Who we are
Overagent operates an API gateway that routes your requests to third-party language models and bills them against prepaid credit. We decide how the data described here is used, which makes us the controller of it.
For anything in this policy, including access and deletion requests, reach us through the channel on the support page.
Account data
When you register we store your email address and a hash of your password. We never store the password itself and cannot recover it. We also record the date you accepted the Terms of Service and which version you accepted, because we have to be able to show that acceptance happened.
API keys are stored as a hash plus a short visible prefix, so we can identify a key in your dashboard without being able to reproduce the secret. The full key is shown once, when you create it.
Request and usage data
For every request through the gateway we record which model you called, which key was used, token counts, latency, the status of the run, an error code when it fails, timestamps, and the cost. This is what produces your request history and your bill, so we cannot operate without it.
We store the model’s response text alongside that record so a request can be reconciled and replayed to you in the dashboard. We do not store your prompt text. If the content of a response is sensitive, ask us to delete the request record.
Billing data
Credit, charges, refunds, and reservations are recorded in a ledger tied to your account. Each top-up stores the amount, our order reference, the payment gateway’s invoice reference, the crypto network used, and the status the gateway reported.
Payments are handled by our crypto payment provider. Your funds and wallet addresses go through them, not through us: we never see or hold a card number, and we do not receive your wallet’s private keys. Their handling of your payment is governed by their own privacy policy.
Technical and security data
Our servers keep operational logs: the requested path, response status, timing, and the IP address the request came from. Sensitive actions on an account, such as connecting or removing an upstream credential, are written to an audit log with the actor, the action, and the originating IP address.
We keep these to investigate abuse, debug failures, and reconstruct what happened to an account. They are not used to profile you or to build an advertising audience.
Why we are allowed to hold it
Account, request, and billing data is processed because it is necessary to perform the contract you entered when you started using the service. Security logs and audit records are processed under our legitimate interest in keeping the service safe and available. Records we keep after your account closes are kept to satisfy tax and accounting obligations.
How long we keep it
Account, request, and ledger records stay while your account is open. When you ask us to delete your account, we remove your account data and your stored responses. Financial records connected to completed payments are retained for as long as tax and accounting rules require, even after the account is closed.
Operational logs are short-lived and are rotated out in the normal course of running the service.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable format. Depending on where you live, some of these are legal rights rather than courtesies; we honour them either way.
Much of it is already in your hands: your request history, ledger, payments, and keys are all in the dashboard, and request history can be exported to CSV at any time.
We respond to requests within 30 days. If you believe we have handled your data badly, you may complain to your local data protection authority.
How it is protected
Passwords are hashed, gateway API keys are stored only as hashes, and upstream provider credentials are encrypted before they are written to the database. Sessions use httpOnly cookies. The measures we take are described in more detail on the security page.
No system is perfectly secure. If a breach affects your data and creates a real risk to you, we will notify you and the relevant authority as the law requires.
International transfers
Our infrastructure, model providers, and payment provider may be located outside your country, so using the service involves transferring your data across borders. Where the law requires a safeguard for that transfer, we rely on standard contractual clauses or an equivalent mechanism.
Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
When this policy changes we update the version and effective date at the top of the page. If a change materially affects your rights, we will give notice in the dashboard or by email before it takes effect.
Contact
Questions about this policy, requests about your data, and privacy complaints all go to the channel listed on the support page.
Contact support