Privacy policy
Last updated 2026-09-23
What this covers
agentleFS is a place for a team to keep what it knows, so that people and the AI agents working for them can find it — with the same permissions applying to both.
This policy explains what we collect, why, and what we will never do with it. It applies to the agentleFS service at agentlefs.com and to the connectors and integrations that are part of it.
What we collect
Mostly two kinds of thing: the account details needed to know who you are, and the content you choose to put in or connect. On our public pages we also count visits.
- Account information — your name and email address, from whoever you sign in with. We use it to identify you, to show who wrote what, and to contact you about the service.
- Content you create or upload — the documents in your organization, their history, and who you have granted access to.
- Content you connect — from Google Drive or GitHub, when you connect them. See the Google section below.
- Operational records — an audit log of what was read and changed, which is a feature of the product rather than a by-product: it is how an organization can answer who saw what.
- Visits to our public pages — the page you landed on, where you came from, and your browser and approximate location, counted by Google Analytics. This is collected only on the home page, docs, privacy policy and terms, never inside the console. See Who we share with below.
- How you found us — when you create an account, the name of the site that sent you (never the full address) and any campaign tag on the link you arrived by. It is recorded once, kept in our own database, and not shared with Google Analytics or anyone else.
Google user data
If you connect Google Drive, agentleFS reads the folders you choose so their documents can be searched and read inside your organization. This is optional, and it is scoped: you pick the folders, we read those, and nothing else in your Drive is touched. You can disconnect at any time.
We request one Google scope: drive.readonly. It is read-only. agentleFS never creates, edits, moves or deletes anything in your Google Drive. When you choose to edit a document, we send you to Google's own interface, signed in as yourself — that edit happens in Google, not here.
We request read access to the whole Drive rather than a narrower scope for two reasons. The feature mirrors a folder continuously — after you connect it, other people add files, rename them and edit them, and those changes have to arrive without you picking each file again. And in an organization it mirrors the folder's sharing as well, so that a document restricted in Drive stays restricted here. Google's narrower alternatives cannot express either: drive.file reaches only the files one person selects individually through Google's picker and never the ones a colleague adds afterwards, and drive.metadata.readonly withholds the document contents we index.
- What we read: the files in the folders you connect — their contents, their names, and, for an organization, who Google says may read them.
- Why we read the sharing: in an organization, so a document restricted in Drive stays restricted here. Who may read a mirrored document in an organization IS its Drive sharing — agentleFS re-reads it on every sync, so removing someone in Drive removes them here, and adding someone in Drive adds them here. Nobody can be given access to a mirrored folder from inside agentleFS; the attempt is refused and points you back to Drive.
- Where it goes: our own systems, inside your organization's boundary. It is encrypted in transit. It is not sold, never used for advertising, and never used to assess creditworthiness. One thing does leave, and it is described below: session recording, which captures names and never document contents.
- Who can see it: in an organization, exactly the people the Drive folder is shared with, plus an approver of the organization — who can already read everything in it, which is why only an approver may connect a Drive folder. In a personal workspace there is nobody else, so nothing is mirrored and only you can see it.
- How long we keep it: a copy stays in agentleFS until you remove it. Disconnecting a connector stops us reading anything further from Drive, but it deliberately leaves the documents already synced in place, so the people who could read them still can. Removing the folder is what takes the content out of use.
AI models and your data
We do not use your content to train or improve AI models. Not ours, and not anyone else's. It is never included in a training set.
agentleFS exists so an AI assistant can answer questions using what your organization has written down — but the answering does not happen here. Your assistant connects to agentleFS, and we serve it the documents you have given it access to, using your own credentials. What that assistant does next, and which model provider it uses, is between you and whoever you connected. agentleFS makes no call to any model to answer your questions.
The indexing that makes search work also runs on our own systems, using a local algorithm rather than an outside model. Building the index sends your content nowhere.
Nothing else here calls a model either. We once sent folder metadata to an outside model, to compose one written sentence about who could reach a folder. That feature has been removed. Nothing replaced it.
