Skip to main content

    Privacy Policy

    Published privacy notice for the Agent Smith website and product. Related legal pages on this site are linked below and in the footer.

    Legal Notices — all published notices in one place.

    Effective date: 2026-08-16 · Last updated: 2026-08-16

    Controller: Alessandro Scire Calabrisotto, sole proprietor (registered firm The Swiss Standard by Alessandro Scire Calabrisotto), operating Agent Smith

    Address: Seebahnstrasse 121, 8003 Zürich, Switzerland

    Contact for privacy requests: support@agentsmith.ch

    Legal notices: legal@agentsmith.ch

    Overview

    This Privacy Policy explains what personal data we process, why we process it, who we share it with, how long we keep it, and the choices and rights available to you.

    It applies to personal data processed through:

    • our public website and marketing pages
    • the authenticated Agent Smith platform and workspaces
    • community/Academy features (where enabled)
    • public-by-link sharing pages (where used)

    This Privacy Policy should be read together with:

    Who we are

    The controller for personal data we process to operate the Service (for example: accounts, authentication, billing administration, website operations, and platform security) is:

    Contracting party:
    Alessandro Scire Calabrisotto
    sole proprietor (Einzelunternehmen), operating the “Agent Smith” service

    Registered firm name:
    The Swiss Standard by Alessandro Scire Calabrisotto

    Business address:
    Seebahnstrasse 121
    8003 Zürich
    Switzerland

    Commercial register: entered and active in the Commercial Register of the Canton of Zurich.
    Business identification number (UID): CHE-228.447.426
    Register reference: CH-020.1.087.436-7

    VAT: not registered for Swiss VAT. Swiss VAT liability begins at CHF 100,000 of annual turnover. No VAT is charged or shown on our prices or invoices at this time. If we become VAT-liable we will update this notice and state VAT separately before you are charged.

    Agent Smith is currently operated as a Swiss sole proprietorship, which has no legal personality separate from its owner. The controller is therefore Alessandro Scire Calabrisotto personally. The service is provided through his existing registered firm, The Swiss Standard by Alessandro Scire Calabrisotto, which is why the register entry does not read “Agent Smith” — Section 1 of the Beta Terms of Service explains that. We intend to incorporate a Swiss company (Aktiengesellschaft or Gesellschaft mit beschränkter Haftung) with its seat in Zurich or Zug; when we do, that company becomes the controller and we will update this policy and notify you. Section 1a of the Beta Terms of Service explains the transfer and your right to object by closing your account first.

    Contact for privacy matters: support@agentsmith.ch — or legal@agentsmith.ch for formal legal notices.

    If you upload or manage third-party data inside a workspace (for example: employee, customer, or client data), the workspace owner may be the controller for that data. In those cases, Agent Smith typically acts as a processor providing the Service. For B2B use, the DPA describes those roles more formally.

    DPO: We do not designate a Data Protection Officer at this time.

    EU representative: Not currently appointed. If required by GDPR Article 27, we will appoint an EU representative and publish contact details.

    Categories of personal data we process

    We process personal data that you provide, data created through your use of the Service, and limited technical data needed to operate and secure the platform.

    Below are typical categories (non-exhaustive examples):

    CategoryExamples (non-exhaustive)Typical source
    Account identityemail address, user ID, authentication/session infoyou + system-generated
    Profile/contactname, phone, bio, avatar, social links, timezoneyou
    Workspace/companyworkspace name, settings, document metadatayou + system-generated
    Member/teamroles, departments, skills, internal preferencesyou + workspace admins
    User contentuploads, documents, messages, postsyou
    AI-related contentprompts, outputs, suggestions, AI run logs (where enabled)you + system-generated
    Billingsubscription status, Stripe customer IDs, credit balancesyou + Stripe
    Support/adminwaitlist entries, feedback messages, attachments, support correspondenceyou
    Communitycommunity posts, reports, votes, moderation actionsyou
    IntegrationsOAuth tokens (stored encrypted where applicable), provider account IDsyou + providers
    Device/usage (limited)IP address (abuse prevention), user agent, page URLs, timestampssystem-generated

    Why we process personal data (purposes) and legal bases

    We process personal data for the following purposes.

    Provide and operate the Service (contract)

    We process personal data to authenticate users, operate accounts, enable workspace collaboration, handle files, deliver features (including AI features when used), and provide customer support.

    Legal basis: performance of a contract.

    Safety, security, and abuse prevention (legitimate interests)

    We process limited technical data (such as IP address and logs) to protect users and the Service, prevent abuse, enforce rate limits, investigate suspicious activity, and maintain platform integrity.

