Our Policies

Agiloop Terms of Service

Last updated: September 2, 2026

These Terms of Service (“Terms”) govern your access to and use of the Agiloop platform, websites, applications, features, and related services (collectively, the “Service”) operated by Agiloop Inc., a Delaware corporation(“Agiloop,” “we,” “our,” or “us”).

By accessing or using the Service, you agree to be bound by these Terms. If you do not agree to these Terms, you may not use the Service.

If you use the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms, and references to “you” include that organization.

1. Eligibility

You must:

  • Be at least 18 years old or the age of legal majority in your jurisdiction;
  • Have the legal authority to accept these Terms; and
  • Not be prohibited from using the Service under applicable law.

2. Account Registration and Security

You may be required to create an account to use the Service.

You agree to provide accurate and current account information and are responsible for:

  • Maintaining the confidentiality and security of your credentials;
  • All activity occurring through your account;
  • Managing users and access associated with your organization, where applicable; and
  • Promptly notifying Agiloop if you become aware of unauthorized access to your account.

You may not share credentials in a manner that circumvents applicable account or access restrictions.

Agiloop may suspend or restrict accounts that contain materially inaccurate information or are reasonably suspected of unauthorized, fraudulent, abusive, or unlawful activity.

3. Free and Paid Services

Agiloop provides many Service features without charge.

Certain functionality requires payment, including:

  • Usage of IMPLEMENT to generate or build software; and
  • Optional ITERATE+ subscriptions activated for individual projects.

Agiloop may add, remove, modify, or change the availability of free and paid functionality from time to time.

The price applicable to a paid transaction will be displayed or otherwise communicated before the applicable purchase, usage, or subscription is authorized.

4. IMPLEMENT Credits and Usage

4.1 Usage-Based Pricing

IMPLEMENT is a usage-based service.

The cost of an IMPLEMENT action is based on the story points associated with the feature or work being generated and may vary based on whether you use AI services provided through Agiloop or your own supported AI provider credentials.

The applicable cost will be presented before you authorize the generation or build action.

4.2 Credits and Wallets

IMPLEMENT usage is paid through credits purchased and maintained within an Agiloop account wallet.

Credits may be allocated or transferred to authorized users and eligible projects using functionality provided by Agiloop.

Purchased credits:

  • Remain available until used;
  • Do not expire; and
  • Have no cash value and are not redeemable or refundable for cash except where required by applicable law.

Credits may only be used for eligible Agiloop services and may not be sold, exchanged, or transferred outside the functionality Agiloop provides.

4.3 Credit Consumption

When you authorize an IMPLEMENT generation or build action, you authorize Agiloop to deduct the displayed amount of credits.

Credits are considered consumed when Agiloop begins processing the authorized generation or build request.

Before processing begins, Agiloop provides information concerning the feature or work to be generated and the applicable usage cost.

Once processing begins, consumed credits are not refundable because generated code or other output does not meet your expectations, preferences, or intended use.

4.4 Processing Failures

If an IMPLEMENT action fails because of an Agiloop platform or processing error after credits have been consumed, Agiloop will restore the applicable credits to the appropriate wallet.

Restoration of credits does not constitute a cash refund.

5. ITERATE+ Subscriptions

ITERATE+ is an optional paid subscription that may be activated for individual projects.

ITERATE+ may be offered on a monthly or annual basis. The applicable price and billing term will be presented when you activate the subscription.

Unless otherwise stated at purchase, ITERATE+ subscriptions automatically renew for successive billing terms until cancelled.

You authorize Agiloop and its payment processor to charge the applicable payment method for each renewal.

You may cancel an ITERATE+ subscription at any time. Cancellation:

  • Stops future automatic renewals;
  • Does not provide a refund or prorated refund for the current paid billing term; and
  • Allows access to ITERATE+ functionality through the end of the current paid billing term.

After the paid billing term ends, ITERATE+ functionality for the applicable project will no longer be available. Analyses, assessments, results, or other content available specifically through ITERATE+ may also become inaccessible after the subscription ends.

Additional payment and refund terms are described in the Agiloop Refund Policy.

6. Billing and Payment

Agiloop uses third-party payment processors to process payments.

By purchasing credits, activating a paid subscription, or otherwise authorizing a paid transaction, you authorize Agiloop and its payment processor to charge your selected payment method for the applicable amount.

You agree to provide accurate and current billing information and are responsible for applicable charges authorized through your account.

Except for confirmed billing errors, restoration of credits as expressly described in these Terms, or where otherwise required by applicable law, payments are non-refundable as provided in the Agiloop Refund Policy.

If we confirm that a billing error has occurred, Agiloop will correct the error, including by issuing an appropriate refund or restoring credits where applicable.

Taxes may apply to purchases based on your location and applicable law.

7. Customer Content and Intellectual Property

Customer Content” means information, materials, data, text, specifications, prompts, documents, repository content, source code, project information, comments, and other content that you or your authorized users submit, provide, connect, develop, or make available through the Service.

7.1 Customer Ownership

As between you and Agiloop, you retain all right, title, and interest in and to your Customer Content and intellectual property.

Agiloop does not acquire ownership of your:

  • Source code or repositories;
  • Applications or software products;
  • Product ideas or concepts;
  • Business requirements;
  • Specifications or designs;
  • Documents or other materials;
  • Data; or
  • Other intellectual property that you provide, connect, develop, or make available through the Service.

Your use of Agiloop does not transfer ownership of your intellectual property to Agiloop.

7.2 Limited License to Agiloop

You grant Agiloop a worldwide, non-exclusive, royalty-free license to access, use, host, reproduce, process, transmit, analyze, modify, and transform Customer Content solely as reasonably necessary to provide and operate the Service for you, including to:

  • Perform actions you request;
  • Access authorized repositories and integrations;
  • Generate specifications, assessments, analyses, recommendations, code, and other requested outputs;
  • Transmit relevant information to AI providers and other service providers as necessary to perform requested functionality;
  • Maintain and secure the Service;
  • Provide customer support; and
  • Fulfill Agiloop's legal and contractual obligations.

This license does not transfer ownership of Customer Content to Agiloop and does not give Agiloop the right to use your Customer Content to develop products for other customers or train AI models.

The license continues only for as long as reasonably necessary to provide the Service and fulfill Agiloop's applicable legal and contractual obligations.

7.3 Your Responsibilities

You represent and warrant that:

  • You own or have sufficient rights and permissions to provide Customer Content to Agiloop;
  • Agiloop's processing of Customer Content as contemplated by these Terms will not violate third-party rights;
  • Your use of Customer Content through the Service complies with applicable law; and
  • You have obtained any permissions or authorizations necessary for information you direct Agiloop to process.

You are responsible for Customer Content and for determining whether information is appropriate for processing through the Service.

8. Repository Access

Agiloop may allow you to connect supported repository and development services, including GitHub, GitLab, and Azure DevOps.

By connecting a repository or related service, you authorize Agiloop to access and process repository information and source code as necessary to perform the functionality you request.

Agiloop does not acquire any ownership interest in your repository or source code by accessing or processing it.

Agiloop does not persistently store repository source code. Relevant source code and context may be temporarily accessed and processed and may be transmitted to supported AI providers when necessary to provide requested functionality.

You are responsible for ensuring that you have authority to connect a repository and authorize Agiloop to process its contents.

You may revoke repository access through available Agiloop or third-party controls, subject to the technical functionality of the applicable integration.

9. Artificial Intelligence Services

Agiloop uses artificial intelligence, including large language models and other AI systems, throughout portions of the Service.

AI may be used to assist with activities including product definition, requirements, architecture, software generation, assessments, analysis, recommendations, testing, review, and iteration.

9.1 AI Providers

Agiloop may use third-party AI providers to process Customer Content and generate requested outputs.

When Agiloop-provided AI credentials are used, Agiloop uses available commercial or API configurations intended to prevent Customer Content from being used to train the provider's foundational models.

Agiloop does not use Customer Content, repository content, source code, prompts, or Generated Output to train or fine-tune AI models.

9.2 Customer-Provided AI Credentials

Agiloop may allow you to use your own credentials for supported AI providers.

When you use your own credentials, Agiloop may act as an intermediary and transmit relevant Customer Content or code context to the selected provider to perform the requested action.

Your use of your own AI provider credentials is also subject to your agreement with that provider, including its pricing, privacy, retention, security, and data-use practices.

You are responsible for your selection, configuration, and authorized use of third-party AI provider accounts.

9.3 AI Output

Artificial intelligence is probabilistic and may produce inaccurate, incomplete, inconsistent, insecure, outdated, or otherwise unsuitable output.

You acknowledge that:

  • AI-generated output may contain errors;
  • Similar or identical output may be generated for other users;
  • Agiloop does not guarantee that AI output is unique;
  • Assessments and recommendations represent automated analyses and are not guarantees;
  • AI-generated code may contain defects, security vulnerabilities, licensing issues, or other problems; and
  • AI output should be reviewed and validated before being relied upon or deployed.

10. Generated Software and Customer Responsibility

Agiloop provides tools that may generate, modify, analyze, assess, or recommend software.

You are responsible for reviewing, testing, validating, securing, and approving software before deploying or using it in a production environment.

Agiloop assessments, tests, compliance analyses, readiness scores, bug analyses, security analyses, competitive analyses, usability analyses, recommendations, and other outputs are intended to assist your decision-making. They do not constitute a guarantee that software:

  • Is error-free or secure;
  • Is suitable for production;
  • Complies with any particular law, regulation, industry standard, or contractual requirement;
  • Will achieve a particular business or technical result; or
  • Is free from third-party intellectual-property claims.

You remain responsible for determining whether software and other output produced or analyzed through Agiloop is appropriate for your intended use.

11. Ownership of Generated Output

11.1 Your Generated Output

Generated Output” means specifications, requirements, designs, analyses, recommendations, documentation, source code, software, and other materials generated specifically for you through your use of the Service.

As between you and Agiloop, and to the extent permitted by applicable law, you own the Generated Output produced through your use of Agiloop.

Agiloop does not claim ownership of your Generated Output.

This includes code and other materials generated through IMPLEMENT and other Agiloop functionality, whether Generated Output is created for a new product or is based on an existing application, repository, project, specification, or other Customer Content.

Subject to applicable law and third-party rights, you may use, modify, reproduce, distribute, commercialize, license, deploy, sell, or otherwise use your Generated Output for any lawful purpose.

11.2 AI-Generated Content and Third-Party Rights

Because artificial intelligence systems may generate similar or identical content for different users, Agiloop cannot guarantee that Generated Output is unique or that all Generated Output is eligible for copyright, patent, or other intellectual-property protection.

Generated Output may also incorporate or be subject to third-party rights, open-source licenses, or other restrictions.

You are responsible for reviewing Generated Output and determining whether it is appropriate for your intended use.

11.3 Agiloop Intellectual Property

Your ownership of Customer Content and Generated Output does not give you ownership of the Agiloop Service or its underlying technology.

Agiloop retains all right, title, and interest in and to its proprietary platform, software, orchestration systems, workflows, interfaces, prompts, methodologies, templates, designs, trademarks, branding, and other technology used to provide the Service.

For clarity, Agiloop's use or processing of your Customer Content to provide the Service does not give Agiloop any ownership interest in your Customer Content, your applications, your source code, your repositories, or your Generated Output.

12. INSPECT and Customer Application Data

Customers may choose to enable INSPECT telemetry within applications created or managed using Agiloop.

When enabled, INSPECT may collect and process application telemetry and information associated with users of the customer's application, including user IDs and email addresses.

