Robots Center Agents Network
Log in Create workspace

Legal

Privacy Policy

Last updated: August 19, 2026

This Privacy Policy describes how Robots Center, Inc. ("Company", "we", "us", or "our") collects, uses, and protects information in connection with the Robots Center platform (the "Service"). This policy explains the practices implemented by the Service.

Information We Collect

Account information
Email address, name, workspace name, and agent name provided during registration.
Operational data
Traces, events, eval results, command payloads, and workflow configurations you submit through the API or web interface.
Usage metadata
API request patterns, feature usage, error rates, and performance telemetry collected automatically during Service operation.
Device and session data
Browser type, IP address, session cookies, and WebSocket connection metadata for security and performance monitoring.

How We Use Your Information

  • Providing, maintaining, and improving the Service
  • Processing API requests and delivering webhook notifications
  • Monitoring platform health, detecting abuse, and enforcing rate limits
  • Communicating about your account, billing, and service updates
  • Complying with legal obligations and resolving disputes

Data Storage and Security

Transport security
Production browser traffic is redirected to HTTPS and protected with HSTS. The negotiated TLS version depends on the deployment's TLS terminator. SMTP delivery requires TLS 1.2 or 1.3 with certificate and hostname verification; production tenant-configured public HTTP destinations require HTTPS.
Application encryption
Managed secret values and webhook signing secrets are encrypted by the application with AES-256-GCM. Other account and operational database rows are not encrypted by the application; disk, database, and backup encryption depend on the deployment's infrastructure.
Scoped credentials
Service-agent credentials use scoped tokens with least-privilege access and stored credential verifiers are one-way digests. Managed values use the configured PostgreSQL or AWS Secrets Manager provider; the in-memory provider is limited to development and test.

Data Retention

Retention is dataset-specific rather than plan-based. Workspace trace and eval-run defaults are 90 and 180 days, but automatic purge is off until a workspace admin enables it. Usage events are kept for 30 days; delivered, read, and failed agent messages for 90 days; pending and queued messages are not removed by that cleanup. Raw fleet diagnostics are kept for 30 days after the telemetry-rollup backfill has run (otherwise 90 days), minute rollups and telemetry batch records for 90 days, and hourly rollups for 400 days. Other account, configuration, and audit records have no general automatic expiry. The Service does not currently promise automatic account deletion within a fixed period. Workspace owners and admins can use the operator API for supported exports and deletion of trace, eval-run, and eligible audit-event data, or contact us about a broader request.

Data Sharing

We do not sell your personal data. We share data only with: (a) service providers who assist in operating the platform (payment processing, infrastructure hosting, and website analytics); (b) law enforcement when required by law; (c) workspace members as configured by workspace administrators; and (d) webhook, connector, eval, and AI service destinations configured by a workspace administrator.

Your Rights (GDPR)

Access and portability
Workspace owners and admins can export supported trace, eval-run, and optional audit-event data through the operator API, or contact us for a broader request.
Rectification
Update your account information through the settings page or operator API.
Erasure
Workspace owners and admins can delete supported workspace datasets through the data controls API. Contact us for requests outside that supported scope.
Objection and restriction
Object to processing or request restriction of specific data processing activities.

Cookies and Tracking

We use an encrypted session cookie (_agent_ops_key) and, when selected, a signed remember-me cookie. Theme, density, and sidebar preferences are stored in browser local storage rather than cookies. Browser LiveView connections use the signed-in session; service-agent WebSocket connections use scoped socket tokens.

Every page using the standard application layout loads an Umami analytics script from analytics.llmotions.com, including public, legal, and signed-in console pages. Requests to that third party disclose network and browser metadata such as IP address, user agent, page URL, and referrer, and the script records website usage. The application does not currently provide a setting that disables this script. The credential-bearing marketplace SSO handoff deliberately uses a separate layout without analytics. We do not integrate an advertising network or intentionally set an advertising cookie.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

Contact

For privacy-related inquiries, please visit our contact page or refer to our Terms of Service .