    Legal basis: legitimate interests (where applicable).

    Billing and payments (contract and/or legal obligations)

    If you use paid features, we process billing identifiers, subscription status, and payment metadata to administer purchases, invoices, account credits, and refunds (if granted).

    Legal basis: performance of a contract and/or legal obligations (accounting/recordkeeping).

    Communications (contract; consent where required)

    We send transactional communications such as sign-in links, invites, security messages, and billing notices.

    If we offer marketing communications, we will send them only if you opt in (and you can unsubscribe at any time).

    Legal basis: contract for transactional messages; consent for marketing where required.

    Product improvement (legitimate interests)

    We may process limited usage and diagnostic information to improve reliability and user experience during beta (for example: bug reports and aggregated service performance signals). Where possible, we aim to minimize personal data for this purpose.

    Legal basis: legitimate interests.

    Automated decisions: We do not intend to make decisions based solely on automated processing that produces legal or similarly significant effects. If that changes, we will update this policy and provide required information.

    AI processing and transparency

    Agent Smith includes AI-powered features (for example: chat, drafting, suggestions, summarization, and optional background workflows depending on workspace settings).

    When you use AI-powered features, the content you submit (such as messages, prompts, and any attachments you choose to include) may be processed by third-party AI providers in order to generate outputs.

    Active inference providers may include:

    • OpenRouter (model routing)
    • OpenAI
    • Anthropic
    • Google (Gemini)
    • xAI (Grok)
    • NVIDIA (Nemotron)
    • DeepSeek

    We do not train our own models on your prompts or files.

    For non-free text models routed through OpenRouter, we request Zero Data Retention (ZDR) and deny provider data collection. OpenRouter then restricts the request to endpoints that declare those controls. OpenRouter still keeps request metadata such as token counts and latency, but not prompt or response content unless account-level content logging is enabled.

    NVIDIA Nemotron Free exception: This free route is not covered by the paid-route ZDR/no-collection control. Its upstream notice states that submitted content may be logged and used to improve NVIDIA products and services. Do not submit confidential, personal, regulated, privileged, credential-bearing, or secret workspace data through the Free model.

    A direct-provider fallback does not inherit OpenRouter's per-request ZDR setting. It follows that provider's API retention and no-training terms and our applicable agreement. We do not describe a direct route as ZDR unless it is separately configured and verified. For more information, see the Subprocessor List and AI Transparency, Human Review & Limitations Notice.

    Public website assistant and voice: If you use the public website assistant or voice transcription features, your inputs (including audio where you enable voice) may be processed by AI providers to generate a response or transcription.

    Sharing and visibility

    Some features can make data visible to others. You should understand these visibility settings before sharing content.

    Workspaces and members

    Workspace owners/admins control membership and roles. Workspace data is generally visible to workspace members based on role and settings.

    Some profile or contact details may be visible to workspace members depending on visibility configuration.

    Public-by-link sharing

    If you create a share link, content shared through that link may be accessible to anyone with the URL. Links can be forwarded by recipients.

    Share links do not automatically expire by default at this stage. You should revoke share links when you no longer want the content accessible. See the Share-Link Warning Notice.

    Community/Academy content

    If you post in community areas, your posts may be visible to other authenticated users. Do not post confidential or sensitive information you do not have permission to share.

    Public avatars

    Profile avatars may be publicly accessible. If you do not want a public avatar, do not upload one or replace it with a non-identifying image.

    Who we share data with

    We share personal data with service providers ("subprocessors") that help us run the Service. Examples include:

    • hosting/auth/database/storage providers (such as Supabase)
    • billing providers (such as Stripe)
    • email delivery providers (such as Resend)
    • AI providers (as listed above)
    • optional security/diagnostic tools (such as error monitoring) if enabled
    • captcha providers if enabled for abuse prevention
    • integration providers that you choose to connect

    We do not sell personal data.

    For the current list and categories, see our Subprocessor List.

    Embedded video on our public pages

    Some public pages — currently our Investors page — embed a video hosted on YouTube (Google Ireland Limited). We use a click-to-play embed: until you press play, the video is a still image served from our own servers and no request is made to YouTube or Google, and no cookies are set by them.

    If you press play, the player loads from youtube-nocookie.com, Google’s reduced-tracking host. At that point YouTube receives your IP address, browser and device information, and the page you played it from, and may set storage on your device. That processing is Google’s, under its own privacy policy — it is not something we control or receive. You can avoid it entirely by not pressing play; where an alternative link to the publisher’s own site exists, we provide it alongside.