You are responsible for:

  • Providing appropriate privacy notices to users of your application;
  • Obtaining any consents or permissions required by applicable law;
  • Ensuring you have a lawful basis to collect and transmit such information to Agiloop; and
  • Configuring your application and use of INSPECT in accordance with applicable law.

Where Agiloop processes such information on your behalf, Agiloop will process it as described in the Agiloop Privacy Policy and any applicable Data Processing Addendum or other agreement between you and Agiloop.

13. Acceptable Use

You may not use the Service to:

  • Violate applicable law or regulation;
  • Infringe, misappropriate, or violate intellectual-property, privacy, confidentiality, or other rights;
  • Access or process information you do not have authorization to use;
  • Upload or distribute malware or malicious code;
  • Attempt unauthorized access to accounts, systems, repositories, or data;
  • Circumvent security, usage, billing, access, or technical restrictions;
  • Reverse engineer or attempt to discover non-public source code or underlying components of the Service except where such restriction is prohibited by law;
  • Interfere with or disrupt the Service or its infrastructure;
  • Misrepresent your identity or affiliation;
  • Use Agiloop's proprietary content, technology, or non-public data to build or train a competing product or model without Agiloop's written authorization;
  • Use the Service for fraudulent, deceptive, harmful, or abusive purposes; or
  • Use the Service in a manner that could materially damage Agiloop, its infrastructure, its providers, or other users.

Agiloop may investigate suspected violations and take reasonable action, including restricting or suspending access.

14. Agiloop Intellectual Property

Agiloop and its licensors own all rights, title, and interest in and to the Service and its underlying technology, including its proprietary software, interfaces, workflows, designs, trademarks, branding, orchestration technology, prompts, methodologies, and functionality.

For avoidance of doubt, Agiloop's intellectual-property rights do not include your Customer Content, your applications, your source code, your repositories, or your Generated Output.

Subject to your compliance with these Terms, Agiloop grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Service for its intended purposes.

You may not copy, sell, license, distribute, modify, or create derivative works from Agiloop's proprietary Service or technology except as expressly permitted by Agiloop or applicable law.

15. Feedback

If you voluntarily provide suggestions, ideas, recommendations, or other feedback specifically concerning Agiloop or the Service (“Feedback”), you grant Agiloop a worldwide, perpetual, irrevocable, royalty-free right to use, modify, incorporate, and otherwise use that Feedback without restriction or compensation to you.

Feedback does not include Customer Content, product ideas submitted as part of your own project, your source code, your Generated Output, or other proprietary information belonging to you.

16. Third-Party Services

The Service may integrate with or depend upon third-party services, including repository providers, AI providers, cloud infrastructure, payment processors, deployment services, and other development tools.

Your use of third-party services may be subject to separate terms and policies.

Agiloop does not control and is not responsible for the independent operation, availability, security, pricing, policies, or performance of third-party services.

Changes, outages, restrictions, or discontinuation of a third-party service may affect Agiloop functionality.

17. Privacy

Agiloop's collection and processing of personal information is described in the Agiloop Privacy Policy.

When you use Agiloop to process personal information on behalf of your own users, customers, employees, or other individuals, you are responsible for ensuring that you have the rights and lawful basis necessary to provide that information to Agiloop.

Additional data-processing terms may apply to enterprise or other customers under a separate Data Processing Addendum.

18. Confidentiality

Through use of the Service, either party may receive non-public information that is identified as confidential or that reasonably should be understood to be confidential given the nature of the information or circumstances of disclosure (“Confidential Information”).

Customer Content, source code, repositories, product specifications, business requirements, and other non-public proprietary materials provided by you are considered your Confidential Information.

Each party agrees to:

  • Use the other party's Confidential Information only as necessary to perform or receive the Service;
  • Take reasonable measures to protect it from unauthorized access, use, or disclosure; and
  • Disclose it only to personnel and service providers who reasonably need access and are subject to appropriate confidentiality obligations.

Confidential Information does not include information that:

  • Becomes publicly available without breach of these Terms;
  • Was lawfully known without confidentiality obligations before disclosure;
  • Is received lawfully from another source without confidentiality obligations; or
  • Is independently developed without use of the other party's Confidential Information.

A party may disclose Confidential Information where required by law, provided it gives notice where legally permitted.

19. Disclaimers

THE SERVICE, GENERATED OUTPUT, ASSESSMENTS, RECOMMENDATIONS, AND OTHER MATERIALS PROVIDED THROUGH AGILOOP ARE PROVIDED “AS IS” AND “AS AVAILABLE” TO THE MAXIMUM EXTENT PERMITTED BY LAW.

AGILOOP DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF:

  • MERCHANTABILITY;
  • FITNESS FOR A PARTICULAR PURPOSE;
  • TITLE;
  • NON-INFRINGEMENT;
  • ACCURACY OR COMPLETENESS;
  • SECURITY;
  • AVAILABILITY; AND
  • RELIABILITY.

AGILOOP DOES NOT WARRANT THAT THE SERVICE OR GENERATED OUTPUT WILL BE ERROR-FREE, SECURE, UNINTERRUPTED, OR SUITABLE FOR ANY PARTICULAR PURPOSE.

Unless expressly agreed in a separate written agreement, Agiloop does not provide a service-level agreement or uptime guarantee.

20. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, AGILOOP AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AFFILIATES, CONTRACTORS, AND LICENSORS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS OPPORTUNITY, GOODWILL, OR DATA, ARISING OUT OF OR RELATING TO THE SERVICE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, AGILOOP'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF:

  • THE AMOUNT YOU PAID TO AGILOOP DURING THE 12 MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR
  • $100.

These limitations apply regardless of the legal theory upon which a claim is based and even if Agiloop has been advised of the possibility of such damages.

Some jurisdictions do not allow certain exclusions or limitations of liability, so portions of this section may not apply to you.

21. Indemnification

To the extent permitted by applicable law, you agree to indemnify, defend, and hold harmless Agiloop and its officers, directors, employees, contractors, and affiliates from and against third-party claims, damages, liabilities, losses, and reasonable costs and expenses, including attorneys' fees, arising from or relating to:

  • Your Customer Content;
  • Your application or software;
  • Your use of Generated Output;
  • Your collection or processing of Customer End-User Data;
  • Your violation of these Terms;
  • Your violation of applicable law; or
  • Your infringement or violation of a third party's rights.

22. Suspension and Termination

You may stop using the Service at any time.

Agiloop may suspend, restrict, or terminate access to all or part of the Service where reasonably necessary because:

  • You materially violate these Terms;
  • You fail to pay amounts due;
  • Your activity creates a security or legal risk;
  • Agiloop reasonably suspects fraud, abuse, or unauthorized activity;
  • Agiloop is required to do so by law; or
  • Continued provision of the Service is no longer reasonably practicable.

Where reasonable under the circumstances, Agiloop will attempt to provide notice before suspension or termination.

Termination does not entitle you to a refund of purchased credits, consumed credits, or subscription payments except as required by applicable law or expressly provided in the Agiloop Refund Policy.

If Agiloop terminates your account for reasons unrelated to your violation of these Terms, nonpayment, fraud, abuse, security risk, or unlawful activity, Agiloop will provide a reasonable opportunity, where practicable, for you to use or otherwise resolve unused purchased credits.

Upon termination, your right to access and use the Service ends, subject to any rights or obligations that by their nature survive termination.

Termination of your Agiloop account does not transfer ownership of your Customer Content, Generated Output, source code, applications, or other intellectual property to Agiloop.

Sections concerning ownership, payment obligations, confidentiality, disclaimers, limitations of liability, indemnification, dispute resolution, and other provisions that by their nature should survive will remain in effect.

23. Data Following Account Termination

Following account deletion or termination, Agiloop may delete Customer Content and account information in accordance with the Agiloop Privacy Policy.

You are responsible for exporting or otherwise retaining information you wish to preserve before deleting your account or before termination becomes effective, where export functionality is available.

Agiloop is not obligated to retain Customer Content indefinitely following account deletion or termination.

Deletion of Customer Content from Agiloop systems does not affect your ownership of copies of your Customer Content or Generated Output that you possess outside the Service.

24. Governing Law and Dispute Resolution

These Terms are governed by the laws of the State of Delaware, without regard to its conflict-of-law principles.

Unless otherwise required by applicable law or agreed in writing, any dispute arising out of or relating to these Terms or the Service will be brought in the state or federal courts having jurisdiction in Delaware, and each party consents to the personal jurisdiction and venue of those courts.

Nothing in these Terms prevents either party from seeking appropriate injunctive or equitable relief where legally available.

25. Changes to the Service, Pricing, or Terms

Agiloop may modify the Service, features, pricing, credit rates, subscription offerings, or these Terms from time to time.

The applicable cost of a new IMPLEMENT action or other usage-based transaction will be displayed before you authorize that transaction.

If a pricing change affects the future renewal of an automatically renewing paid subscription, Agiloop will provide advance notice where required by applicable law.

If Agiloop makes material changes to these Terms, we will provide notice where required by applicable law, such as through email or an in-product notification.

Continued use of the Service after revised Terms become effective constitutes acceptance of those Terms to the extent permitted by applicable law.

26. Enterprise and Custom Agreements

Agiloop may enter into separate enterprise agreements, order forms, statements of work, Data Processing Addenda, service-level agreements, or other written agreements with customers.

If a separate written agreement between you and Agiloop conflicts with these Terms, the separate agreement will control to the extent of that conflict.

27. Miscellaneous

These Terms, together with policies and agreements expressly incorporated by reference, constitute the agreement between you and Agiloop concerning use of the Service, except where a separate written agreement applies.

If any provision of these Terms is found unenforceable, the remaining provisions will remain in effect.

You may not assign or transfer these Terms without Agiloop's prior written consent. Agiloop may assign these Terms in connection with a merger, acquisition, corporate reorganization, or sale of substantially all of its relevant assets.

Agiloop's failure to enforce a provision of these Terms does not constitute a waiver of that provision.

Headings are provided for convenience and do not affect interpretation of these Terms.

28. Contact Information

For questions concerning these Terms, contact:

Agiloop Inc.
Email: legal@agiloop.ai
Website: agiloop.ai

Agiloop Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Agiloop Inc., a Delaware corporation (“Agiloop,” “we,” “our,” or “us”) collects, uses, processes, shares, and protects personal information when you use our websites, services, applications, and platform (collectively, the “Service”).

This Privacy Policy also explains how Agiloop processes certain information on behalf of customers who use Agiloop features, including INSPECT telemetry, in applications they develop or manage.

1. Information We Collect

The information Agiloop collects depends on how you use the Service.

1.1 Account and Contact Information

When you create or use an Agiloop account, communicate with us, or request support, we may collect information such as:

  • Name;
  • Email address;
  • Account credentials and authentication information;
  • Organization or company information;
  • Communications with Agiloop;
  • Support requests; and
  • Other information you choose to provide.

1.2 Customer Content

Users may provide or make available information and materials through the Service (“Customer Content”), including:

  • Product and feature descriptions;
  • Ideas, requirements, specifications, and acceptance criteria;
  • Prompts and instructions;
  • Project information;
  • Text extracted from uploaded documents;
  • Repository content accessed through authorized integrations;
  • Source code and code-related information processed to provide requested functionality;
  • Generated code and other AI-generated outputs;
  • Assessment inputs and results;
  • Comments and collaboration content; and
  • Other materials submitted to or processed through the Service.

When users upload supported documents through INVENT, Agiloop temporarily processes those files to extract text for use within the applicable project. Agiloop retains the extracted text as part of the Customer Content associated with the project. The original uploaded files are temporarily processed and subsequently deleted after the text extraction process is completed.

