Privacy Policy — Command Agentic
This policy describes how Command Agentic handles the data you (the customer) give it. It mirrors what the product actually does — nothing in here is a marketing claim.
What we store, and why
When you use your personal agent, we store only what is needed to operate it:
| What we keep | Why | Where it lives |
|---|---|---|
| Your login name + a hashed password | So only you can get in | On the server (never stored in plain text) |
| Your profile: your name, your agent's name, your avatar, dark-mode choice | So your chats look/feel like yours | In your private account folder |
| Your notes, tasks (kanban board), and the files/attachments you send | This is the "memory" your agent works from | In your private, isolated folder on the server |
| Your chat transcripts with the agent | So you can scroll back and keep continuity | In your private, isolated folder |
| Your agent's persona/profile | So the agent behaves as you've configured | In your private, isolated folder |
Per-customer isolation: your data lives in a folder (and a container) that is separate from every other customer's. Other users cannot read, write, or search your files, and you cannot reach theirs. That separation is enforced at the infrastructure level, not just as a promise.
What we do NOT store
- ❌ Your cloud passwords, API keys, or OAuth tokens. We refuse and have no mechanism to hold them. Your agent is instructed to decline them too.
- ❌ Payment card details. Billing is handled by a PCI-compliant processor.
- ❌ Anything you never gave us. We don't scrape, track, or sell your data.
When your messages are processed by a third-party AI
To generate replies, your chat message is sent to a third-party LLM provider (currently via OpenRouter) as part of normal operation. This happens on the fly for the single message, and is not used to train or improve AI models — we have selected providers that do not train on your data. We do not sell or share your data.
Your rights over your data (this is real, not boilerplate)
- Export / portability: In the dashboard (Profile → Download all my data) you can download everything we store about you in one file, anytime.
- Deletion: In the dashboard (Profile → Delete my account & data) you can permanently erase your account — your notes, files, media, chats and profile. This is irreversible and done on request by you.
- Correction: You can edit your profile and your own vault/notes directly.
Retention
We keep nightly encrypted backups for disaster recovery. When you delete your account, your active data is removed; copies may persist briefly in backups before being rotated out per our backup policy, and are not used for any other purpose.
Security
- Passwords are hashed with a salted, one-way algorithm — we cannot read them.
- Access control is per-login; sessions expire.
- Each customer's data is isolated from others at the infrastructure level.
- We run regular security reviews of the codebase.
Operator access & transparency
Running the service means the operator (Command Agentic) has the technical ability to reach the data on the server, including your account. That is normal for any hosted service. To keep that honest and defensible, here is exactly what it means:
- Why we might access your data: only to keep the service working (support, troubleshooting, security, backups, and responding to your requests). We do not read customer data for any other purpose — never to sell, share, profile, or market.
- Most fixes need no data access at all. Most problems are infrastructure (is your container up? is the network reachable? is the service responding?), which we can diagnose without reading your notes, files, or chats. We only look at your data when the problem is specifically about its content and you have asked us to fix it.
- Nothing is ever read casually. We treat your data as private and touch it only to help you, on request, one account at a time.
- Access is logged. Support and administrative actions that touch customer data are recorded (who, what, when) so there is an auditable trail.
Where we process
Data is stored on our own server infrastructure. By using the service you agree to data being stored and processed there.
Changes to this policy
We'll notify you of material changes.
Contact
For privacy requests (export/delete/questions), contact: [email protected]
Command Agentic