Privacy Policy
How agentcommunity.org collects, uses, stores, and protects your personal information.
Effective date: March 8, 2026.
This policy describes what information agentcommunity.org ("we" or "the Service") collects, why we collect it, who we share it with, and what rights you have over it. The Service is operated by Open Agent Registry, Inc., a Delaware corporation.
If something in this policy is unclear, email us at privacy@agentcommunity.org and we will explain it.
01. What we collect and why
Account and registration data
When you sign up (via Google, GitHub, or email one-time password), we collect:
- Email address (from your OAuth provider or entered directly)
- Name and profile information, if your OAuth provider shares it
During registration, you may also provide:
- Full name, organization name, job title, and organization function
- Country, geographic regions of operation
- Contact phone number
- Organization website, logo URL, description, and legal address
- Company agent description (what agents you are building or plan to build)
- Preferred
.agentdomain name(s)
We use this data to manage your membership, process your .agent domain pre-registration, and demonstrate community support in our ICANN application.
Anonymous A2A, MCP, and ChatGPT pre-registration
You can pre-register an agent through our anonymous A2A endpoint or an MCP client, including ChatGPT, without first signing in to agentcommunity.org. When you explicitly ask it to do so, our hosted A2A or MCP service sends the following to Agent Community's Department of Machine Verification (DMV):
- Requested agent name, email address, operator name, and any optional description
- A registration type of AGENT and a source label of A2A, MCP, or ChatGPT
- A SHA-256 fingerprint derived from the request IP address
We use these fields to record the pre-registration, issue its certificate ID, create or find the associated Agent Community authentication record, send verification and certificate emails, attribute the registration source, and prevent abuse. The DMV hashes the fingerprint again for its cooldown key; the fingerprint is not written to the registration row. The DMV service also processes the IP address that reaches its registration endpoint for rate limiting and records that address in registration metadata.
The stored pre-registration fields and registration metadata have no automatic expiry. If you delete your account or request deletion, we delete or anonymize primary account and registration records according to the account type and applicable obligations. Some audit, suppression, legal, and operational records may remain under the retention rules below; legacy import tables, Resend webhook payloads, and activity-log payload data are not automatically scrubbed by the current account-deletion flow. The DMV fingerprint cooldown key expires 24 hours after the last counted request. See Sections 3, 6, and 7 for service providers, other retention periods, and your controls.
We cache A2A message/send task results in Cloudflare KV for 24 hours so tasks/get can retrieve them. The cache is keyed by an unguessable task ID and contains only task status and result artifacts. It does not include the incoming message history, submitted email, or operator name, and expires automatically after 24 hours.
For MCP register_agent requests that use an Idempotency-Key, we cache an MCP Idempotency-Key result in Cloudflare KV for 24 hours. The cache value contains a normalized-argument hash and the returned tool result, which may include a certificate ID and registration metadata. Its key is a SHA-256 hash scoped to the caller IP and supplied key; this cache does not store the raw request arguments or raw IP address.
Charter agreement data
When you accept the .agent Community Charter, we record which version you agreed to, an identifier that pins the exact text of that version, the time you accepted it, and the IP address recorded at signup. We keep this as a record of what was agreed and when. See Section 6 for retention details.
IP addresses
We collect your IP address in several contexts:
- Charter agreement signing (stored as raw IP, retained 36 months, then anonymized)
- Authentication requests (hashed with SHA-256, used for rate limiting)
- Newsletter subscription (stored in subscription metadata)
- A2A, MCP, and ChatGPT pre-registration (used as described above for abuse prevention and DMV registration metadata)
For rate limiting, we process hashed IP and email values via Cloudflare Workers. These are ephemeral and expire automatically (within 10 minutes for most limits).
Human map-search abuse prevention
The same-origin /api/map/search endpoint supports the human /map interface; it is not a machine or bulk API. To prevent abuse, it uses a SHA-256-derived caller IP hash as its Durable Object name. The Durable Object stores at most ten millisecond timestamps for the rolling 60-second budget and does not store the raw IP address. It does not use Cloudflare KV for map-search counting.