1.3 Repository Integrations

Agiloop allows users to connect supported source-code repositories and development services, including GitHub, GitLab, and Azure DevOps.

When you authorize an integration, Agiloop may store authentication credentials or OAuth tokens necessary to maintain the authorized connection.

Agiloop does not persistently store repository source code. Agiloop may access, retrieve, and temporarily process relevant source code and repository information as necessary to provide requested functionality, including assessments, analysis, code generation, and IMPLEMENT functionality.

Relevant source code or code context may be transmitted to supported artificial intelligence providers when necessary to perform a user-requested function.

1.4 Billing and Transaction Information

When you use paid Agiloop functionality, we may collect or maintain information relating to:

  • Credit purchases;
  • Account wallet balances and activity;
  • Credit allocations;
  • IMPLEMENT usage;
  • Project-level paid features;
  • ITERATE+ subscriptions;
  • Billing history;
  • Transaction records; and
  • Subscription and renewal status.

Payment card information is processed by our payment processor. Agiloop does not store full payment card numbers.

1.5 Automatically Collected Information

When you access or use the Service, we may automatically collect technical and usage information such as:

  • IP address;
  • Browser type and version;
  • Operating system;
  • Device and technical information;
  • Date and time of access;
  • Pages and features accessed;
  • Usage and interaction information;
  • Session and authentication information; and
  • Analytics event data.

We use this information to operate, secure, understand, and improve the Service.

1.6 INSPECT Telemetry and Customer End-User Data

Customers may choose to enable Agiloop INSPECT telemetry within applications created or managed using Agiloop.

When INSPECT telemetry is enabled, the customer's application may transmit application usage and telemetry information to Agiloop. Depending on the customer's implementation, this information may include identifiers such as user IDs and email addresses associated with users of the customer's application (“Customer End-User Data”).

These individuals are users of an Agiloop customer's application and are not necessarily users of Agiloop.

Agiloop processes Customer End-User Data on behalf of the applicable customer to provide INSPECT, analytics, monitoring, product feedback, and related functionality.

The Agiloop customer is responsible for providing appropriate privacy notices to its application users and obtaining any permissions or consents required by applicable law for the collection and transmission of Customer End-User Data to Agiloop.

2. How We Use Information

We may use information collected or processed through the Service to:

  • Provide, operate, maintain, and improve Agiloop;
  • Create and manage user accounts;
  • Authenticate users and maintain authorized integrations;
  • Provide INVENT, IMPLEMENT, INSPECT, ITERATE, ITERATE+, assessments, and other Agiloop functionality;
  • Process Customer Content and repository content in response to user requests;
  • Generate specifications, analyses, recommendations, assessments, software code, and other requested outputs;
  • Provide application telemetry and analytics through INSPECT;
  • Process purchases and manage credits, wallets, subscriptions, and billing;
  • Provide customer support;
  • Send service-related, account, onboarding, billing, security, and other communications;
  • Analyze how the Service is used;
  • Protect the Service and detect fraud, abuse, security incidents, or unauthorized activity;
  • Enforce our agreements and policies;
  • Comply with applicable legal and regulatory obligations; and
  • Establish, exercise, or defend legal claims.

Agiloop does not sell personal information.

3. Artificial Intelligence Processing

Artificial intelligence is a core component of the Agiloop Service.

To provide AI-powered functionality, Agiloop may transmit Customer Content, repository content, source-code context, prompts, specifications, and other information relevant to a requested operation to supported AI providers.

Agiloop currently supports AI services from providers including OpenAI, Anthropic, and xAI. The specific provider used may depend on the Agiloop feature, configuration, and choices available to the user.

3.1 Agiloop-Provided AI Services

When Agiloop provides access to an AI service using Agiloop's credentials, Agiloop uses available commercial or API configurations intended to prevent Customer Content from being used to train the provider's foundational models.

Agiloop does not use Customer Content, repository content, source code, prompts, or generated outputs to train or fine-tune Agiloop models.

3.2 Customer-Provided AI Credentials

Agiloop may allow customers to use their own API credentials or supported AI provider accounts.

When a customer uses its own AI credentials, Agiloop may continue to act as an intermediary by transmitting relevant information to the selected AI provider in order to perform the requested operation.

Processing performed through a customer's own AI provider account is also subject to the terms, privacy practices, data-retention settings, and other configurations applicable to that customer's relationship with the selected provider.

Users are responsible for ensuring that their use of a selected AI provider is appropriate for the information they choose to process through that provider.

4. How We Share Information

We may share information in the circumstances described below.

4.1 Service Providers and Subprocessors

Agiloop uses third-party service providers to operate and deliver the Service. These may include providers of:

  • Cloud hosting and infrastructure;
  • Databases and data storage;
  • Artificial intelligence and machine-learning services;
  • Payment processing;
  • Analytics;
  • Email and customer communications;
  • Customer support;
  • Authentication and repository integrations; and
  • Other technical and operational services.

These providers may process information only as necessary to perform services for Agiloop or as otherwise permitted by their applicable agreements and law.

Agiloop's service providers currently include services provided by companies such as Google, Supabase, ClickHouse, Stripe, HubSpot, Freshworks/Freshdesk, OpenAI, Anthropic, and xAI.

4.2 At Your Direction

We may disclose or transmit information when you direct or authorize us to do so, including when you connect third-party services, repositories, AI providers, or other integrations to Agiloop.

4.3 Legal and Safety Requirements

We may disclose information when we reasonably believe disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request;
  • Protect the rights, property, or safety of Agiloop, our customers, users, or others;
  • Investigate fraud, abuse, security incidents, or violations of our agreements; or
  • Establish, exercise, or defend legal claims.

4.4 Business Transactions

If Agiloop is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, information may be disclosed or transferred as part of that transaction, subject to applicable law.

Agiloop does not share personal information for third-party cross-context behavioral advertising.

5. Cookies and Analytics

Agiloop uses cookies and similar technologies to operate the Service, maintain secure sessions, remember preferences, and understand how users interact with our websites and platform.

We use Google Analytics to help us understand website and Service usage. Google Analytics may collect information about devices, browsers, interactions, pages visited, and similar usage information.

You may be able to manage cookies through your browser settings and, where provided, Agiloop's cookie or consent controls. Disabling certain cookies may affect Service functionality.

Agiloop does not currently use third-party advertising pixels to serve targeted advertisements based on activity across unrelated websites or services.

6. Payment Processing

Agiloop uses third-party payment processors, including Stripe, to process payments for paid features and services.

Payment processors may collect and store payment card information, billing addresses, and other information necessary to process transactions.

Agiloop does not store full payment card numbers.

Agiloop may retain transaction information necessary to manage IMPLEMENT credits, wallet balances, ITERATE+ subscriptions, billing records, and other paid functionality.

Payment processors process information according to their own privacy policies and applicable agreements.

7. Customer End-User Data

When Agiloop processes Customer End-User Data through INSPECT or another customer-configured feature, Agiloop generally processes that information on behalf of and according to the instructions of the applicable Agiloop customer.

The customer determines why and how its application collects information from its end users and is responsible for its relationship with those users, including providing legally required privacy notices and obtaining required permissions or consents.

If you are an end user of an application operated by an Agiloop customer and wish to exercise privacy rights relating to information collected through that application, you should generally contact the operator of that application directly.

Agiloop will reasonably assist its customers in responding to applicable data-subject requests where required by law or contract.

8. Data Security

Agiloop uses reasonable technical and organizational measures designed to protect information from unauthorized access, use, alteration, loss, or disclosure.

These measures include, as appropriate:

  • Encryption in transit;
  • Access controls;
  • Secure credential and authentication practices;
  • Restricted access to customer information; and
  • Security monitoring and operational safeguards.

OAuth tokens and other credentials used to connect external services are treated as sensitive credentials and protected accordingly.

No method of electronic transmission, processing, or storage is completely secure, and Agiloop cannot guarantee absolute security.

9. Data Retention and Deletion

Agiloop retains personal information and Customer Content for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and protect against fraud or abuse.

When an Agiloop account is deleted, account information and associated Customer Content are scheduled for deletion.

Deleted information may remain within Agiloop systems, backups, or deletion workflows for up to 30 days following account deletion.

Certain information may be retained for longer where reasonably necessary or required for:

  • Legal or regulatory obligations;
  • Financial, tax, or accounting records;
  • Fraud prevention;
  • Security and abuse prevention;
  • Resolving disputes; or
  • Establishing, exercising, or defending legal claims.

Information that has been aggregated or de-identified so that it can no longer reasonably identify an individual may be retained and used for legitimate business purposes.

Original files uploaded through INVENT are subject to a different retention process. These files are temporarily processed to extract text and are subsequently deleted after the extraction process is completed. Extracted text retained as Customer Content remains subject to the retention and deletion practices described above.

10. International Data Transfers

Agiloop is based in the United States, and information processed through the Service may be transferred to, stored in, or processed in the United States or other jurisdictions where Agiloop or its service providers operate.

Where applicable law requires safeguards for international transfers of personal information, Agiloop will use appropriate legal mechanisms and safeguards for such transfers.

11. Your Privacy Rights

Depending on where you live and applicable law, you may have rights concerning your personal information, including the right to:

  • Request access to personal information;
  • Request correction of inaccurate information;
  • Request deletion of personal information;
  • Request or obtain a portable copy of certain information;
  • Restrict or object to certain processing;
  • Withdraw consent where processing is based on consent; and
  • Exercise other privacy rights provided under applicable law.

To exercise a privacy right concerning your Agiloop account or Agiloop's processing of your personal information, contact legal@agiloop.ai.

We may need to verify your identity before fulfilling certain requests.

If your request concerns information collected by an application operated by an Agiloop customer, please contact that application's operator first. Where Agiloop processes the information on that customer's behalf, we will assist the customer as appropriate.

You will not be discriminated against for exercising privacy rights provided by applicable law.

12. Sensitive Information

Agiloop does not require users to provide sensitive personal information as part of ordinary use of the Service.

However, Customer Content, repository content, documents, source code, or Customer End-User Data submitted or processed at a customer's direction may contain personal or sensitive information.

Customers are responsible for determining whether the information they submit or process through Agiloop is appropriate for the Service and for complying with laws applicable to that information.

Customers should not submit highly sensitive, regulated, or legally restricted information to Agiloop unless their use of the Service and applicable agreement with Agiloop expressly permits such processing.

13. Children's Privacy

Agiloop's Service is not directed to children under 16, and Agiloop does not knowingly collect personal information directly from children under 16.

If we learn that we have collected personal information directly from a child under 16 in violation of applicable law, we will take appropriate steps to delete it.

Agiloop customers are responsible for determining whether their own applications are appropriate for children and for complying with applicable children's privacy requirements relating to Customer End-User Data.

14. Third-Party Services and Integrations

The Service may integrate with or contain links to third-party websites, repositories, AI providers, deployment platforms, development tools, or other services.

Your use of third-party services may be subject to separate terms and privacy policies provided by those third parties.

Agiloop is not responsible for the independent privacy practices of third parties except to the extent Agiloop has obligations regarding a service provider processing information on Agiloop's behalf.

15. Enterprise Customers and Data Processing Agreements

Agiloop may enter into separate agreements with enterprise or other customers governing the processing, security, retention, or handling of Customer Content and personal information.

Where Agiloop and a customer enter into a Data Processing Addendum or other written agreement containing privacy or data-processing terms that differ from this Privacy Policy, the applicable agreement will govern the parties' respective obligations to the extent of any conflict.

