LEGAL — LAST UPDATED 15 September 2026
This explains what we collect to run AgentID, why, and what your rights are over it.
We do not use advertising or cross-site tracking cookies, and we do not sell personal data to third parties. We do not currently integrate a third-party analytics or advertising service on this site.
To create and secure your account, to issue and verify agent certificates, to respond to lookups from sites checking a certificate (which see only what you declared as public on that certificate — see Terms §10), and to prevent abuse of the service.
When you register an agent, the certificate's public page (/c/<agent id>) and public API show: your display name, the agent's name, its declared permissions and limits, its issue and expiry dates, and its current status. This is intentional — it is what lets a third party verify the certificate — so only enter a display name you're comfortable being shown on a shared, public link.
Account and agent records are kept while your account is active. If you close your account, we delete personal data within 30 days except where we must keep minimal records for legal, security, or fraud-prevention purposes. Revoked or expired certificates are kept in read-only form so public links don't silently start pointing at reused data.
You can review and correct your account details, revoke or delete an agent, and request a copy or deletion of your account data at any time by writing to pilot@vagentid.com. Depending on your location, you may have additional rights (e.g. under UK GDPR or EU GDPR) to access, rectify, erase, restrict, or port your data, and to object to certain processing.
Passwords and secret keys are stored as one-way hashes, never in plain text. We use rate limiting, CSRF protection, and standard secure-cookie settings. No system is unhackable — see our security notes if you'd like the specifics, and please report any vulnerability to pilot@vagentid.com.
We'll update this notice as the pilot evolves and post the new date above.