Expired timestamps are transactionally pruned on each request. Cleanup is also ordinarily scheduled within 60 seconds after the last request. That alarm cleanup is best-effort and may be retried during a platform or storage failure; it is not a guaranteed wall-clock deletion deadline.
This limiter state is separate from unrelated short-lived result caches used for A2A task results and MCP idempotency replay. Those caches have their own purposes and expiry periods; they are not map-search counters.
Email tracking
When we send you an email (welcome messages, endorsement requests, reminders, campaigns), we record the email subject, Resend message ID, delivery status, and timestamps for events like delivery, opens, clicks, bounces, and complaints. We also store a SHA-256 hash of your email address and IP address alongside the tracking record. We do not store the full email body.
If your email hard-bounces or you file a complaint, we add you to a suppression list so we do not email you again.
Document signing
Organizations that go through the endorsement process sign documents via DocuSeal, an e-signature service. We send DocuSeal your name, email, organization name, and form fields relevant to the endorsement (like year established and professional count). DocuSeal sends us signing status and timestamps.
For our migration from hosted DocuSeal, the private archive is designed to retain raw submission JSON, PDFs returned for completed and unfinished submissions, merged signed PDFs and audit-log PDFs. These records can include signer names, email addresses, signatures, form answers, and signing-event metadata. We retain them to preserve endorsement records and recover documents. Once activated and verified, signed-letter downloads may become available before we leave the hosted service.
The archive is designed to use Cloudflare R2's EU jurisdiction with no public URL or custom domain. Only signed letters with verified bytes and a finalized private link to their owner's account would be available through the authenticated Agent Community download route. Records whose account or endorsement link remains unresolved stay restricted and quarantined; they are not member downloads. Raw JSON, other PDFs, and audit logs are not public downloads.
Account erasure makes finalized archived objects linked to the erased account or registration unavailable. When no archive write can still be in flight, the object is deleted. When an archive write was dispatched but its outcome is uncertain, attended cleanup instead permanently replaces the bytes at that opaque key with a small PII-free erasure marker. The marker contains only a format/version string and a random nonce. It is retained at the same key so a delayed create-only archive write cannot recreate the deleted personal data. The private deletion queue stores only the opaque key and the marker's nonce and R2 receipt; queue completion requires a verified marker readback. Provider-side deletion is tracked separately in a provider-deletion queue and is complete only after absence is confirmed. A queued deletion is not a completed deletion. Unresolved or quarantined material remains outside member delivery and requires separate attended retention and erasure review; contact privacy@agentcommunity.org to request that review.
No lifecycle expiration rule is permitted to match the private owner-data namespaces or the same opaque keys that retain these permanent erasure markers.
During an attended hosted-DocuSeal reconciliation, a temporary private operational copy of the exact before/after reconciliation data is retained locally so an attended operator can safely resume or roll back the run. If you erase your account, we remove that raw database reconciliation entry in the same transaction as the account-erasure boundary. After final cutover acceptance, we remove the remaining raw database reconciliation entries. Only successful --retire --resume removes those local copies. In either case, a permanent minimum replay-denial marker remains with only the opaque run and request identifiers, the prior reconciliation state, a SHA-256 hash of the old entry, the terminal reason, and a timestamp; it does not retain your name, email, signature, submission ID, form data, URL, registration ID, or raw JSON preimage.
This archive and download design is checked into our application repository but, as of this policy revision, its production activation is an owner-authorized cutover task. We will update this policy when the bucket, migration, deployment, and verification evidence establish that the archive is operating in production.
We set the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Supabase auth session | Keeps you logged in | Session |
| reg_intent | Holds registration info during auth flow (httpOnly) | 10 minutes |
| invite_code | Tracks referral source | 7 days |
| _ga, _gid | Google Analytics (see below) | Up to 2 years |
During the OAuth flow, we may also set short-lived cookies for pending registration fields (domain, registration type, name, organization name). These are cleared after registration completes.
