overagent
ModelsDocsTermsSupport
Sign inGet started
Legal

Privacy Policy

Effective August 13, 2026 · Version 2026-08-13

This describes the data Overagent holds about you, why it is held, who else sees it, and what you can ask us to do with it. It covers the website, the dashboard, and the API gateway.
01

Who we are

Overagent operates an API gateway that routes your requests to third-party language models and bills them against prepaid credit. We decide how the data described here is used, which makes us the controller of it.

For anything in this policy, including access and deletion requests, reach us through the channel on the support page.

02

Account data

When you register we store your email address and a hash of your password. We never store the password itself and cannot recover it. We also record the date you accepted the Terms of Service and which version you accepted, because we have to be able to show that acceptance happened.

API keys are stored as a hash plus a short visible prefix, so we can identify a key in your dashboard without being able to reproduce the secret. The full key is shown once, when you create it.

03

Request and usage data

For every request through the gateway we record which model you called, which key was used, token counts, latency, the status of the run, an error code when it fails, timestamps, and the cost. This is what produces your request history and your bill, so we cannot operate without it.

We store the model’s response text alongside that record so a request can be reconciled and replayed to you in the dashboard. We do not store your prompt text. If the content of a response is sensitive, ask us to delete the request record.

04

Billing data

Credit, charges, refunds, and reservations are recorded in a ledger tied to your account. Each top-up stores the amount, our order reference, the payment gateway’s invoice reference, the crypto network used, and the status the gateway reported.

Payments are handled by our crypto payment provider. Your funds and wallet addresses go through them, not through us: we never see or hold a card number, and we do not receive your wallet’s private keys. Their handling of your payment is governed by their own privacy policy.

05

Technical and security data

Our servers keep operational logs: the requested path, response status, timing, and the IP address the request came from. Sensitive actions on an account, such as connecting or removing an upstream credential, are written to an audit log with the actor, the action, and the originating IP address.

We keep these to investigate abuse, debug failures, and reconstruct what happened to an account. They are not used to profile you or to build an advertising audience.

06

Cookies and local storage

We set one cookie: your session, which keeps you signed in. It is httpOnly, so page scripts cannot read it, and removing it signs you out. Your theme and language preferences are stored in your browser and never sent to us as identifiers.

There are no advertising cookies, no third-party analytics, and no tracking pixels on this site.

07

Who else sees your data

Model providers. To answer a request, the content you send is transmitted to the upstream provider that serves the model you selected. They process it under their own terms. Do not send anything through the gateway that you are not permitted to share with a third-party model provider.

Payment provider. Top-ups are processed by our crypto payment gateway, which receives the amount and our order reference.

Infrastructure. Hosting, database, and queue providers process data on our behalf under contract and may not use it for their own purposes.

Legal. We disclose data when a valid legal obligation requires it, or where it is necessary to establish or defend a legal claim. We do not sell your data and we do not share it for advertising.

08

Why we are allowed to hold it

Account, request, and billing data is processed because it is necessary to perform the contract you entered when you started using the service. Security logs and audit records are processed under our legitimate interest in keeping the service safe and available. Records we keep after your account closes are kept to satisfy tax and accounting obligations.

09

How long we keep it

Account, request, and ledger records stay while your account is open. When you ask us to delete your account, we remove your account data and your stored responses. Financial records connected to completed payments are retained for as long as tax and accounting rules require, even after the account is closed.

Operational logs are short-lived and are rotated out in the normal course of running the service.

10

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable format. Depending on where you live, some of these are legal rights rather than courtesies; we honour them either way.

Much of it is already in your hands: your request history, ledger, payments, and keys are all in the dashboard, and request history can be exported to CSV at any time.

We respond to requests within 30 days. If you believe we have handled your data badly, you may complain to your local data protection authority.

11

How it is protected

Passwords are hashed, gateway API keys are stored only as hashes, and upstream provider credentials are encrypted before they are written to the database. Sessions use httpOnly cookies. The measures we take are described in more detail on the security page.

No system is perfectly secure. If a breach affects your data and creates a real risk to you, we will notify you and the relevant authority as the law requires.

12

International transfers

Our infrastructure, model providers, and payment provider may be located outside your country, so using the service involves transferring your data across borders. Where the law requires a safeguard for that transfer, we rely on standard contractual clauses or an equivalent mechanism.

13

Children

The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.

14

Changes to this policy

When this policy changes we update the version and effective date at the top of the page. If a change materially affects your rights, we will give notice in the dashboard or by email before it takes effect.

15

Contact

Questions about this policy, requests about your data, and privacy complaints all go to the channel listed on the support page.

Contact support
overagent
ModelsDocsTermsPrivacySupportSign inCreate account
© 2026 Overagent