16. Changes to This Privacy Policy

Agiloop may update this Privacy Policy from time to time to reflect changes to our Service, technology, business practices, legal requirements, or data-processing activities.

When we make changes, we will update the “Last updated” date at the top of this Privacy Policy.

If we make material changes, we will provide additional notice where required by applicable law, such as by email or through an in-product notification.

17. Contact Information

If you have questions about this Privacy Policy, Agiloop's privacy practices, or your personal information, or if you wish to exercise an applicable privacy right, contact:

Agiloop Inc.
Email: legal@agiloop.ai
Website: agiloop.ai

Agiloop Acceptable Use Policy (AUP)

Last updated: September 2, 2026

This Acceptable Use Policy (“AUP”) describes the rules and restrictions governing use of the Agiloop platform, websites, applications, features, and related services (collectively, the “Service”) provided by Agiloop Inc., a Delaware corporation (“Agiloop,” “we,” “our,” or “us”).

This AUP forms part of the Agiloop Terms of Service. By using the Service, you agree to comply with this AUP.

Violations may result in restrictions on use, suspension or termination of access, removal or restriction of content where appropriate, or other reasonable actions necessary to protect Agiloop, our customers, our service providers, or others.

1. Purpose and Scope

The purpose of this AUP is to help ensure that Agiloop is used safely, responsibly, lawfully, and in a manner that protects the security and reliability of the Service.

This AUP applies to all users, accounts, organizations, projects, and persons accessing or using the Service.

You are also responsible for ensuring that persons who access the Service through your account or organization comply with this AUP.

2. Prohibited Activities

You may not use the Service, or knowingly allow another person to use the Service through your account, in a manner prohibited below.

2.1 Illegal or Unauthorized Activity

You may not use the Service to:

  • Violate applicable local, state, federal, national, or international law or regulation;
  • Facilitate or promote unlawful activity;
  • Violate applicable export-control, sanctions, or anti-corruption laws;
  • Infringe, misappropriate, or violate intellectual-property, privacy, confidentiality, contractual, or other rights of another person;
  • Access, use, submit, or process information, software, repositories, systems, or data that you do not have authorization to access or use; or
  • Impersonate another person or organization or materially misrepresent your identity or authority.

3. Security and Harmful Activity

You may not use the Service to:

  • Gain or attempt to gain unauthorized access to accounts, repositories, applications, networks, systems, credentials, or data;
  • Bypass, defeat, disable, or circumvent authentication, security, access, billing, or technical controls;
  • Introduce, distribute, deploy, or facilitate malware, ransomware, viruses, destructive code, or other malicious software;
  • Disrupt, interfere with, or materially degrade the Service or systems connected to it;
  • Conduct denial-of-service attacks or intentionally impose an unreasonable load on Agiloop infrastructure;
  • Obtain credentials, authentication tokens, API keys, or other secrets without authorization; or
  • Use Agiloop to conduct malicious exploitation of third-party systems.

This section does not prohibit legitimate security testing, vulnerability analysis, code assessment, bug detection, or similar activities performed on software, repositories, or systems that you own or are expressly authorized to test.

4. Repository and Development-System Access

Agiloop may allow users to connect source-code repositories and other development systems.

You may connect or access a repository, project, application, development environment, or related system through Agiloop only if you have the authority to do so.

You may not:

  • Connect another person's or organization's private repository without authorization;
  • Use Agiloop to obtain unauthorized access to source code or proprietary information;
  • Circumvent repository permissions or access controls;
  • Use repository credentials or OAuth authorizations belonging to another person without permission; or
  • Direct Agiloop to modify, generate, deploy, or otherwise interact with software or systems you are not authorized to modify or manage.

You are responsible for the repositories, systems, and integrations you authorize Agiloop to access.

5. Misuse of AI and Generated Output

You may not use Agiloop's AI functionality to knowingly:

  • Facilitate fraud, deception, unlawful activity, or material harm;
  • Generate or deploy malicious code intended to compromise, damage, disrupt, or obtain unauthorized access to systems or data;
  • Circumvent security, usage, billing, or access restrictions;
  • Misrepresent AI-generated material in a manner that violates applicable law;
  • Use Agiloop's proprietary technology, non-public information, or Service output to reverse engineer Agiloop or build or train a competing service or model in violation of the Terms of Service; or
  • Use the Service in a manner that violates applicable requirements imposed by an AI provider whose services you choose to use through Agiloop.

Artificial intelligence may produce inaccurate or unsuitable output. You are responsible for reviewing, testing, validating, and appropriately using AI-generated output, including software code, before relying upon or deploying it.

6. Customer-Provided AI Credentials and Integrations

Where Agiloop permits you to connect your own AI provider account, API key, repository credentials, or other third-party integration, you may only provide credentials that you are authorized to use.

You may not:

  • Use stolen, compromised, or unauthorized credentials;
  • Share or use credentials in violation of the applicable provider's terms;
  • Attempt to use another customer's credentials or account;
  • Manipulate integrations to avoid applicable charges or restrictions; or
  • Use third-party services through Agiloop for purposes prohibited by the applicable provider.

You are responsible for maintaining appropriate security for credentials and integrations under your control.

7. Customer Content

You are responsible for Customer Content you submit, connect, upload, transmit, or otherwise make available through the Service.

You may not knowingly provide Customer Content that:

  • You do not own or have sufficient rights or authorization to use;
  • Violates intellectual-property, confidentiality, privacy, or other rights of another person;
  • Contains malicious software intended to harm Agiloop or another system;
  • Was unlawfully obtained; or
  • You are legally prohibited from providing to Agiloop.

Customer Content may include source code, repository information, product information, specifications, documents, prompts, data, and other materials as described in the Agiloop Terms of Service.

8. Personal, Sensitive, and Regulated Information

Agiloop does not require highly sensitive personal information as part of ordinary use of the Service.

However, Customer Content, source code, documents, repository content, and Customer End-User Data may contain personal or sensitive information.

You are responsible for determining whether information you process through Agiloop is appropriate for the Service and whether you have the legal authority and required notices, permissions, consents, or agreements to process that information.

You should not use the Service to process highly sensitive, regulated, or legally restricted information unless:

  • Your use of the Service is appropriate for that information;
  • You have all necessary rights, permissions, and lawful bases for processing it;
  • Your use complies with applicable law; and
  • Where required, your agreement with Agiloop expressly permits such processing.

Nothing in Agiloop's assessments, compliance features, security functionality, or other Service functionality constitutes a representation that your use of Agiloop automatically satisfies laws or regulatory requirements applicable to your organization or data.

9. Customer End-User Data and INSPECT

If you enable INSPECT or another Agiloop feature that collects or processes information from users of your application, you are responsible for:

  • Providing legally required privacy notices;
  • Obtaining required permissions or consents;
  • Having an appropriate lawful basis for the collection and processing;
  • Configuring your application appropriately; and
  • Complying with laws applicable to your collection and use of Customer End-User Data.

You may not use INSPECT or other Agiloop functionality to collect information about individuals unlawfully or for unauthorized surveillance, tracking, harassment, discrimination, or other prohibited purposes.

10. Abuse, Harassment, and Deceptive Conduct

You may not use the Service to:

  • Harass, threaten, stalk, intimidate, or abuse another person;
  • Facilitate unlawful discrimination;
  • Engage in fraud, impersonation, or materially deceptive conduct;
  • Violate another person's privacy rights; or
  • Facilitate activities intended to cause material harm to another person.

11. Service Integrity and Resource Use

To protect the availability, security, and performance of the Service, Agiloop may implement reasonable technical restrictions such as:

  • Rate limits;
  • API or AI usage limits;
  • Storage or data-transfer limits;
  • Concurrency restrictions;
  • Project or feature limits;
  • Credit and wallet controls; or
  • Other safeguards reasonably necessary to protect the Service and its users.

You may not intentionally bypass, manipulate, defeat, or circumvent these restrictions.

12. Scraping, Reverse Engineering, and Competitive Misuse

Except where expressly permitted by Agiloop or applicable law, you may not:

  • Scrape or systematically extract non-public data from the Service;
  • Reverse engineer, decompile, disassemble, or attempt to discover Agiloop's non-public source code or proprietary technology;
  • Circumvent technical measures designed to protect Agiloop's proprietary functionality;
  • Copy or reproduce substantial portions of Agiloop's proprietary Service; or
  • Use Agiloop's proprietary technology, non-public data, prompts, workflows, orchestration, or other protected materials to develop or train a competing product or service.

These restrictions do not limit your ownership or permitted use of your own Customer Content, your source code, your applications, or Generated Output that belongs to you under the Agiloop Terms of Service.

13. Account and Credential Security

You are responsible for maintaining reasonable security for your Agiloop account.

You must:

  • Protect your account credentials;
  • Use reasonable measures to prevent unauthorized access;
  • Promptly notify Agiloop if you become aware of unauthorized access to your account; and
  • Take reasonable action to secure integrations and credentials under your control.

You may not knowingly allow unauthorized persons to access your account.

14. Reporting Violations

If you believe the Service is being used in violation of this AUP, contact:

legal@agiloop.ai

Please provide sufficient information for Agiloop to reasonably investigate the reported activity.

15. Enforcement

Agiloop may investigate suspected violations of this AUP.

Depending on the nature, severity, and circumstances of a violation, Agiloop may take reasonable actions including:

  • Providing a warning;
  • Requesting corrective action;
  • Restricting particular functionality;
  • Removing or restricting access to content where appropriate;
  • Temporarily suspending access;
  • Terminating an account for material or repeated violations; or
  • Taking legal action where appropriate.

Where reasonable under the circumstances, Agiloop may provide notice and an opportunity to correct a violation before terminating an account.

Agiloop may take immediate action where reasonably necessary to address security threats, unlawful activity, fraud, abuse, material harm, or risks to Agiloop, its customers, its service providers, or others.

16. Relationship to Other Agiloop Terms

This AUP forms part of and is incorporated into the Agiloop Terms of Service.

Your use of the Service is also subject to the Agiloop Privacy Policy, Refund Policy, and any other applicable agreement between you and Agiloop.

If you have entered into a separate enterprise or custom agreement with Agiloop, that agreement will control to the extent it expressly conflicts with this AUP.

17. Changes to This Acceptable Use Policy

Agiloop may update this AUP from time to time to reflect changes to the Service, technology, security practices, legal requirements, or acceptable-use standards.

When we make changes, we will update the “Last updated” date above.

If changes are material, Agiloop will provide additional notice where required by applicable law, such as by email or through an in-product notification.

Continued use of the Service after an updated AUP becomes effective constitutes acceptance of the updated AUP to the extent permitted by applicable law.

18. Contact Information

For questions about this AUP, contact:

Agiloop Inc.
Email: legal@agiloop.ai
Website: agiloop.ai

Agiloop Refund Policy

Last updated: September 2, 2026

Thank you for using Agiloop. This Refund Policy explains our policies regarding payments, credits, subscriptions, cancellations, and refunds for paid features and services offered through the Agiloop platform.

Many Agiloop features are available at no charge. Fees currently apply to certain usage through IMPLEMENT and to optional ITERATE+ project subscriptions.

By purchasing credits, subscribing to ITERATE+, or otherwise using paid Agiloop services, you agree to this Refund Policy.

1. General Policy — No Refunds

Except as expressly described in this policy or as required by applicable law, all fees paid to Agiloop are non-refundable.

This includes, without limitation:

  • Purchased IMPLEMENT credits;
  • Used or unused IMPLEMENT credits;
  • IMPLEMENT usage charges;
  • Monthly or annual ITERATE+ subscription fees;
  • Partial billing periods;
  • Unused time or features;
  • Fees paid prior to cancellation; and
  • Renewal charges incurred before a subscription is cancelled.