02. Analytics
We use Google Analytics 4 (measurement ID: G-NM99G6DPGB) to understand how people use the site. GA4 collects page views, referrer URLs, device and browser information, and events we define (like domain searches, join button clicks, and form interactions). This data is processed by Google under their privacy policy. We do not send Google your name or email.
We also use Cloudflare Web Analytics for page views, unique visitors, referrer, country, and device class. It does not use cookies, fingerprinting, or cross-site tracking, and we do not send it your name or email.
03. Third-party services that receive your data
| Service | What they get | Why |
|---|---|---|
| Supabase (US) | Account, pre-registration, and registration metadata | Database, authentication, and DMV processing |
| Google OAuth | OAuth handshake data | Login |
| GitHub OAuth | OAuth handshake data | Login |
| Resend (US) | Email address, verification and certificate email content | Email delivery |
| DocuSeal | Name, email, org details | Document signing (endorsements) |
| Cloudflare Workers and R2 | Request IP, registration fields (agent name, email, operator name, and optional description), hashed email/IP, IP-derived cooldown keys, A2A task status/result artifacts, MCP idempotency hashes/results, cookie-free page-view/device data, and—when the private archive is activated—raw submission JSON, PDFs returned for completed and unfinished submissions, and merged signed PDFs and audit-log PDFs, which can include signer names, email addresses, signatures, form answers, and signing-event metadata; verified owner-linked signed letters may become member downloads, while unresolved records remain restricted and quarantined | Hosting, task caching, private document archive to preserve endorsement records, recover documents, and provide signed-letter downloads; account erasure makes finalized archived objects linked to the erased account or registration unavailable, deletes settled objects, or permanently overwrites an uncertain in-flight object's opaque key with a PII-free erasure marker that prevents delayed recreation; unresolved or quarantined material stays outside member delivery and requires separate attended retention and erasure review; provider-side deletion remains in a provider-deletion queue until absence is confirmed; web analytics, and rate limiting |
| Google Analytics | Page views, events, device info | Usage analytics |
We do not sell your personal information. We do not share it for advertising purposes. The services listed above receive data only as needed to operate the Service.
04. International data transfers
Our website and APIs run on Cloudflare Workers, which processes requests at its global edge. Our primary database and authentication service, Supabase, is hosted in the United States, and Resend processes email delivery in the United States. If activated, the private endorsement archive uses Cloudflare R2's EU jurisdiction, while the authenticated download request is still served through the Cloudflare edge. As a result, your data may be processed outside your country, including at Cloudflare's global edge and in the United States. We rely on standard contractual protections where applicable.
05. How we protect your data
- Supabase Row-Level Security (RLS) policies protect private account and authenticated browser data according to each table's access rules.
- Listed public profiles are intentionally public. PAGE reads them through server-only service-role clients with explicit is_listed = true filters; the service-role key is never exposed to the browser.
- Authentication cookies are httpOnly to prevent client-side script access.
- IP addresses in email tracking logs are hashed with SHA-256, not stored in cleartext.
- Webhook debug logs mask email addresses (e.g., j***@example.com).
- When the private endorsement archive is activated, its R2 bucket has no public URL or custom domain. An authenticated owner-only route streams signed PDFs with
private, no-storecaching; it does not issue direct R2 or presigned links. - The site enforces HSTS with a two-year max-age and preload.
No system is perfectly secure. We take reasonable measures to protect your information, but we cannot guarantee absolute security.
06. Data retention
- Charter agreement IP addresses: retained for 36 months from collection, then anonymized.
- Account data (email, registration details): retained as long as your account is active.
- A2A, MCP, and ChatGPT pre-registration fields and DMV registration metadata: no automatic expiry; a deletion request deletes or anonymizes primary records, while applicable audit, suppression, legal, and operational records may remain.
- A2A, MCP, and ChatGPT IP-derived fingerprint cooldown key: expires 24 hours after the last counted request.
