Privacy Policy

Last updated: 4th August 2026 Version: 1.0


1. Who we are

Agnis is an AI workspace that stores context about you and your work and uses it to produce answers, documents and other output.

For the purposes of UK data protection law, the data controller is:

Nimble Technology Group Ltd. 16208557, 32 Trafalgar House, Juniper Drive, London, SW18 1GY Email: privacy@agnis.io

Roles: controller and processor

Our role depends on the data:

  • For your account data (name, email, billing, usage records), we are the controller.
  • For the content you put into Agnis — your context items, chats, documents and uploaded files — we act as a processor on your behalf where that content contains personal data about other people. You are the controller of that content and you decide what goes into it. Section 12 explains what this means for you.

2. What we collect

2.1 Information you give us

DataWhere it comes fromWhy
First name, last nameYou, at sign-upTo address you in the product
Email addressYou, at sign-upAccount identity, sign-in, service emails, password reset
PasswordYou, at sign-upAuthentication. Stored only as a salted hash by our authentication provider, we never see your password
Your context content, profile, business and role information, project and layer context, chats, documents, emails and posts you createYou, as you use AgnisThis is the product. It is stored so it can be reused and inherited by your later work
Files you upload, documents, spreadsheets, presentations, PDFs, imagesYouSo Agnis can read them and use them as context
Voice input, if you use dictationYouSee section 6, this is processed by your browser, not by us
Your own AI provider API keys, if you add them ("BYOK")YouSo your requests run on your provider account. Encrypted at rest with AES-256-GCM. Only ever decrypted server-side at the moment of use; never readable by your browser and never displayed back to you
Payment details, once paid plans launchYou, via our payment providerBilling. We do not store card numbers, our payment provider does

2.2 Information generated by your use

DataWhy
Usage records: which model you used, token counts, estimated cost, timestamps, which chat or layer a call belonged toTo operate allowances and spend caps, to show you your own usage, and to work out what things cost
Your settings: selected model, effort level, caching preference, budgets and spend caps, disabled modelsTo make the product work the way you set it
Technical logs from our hosting and database providers, including IP address, browser user-agent, request paths and error tracesSecurity, abuse prevention, debugging and service reliability
Authentication cookiesTo keep you signed in. See section 9

2.3 What we do not collect

  • No analytics or tracking. At the time of writing, Agnis contains no analytics SDK, no advertising pixels, no session-recording and no third-party trackers. If that changes, this policy will be updated and, where the law requires it, we will ask for your consent first.
  • No special category data is requested. We do not ask for information about health, ethnicity, religion, sexual orientation, political opinions, trade union membership, biometrics or genetics. If you choose to put such information into your context or files, you are doing so on your own initiative and you should read section 12.
  • No children's data. Agnis is not for under-18s. See section 13.

3. Lawful bases

We must have a lawful basis for each purpose. Ours are:

PurposeLawful basis (UK GDPR Art. 6)
Creating and running your account; storing and processing your content so the product works; sending service emails such as confirmation and password resetContract, Art. 6(1)(b). We cannot provide Agnis without doing these things
Sending your requests and the relevant context to the AI provider you have selectedContract, Art. 6(1)(b)
Metering usage, applying allowances and spend caps, billingContract, Art. 6(1)(b)
Security, abuse prevention, rate limiting, debugging, keeping backupsLegitimate interests, Art. 6(1)(f). Our interest is running a secure, working service; we have considered your interests and consider this proportionate because the data involved is limited and technical
Understanding how the product is used in aggregate to improve itLegitimate interests, Art. 6(1)(f)
Marketing emails, if we ever send themConsent, Art. 6(1)(a), and PECR. Opt-in, withdrawable at any time
Complying with legal obligations, responding to lawful requestsLegal obligation, Art. 6(1)(c)

You can object to processing based on legitimate interests, see section 10.

4. AI model providers: what leaves Agnis

When you send a message, Agnis assembles the context you have chosen to include and sends it, with your message, to the AI provider whose model you selected. That transmission is the product. The provider processes it and returns a response.

Depending on which model you pick, that provider is one of:

ProviderModelsLocation of processing
Anthropic PBCClaudeUnited States
OpenAI, L.L.C.GPTUnited States
Google LLCGeminiUnited States
Moonshot AIKimiPeople's Republic of China

Things you should know:

  • You control which provider sees your data, by choosing the model. If you would rather no data went to a particular provider, do not select its models. You can also disable models you never want used, in Settings.
  • You control what context is sent. Agnis shows you the context travelling with each request and lets you switch items off per task. Turning something off means it is not transmitted.
  • Automatic model selection. If you leave model choice on Auto, Agnis picks a model for you, which means it picks the provider. If you need certainty about destination, select the model yourself.
  • We do not train AI models. Not on your content, not on anything. We do not build models.
  • Providers process under their own API terms. For the providers above, those terms currently state that data submitted through their APIs is not used to train their models. We rely on their terms; we cannot guarantee their conduct. Links are in the sub-processor list.
  • Web search. If a request uses web search, your search query is sent to the provider's search integration and out to the web. Do not put confidential information in something you expect to be searched.
  • Bring your own key. If you add your own API key, requests run against your account with that provider, under your contract with them. Your relationship on that data is directly with them.