    Social media platform integrations

    Agent Smith offers a social media scheduling tool at /tools/social that publishes posts to third-party platforms on your behalf. To do this, we ask you to authorize Agent Smith with each platform via OAuth — you complete the platform’s own consent screen, and the platform issues us an access token scoped to the permissions you approve.

    Currently available:

    • LinkedIn — personal profile posting via the w_member_social scope; profile metadata via openid profile email. We call api.linkedin.com directly using the OAuth token you authorize.

    Coming soon (subject to platform review):

    • Facebook Pages — publishing via the Meta Graph API with scopes pages_show_list pages_read_engagement pages_manage_posts.
    • Instagram Business accounts — publishing via the Meta Graph API with scopes instagram_basic instagram_content_publish. Requires that the Instagram account is linked to a Facebook Page you administer.
    • YouTube — uploading videos via the YouTube Data API v3 with the youtube.upload scope.
    • TikTok — pending Content Posting API access (TikTok TSP partnership).
    • X (formerly Twitter) — paused; the X free tier is unsuitable for multi-tenant scheduling and we have not enabled the paid tier.

    How we handle the tokens: the OAuth access tokens (and refresh tokens, where issued) are stored in our database with authenticated encryption (pgsodium AEAD), readable only by service-role server code and never exposed in the client UI. We use the tokens solely to (a) publish posts you schedule and (b) fetch the basic account profile we display on /tools/social/connections.

    When posts go live: a post you schedule is published live to the connected platform at the scheduled time. There is no draft preview after the scheduled moment.

    Disconnect at any time: use the Disconnect button on /tools/social/connections to delete the stored token and revoke our ability to publish on your behalf. You can also revoke authorization directly from each platform’s account settings (LinkedIn, Facebook, etc.). When you delete your Agent Smith account, all stored tokens for your account are deleted along with the account row.

    What we do not do: we do not read your private messages, browse your contacts, or post anything you have not explicitly scheduled. The OAuth scopes we request are listed above and limited to the functionality of the scheduler.

    The platform’s own terms apply: your use of LinkedIn, Meta’s products (Facebook / Instagram), YouTube, TikTok, and X is also subject to each platform’s respective Terms of Service and Privacy Policy. Agent Smith is not responsible for actions you take or content you publish to those platforms.

    International data transfers

    We operate from Switzerland.

    Switzerland is recognized by the European Commission as providing an adequate level of data protection, which supports EU-to-Switzerland transfers in many cases.

    Some subprocessors (including AI providers and payment providers) may process data outside Switzerland and the EEA. Where required, transfers are made using appropriate safeguards (for example, Standard Contractual Clauses) or other lawful transfer mechanisms.

    Retention

    We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required by law.

    Because Agent Smith is in beta, our retention practices are evolving. Our current retention targets include:

    • Account deletion: remove access promptly; aim to complete deletion typically within ~30 days (timing may vary for security/legal reasons).
    • Workspace deletion: target completion within ~30 days, subject to confirmation flows and security/legal needs.
    • Billing records: retained for accounting and legal compliance for the minimum required period.
    • Security and abuse-prevention logs: retained for a limited period needed to prevent abuse and investigate incidents.

    Backups: Data may remain in backups for a limited period and be deleted according to our backup rotation schedule. We continue to protect backup data and do not restore deleted data to active systems except where required for incident recovery.

    Your rights (EEA/UK)

    If you are in the EEA/UK, you may have rights including:

    • access to your personal data
    • correction (rectification)
    • deletion (erasure), subject to legal obligations
    • restriction of processing
    • objection to processing in certain cases
    • data portability (where applicable)
    • withdrawal of consent (where processing is based on consent)

    We aim to respond without undue delay and within one month. For complex requests, we may extend by up to two additional months and will inform you.

    To exercise rights, email: support@agentsmith.ch

    If a workspace owner is the controller for specific data (for example, employee/customer data uploaded by a company), we may direct you to the workspace owner and assist them as required.

    Complaints

    If you are in the EEA/UK, you can lodge a complaint with your local supervisory authority.

    Security

    We use technical and organizational measures intended to protect the confidentiality, integrity, and availability of the Service. This includes access controls, workspace-scoped restrictions, and security monitoring.

    No system is perfectly secure. You are responsible for keeping your email account secure, since email-based authentication is used for sign-in.

    Contact

    Privacy requests: support@agentsmith.ch

    Legal notices: legal@agentsmith.ch