Privacy Policy

Effective September 4, 2026

What we collect

Account details Google gives us when you sign in (name, email address, and Google account ID — there is no AgentGrown password), the sites you add, the API keys and agent authorizations you create, and the usage counts needed to enforce the monthly free keyword-lookup limit. For each site you add we store the keyword demand data our provider returns for it.

Google data

When you connect Google, we access your Search Console data (queries, clicks, impressions, positions) and Google Analytics data (sessions, traffic sources, engagement) for the properties you choose. We use this data only to show you your own dashboards and to answer queries from agents you authorize, for your own sites. We store it in our database — daily Search Console rows (date, query, page), daily Analytics rows (date, landing page, channel and source), and keyword rollups derived from them — for up to 16 months so your dashboards and your agent's queries work; we never sell it, never use it for advertising, and never share it with other customers. Agents reach it only through our MCP server, using an API key or authorization you create at /connect and can revoke there. Your OAuth refresh token is stored encrypted; disconnecting Google at /connect revokes the token with Google, deletes it from our systems, and stops all future syncs. AgentGrown's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who processes data for us

We run on Cloudflare (hosting, database, and key-value storage on Cloudflare Workers, served from Cloudflare's US and global edge), read your data from Google APIs, and fetch public keyword demand data through DataForSEO, which receives the keyword queries you or your agent look up (results are cached for 30 days). Google Analytics (gtag) runs on our marketing pages. Each receives only what it needs to do its job. We don't sell personal data to anyone.

Retention and deletion

Synced Search Console and Analytics rows are kept for up to 16 months; everything else stays as long as your account does. Remove a site to delete its data, disconnect Google at /connect to delete the stored token, or email support@agentgrown.com to delete your account and we remove your personal data and site data within 30 days.

Security

There are no AgentGrown passwords — sign-in is Google only. Google tokens are encrypted at rest, connections use TLS, and every data query in the product is scoped to the account that owns it.

Your rights and contact

You can access, correct, export, or delete your data — email support@agentgrown.com and we'll handle it. If we change this policy materially, we'll tell you by email or in the dashboard first.