5. International transfers

We are in the UK. Your data is stored in the European Union and is transmitted to providers in the United States and, if you select Kimi, China.

  • UK → EU. Our database, authentication, file storage and email are hosted in the EU (Ireland and Germany). The EU has recognised the UK as providing an adequate level of protection, and the UK recognises the EEA as adequate, so these flows need no additional safeguard.
  • UK → United States. Where a provider participates in the UK Extension to the EU–US Data Privacy Framework, we rely on the UK's adequacy regulations for it. Where a provider does not participate, we rely on the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with a transfer risk assessment.
  • UK → China. There is no equivalent UK extension, we will only run Moonshot on your keys where you are wholly responsible for the data being transferred.

You can ask us for details of the safeguard applying to a specific transfer: privacy@agnis.io.

6. Dictation and your microphone

Agnis uses your browser's built-in Web Speech API for dictation. This matters:

  • Audio is captured and transcribed by your browser, not by Agnis. We never receive audio.
  • In some browsers, Google Chrome in particular, that transcription is performed on the browser vendor's servers, meaning your speech may be sent to that vendor. That processing is governed by your browser vendor's privacy policy, not ours.
  • Agnis receives only the resulting text, and only once it appears in the message box.
  • If this concerns you, do not use the microphone button. Everything in Agnis works by typing.

7. How long we keep things

DataRetention
Account dataFor as long as your account exists
Your context, chats, documents and filesUntil you delete them, or your account is deleted. Note that deleting an item in the workspace is a "soft delete" — it disappears from your view immediately and is purged from our database within 30 days
Uploaded filesAs above, plus removal from file storage
BYOK API keysUntil you remove the key or delete your account, at which point the encrypted record is deleted
Usage records24 months, for billing, accounting and dispute resolution
Technical and security logs90 days, unless retained longer for an active security investigation
BackupsRolling backups retained for up to 30 days; deleted data disappears from backups as they age out
Billing records6 years after the transaction, as UK tax law requires

After you delete your account we remove your personal data within 30 days, other than the billing records above and anything we are legally required to keep.

8. Security

  • All traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting providers.
  • Every database table enforces row-level security, so your rows are only reachable by your authenticated session. Access is isolated per account by default rather than by application logic alone.
  • BYOK API keys are encrypted with AES-256-GCM using a server-held key, are never sent to the browser, and are never displayed back to you after saving.
  • Uploaded files sit in private storage partitioned per user; there are no public file URLs.
  • Passwords are hashed by our authentication provider. We cannot see them.
  • Security headers, HSTS, and rate limiting are applied at the edge.

No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours as required, and tell you without undue delay where the risk is high.

9. Cookies

Agnis sets a small number of cookies. We do not use advertising or tracking cookies.

CookiePurposeTypeDuration
sb-<project>-auth-token (and related)Keeps you signed in; issued by our authentication providerStrictly necessarySession / until sign-out or expiry

Strictly necessary cookies do not require consent under PECR, which is why Agnis does not show a cookie banner. Some preferences (such as which panels you have collapsed) are kept in your browser's local storage, not in cookies, and never leave your device.

10. Your rights

Under UK GDPR you have the right to:

  • Be informed, this policy
  • Access a copy of your personal data
  • Rectify inaccurate data
  • Erasure, ask us to delete your data
  • Restrict processing
  • Data portability, receive your data in a structured, commonly used, machine-readable format. Your content is stored as plain Markdown. Self-serve export is not yet available in the product, so ask us and we will send you a copy within one month
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Not be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions. Agnis generates content at your instruction; it does not decide anything about you
  • Withdraw consent where we relied on it

To exercise any of these, email privacy@agnis.io. We will respond within one month. We will not charge you or make it difficult.

Complaints

If you are unhappy with how we have handled your personal data, tell us first, privacy@agnis.io. We will acknowledge your complaint within 30 days and respond without undue delay.

You can also complain to the ICO at any time: ico.org.uk/make-a-complaint, 0303 123 1113.

11. Automated content generation

Agnis produces text using AI models. You should know:

  • Output can be wrong, outdated, biased or fabricated, including where it sounds confident and cites sources.
  • Output is not professional advice of any kind.
  • You are responsible for checking anything you rely on or publish.
  • Because the same context can produce different output on different runs, output is not reproducible.

12. If you put other people's data into Agnis

Much of what you write into Agnis will mention other people, colleagues, clients, prospects, suppliers.

Where that happens you are the controller of that content and we process it on your instructions. That means:

  • You need your own lawful basis for putting it there.
  • You should tell the people concerned, in your own privacy notice, that you use AI tools in your work.
  • You should not upload special category data, and should think hard before uploading anything confidential, privileged or subject to a duty of confidence.
  • Your context will be transmitted to the AI provider you select, in the country listed in section 4. If you are handling client data under a contract that restricts where it can go, check that contract first.
  • If you need a data processing agreement with us before doing this, ask: privacy@agnis.io.

13. Age

Agnis is for people aged 18 or over and is intended for professional use. We do not knowingly collect data from children. If you believe a child has created an account, contact privacy@agnis.io and we will delete it.

14. Changes

We will update this policy as the product changes. The version and date are at the top. For material changes we will notify you by email or in the product before they take effect, and where the change requires it, ask you to accept the new version.

15. Contact

Nimble Technology Group Ltd. privacy@agnis.io