2. IMPLEMENT Credits and Usage

IMPLEMENT is a usage-based service that allows users to build software features through Agiloop. Usage is measured based on the story points associated with the features being built.

Users purchase credits that are added to their Agiloop account wallet. Credits may then be allocated to users and projects in accordance with the functionality available within Agiloop.

The applicable cost of an IMPLEMENT action is presented to the user before generation or build processing begins. Pricing may vary depending on factors such as whether the user uses Agiloop-provided AI services or the user's own supported AI services.

Purchased Credits

Credits purchased for IMPLEMENT:

  • Remain available in the account wallet until used;
  • Do not expire; and
  • Are non-refundable, including upon cancellation or closure of an account, except where required by applicable law.

Consumption of Credits

IMPLEMENT credits are considered consumed when the user authorizes the generation or build action and Agiloop begins processing the request.

Before processing begins, Agiloop provides information about the feature or work to be generated and the applicable usage cost.

Once processing has begun, credits are non-refundable based on the quality, suitability, completeness, or user's satisfaction with the generated output. AI-generated software may require user review, modification, testing, or additional development.

Failed Processing

If an IMPLEMENT action fails due to an Agiloop platform or processing error and the applicable credits were consumed, Agiloop will restore those credits to the appropriate wallet.

Restoration of credits for a failed processing action is not considered a cash refund.

3. ITERATE+ Subscriptions

ITERATE+ is an optional paid add-on that may be activated for individual projects.

ITERATE+ may be offered on a monthly or annual subscription basis. The applicable price and billing term will be displayed when the subscription is purchased.

Unless otherwise stated at the time of purchase, ITERATE+ subscriptions automatically renew at the end of each applicable billing term until cancelled.

4. ITERATE+ Cancellations

You may cancel an ITERATE+ subscription at any time.

When you cancel:

  • Future automatic renewals for that subscription will stop;
  • No prorated refund will be provided for the remaining portion of the current billing term; and
  • ITERATE+ functionality will remain available for that project through the end of the current paid billing term.

At the end of the paid billing term, access to ITERATE+ functionality for that project will end.

Content, analyses, assessments, or results available specifically through ITERATE+ may no longer be accessible after the ITERATE+ subscription ends.

To avoid being charged for the next billing term, you must cancel the ITERATE+ subscription before its renewal date.

5. Free Agiloop Features

Agiloop provides many features and capabilities without requiring a paid subscription.

Payment is required only when a user chooses to use a paid service or feature, such as purchasing credits for IMPLEMENT or activating ITERATE+ for a project.

The availability and scope of free and paid features may change over time.

6. Billing Errors

If you believe a billing error has occurred, such as a duplicate or incorrect charge, please contact us at support@agiloop.ai within 30 days of the charge.

Agiloop will investigate reported billing errors and will correct confirmed billing errors, including issuing a refund or restoring credits when appropriate.

Requests based on dissatisfaction with properly delivered services or AI-generated results are not considered billing errors.

7. Payment Disputes and Chargebacks

If you believe a charge is incorrect, we encourage you to contact Agiloop at support@agiloop.ai before initiating a payment dispute or chargeback so that we have an opportunity to investigate and resolve the issue.

Agiloop reserves the right to restrict or suspend paid services associated with unresolved payment disputes, chargebacks, fraudulent activity, or payment abuse where reasonably necessary to protect Agiloop and its users.

Nothing in this section limits any rights you may have under applicable law or through your payment provider.

8. Changes to Pricing

Agiloop may change its pricing, credit rates, subscription fees, or paid service offerings from time to time.

The applicable price or credit cost will be displayed before a new purchase or paid usage is authorized.

For automatically renewing subscriptions, material pricing changes applicable to a future renewal will be communicated in advance as required by applicable law.

Continued use of a paid service following the effective date of an applicable pricing change constitutes acceptance of the updated pricing.

9. Enterprise and Custom Agreements

Agiloop may offer enterprise plans, negotiated pricing, volume arrangements, or other custom commercial agreements.

If you have entered into a separate written agreement with Agiloop that contains payment, credit, cancellation, or refund terms that differ from this Refund Policy, the terms of that agreement will control to the extent of any conflict.

10. Legal Requirements

Nothing in this Refund Policy limits any refund, cancellation, or other consumer rights that cannot lawfully be waived.

If applicable law in your jurisdiction requires specific refund or cancellation rights, those rights will apply to the extent required by law.

11. Changes to This Refund Policy

Agiloop may update this Refund Policy from time to time to reflect changes to our services, pricing model, business practices, or legal requirements.

When we make changes, we will update the “Last updated” date at the top of this policy. Where required by applicable law, we will provide additional notice of material changes.

12. Contact Information

For questions about this Refund Policy, billing, credits, or payments, contact:

Agiloop Inc.
Email: support@agiloop.ai
Website: agiloop.ai

Agiloop Security & Compliance Overview

Last updated: September 3, 2026

At Agiloop, security, privacy, and protection of customer intellectual property are foundational to how we design and operate the Service.

Agiloop may process sensitive business information, including product ideas, requirements, specifications, source-code context, repository information, project data, assessments, and application telemetry. We are committed to protecting that information through technical, organizational, and operational safeguards appropriate to the nature of the Service.

This Security & Compliance Overview describes Agiloop's current approach to infrastructure security, application security, data protection, AI processing, and compliance.

1. Security Philosophy

Agiloop is designed around principles intended to protect customer information and maintain a secure and reliable Service.

Our approach includes:

  • Minimizing the information we process to what is reasonably necessary to provide the Service;
  • Protecting customer intellectual property, source code, proprietary information, and Customer Content;
  • Limiting access to systems and information based on legitimate operational needs;
  • Using established third-party infrastructure and service providers where appropriate;
  • Applying security controls throughout product development and operations;
  • Monitoring and addressing security risks and vulnerabilities; and
  • Continuously improving our security and privacy practices as the Service evolves.

Security is a shared responsibility between Agiloop, our service providers, and our customers.

2. Infrastructure Security

2.1 Cloud Infrastructure

Agiloop uses managed cloud infrastructure and service providers to operate the Service.

Infrastructure and hosting providers are selected in part based on their ability to provide established security, availability, and data-protection capabilities.

Agiloop applies technical and administrative controls designed to limit unauthorized access to production infrastructure and Customer Content.

Measures may include:

  • Restricted administrative access;
  • Environment and access controls;
  • Network and infrastructure protections;
  • Secure configuration practices;
  • Logging and monitoring; and
  • Controls designed to limit access to authorized personnel and systems.

Where Agiloop relies on third-party infrastructure providers, those providers may maintain their own security certifications and compliance programs. Such certifications apply to the provider's services and do not constitute an Agiloop certification.

2.2 Encryption and Transmission Security

Agiloop uses encrypted connections for supported communications involving Customer Content and Personal Data.

Secure communication protocols are used to protect information transmitted between:

  • Users and Agiloop;
  • Agiloop systems;
  • Connected repositories and integrations; and
  • Authorized third-party service providers.

Agiloop also relies on security capabilities provided by its cloud and infrastructure providers to protect stored information.

2.3 Access Controls

Agiloop uses access controls designed to limit access to production systems and Customer Content to authorized personnel and systems with a legitimate need for access.

Controls may include:

  • Authentication requirements;
  • Role-based or restricted access;
  • Least-privilege access practices;
  • Protection of credentials and authentication tokens; and
  • Revocation or modification of access when no longer required.

3. Application Security

3.1 Authentication and Account Security

Agiloop uses security controls designed to protect customer accounts and authentication information.

These may include:

  • Secure authentication mechanisms;
  • Protection of authentication credentials;
  • Encryption of login communications;
  • Session-security controls; and
  • Access restrictions appropriate to account and organizational roles.

Customers are responsible for protecting their credentials and maintaining appropriate access controls for their own users.

Enterprise authentication capabilities may be made available under applicable enterprise arrangements.

3.2 Secure Development Practices

Agiloop incorporates security considerations into the development and operation of the Service.

Practices may include:

  • Source-code management and version control;
  • Code review;
  • Dependency management;
  • Security testing and analysis;
  • Vulnerability identification and remediation;
  • Separation of development and production activities where appropriate;
  • Configuration management; and
  • Monitoring for operational and security issues.

Agiloop may update its development and security processes as tools, technology, threats, and industry practices evolve.

3.3 Abuse Prevention and Service Protection

Agiloop may use technical controls designed to protect the Service against abuse, unauthorized activity, and excessive resource consumption.

These controls may include:

  • Rate limits;
  • Authentication protections;
  • Usage restrictions;
  • Credit and billing controls;
  • Automated abuse detection;
  • API protections; and
  • Other safeguards designed to protect the integrity and availability of the Service.

4. Customer Data and Intellectual Property

4.1 Customer Ownership

Customers retain ownership of their Customer Content and intellectual property.

Agiloop does not acquire ownership of customer:

  • Source code or repositories;
  • Applications or software products;
  • Product ideas or concepts;
  • Requirements or specifications;
  • Documents;
  • Data; or
  • Other proprietary information submitted, connected, or processed through the Service.

As described in the Agiloop Terms of Service, Agiloop also does not claim ownership of Generated Output created specifically for the customer through use of the Service, subject to applicable law and third-party rights.

Agiloop processes Customer Content only as necessary to provide, operate, secure, support, and maintain the Service and fulfill customer-requested functionality.

4.2 Repository and Source-Code Handling

Customers may authorize Agiloop to connect to supported source-code repositories and development systems.

Agiloop does not persistently store repository source code.

Relevant source code and repository context may be temporarily accessed and processed as necessary to provide requested functionality.

Where required to perform a customer-requested action, relevant code or context may be transmitted to authorized AI or infrastructure providers.

Repository access is governed by customer authorization and the permissions available through the applicable integration.

4.3 Uploaded Documents

When customers upload supported documents through INVENT or other applicable functionality, Agiloop may temporarily process the original file to extract text.

The extracted text may be retained as Customer Content associated with the applicable project.

The original uploaded file is temporarily processed and subsequently deleted after the applicable text-extraction process is completed.

5. AI Security and Data Handling

Artificial intelligence is used throughout portions of the Agiloop Service, including product discovery, requirements, architecture, software generation, assessments, recommendations, testing, review, and iteration.

5.1 AI Provider Processing

Agiloop currently supports AI services from providers including:

  • Anthropic;
  • OpenAI; and
  • xAI.

When AI functionality is used, relevant Customer Content, prompts, specifications, repository context, source-code context, or other information necessary to perform the requested action may be transmitted to the applicable provider.

5.2 Agiloop-Provided AI Credentials

When Agiloop uses its own commercial or API credentials to access supported AI providers, Agiloop uses available provider configurations intended to prevent Customer Content from being used to train the provider's foundational models.

Agiloop does not use Customer Content, source code, repositories, prompts, assessments, or Generated Output to train or fine-tune AI models.

5.3 Customer-Provided AI Credentials

Customers may choose to use their own credentials for supported AI providers.

When Customer-provided credentials are used, information still passes through Agiloop as necessary to perform the requested functionality.

The AI provider's handling of information may also be governed by the customer's own agreement, configuration, privacy settings, security settings, and retention settings with that provider.

Customers are responsible for configuring their own provider accounts appropriately.

6. INSPECT and Customer End-User Data

Customers may choose to enable INSPECT telemetry or related functionality for applications created or managed using Agiloop.

