Privacy Policy
Last updated: July 20, 2026.
This Privacy Policy explains what data AnyAgent HQ (operated by Billie-Tech Ltd.) collects, why, and how it's handled when you use our website, portal, or the chat widget you install on your own site.
1. What we collect
- Account data: email address, hashed password (or Google account id if you sign in with Google), and the businesses (tenants) you own.
- Content you provide: documents, URLs, branding, and instructions you upload to train your agent.
- Conversation data:messages sent to your agent (by you in Test chat, or by your website's visitors) and the answers it gives, so you can review conversations and we can operate the Service.
- Billing data: we never see or store your card number — PayPal handles payment details directly and gives us only a subscription id and status.
- Usage & log data: pages visited, IP address, and basic device/browser info, for security and abuse prevention.
2. How we use it
- To operate and improve the Service (train and serve your agent, show your dashboard);
- To process payments and manage subscriptions via PayPal;
- To send account, billing, and (if you opt in) product emails;
- To prevent abuse and enforce our Terms of Service.
3. Third parties we share data with
Data is shared only as needed to run the Service:
- AI providers (e.g. Anthropic, OpenAI, or another provider you configure) — to generate answers from your knowledge base and conversation history.
- PayPal — to process subscription payments.
- Resend — to send transactional email (password resets, receipts).
- Infrastructure providers hosting our database and servers.
We do not sell your data or your customers' conversation data to third parties.
4. Google Calendar & Calendly (meeting scheduling)
If you connect Google Calendarso your agent can book meetings, we ask Google for permission to (a) read your primary calendar's free/busy information and (b) create calendar events. Free/busy data is used only to compute the open time slots the agent offers in chat — we never read the titles, descriptions, attendees, or any other details of your existing events. When one of your visitors confirms a time, we create a single event on your calendar (containing the visitor's name, email, and optional note, plus a Google Meet link); Google sends the invitation emails. We store your Google account email (so your portal shows which account is connected) and an encrypted OAuth refresh token; we never see your Google password. Google user data is used solely to provide the scheduling feature you enabled — it is never sold, never used for advertising, never used to train AI models, and never shared with third parties. You can disconnect at any time from the Scheduling tab (which deletes the stored token) or revoke access at myaccount.google.com/permissions.
AnyAgent HQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect Calendlyinstead, we store the Personal Access Token you paste (encrypted), read the availability of the event type you choose, and share Calendly's own booking links in chat; booking itself happens on Calendly's page. Disconnecting deletes the stored token. Booked-meeting records (time, visitor name and email, optional note, meeting link) are stored in your tenant's isolated data so you can review them in your portal.
5. Data isolation
Each business's data is isolated at the database level (row-level security) — one tenant cannot read another's documents, conversations, or settings.
6. Data retention
We retain account and conversation data for as long as your account is active, plus a reasonable period afterward for backups and legal compliance. You can request deletion — see "Your rights" below.
7. Cookies
We use a small number of essential cookies: a signed session cookie for the portal (sap_admin/sap_user) and a per-browser session id for the widget (zl_session, in your visitors' localStorage) so conversations survive a page reload. We don't use third-party advertising cookies.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data. Email hello@anyagenthq.com to make a request.
9. Data deletion requests
You can request deletion of your personal data at any time, whether you interacted with us directly or through a third-party login (such as Facebook or Google):
- Email hello@anyagenthq.comfrom the address associated with your account, with the subject "Data deletion request".
- We will delete your account data, uploaded documents, and conversation history within 30 days, and confirm by email when it's done. Backup copies are purged on their normal rotation schedule shortly after.
- If you connected a messaging channel (e.g. WhatsApp, Telegram, or Slack), disconnecting it in your portal immediately removes the stored credentials; the deletion request above covers any remaining conversation history.
10. Changes to this policy
We may update this policy from time to time; material changes will be posted here.
11. Contact
Questions about this policy? Email hello@anyagenthq.com.
