Privacy Policy
Last updated: June 13, 2026
Server4Agent, Inc. (“we,” “our,” or “us”), located at 440 N Wolfe Rd, Sunnyvale, CA 94085, USA, operates a platform that provisions and runs compute servers for AI agents. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it. We collect only what we need to run the service.
1. Data we collect
We collect the following categories of data:
- Account data. Your email address, password hash, and any profile information you provide at sign-up or in settings.
- Billing data. Payment method details processed by our payment processor (Stripe). We store only a tokenised reference; we never see or store your full card number.
- API keys and secrets. Keys you create to authenticate agents, and secrets you store in the encrypted secrets vault. Recoverable secret values are encrypted at rest and decrypted only to provide requested product functionality.
- Server and project data. Configuration you provide when creating servers and projects: tier, slug, visibility settings, and deployed code.
- Usage and logs. Compute metrics (CPU, memory, bandwidth), request logs, build logs, and error traces needed to run, monitor, and bill the service.
- Communications data. Messages you send us through the contact form or support email.
- Technical metadata. IP address, browser or agent user-agent string, and session tokens collected automatically when you access the dashboard or API, or submit a form such as the waitlist signup.
2. How we use your data
- Providing the service. Provisioning servers, routing API traffic, enforcing budget caps, and delivering webhooks.
- Billing and metering. Calculating usage, generating invoices, and processing payments.
- Security and abuse prevention. Detecting malicious activity, isolating untrusted workloads, and protecting the platform and other users.
- Service communications. Transactional emails (receipts, password resets, quota alerts). We do not send marketing email without opt-in consent.
- Product improvement. Aggregate, anonymised usage statistics to understand how the platform is used and to prioritise improvements. We do not correlate these statistics back to individual accounts for any purpose other than the service itself.
- Legal compliance. Responding to lawful requests from authorities, or resolving disputes and enforcing our agreements.
Legal bases (EEA, UK, and Swiss users). We rely on one or more of the following legal bases for each purpose above: performance of a contract (providing and operating the Service you signed up for), legitimate interests (security, abuse prevention, and product improvement, weighed against your rights and interests), legal obligation (tax, accounting, and regulatory compliance), and consent (for optional marketing communications, which you can withdraw at any time without affecting processing carried out before withdrawal).
Automated decision-making. We do not currently carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. If that changes, we will update this policy and provide the information required by applicable law before doing so.
3. AI and model training
We do not use your code, agent prompts, file contents, or any other customer content to train, fine-tune, or evaluate AI or machine-learning models, ours or anyone else's. Your content is processed solely to operate the service on your behalf.
Infrastructure-level telemetry (request counts, latency histograms, error rates) may be used to improve platform reliability; this data is always aggregated and stripped of content before any analysis.
4. Data sharing and subprocessors
We do not sell your personal data. We share it only with the subprocessors needed to operate the service:
- Payment processing: Stripe. For billing and subscription management.
- Cloud infrastructure. The compute providers that host your servers. Their data centres process your workloads; they operate under data-processing agreements with us.
- Transactional email. For delivering account and billing emails.
- Error tracking and observability. Tools used to detect and diagnose platform issues. These receive only technical metadata, never customer content.
We may also disclose data when required by law, court order, or to protect the rights, property, or safety of Server4Agent, our users, or the public.
If you are a business customer, and personal data about your own end users passes through Servers or Projects you operate, we act as a processor (or “service provider” under the CCPA) on your behalf, and you remain the controller of that data. Email privacy@server4agent.com to request our standard Data Processing Addendum (DPA) for GDPR/UK GDPR purposes.
5. Data retention
We retain account data for as long as your account is active and for up to 90 days after deletion (to allow recovery and to resolve disputes). Billing records are kept for seven years as required by financial regulations. Server logs and usage metrics are retained for 30 days and then deleted or anonymised. You may request earlier deletion (see Section 7).
6. Security
We encrypt data in transit (TLS 1.2+) and at rest (AES-256). Secrets vault values are encrypted with keys you do not share with us. We enforce access controls internally and conduct periodic security reviews. Despite these measures, no system is perfectly secure; we will notify you promptly in the event of a breach that affects your personal data, as required by applicable law.
7. Your rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access. Request a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete data.
- Deletion. Request deletion of your account and associated personal data, subject to legal retention obligations.
- Portability. Receive your data in a machine-readable format.
- Objection / restriction. Object to or restrict certain processing activities.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting prior processing.
- Lodge a complaint. If you are in the EEA, UK, or Switzerland, you may lodge a complaint with your local data protection supervisory authority. We'd appreciate the chance to address your concern directly first.
To exercise any of these rights, email privacy@server4agent.com. We will respond within 30 days. California residents may also submit requests under the CCPA using the same address.
California residents (CCPA/CPRA). We do not sell personal data, and we do not share it for cross-context behavioural advertising. The categories of data we collect and why are described in Sections 1 and 2 above. You have the right to know, delete, correct, and not be discriminated against for exercising these rights.
8. Cookies and tracking
We use a session cookie to keep you logged in and a CSRF token cookie for security. On our public marketing pages we also use third-party analytics and conversion-tracking technologies to measure traffic and the performance of our campaigns; these may set cookies and share limited event data with those providers. These analytics and advertising technologies are non-essential and load only after you accept them in our cookie banner; you can decline, or later block or delete their cookies through your browser settings. We also honour Global Privacy Control signals, treating them as a decline.
9. International data transfers
Your data may be processed in countries outside your own, including the United States. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms approved under applicable data protection law.
10. Children's privacy
The service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently done so, contact us and we will delete it promptly.
11. Changes to this policy
We may update this policy as the service evolves. We will notify you by email and update the “Last updated” date at the top. For material changes, we will provide at least 30 days' notice before the change takes effect.
12. Contact
Questions or concerns about this policy? Email privacy@server4agent.com or write to us at Server4Agent, Inc., 440 N Wolfe Rd, Sunnyvale, CA 94085, USA.