Depending on customer configuration, INSPECT may process:

  • Application usage information;
  • Performance and operational information;
  • User identifiers;
  • Email addresses; and
  • Other telemetry associated with users of the customer's application.

Agiloop generally processes this information on behalf of the customer.

Customers are responsible for providing appropriate notices, obtaining required permissions or consents, and ensuring they have a lawful basis for collecting and transmitting Customer End-User Data to Agiloop.

INSPECT data is handled in accordance with the Agiloop Privacy Policy and applicable Data Processing Addendum.

7. Personal and Sensitive Information

Agiloop does not require highly sensitive Personal Data for ordinary use of the Service.

However, Customer Content, source code, repositories, uploaded documents, project information, and Customer End-User Data may contain Personal Data or sensitive information depending on how a customer uses Agiloop.

Customers are responsible for determining whether information they process through Agiloop is appropriate for the Service and whether they have the legal authority, permissions, notices, consents, and agreements required for that Processing.

Customers should not process highly sensitive, regulated, or legally restricted information through Agiloop unless the applicable use is appropriate and expressly permitted under their agreement with Agiloop.

8. Subprocessors and Service Providers

Agiloop uses third-party providers to operate and support portions of the Service.

Current material providers include:

ProviderGeneral PurposeGoogle CloudCloud infrastructure and hostingSupabaseDatabase and application infrastructureClickHouseData and analytics infrastructureAnthropicArtificial intelligence processing, when applicableOpenAIArtificial intelligence processing, when applicablexAIArtificial intelligence processing, when applicableHubSpotCustomer communications and related business servicesFreshworks / FreshdeskCustomer support servicesStripePayment processing and related billing services

Not every provider processes Customer Personal Data for every customer. Processing depends on the functionality used and the customer's configuration of the Service.

Agiloop uses contractual and other safeguards intended to require providers that process Customer Personal Data on Agiloop's behalf to protect that information appropriately.

Additional information regarding data processing and subprocessors is available in the Agiloop Data Processing Addendum.

9. Payment Security

Agiloop uses third-party payment processors, including Stripe, to process payments.

Agiloop does not store full payment-card numbers.

Payment information submitted through applicable payment workflows is processed by the payment provider in accordance with its own security and privacy practices.

10. Security Monitoring and Incident Response

10.1 Monitoring

Agiloop uses logging, monitoring, and operational controls designed to help identify:

  • Unauthorized access;
  • Suspicious or abusive activity;
  • Application or infrastructure errors;
  • Security anomalies;
  • Service-integrity issues; and
  • Operational failures.

Monitoring capabilities may vary by system and Service component.

10.2 Incident Response

Agiloop maintains processes designed to identify, investigate, contain, mitigate, remediate, and document security incidents.

If Agiloop becomes aware of a Personal Data Breach involving Customer Personal Data, Agiloop will notify affected customers without undue delay as required by applicable law and the Agiloop Data Processing Addendum.

Agiloop will provide relevant information as it becomes reasonably available and will cooperate with affected customers as appropriate.

11. Vulnerability Management

Agiloop uses processes designed to identify, evaluate, and remediate vulnerabilities affecting the Service.

These processes may include:

  • Dependency review;
  • Software-security analysis;
  • Code review;
  • Automated or manual security testing;
  • Infrastructure review; and
  • Remediation based on risk and severity.

Agiloop continuously evaluates and evolves these practices as the Service matures.

12. Data Retention and Deletion

Agiloop retains information for as long as reasonably necessary to provide the Service and fulfill legitimate legal, security, billing, and operational requirements.

When a customer deletes an account or an account is terminated, applicable Customer Content and account information are scheduled for deletion.

Data may remain in Agiloop systems, backups, or deletion workflows for up to 30 days after account deletion or termination.

Certain limited information may be retained longer where necessary for:

  • Legal or regulatory requirements;
  • Tax or accounting obligations;
  • Security and fraud prevention;
  • Billing records;
  • Dispute resolution; or
  • Establishing, exercising, or defending legal claims.

Aggregated or deidentified information may be retained where it no longer reasonably identifies a customer or individual.

Specific retention practices for uploaded documents, repositories, Customer End-User Data, and other Customer Content are described in the Agiloop Privacy Policy and Data Processing Addendum.

13. Privacy and Data Protection

Agiloop's privacy program is designed to address applicable privacy and data-protection requirements based on Agiloop's role and the nature of the Processing.

This includes, where applicable:

  • EU GDPR and processor obligations;
  • UK GDPR;
  • Applicable U.S. state privacy laws, including service-provider, contractor, and processor requirements;
  • Restrictions on the sale or sharing of Customer Personal Data;
  • Data Subject rights;
  • Data-processing agreements;
  • International data-transfer safeguards; and
  • Subprocessor management.

Agiloop's Data Processing Addendum includes provisions addressing international transfers, including Standard Contractual Clauses and UK transfer mechanisms where applicable.

14. Compliance Assessments

Agiloop may provide compliance, security, readiness, code-health, and related assessments as part of the Service.

These assessments are intended to help customers identify potential issues, risks, gaps, and opportunities for improvement.

Agiloop assessments do not constitute:

  • Legal advice;
  • A certification;
  • An audit opinion;
  • A guarantee of regulatory compliance;
  • A representation that software satisfies every requirement of a law or standard; or
  • A substitute for professional legal, security, compliance, or certification services where those services are required.

Customers remain responsible for determining which laws, regulations, standards, contractual obligations, and compliance requirements apply to their products and organizations.

15. SOC 2 and Security Program Development

Agiloop is continuing to develop and formalize security and operational controls with reference to recognized security practices and frameworks, including areas addressed by SOC 2 such as:

  • Security;
  • Availability; and
  • Confidentiality.

Agiloop is not currently representing that it is SOC 2 certified or has completed a SOC 2 examination unless and until such status is formally achieved.

As the company and platform mature, Agiloop intends to continue strengthening its security program and evaluate formal third-party assurance and certification activities where appropriate.

16. Customer Responsibilities

Security is a shared responsibility.

Customers are responsible for:

  • Protecting their Agiloop account credentials;
  • Managing access for their authorized users;
  • Maintaining appropriate security for connected repositories and third-party accounts;
  • Protecting Customer-provided API keys and credentials;
  • Ensuring they have authority to connect repositories and systems to Agiloop;
  • Reviewing and testing Generated Output before production deployment;
  • Configuring applications and integrations appropriately;
  • Providing privacy notices and obtaining required permissions for Customer End-User Data; and
  • Determining whether particular information is appropriate for Processing through the Service.

Customers should promptly notify Agiloop if they become aware of unauthorized access or other security concerns involving their Agiloop account.

17. Additional Security and Privacy Documentation

Additional information regarding Agiloop's privacy, security, and data-handling practices is available in:

  • The Agiloop Privacy Policy;
  • The Agiloop Terms of Service;
  • The Agiloop Data Processing Addendum;
  • The Agiloop Acceptable Use Policy; and
  • Applicable enterprise or customer-specific agreements.

Enterprise customers may request additional security information where reasonably necessary for procurement, privacy, or security review.

18. Changes to This Overview

Agiloop may update this Security & Compliance Overview as the Service, security program, technology, legal requirements, and operational practices evolve.

The “Last updated” date above reflects the most recent revision.

Because security practices evolve, this Overview describes Agiloop's current practices and should not be interpreted as a guarantee that specific technologies, providers, or controls will remain unchanged.

19. Contact Us

For security or compliance questions, contact:

Agiloop Inc.
Email: security@agiloop.ai
Website: agiloop.ai

Agiloop Data Processing Addendum (DPA)

Last updated: September 2, 2026

This Data Processing Addendum (“DPA”) forms part of the Agiloop Terms of Service or other written agreement governing Customer's use of the Agiloop Service (the “Agreement”) between Agiloop Inc., a Delaware corporation(“Agiloop,” “Processor,” “Service Provider,” “Contractor,” “we,” or “us”) and the customer entity or individual entering into the Agreement (“Customer,” “Controller,” “Business,” or “you”).

This DPA governs Agiloop's Processing of Personal Data on behalf of Customer in connection with the Agiloop platform and related services (the “Service”).

This DPA becomes effective when Customer accepts or enters into an Agreement that incorporates this DPA.

1. Definitions

For purposes of this DPA:

“Customer Personal Data” means Personal Data that Agiloop Processes on behalf of Customer in connection with the Service.

“Customer End-User Data” means information relating to users of applications operated by Customer that is transmitted to Agiloop through INSPECT or another Customer-configured feature.

“Data Protection Laws” means privacy, data-protection, and data-security laws applicable to Agiloop's Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, applicable U.S. state privacy laws, and other applicable privacy laws.

“EU GDPR” means Regulation (EU) 2016/679.

“UK GDPR” means the EU GDPR as incorporated into United Kingdom law, as amended or replaced.

“Personal Data” means information relating to an identified or identifiable natural person or other information treated as personal information or personal data under applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Agiloop.

“Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given to them under applicable Data Protection Laws.

“Subprocessor” means a third party engaged by Agiloop to Process Customer Personal Data on behalf of Customer.

“Standard Contractual Clauses” or “SCCs” means the European Commission's standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded.

2. Scope and Roles of the Parties

For Customer Personal Data Processed by Agiloop on Customer's behalf:

  • Customer acts as the Controller or Business, as applicable; and
  • Agiloop acts as the Processor, Service Provider, or Contractor, as applicable.

Customer determines the purposes of Processing Customer Personal Data and instructs Agiloop regarding the Processing necessary to provide the Service.

This DPA does not apply to Personal Data that Agiloop Processes as an independent controller for its own legitimate business purposes, such as account administration, billing, fraud prevention, security, legal compliance, or business communications. Such Processing is governed by the Agiloop Privacy Policy.

If Customer itself acts as a Processor on behalf of another Controller, Customer appoints Agiloop as a Subprocessor and represents that it has authority to do so.

3. Customer Instructions

Agiloop will Process Customer Personal Data only:

  1. As necessary to provide, secure, support, and maintain the Service;
  2. In accordance with the Agreement, this DPA, Customer's configuration and use of the Service, and other documented instructions from Customer; or
  3. As required by applicable law.

Customer's use and configuration of the Service constitute documented instructions to Agiloop.

If Agiloop reasonably believes that a Customer instruction violates applicable Data Protection Laws, Agiloop will notify Customer unless prohibited by law and may suspend the affected Processing until the parties resolve the issue.

If Agiloop is required by law to Process Customer Personal Data outside Customer's instructions, Agiloop will notify Customer before doing so unless applicable law prohibits such notice.

4. Nature and Purpose of Processing

Agiloop may Process Customer Personal Data as necessary to provide functionality requested or configured by Customer, including:

  • INVENT product and feature definition;
  • Interviews, requirements, specifications, and related product-development activities;
  • Document processing and text extraction;
  • Repository access and analysis;
  • Software assessments;
  • Code-health and production-readiness analysis;
  • Bug, usability, compliance, competitive, and other analyses;
  • IMPLEMENT software generation and development functionality;
  • AI-assisted generation, analysis, testing, review, and recommendations;
  • INSPECT telemetry and application analytics;
  • ITERATE and ITERATE+ functionality;
  • Collaboration and project-management functionality;
  • Authentication and authorized integrations;
  • Customer support;
  • Security, abuse prevention, and Service integrity; and
  • Other functionality requested or configured by Customer through the Service.

The specific nature and scope of Processing depends on the functionality Customer elects to use and the information Customer chooses to provide or connect.

Agiloop does not use Customer Personal Data, Customer Content, repository content, source code, prompts, or Generated Output to train or fine-tune AI models.

5. Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer employees;
  • Customer contractors;
  • Customer representatives;
  • Customer application users;
  • Customer clients or customers;
  • Individuals identified within Customer documents, repositories, specifications, or other Customer Content; and
  • Other individuals whose Personal Data Customer is authorized to Process through the Service.

The actual categories of Data Subjects depend on Customer's use and configuration of the Service.

6. Categories of Personal Data

Depending on Customer's use and configuration of the Service, Customer Personal Data may include:

  • Names;
  • Email addresses;
  • User or account identifiers;
  • Application end-user identifiers;
  • IP addresses;
  • Usage information;
  • Application telemetry;
  • Technical and device information;
  • Project and collaboration information;
  • Information contained within specifications, requirements, prompts, and product documentation;
  • Text extracted from documents;
  • Information contained within source code or repositories;
  • Information contained within assessment inputs and outputs; and
  • Other Personal Data submitted, connected, generated, or transmitted by Customer through the Service.

Customer determines the Personal Data it makes available to Agiloop.

7. Sensitive and Regulated Personal Data

Agiloop does not require Customer to provide sensitive or special-category Personal Data as part of ordinary use of the Service.

However, Customer Content, repositories, source code, documents, and Customer End-User Data may contain sensitive or regulated Personal Data depending on Customer's use of the Service.

Customer is responsible for determining whether such Processing is permitted and appropriate and for ensuring that:

  • Customer has a lawful basis and all required permissions for the Processing;
  • Customer provides legally required notices;
  • Customer obtains required consent where applicable;
  • Customer complies with laws applicable to the data; and
  • Where necessary, Customer has entered into an agreement with Agiloop expressly permitting the applicable Processing.

Customer should not Process highly sensitive, regulated, or legally restricted information through the Service unless its use of Agiloop is appropriate for that information and expressly permitted by the applicable Agreement.

Nothing in the Service, including Agiloop's compliance or security assessments, constitutes a representation that use of the Service automatically satisfies any particular legal or regulatory requirement.

8. Repository and Source-Code Processing

Customer may authorize Agiloop to access supported source-code repositories and development systems.

Agiloop does not persistently store repository source code.

Agiloop may access, retrieve, and temporarily Process relevant source code and repository information as necessary to perform Customer-requested functionality.

Relevant source code, repository information, or code context may be transmitted to authorized Subprocessors, including AI providers, where necessary to perform Customer-requested functionality.

Customer represents that it has authority to provide Agiloop access to repositories and other development systems it connects to the Service.

9. Uploaded Documents

When Customer uploads supported documents through INVENT or other applicable Service functionality, Agiloop may temporarily Process the original file to extract text.

Agiloop may retain the extracted text as Customer Content associated with the applicable project.

The original uploaded file is temporarily processed and subsequently deleted after the applicable text-extraction process is completed.

Extracted text remains subject to the retention and deletion provisions of this DPA and the Agreement.

10. INSPECT and Customer End-User Data

Customer may enable INSPECT telemetry or related functionality within applications operated or managed by Customer.

When enabled, Agiloop may Process Customer End-User Data on Customer's behalf, which may include:

  • User IDs;
  • Email addresses;
  • Application usage information;
  • Application telemetry;
  • Performance information; and
  • Other information configured by Customer or generated through Customer's implementation of INSPECT.

Customer determines whether and how INSPECT is enabled.

Customer is responsible for providing legally required notices, obtaining required permissions or consents, and establishing a lawful basis for Customer's collection and transmission of Customer End-User Data to Agiloop.

Agiloop will Process Customer End-User Data only as necessary to provide the applicable functionality and in accordance with Customer's documented instructions.

11. Artificial Intelligence Processing

Artificial intelligence is a core component of portions of the Service.

Agiloop may transmit Customer Personal Data, Customer Content, repository context, source-code context, prompts, specifications, or other information necessary to perform Customer-requested functionality to supported AI providers.

11.1 Agiloop-Provided AI Services

Where Agiloop uses its own credentials to access a third-party AI provider, the provider may act as a Subprocessor of Agiloop.

Agiloop uses available commercial or API configurations intended to prevent Customer Content from being used to train the provider's foundational models.

Agiloop does not use Customer Personal Data, Customer Content, source code, repositories, prompts, assessments, or Generated Output to train or fine-tune AI models.

11.2 Customer-Provided AI Credentials

Customer may choose to use its own credentials or account with a supported AI provider.

When Customer uses its own credentials, Agiloop acts as an intermediary and may transmit relevant information to the selected provider to perform Customer-requested functionality.

To the extent the AI provider Processes information under Customer's direct contractual relationship with that provider, such Processing may be governed by Customer's agreement with the provider, including the provider's privacy, security, retention, and data-use practices.

Customer is responsible for reviewing and configuring its provider account appropriately for the Personal Data it chooses to Process.

12. Confidentiality

Agiloop will ensure that personnel authorized to Process Customer Personal Data:

  • Have access only as reasonably necessary to perform their responsibilities;
  • Are subject to appropriate confidentiality obligations; and
  • Receive appropriate privacy and security guidance consistent with their responsibilities.

13. Security Measures

Agiloop will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Agiloop's technical and organizational measures are further described in Annex II to this DPA.

Agiloop may update its security measures as technologies and practices evolve, provided that Agiloop does not materially reduce the overall level of protection applicable to Customer Personal Data during the term of the Agreement.

Additional security information may be made available to Customer upon reasonable request.

14. Subprocessors and Service Providers

Customer provides general authorization for Agiloop to engage Subprocessors to assist in providing the Service.

Agiloop currently uses the following material Subprocessors and service providers in connection with the Service:

Subprocessor / Service ProviderGeneral PurposeGoogle CloudCloud infrastructure and hostingSupabaseDatabase and application infrastructureClickHouseData and analytics infrastructureAnthropicArtificial intelligence processing, when applicableOpenAIArtificial intelligence processing, when applicablexAIArtificial intelligence processing, when applicableHubSpotCustomer communications and related business servicesFreshworks / FreshdeskCustomer support servicesStripePayment processing and related billing services

Not every Subprocessor or service provider necessarily Processes Customer Personal Data for every Customer. Processing depends on the functionality Customer uses, Customer's configuration of the Service, and the nature of the information involved.

Agiloop will:

  1. Maintain appropriate written agreements with Subprocessors that Process Customer Personal Data on Agiloop's behalf requiring them to protect Customer Personal Data in a manner consistent with applicable Data Protection Laws and Agiloop's obligations under this DPA;
  2. Remain responsible for the performance of its Subprocessors to the extent required by applicable law;
  3. Maintain current information concerning material Subprocessors used to Process Customer Personal Data; and
  4. Provide notice of material additions or replacements of Subprocessors where required by applicable Data Protection Laws or contractual commitments.

Agiloop may add, remove, or replace Subprocessors or service providers as the Service evolves.

14.1 Subprocessor Objections

Where required by applicable Data Protection Laws, Customer may object to a new Subprocessor on reasonable and documented data-protection grounds.

Customer must provide its objection within any notice period provided by Agiloop.

The parties will work in good faith to address the objection.

If Agiloop cannot provide a commercially reasonable alternative, Customer may terminate the portion of the Service materially affected by the new Subprocessor, subject to the applicable Agreement.

15. Personal Data Breach

If Agiloop becomes aware of a Personal Data Breach involving Customer Personal Data, Agiloop will notify Customer without undue delay.

To the extent reasonably available and legally required, Agiloop will provide information concerning:

  • The nature of the Personal Data Breach;
  • Categories of affected Personal Data;
  • Categories of affected Data Subjects;
  • Known or reasonably anticipated consequences;
  • Measures taken or proposed to address the Personal Data Breach; and
  • Information reasonably necessary for Customer to meet applicable notification obligations.

Agiloop's notification of a Personal Data Breach does not constitute an admission of fault or liability.

Agiloop will take reasonable measures to investigate, mitigate, and remediate Personal Data Breaches within its responsibility.

16. Data Subject Requests

Taking into account the nature of the Processing, Agiloop will provide reasonable assistance to Customer in responding to Data Subject requests where required by applicable Data Protection Laws.

If Agiloop receives a request directly from a Data Subject concerning Customer Personal Data Processed on Customer's behalf, Agiloop will generally direct the Data Subject to Customer unless Agiloop is required by law to respond directly.

Customer is responsible for determining how to respond to Data Subject requests.

Agiloop may require reasonable verification of Customer instructions before taking action affecting Customer Personal Data.

17. Assistance With Compliance

Taking into account the nature of Processing and information available to Agiloop, Agiloop will provide reasonable assistance to Customer with obligations under applicable Data Protection Laws relating to:

  • Security of Processing;
  • Personal Data Breach notification;
  • Data-protection impact assessments;
  • Prior consultation with Supervisory Authorities; and
  • Data Subject rights.

Customer remains responsible for determining whether such requirements apply to Customer.

18. Customer Responsibilities

Customer is responsible for:

  • Complying with Data Protection Laws applicable to Customer;
  • Providing lawful and documented Processing instructions;
  • Ensuring it has a lawful basis for Processing Customer Personal Data;
  • Providing required privacy notices;
  • Obtaining required permissions or consents;
  • Ensuring Customer has authority to provide Customer Personal Data to Agiloop;
  • Appropriately configuring the Service;
  • Maintaining appropriate security for Customer-controlled accounts, credentials, integrations, applications, and systems; and
  • Responding to Data Subject requests where Customer is responsible for doing so.

Customer will not direct Agiloop to Process Customer Personal Data in violation of applicable law.

19. Data Retention, Return, and Deletion

Agiloop will retain Customer Personal Data for as long as reasonably necessary to provide the Service and fulfill its obligations under the Agreement.

Upon termination or deletion of Customer's account, Agiloop will schedule Customer Personal Data and associated Customer Content for deletion unless applicable law requires continued retention.

Customer Personal Data may remain in Agiloop systems, backups, or deletion workflows for up to 30 days after account deletion or termination.

Agiloop may retain limited information for longer where necessary for:

  • Legal or regulatory obligations;
  • Tax, accounting, or financial recordkeeping;
  • Fraud prevention;
  • Security and abuse prevention;
  • Resolving disputes; or
  • Establishing, exercising, or defending legal claims.

Aggregated or deidentified information may be retained where it no longer reasonably identifies Customer or an individual.

Upon written request and where reasonably practicable, Agiloop will provide Customer an opportunity to retrieve or export Customer Personal Data before deletion, subject to the functionality of the Service.

20. International Data Transfers

Customer authorizes Agiloop and its Subprocessors to Process Customer Personal Data in the United States and other jurisdictions where Agiloop or its authorized Subprocessors operate, subject to applicable Data Protection Laws.

Where applicable Data Protection Laws require a valid transfer mechanism for Customer Personal Data transferred from the European Economic Area, United Kingdom, or Switzerland, the parties will use an appropriate lawful transfer mechanism.

Such mechanisms may include:

  • The Standard Contractual Clauses;
  • The UK International Data Transfer Addendum to the EU SCCs;
  • The UK International Data Transfer Agreement;
  • Applicable adequacy decisions; or
  • Other legally recognized transfer mechanisms.

21. European Economic Area Transfers

Where the SCCs are required for a transfer of Customer Personal Data subject to the EU GDPR, the SCCs are incorporated into this DPA by reference.

