← Back to Home

Privacy Policy

Last updated: July 16, 2026

1. Introduction

AgentBox is a product owned and operated by MAYVK ("we", "our", or "us"). MAYVK operates the AgentBox mobile application and website (agentbox.mayvk.com). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

2. Information We Collect

Account Information

  • Name and email address
  • Password (encrypted with bcrypt, never stored in plain text)
  • Authentication tokens for session management

Third-Party Login

  • If you sign in with Facebook or other providers, we receive your public profile information (name, email, profile picture)
  • We do not post to your social media accounts or access your friends list

Task Data

  • Tasks you submit to AgentBox (text descriptions)
  • Files you upload for task processing
  • Task results, screen recordings, and outputs generated by your agent

Browser Session Data

  • When you use cookie sync to log into websites through AgentBox, browser cookies are transferred from your device to your private cloud machine
  • These cookies are stored only on your dedicated machine and are not accessible to us or other users

Usage Data

  • Device information and app usage patterns
  • Error logs for debugging and service improvement

3. How We Use Your Information

  • To create and manage your account
  • To provision and maintain your private cloud machine
  • To execute tasks you submit
  • To improve our service and fix bugs
  • To communicate with you about your account or service updates
  • To detect and prevent fraud or abuse

4. Data Isolation

Each AgentBox user receives their own dedicated cloud machine. Your data, files, browser sessions, and credentials are completely isolated from other users. We do not share resources between users.

5. Data Sharing

We do not sell your personal information. We may share data only in these cases:

  • AI Providers: Task descriptions are sent to AI providers (such as Anthropic Claude or OpenAI) to process your tasks. These providers have their own privacy policies.
  • Infrastructure: We use cloud providers (Hetzner, Cloudflare) to host your machine. They do not have access to your data.
  • Legal Requirements: If required by law, regulation, or legal process.

6. Google User Data

AgentBox lets you connect Google services (Gmail, Google Calendar, Google Drive, Google Search Console, Google Ads, Google Analytics, and Firebase) to your private AI assistant. Each connection is optional and initiated by you through Google's OAuth consent screen.

What Google Data We Access

Only after you explicitly connect a service, and only the services you connect:

  • Gmail: read, compose, send, and manage email messages and settings
  • Google Calendar: read, create, and manage calendar events
  • Google Drive: read, create, edit, and organize files and folders
  • Google Search Console: read and manage site search performance data
  • Google Ads: read and manage advertising campaigns
  • Google Analytics: read and manage analytics properties and reports
  • Firebase / Google Cloud: read and manage Firebase project resources
  • Basic profile: your name, email address, and profile picture, to identify which Google account is connected

How We Use Google Data

Google user data is used solely to perform the tasks you explicitly ask your assistant to do — for example, reading and replying to emails, scheduling events, or organizing Drive files at your request. We do not use Google user data for advertising, marketing, profiling, or any purpose unrelated to the features you actively use.

How We Share Google Data

We do not sell or transfer Google user data to third parties. When you ask your assistant to perform a task involving your Google data, the relevant content is processed by our AI model providers (such as Anthropic and OpenAI) strictly to complete that task. These providers are contractually prohibited from using this data for their own purposes and do not use it to train their models. Google user data is never shared with data brokers, advertisers, or any other third party.

How We Protect Google Data

  • OAuth access and refresh tokens are encrypted at rest using AES-256-GCM
  • All data is transmitted over HTTPS/TLS encryption
  • Your Google data is processed on your own dedicated, isolated cloud machine — never shared with other users
  • We never see or store your Google password; access is granted only via Google's OAuth system

Retention and Deletion of Google Data

  • You can disconnect any Google service at any time from the Services page; the stored tokens are deleted immediately
  • You can also revoke AgentBox's access at any time from your Google Account security settings
  • If you delete your AgentBox account, all Google user data and tokens are permanently deleted within 30 days

Limited Use Disclosure

AgentBox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace or Google user data to develop, improve, or train generalized AI or machine learning models, and we do not transfer this data to any third-party AI tools or services that train on it.

7. Data Retention

Your data is retained for as long as your account is active. If you delete your account, your cloud machine and all associated data (tasks, files, browser sessions, recordings) are permanently deleted within 30 days.

8. Data Deletion

You can request deletion of your data at any time. See our Data Deletion Policy for instructions.

9. Security

  • Passwords are hashed with bcrypt
  • All connections use HTTPS/TLS encryption
  • Authentication uses short-lived JWT tokens with secure refresh
  • Each user's cloud machine is isolated with its own environment

10. Children's Privacy

AgentBox is not intended for use by anyone under the age of 18. We do not knowingly collect information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have questions about this Privacy Policy, contact us at: info@support.mayvk.com