- A2A task status and result artifacts in Cloudflare KV: expire automatically after 24 hours.
- MCP Idempotency-Key argument hashes and result artifacts in Cloudflare KV: expire automatically after 24 hours.
- Email tracking records: retained indefinitely for deliverability management.
- Hard bounce and complaint suppression entries: retained permanently to prevent re-mailing.
- Map-search limiter state: at most ten millisecond timestamps, transactionally pruned on each request; an alarm is ordinarily scheduled within 60 seconds after the last request, with best-effort retry during platform or storage failure.
- Other rate limiting data in Cloudflare Workers: expires automatically within minutes.
- Audit logs (activity_log, registrations_audit): retained indefinitely for compliance.
- When the private endorsement archive is activated, raw submission JSON, PDFs returned for completed and unfinished submissions, and merged signed PDFs and audit-log PDFs are retained while associated account data is retained. Only verified, finalized owner-linked signed letters would become member downloads through their private database link; unresolved objects remain restricted and quarantined. We retain these records to preserve endorsement records and recover documents. On account erasure, we first make linked archived objects unavailable. Settled objects are deleted. If an archive write's outcome is uncertain, attended cleanup permanently replaces that opaque key's bytes with the PII-free random-nonce erasure marker described in Section 1 and verifies the replacement before completing its private queue entry. The marker remains to prevent delayed recreation and contains no owner data. Provider-side deletion is tracked separately in a provider-deletion queue and is complete only after absence is confirmed; a queued deletion is not a completed deletion.
- During attended hosted-DocuSeal reconciliation, raw reconciliation plans and preimages are temporary operational copies. Account erasure and accepted final cutover remove the raw database entries; successful
--retire --resumealso removes the local plan and preimage artifacts. The permanent replay-denial marker retains only an opaque run/request identity, prior state, SHA-256 hash, terminal reason, and time, not personal data or raw reconciliation JSON.
07. Your rights
You can:
- Unsubscribe from emails by clicking the unsubscribe link in any email, or by visiting /unsubscribe.
- Delete your account and request deletion of personal data from your member dashboard, or by emailing privacy@agentcommunity.org if you cannot log in. We delete or anonymize primary account and registration records according to the account type. When the private endorsement archive is activated, raw submission JSON, PDFs returned for completed and unfinished submissions, and merged signed PDFs and audit-log PDFs are retained to preserve endorsement records and recover documents. Only verified, finalized owner-linked signed letters would become member downloads; unresolved records remain restricted and quarantined. Account erasure makes linked records unavailable, then deletes settled objects or permanently overwrites an uncertain in-flight object's opaque key with the PII-free random-nonce marker described in Sections 1 and 6. That marker remains only to prevent a delayed create-only archive write from recreating the personal data. Account erasure also removes any raw hosted-DocuSeal reconciliation entry for your account, leaving only the minimum hash-only replay-denial marker described in Section 6. Provider-side deletion is tracked separately in a provider-deletion queue and is complete only after absence is confirmed; a queued deletion is not a completed deletion. We may retain audit, suppression, legal, and operational records where needed; the current flow does not automatically scrub legacy import tables, Resend webhook payloads, or activity-log payload data. Contact us if you want those records reviewed as part of your request.
- Request a copy of the personal data we hold about you.
- Correct inaccurate information in your profile by logging in, or by emailing us.
- For an A2A, MCP, or ChatGPT pre-registration, use the verification email to access your account when available. Whether or not you can sign in, you can email privacy@agentcommunity.org from the registration address to request access, correction, or deletion.
If you are a resident of the European Economic Area, you may also have rights under the GDPR including the right to restrict processing and the right to data portability. Contact us to exercise these rights.
08. Children
The Service is not directed at anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
09. Changes to this policy
If we make material changes to this policy, we will update the effective date at the top and post the revised version on this page. For significant changes, we may also notify you by email.
10. Contact
Open Agent Registry, Inc.
Email: privacy@agentcommunity.org
Website: agentcommunity.org