Privacy Policy

Last updated: {{EFFECTIVE_DATE}}

1. Who we are

Managoat is operated by {{COMPANY_LEGAL_NAME}} ("we", "us"). This policy describes what personal data we collect when you use the Managoat service, why we collect it, and the choices you have. For questions or requests, contact {{CONTACT_EMAIL}}.

2. What we collect

  • Account data. Your email address and a hashed password. If you sign in with GitHub, we receive your GitHub account email and profile identifier; we never see your GitHub password.
  • Billing data. Payments are processed by Stripe. We store your Stripe customer identifier and a ledger of the credit you were granted, bought and spent; your card details go directly to Stripe and never touch our servers.
  • Service content. The agent configurations, environments, vaults, and secrets you create, and the conversations your agents run, including their logs. Environment and vault secrets are encrypted at rest with a per-tenant key.
  • Usage and security records. Usage events (which conversations ran and when, for billing and quota purposes) and audit logs of security-relevant actions, which include your IP address. We also use IP addresses transiently for rate limiting.
  • Cookies. A session cookie to keep you signed in. We do not use advertising or third-party analytics cookies on the Service.

3. How we use it

We use this data to provide and secure the Service: authenticating you, running your agents, keeping your credit balance, sending transactional email (verification, billing and account notices), preventing abuse, and debugging problems. We do not sell personal data, we do not use your content to train AI models, and we do not send marketing email you haven't asked for.

4. Who we share it with

We share data with service providers only as needed to run Managoat:

  • Stripe — payment processing;
  • our email provider — transactional email delivery;
  • sandbox infrastructure — the isolated compute environments your conversations run in, which receive the configuration and decrypted credentials needed to run each conversation;
  • AI model providers you configure — your agents call them with credentials you supply, under those providers' terms;
  • GitHub — only if you choose GitHub sign-in.

We may also disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply to it.

5. Security

Traffic to the Service is encrypted in transit with TLS. Secrets you store are encrypted at rest using envelope encryption with a per-tenant data key. Passwords are stored only as salted hashes. Access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you without undue delay.

6. Retention

We keep your data while your account is active. When you delete your account, your content and personal data are removed from our systems, subject to short-lived backups and any records we must keep for legal or accounting reasons (such as invoices held by Stripe).

7. Your rights

From your account page you can, at any time and without asking us: export your data in a machine-readable format, and permanently delete your account. Depending on where you live you may have additional rights (access, correction, erasure, portability, objection); we honor these regardless of location — email {{CONTACT_EMAIL}} and we will respond within 30 days.

The Service is not directed at children under 16, and we do not knowingly collect their data.

8. International transfers

Our systems and providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for those transfers, such as our providers' standard contractual clauses.

9. Changes

We may update this policy. For material changes we will notify you by email or in-app notice before they take effect. The "Last updated" date above reflects the current version.