Privacy Policy
Last updated: 4th August 2026 Version: 1.0
1. Who we are
Agnis is an AI workspace that stores context about you and your work and uses it to produce answers, documents and other output.
For the purposes of UK data protection law, the data controller is:
Nimble Technology Group Ltd. 16208557, 32 Trafalgar House, Juniper Drive, London, SW18 1GY Email: privacy@agnis.io
Roles: controller and processor
Our role depends on the data:
- For your account data (name, email, billing, usage records), we are the controller.
- For the content you put into Agnis — your context items, chats, documents and uploaded files — we act as a processor on your behalf where that content contains personal data about other people. You are the controller of that content and you decide what goes into it. Section 12 explains what this means for you.
2. What we collect
2.1 Information you give us
| Data | Where it comes from | Why |
|---|---|---|
| First name, last name | You, at sign-up | To address you in the product |
| Email address | You, at sign-up | Account identity, sign-in, service emails, password reset |
| Password | You, at sign-up | Authentication. Stored only as a salted hash by our authentication provider, we never see your password |
| Your context content, profile, business and role information, project and layer context, chats, documents, emails and posts you create | You, as you use Agnis | This is the product. It is stored so it can be reused and inherited by your later work |
| Files you upload, documents, spreadsheets, presentations, PDFs, images | You | So Agnis can read them and use them as context |
| Voice input, if you use dictation | You | See section 6, this is processed by your browser, not by us |
| Your own AI provider API keys, if you add them ("BYOK") | You | So your requests run on your provider account. Encrypted at rest with AES-256-GCM. Only ever decrypted server-side at the moment of use; never readable by your browser and never displayed back to you |
| Payment details, once paid plans launch | You, via our payment provider | Billing. We do not store card numbers, our payment provider does |
2.2 Information generated by your use
| Data | Why |
|---|---|
| Usage records: which model you used, token counts, estimated cost, timestamps, which chat or layer a call belonged to | To operate allowances and spend caps, to show you your own usage, and to work out what things cost |
| Your settings: selected model, effort level, caching preference, budgets and spend caps, disabled models | To make the product work the way you set it |
| Technical logs from our hosting and database providers, including IP address, browser user-agent, request paths and error traces | Security, abuse prevention, debugging and service reliability |
| Authentication cookies | To keep you signed in. See section 9 |
2.3 What we do not collect
- No analytics or tracking. At the time of writing, Agnis contains no analytics SDK, no advertising pixels, no session-recording and no third-party trackers. If that changes, this policy will be updated and, where the law requires it, we will ask for your consent first.
- No special category data is requested. We do not ask for information about health, ethnicity, religion, sexual orientation, political opinions, trade union membership, biometrics or genetics. If you choose to put such information into your context or files, you are doing so on your own initiative and you should read section 12.
- No children's data. Agnis is not for under-18s. See section 13.
3. Lawful bases
We must have a lawful basis for each purpose. Ours are:
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; storing and processing your content so the product works; sending service emails such as confirmation and password reset | Contract, Art. 6(1)(b). We cannot provide Agnis without doing these things |
| Sending your requests and the relevant context to the AI provider you have selected | Contract, Art. 6(1)(b) |
| Metering usage, applying allowances and spend caps, billing | Contract, Art. 6(1)(b) |
| Security, abuse prevention, rate limiting, debugging, keeping backups | Legitimate interests, Art. 6(1)(f). Our interest is running a secure, working service; we have considered your interests and consider this proportionate because the data involved is limited and technical |
| Understanding how the product is used in aggregate to improve it | Legitimate interests, Art. 6(1)(f) |
| Marketing emails, if we ever send them | Consent, Art. 6(1)(a), and PECR. Opt-in, withdrawable at any time |
| Complying with legal obligations, responding to lawful requests | Legal obligation, Art. 6(1)(c) |
You can object to processing based on legitimate interests, see section 10.
4. AI model providers: what leaves Agnis
When you send a message, Agnis assembles the context you have chosen to include and sends it, with your message, to the AI provider whose model you selected. That transmission is the product. The provider processes it and returns a response.
Depending on which model you pick, that provider is one of:
| Provider | Models | Location of processing |
|---|---|---|
| Anthropic PBC | Claude | United States |
| OpenAI, L.L.C. | GPT | United States |
| Google LLC | Gemini | United States |
| Moonshot AI | Kimi | People's Republic of China |
Things you should know:
- You control which provider sees your data, by choosing the model. If you would rather no data went to a particular provider, do not select its models. You can also disable models you never want used, in Settings.
- You control what context is sent. Agnis shows you the context travelling with each request and lets you switch items off per task. Turning something off means it is not transmitted.
- Automatic model selection. If you leave model choice on Auto, Agnis picks a model for you, which means it picks the provider. If you need certainty about destination, select the model yourself.
- We do not train AI models. Not on your content, not on anything. We do not build models.
- Providers process under their own API terms. For the providers above, those terms currently state that data submitted through their APIs is not used to train their models. We rely on their terms; we cannot guarantee their conduct. Links are in the sub-processor list.
- Web search. If a request uses web search, your search query is sent to the provider's search integration and out to the web. Do not put confidential information in something you expect to be searched.
- Bring your own key. If you add your own API key, requests run against your account with that provider, under your contract with them. Your relationship on that data is directly with them.
