that fails closed when an eligible endpoint is unavailable. AgentLodge does not store audio or transcripts and does not retain voice-request content on its servers; it retains the metering, credit, security, and operational metadata described in this policy.
You can decline voice consent, leave voice disabled, or stop using voice at any time. Disabling voice prevents new voice capture but does not erase billing or security records already created.
5. When we disclose information
We disclose information only as needed to provide the Services, follow your instructions, protect users and the Services, or comply with law. Our principal service-provider categories are:
- Google for authentication, hosting, databases, server execution, and operational logging; and Google or Apple when you choose their sign-in method.
- Stripe for checkout, subscriptions, invoices, payment methods, and billing support.
- An email delivery provider for magic-link, sign-in, and account email.
- A voice processing vendor for optional speech-to-text and text-to-speech processing.
- An AI model provider, reached through an AI vendor that routes the request, for optional voice-language-model processing under zero-data-retention routing.
- Professional advisers, authorities, or counterparties when reasonably necessary for legal compliance, protection of rights and safety, or a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards.
6. Retention
We keep account, device, subscription, entitlement, and voice-credit records while your account is active and for as long afterward as reasonably necessary for billing, security, dispute resolution, tax, accounting, and legal obligations. Session cookies expire after up to 30 days, access credentials have shorter expirations, and one-time authentication links are short-lived. Token-mint and rate-limit records are deleted or expire when they are no longer needed for attribution and abuse prevention.
AgentLodge does not store audio or transcripts, and does not retain voice-request content on its servers. Our voice processing and AI model providers process that content according to the zero-data-retention configuration described above. User-submitted reports and operational logs are kept only as long as reasonably needed for support, reliability, security, and legal purposes. Local application data remains on your device until you remove it or uninstall the app, subject to operating-system backup behavior.
Deletion from active systems may not immediately remove information from encrypted backups or records we must retain by law. Our providers may retain limited security, transaction, or operational records under their own legal obligations and our service configurations.
7. Your choices and rights
You may edit available profile information, change or unlink supported sign-in methods, deactivate registered devices, manage billing through Stripe, and keep optional voice disabled. To request access, correction, portability, or deletion of personal information, or to object to or restrict processing where applicable, email support@agentlodge.dev. We may need to verify your identity before completing a request.
Depending on where you live, you may have additional privacy rights and the right to appeal a decision or complain to a data-protection authority. We will not discriminate against you for exercising a privacy right. Some information may be retained where necessary to complete transactions, maintain security, resolve disputes, or meet legal obligations.
8. Security and international processing
We use technical and organizational safeguards designed to protect information, including encrypted transport, scoped credentials, short-lived access tokens, hashed secrets where appropriate, server-only data stores, and access controls. No system is perfectly secure, so we cannot guarantee absolute security.
We and our providers may process information in other countries. Where required, we use appropriate contractual or legal safeguards for international transfers.
9. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
10. Changes to this policy
We may update this policy as the Services or legal requirements change. We will post the updated policy here, change the effective date, and provide additional notice when a change is material and applicable law requires it.
11. Contact
For privacy questions or requests, contact AgentLodge at support@agentlodge.dev.