Beyond that and the session recording described below, no human at agentleFS reads your content except where you ask us to for support, or where the law requires it.
GitHub
If you connect a GitHub repository, we read the files in it so they can be searched and read inside your organization. We request the narrowest permissions that allows: repository metadata, and read access to contents. We do not write to your repositories.
What you control
Your content is yours, and the controls are meant to be usable rather than nominal.
- Disconnect a connector at any time, in Connections. Nothing further is read from it.
- Choose which folders a connector brings in, and change that selection later.
- Delete content. Deleting a document takes it out of every listing, search and read straight away, and nobody can reach it. It stays recoverable by you, so an accidental delete is not a disaster, which also means the underlying copy is still held.
- Erase content permanently. An approver of a document (someone who can share and manage access to it, and edit it) can do this from the console, and it destroys the content, its history, its comments and its name. Nothing in the service brings it back; the one exception, a restore from backup, is set out under "How long we keep things". Erasing a whole folder is still by request at privacy@agentlefs.com.
- Close your organization and have its content removed, by writing to privacy@agentlefs.com. There is no self-service control for this yet, and we would rather say so than point you at a button that does not exist.
- Revoke our access from Google directly, at myaccount.google.com/permissions — you do not have to come here to do it.
- Ask us what we hold about you, or ask us to delete it, at privacy@agentlefs.com.
How long we keep things
We do not delete your content on a schedule, and nothing here expires on its own. There is no timer on a document, no archive tier, and no job that removes old material. What you put in stays until you or your organization takes it out.
The one exception is an agent's drafts: the unpublished working notes an agent keeps while it works. When an agent is retired it gets an hour to publish anything worth keeping, and then its drafts are removed; an agent that stops suddenly loses them at once. Anything it published stays, because what it published is a copy.
Deleting a document withdraws it immediately — it leaves every listing, search and read, and nobody can reach it — and it stays recoverable by you. That is the point of the two words: the underlying copy is still held, which is what makes an accidental delete survivable.
Erasing is the other one. It destroys the content, its history, its comments and its name, at once, and nothing in the live service brings it back; backups are the one caveat, below. The only thing that stops an erase is a legal hold: while one applies to a document or folder, an erase is refused and says so, rather than being queued for later.
Two records survive an erasure, and we would rather say so here than have you find out from a support reply. The first is the audit log: it records that something was erased, where it was, by whom and when — not what was in it. Alongside it we keep one row noting that the object existed, what kind of thing it was and who owned it, and that row deliberately carries neither its name nor its path. Destroying the record of a deletion because the deletion happened would defeat the purpose of keeping one, so those rows stay.
Backups are the honest caveat on both "immediately" and "nothing brings it back". Our hosting platform takes encrypted backups on a rolling schedule — daily kept for six days, weekly for about four weeks, monthly for about three months. Content you erase is gone from the live service straight away, and can still sit in a backup that has not rotated out yet, for up to roughly ninety days. We do not mine backups, and we do not restore one to recover something a person chose to erase; they exist to bring the service back after a failure. A restore of that kind puts the service back as it was when the backup was taken, so content erased since then would come back with it.
If you close your organization, write to privacy@agentlefs.com and we remove its content. There is no self-service control for this yet, and we would rather say so than point you at a button that does not exist.
The providers named above keep their own records for their own periods — session recordings and analytics under the retention settings configured in those services, sign-in records for as long as your account exists. Ask us at privacy@agentlefs.com and we will tell you what applies at the time you ask.
How it is protected
Content is encrypted in transit, and stored with encryption at rest at our hosting platform's storage layer. Credentials for services you connect get a second layer on top of that: they are encrypted in the database under a separate key, and are never shown back to anyone, including us.
Access is decided per person and per document, and every read and write is recorded in a tamper-evident audit log your administrators can inspect.
Changes to this policy
If we change what we do with your data, we will change this page and update the date at the top. Where the change is significant, we will tell you in the product before it takes effect.
Contact
Questions about this policy, or about data we hold: privacy@agentlefs.com.

