Aglet

Privacy Policy

This Policy explains how Remodeled AI, LLC collects, uses, shares, retains, and protects information when you use Aglet or visit agletai.com.

Effective: August 30, 2026

1. Scope and roles

This Policy covers Aglet's website, application, support, and related services. Remodeled AI, LLC is the controller of account, website, billing, and service-administration information. For software telemetry, customer feedback, repository context, and other content a workspace submits on behalf of its users or customers, Remodeled AI, LLC generally acts as that workspace's service provider or processor.

A separate data-processing agreement may apply. If a workspace controls your data, direct the request to that workspace first; we will assist it as required by the agreement and applicable law.

2. Information we collect

  • Account and workspace informationName, email address, preferred name, language, time zone, workspace and project details, membership, and settings.
  • Authentication and security informationPassword hashes, verification state, sessions, timestamps, IP-derived security context, user agent, failed sign-in dimensions, and audit records.
  • Customer DataSignals, events, telemetry, feedback, Work Items, comments, labels, service and environment context, deployment references, agent records, proposed actions, approvals, and verification evidence submitted or created in a workspace.
  • Connection informationProvider identifiers, selected repositories or services, connection health, scoped credential records, and provider delivery metadata. Readable application keys are shown only when created and are stored as one-way fingerprints where supported.
  • Billing informationPlan, billing email, Stripe customer and subscription identifiers, invoice and payment status, and entitlement history. Stripe receives and stores payment-card and bank information; Aglet does not store full card details.
  • Website and support informationPages requested, device and browser information, essential cookies, messages you send, and diagnostic information needed to answer or secure a request.

3. How we use information

Provide Aglet
Create accounts, keep workspaces separate, process submitted evidence, group related reports, manage work, deliver email, and operate enabled connections.
Secure and support the service
Authenticate users, prevent abuse, redact recognized secrets, diagnose failures, preserve audit history, answer support requests, and recover from incidents.
Administer billing
Create Stripe-hosted checkout and portal sessions, reconcile verified subscription events, apply plan limits, and maintain accounting records.
Improve Aglet
Analyze deidentified or aggregated usage, evaluate reliability, and improve workflows. We do not sell Customer Data or use one customer's Customer Data to train a general-purpose model for other customers.
Meet legal obligations
Comply with law, enforce agreements, protect rights and safety, prevent fraud, and respond to valid legal process.

4. Legal bases

Where a legal basis is required, we process information to perform a contract, pursue legitimate interests in providing and securing Aglet, comply with legal obligations, and act with consent where required. You may withdraw consent for future processing, but that does not affect processing already completed or processing based on another lawful basis.

5. How information is shared

We share information only as needed to operate Aglet, follow workspace instructions, complete a business transaction, comply with law, or protect rights and safety. We do not sell personal information or share it for cross-context behavioral advertising.

  • Workspace membersInformation is visible to authorized people in the workspace according to their role and project access.
  • Infrastructure and delivery providersHetzner hosts application and database workloads; Cloudflare provides DNS, network protection, email delivery, edge processing, queues, and object storage; GitHub stores release images and provides connections when enabled.
  • Billing providerStripe processes checkout, payment details, subscriptions, invoices, tax configuration, and the customer portal.
  • Optional connected or model providersWhen a workspace enables a connection or model feature, Aglet sends only the information needed for that feature under the workspace's configuration.
  • Professional and legal recipientsAdvisers, auditors, authorities, or transaction participants may receive information when reasonably necessary and subject to appropriate duties.

6. Automated processing and agents

Aglet may use deterministic rules and, when a workspace enables them, external model providers to classify or group related reports and assist with proposed work. Model output is treated as an inference: it does not establish identity, urgency, revenue, authority, or successful verification. A workspace can review the supporting evidence and correct grouping or categorization.

Customer Data is redacted and minimized before supported model processing. Attachments and sensitive-data classes remain unavailable for model use unless the product expressly discloses and enables them.

7. Retention

We keep information only while needed for the service, security, legal obligations, and the periods below. A legal or security hold can extend a period. We may deidentify information instead of deleting it when it can no longer reasonably identify a person or workspace.

Default Aglet retention periods
DataDefault period
Critical and error telemetry14 days in the hot store; redacted archives up to 90 days
Warning telemetry7 days in the hot store; redacted archives up to 90 days
Info and debug telemetry1 day in the hot store; redacted archives up to 90 days
Customer feedback messages365 days
Direct feedback contact information180 days after the last linked activity
Agent artifacts30 days
Audit and security evidence365 days
Encrypted database backups30 days
Billing and tax recordsAs required for accounting, tax, fraud prevention, and legal compliance

Account deletion has a 14-day recovery period unless an immediate verified request or law requires otherwise. We target active-store deletion within 30 days after that period. Encrypted backup copies expire through the backup lifecycle within 30 additional days.

8. Security and international processing

Aglet uses access controls, tenant scoping, encrypted transport, private database networking, secret redaction, scoped credentials, audit records, backups, and recovery procedures. No security measure can eliminate all risk.

Aglet is operated from the United States, and service providers may process information in the United States or other countries. Where required, we use contractual or other recognized transfer safeguards.

9. Your choices and privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, or an objection to processing; withdraw consent; or appeal a decision. We do not discriminate against people for exercising applicable privacy rights.

Email [email protected] to make a request. Include the email address and workspace needed to locate the account, but do not send passwords or sensitive payloads. We may verify identity and authority before acting. If a workspace controls the data, we may refer the request to its owner.

Aglet uses essential cookies for sessions, security, and saved preferences. We do not currently use cross-site advertising cookies. Browser Do Not Track signals do not have a uniform standard; where legally required, we honor recognized opt-out signals for covered activity.

Operational email includes account verification, password recovery, invitations, billing, and configured notifications. You cannot opt out of messages required to administer or secure an active account.

Aglet is for business users age 18 or older and is not directed to children. Contact us if you believe a child provided personal information.

11. Changes and contact

We may update this Policy as Aglet or applicable law changes. We will update the effective date and provide additional notice for material changes when required.

Remodeled AI, LLC operates Aglet. Send privacy questions, requests, or complaints to [email protected].

Review the security controls.

See how Aglet handles access, credentials, customer boundaries, and operational evidence.

Security controls