5. International transfers
We are in the UK. Your data is stored in the European Union and is transmitted to providers in the United States and, if you select Kimi, China.
- UK → EU. Our database, authentication, file storage and email are hosted in the EU (Ireland and Germany). The EU has recognised the UK as providing an adequate level of protection, and the UK recognises the EEA as adequate, so these flows need no additional safeguard.
- UK → United States. Where a provider participates in the UK Extension to the EU–US Data Privacy Framework, we rely on the UK's adequacy regulations for it. Where a provider does not participate, we rely on the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with a transfer risk assessment.
- UK → China. There is no equivalent UK extension, we will only run Moonshot on your keys where you are wholly responsible for the data being transferred.
You can ask us for details of the safeguard applying to a specific transfer: privacy@agnis.io.
6. Dictation and your microphone
Agnis uses your browser's built-in Web Speech API for dictation. This matters:
- Audio is captured and transcribed by your browser, not by Agnis. We never receive audio.
- In some browsers, Google Chrome in particular, that transcription is performed on the browser vendor's servers, meaning your speech may be sent to that vendor. That processing is governed by your browser vendor's privacy policy, not ours.
- Agnis receives only the resulting text, and only once it appears in the message box.
- If this concerns you, do not use the microphone button. Everything in Agnis works by typing.
7. How long we keep things
| Data | Retention |
|---|---|
| Account data | For as long as your account exists |
| Your context, chats, documents and files | Until you delete them, or your account is deleted. Note that deleting an item in the workspace is a "soft delete" — it disappears from your view immediately and is purged from our database within 30 days |
| Uploaded files | As above, plus removal from file storage |
| BYOK API keys | Until you remove the key or delete your account, at which point the encrypted record is deleted |
| Usage records | 24 months, for billing, accounting and dispute resolution |
| Technical and security logs | 90 days, unless retained longer for an active security investigation |
| Backups | Rolling backups retained for up to 30 days; deleted data disappears from backups as they age out |
| Billing records | 6 years after the transaction, as UK tax law requires |
After you delete your account we remove your personal data within 30 days, other than the billing records above and anything we are legally required to keep.
8. Security
- All traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting providers.
- Every database table enforces row-level security, so your rows are only reachable by your authenticated session. Access is isolated per account by default rather than by application logic alone.
- BYOK API keys are encrypted with AES-256-GCM using a server-held key, are never sent to the browser, and are never displayed back to you after saving.
- Uploaded files sit in private storage partitioned per user; there are no public file URLs.
- Passwords are hashed by our authentication provider. We cannot see them.
- Security headers, HSTS, and rate limiting are applied at the edge.
No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours as required, and tell you without undue delay where the risk is high.
9. Cookies
Agnis sets a small number of cookies. We do not use advertising or tracking cookies.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
sb-<project>-auth-token (and related) | Keeps you signed in; issued by our authentication provider | Strictly necessary | Session / until sign-out or expiry |
Strictly necessary cookies do not require consent under PECR, which is why Agnis does not show a cookie banner. Some preferences (such as which panels you have collapsed) are kept in your browser's local storage, not in cookies, and never leave your device.
10. Your rights
Under UK GDPR you have the right to:
- Be informed, this policy
- Access a copy of your personal data
- Rectify inaccurate data
- Erasure, ask us to delete your data
- Restrict processing
- Data portability, receive your data in a structured, commonly used, machine-readable format. Your content is stored as plain Markdown. Self-serve export is not yet available in the product, so ask us and we will send you a copy within one month
- Object to processing based on legitimate interests, and to direct marketing at any time
- Not be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions. Agnis generates content at your instruction; it does not decide anything about you
- Withdraw consent where we relied on it
To exercise any of these, email privacy@agnis.io. We will respond within one month. We will not charge you or make it difficult.
Complaints
If you are unhappy with how we have handled your personal data, tell us first, privacy@agnis.io. We will acknowledge your complaint within 30 days and respond without undue delay.
You can also complain to the ICO at any time: ico.org.uk/make-a-complaint, 0303 123 1113.
11. Automated content generation
Agnis produces text using AI models. You should know:
- Output can be wrong, outdated, biased or fabricated, including where it sounds confident and cites sources.
- Output is not professional advice of any kind.
- You are responsible for checking anything you rely on or publish.
- Because the same context can produce different output on different runs, output is not reproducible.
12. If you put other people's data into Agnis
Much of what you write into Agnis will mention other people, colleagues, clients, prospects, suppliers.
Where that happens you are the controller of that content and we process it on your instructions. That means:
- You need your own lawful basis for putting it there.
- You should tell the people concerned, in your own privacy notice, that you use AI tools in your work.
- You should not upload special category data, and should think hard before uploading anything confidential, privileged or subject to a duty of confidence.
- Your context will be transmitted to the AI provider you select, in the country listed in section 4. If you are handling client data under a contract that restricts where it can go, check that contract first.
- If you need a data processing agreement with us before doing this, ask: privacy@agnis.io.
13. Age
Agnis is for people aged 18 or over and is intended for professional use. We do not knowingly collect data from children. If you believe a child has created an account, contact privacy@agnis.io and we will delete it.
14. Changes
We will update this policy as the product changes. The version and date are at the top. For material changes we will notify you by email or in the product before they take effect, and where the change requires it, ask you to accept the new version.
15. Contact
Nimble Technology Group Ltd. privacy@agnis.io