Unless otherwise specified in an applicable Order Form or written agreement:

  • Module Two (Controller to Processor) applies where Customer is a Controller and Agiloop is a Processor;
  • Module Three (Processor to Processor) applies where Customer acts as a Processor for another Controller and Agiloop acts as Customer's Subprocessor;
  • The optional docking clause applies;
  • The parties select the option permitting general written authorization for Subprocessors;
  • Agiloop will provide notice of intended Subprocessor changes consistent with Section 14;
  • The competent Supervisory Authority will be determined in accordance with Clause 13 of the applicable SCC module; and
  • The information necessary to complete Annex I and Annex II of the SCCs is provided in Annex I and Annex II of this DPA.

If additional information is reasonably necessary to complete the SCCs for a particular Customer, the parties may supplement the applicable annexes through an Order Form or other written agreement.

22. United Kingdom Transfers

Where Customer Personal Data subject to the UK GDPR is transferred in a manner requiring an international transfer mechanism, the applicable SCCs will be supplemented by the then-current UK International Data Transfer Addendum or another valid transfer mechanism recognized under UK law.

References to the GDPR and Supervisory Authorities will be interpreted as necessary to give effect to applicable UK Data Protection Laws.

23. U.S. State Privacy Laws

To the extent Agiloop Processes Customer Personal Data subject to an applicable U.S. state privacy law as a Service Provider, Contractor, or Processor:

  • Agiloop will Process Customer Personal Data only for the limited and specified purposes described in the Agreement, this DPA, or Customer's documented instructions;
  • Agiloop will not sell Customer Personal Data;
  • Agiloop will not share Customer Personal Data for cross-context behavioral advertising;
  • Agiloop will not retain, use, or disclose Customer Personal Data outside the direct business relationship between Agiloop and Customer except as permitted by applicable law;
  • Agiloop will not combine Customer Personal Data with Personal Data obtained from other persons or from Agiloop's own interactions with individuals except where permitted by applicable law;
  • Agiloop will provide the same level of privacy protection required of a Processor, Service Provider, or Contractor under applicable law; and
  • Customer may take reasonable and appropriate steps to help ensure Agiloop Processes Customer Personal Data consistently with Customer's obligations under applicable law.

If Agiloop determines that it can no longer meet an applicable requirement of this section, it will notify Customer as required by applicable law.

24. Audits and Compliance Information

Agiloop will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Customer may request relevant security documentation, certifications, audit reports, questionnaires, or other compliance information reasonably available to Agiloop.

If such information is insufficient to satisfy Customer's audit rights under applicable Data Protection Laws, Customer may request an audit.

Unless a Personal Data Breach, regulator request, or applicable law reasonably requires otherwise, audits will:

  • Occur no more than once in any 12-month period;
  • Require reasonable advance written notice;
  • Be conducted during normal business hours;
  • Be limited to information and systems relevant to Customer Personal Data;
  • Avoid unreasonable disruption to Agiloop operations;
  • Protect Agiloop and other customers' confidential information; and
  • Be conducted by Customer or a mutually acceptable independent auditor subject to appropriate confidentiality obligations.

Customer is responsible for its audit costs unless applicable law requires otherwise.

25. Government Requests

Unless prohibited by law, Agiloop will notify Customer if it receives a legally binding governmental request specifically seeking Customer Personal Data.

Agiloop will review such requests and may challenge requests that it reasonably believes are unlawful, overbroad, or otherwise inappropriate where legally permitted.

Agiloop will disclose only Customer Personal Data that it is legally required to disclose.

26. Liability

Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability contained in the Agreement, except to the extent such limitations are prohibited by applicable law.

27. Conflict

If there is a conflict between this DPA and the Agreement concerning the Processing or protection of Customer Personal Data, this DPA controls with respect to that conflict.

If there is a conflict between this DPA and applicable Standard Contractual Clauses, the Standard Contractual Clauses control to the extent required by applicable law.

28. Term and Termination

This DPA remains in effect for as long as Agiloop Processes Customer Personal Data on Customer's behalf under the Agreement.

Obligations that by their nature must continue following termination, including confidentiality, security, deletion, and international-transfer obligations, will survive for as long as Agiloop retains Customer Personal Data.

29. Changes to This DPA

Agiloop may update this DPA where reasonably necessary to reflect changes in applicable law, regulatory requirements, Subprocessors or service providers, the Service, or Agiloop's data-processing practices.

Agiloop will provide notice of material changes where required by applicable law or the Agreement.

No update will materially reduce Agiloop's data-protection obligations with respect to Customer Personal Data during an existing contractual term unless required by law or agreed with Customer.

30. Acceptance

This DPA is incorporated into the Agreement and becomes binding when Customer accepts an Agreement incorporating this DPA or otherwise executes or accepts this DPA.

No separate signature is required unless the parties' Agreement, applicable law, or Customer's procurement process requires one.

31. Contact Information

For privacy or data-protection inquiries:

Agiloop Inc.
Email: legal@agiloop.ai
Website: agiloop.ai

Annex I — Details of Processing

This Annex forms part of the DPA and, where applicable, provides information required for Annex I of the Standard Contractual Clauses.

A. List of Parties

Data Exporter

Name: The Customer identified in the Agreement or applicable Order Form.

Address: The address associated with Customer's account, Order Form, or Agreement.

Contact details: The contact information provided by Customer in the Agreement, Order Form, or Agiloop account.

Activities relevant to the data transferred: Customer's use of the Agiloop Service and Customer's submission, connection, transmission, or generation of Customer Personal Data through the Service.

Role: Controller, or Processor where Customer Processes Personal Data on behalf of another Controller.

Data Importer

Name: Agiloop Inc.

Entity: Delaware corporation

Contact: legal@agiloop.ai

Activities relevant to the data transferred: Providing, operating, securing, supporting, and maintaining the Agiloop Service, including AI-assisted product development, software development, assessments, telemetry, and related functionality requested by Customer.

Role: Processor or Subprocessor, as applicable.

B. Description of Transfer and Processing

Categories of Data Subjects

Depending on Customer's use of the Service, Data Subjects may include:

  • Customer employees;
  • Customer contractors;
  • Customer representatives;
  • Customer application users;
  • Customer clients or customers;
  • Individuals referenced in Customer documents, repositories, project information, or other Customer Content; and
  • Other individuals whose Personal Data Customer is authorized to Process.

Categories of Personal Data

Depending on Customer's configuration and use of the Service, Customer Personal Data may include:

  • Names;
  • Email addresses;
  • Account or user identifiers;
  • Customer application end-user identifiers;
  • IP addresses;
  • Usage and interaction information;
  • Application telemetry;
  • Technical and device information;
  • Project and collaboration information;
  • Information contained in requirements, specifications, interviews, prompts, and product documentation;
  • Text extracted from Customer-uploaded documents;
  • Personal Data contained within source code or repositories;
  • Information contained within assessment inputs and outputs; and
  • Other Personal Data Customer chooses to submit, connect, generate, or transmit through the Service.

Not every category applies to every Customer.

Sensitive Personal Data

Agiloop does not require sensitive or special-category Personal Data for ordinary use of the Service.

Customer Content may nevertheless contain sensitive or regulated Personal Data where Customer elects to provide or Process such information.

Where such Personal Data is Processed, Customer is responsible for ensuring that the Processing is permitted under the Agreement and applicable Data Protection Laws.

Frequency of Processing or Transfer

Processing may occur continuously, periodically, or on Customer request for the duration of Customer's use of the applicable Service functionality.

Nature of Processing

Processing activities may include:

  • Collection;
  • Receipt;
  • Access;
  • Retrieval;
  • Organization;
  • Storage where applicable;
  • Temporary processing;
  • Analysis;
  • Transmission;
  • Transformation;
  • Generation;
  • Comparison;
  • Assessment;
  • Extraction;
  • Consultation;
  • Use; and
  • Deletion.

Purpose of Processing

The purpose of Processing is to provide, operate, secure, support, and maintain Agiloop functionality requested or configured by Customer, including:

  • Product and feature discovery;
  • INVENT interviews and specifications;
  • Requirements and architecture;
  • Repository analysis;
  • Code-health and production-readiness assessment;
  • Bug, usability, compliance, competitive, and related analyses;
  • Software generation through IMPLEMENT;
  • AI-assisted analysis and development;
  • INSPECT telemetry;
  • ITERATE and ITERATE+;
  • Collaboration;
  • Support; and
  • Security and Service integrity.

Duration of Processing

Customer Personal Data is Processed for the duration of the Agreement and thereafter only for the retention period described in the DPA.

Following account deletion or termination, Customer Personal Data may remain in systems, backups, or deletion workflows for up to 30 days, subject to the permitted retention exceptions described in the DPA.

Subprocessor Processing

Subprocessors may Process Customer Personal Data for the duration reasonably necessary to provide the services for which Agiloop engages them.

Agiloop's current material Subprocessors and service providers and their general purposes are identified in Section 14 of this DPA.

C. Competent Supervisory Authority

For transfers subject to the EU GDPR, the competent Supervisory Authority will be determined in accordance with Clause 13 of the applicable Standard Contractual Clauses.

Annex II — Technical and Organizational Measures

This Annex describes technical and organizational measures maintained by Agiloop that are designed to protect Customer Personal Data.

The specific controls applicable to particular information may vary based on the nature of the Service functionality, Customer configuration, and the systems involved.

1. Access Control

Agiloop uses measures designed to limit access to Customer Personal Data to authorized persons and systems with a legitimate need for access.

Measures may include:

  • Authentication controls;
  • Role-based or restricted access;
  • Least-privilege access practices;
  • Controls governing administrative access;
  • Protection of credentials and authentication tokens; and
  • Revocation or modification of access when no longer appropriate.

2. Credential and Integration Security

Agiloop uses security practices designed to protect credentials used to connect third-party services, including OAuth tokens and supported AI or repository credentials.

Customer credentials are accessed and used only as necessary to provide authorized functionality.

3. Encryption and Transmission Security

Agiloop uses encryption in transit for supported communications containing Customer Personal Data.

Agiloop uses secure communication protocols and infrastructure controls designed to protect data transmitted between users, Agiloop systems, and authorized service providers.

4. Infrastructure Security

Agiloop uses third-party cloud and infrastructure providers and applies reasonable technical controls designed to protect systems used to provide the Service.

Measures may include:

  • Environment and access controls;
  • Network protections;
  • Secure configuration practices;
  • Infrastructure monitoring; and
  • Restrictions on administrative access.

5. Application Security

Agiloop maintains application-security practices designed to identify and reduce security vulnerabilities.

These measures may include:

  • Secure development practices;
  • Code review;
  • Vulnerability identification and remediation;
  • Dependency management;
  • Security testing; and
  • Controls designed to prevent unauthorized access.

6. Logging and Monitoring

Agiloop maintains logging and monitoring appropriate to the Service and its infrastructure to assist with:

  • Detecting unauthorized access;
  • Identifying suspicious activity;
  • Troubleshooting;
  • Security investigations;
  • Service integrity; and
  • Incident response.

7. Repository Processing

Agiloop does not persistently store repository source code.

Where repository source code is required to perform Customer-requested functionality, relevant source code and context may be temporarily accessed and Processed.

Relevant information may be transmitted to authorized service providers where necessary to perform Customer-requested functionality.

8. Uploaded Document Processing

Original documents uploaded through applicable INVENT functionality are temporarily Processed for purposes such as text extraction.

Following completion of the applicable text-extraction process, the original uploaded file is subsequently deleted.

Extracted text may be retained as Customer Content associated with the applicable project.

9. AI Provider Controls

When Agiloop uses third-party AI providers through Agiloop-provided commercial or API accounts, Agiloop uses available configurations intended to prevent Customer Content from being used to train the provider's foundational models.

Agiloop does not use Customer Personal Data, Customer Content, repositories, source code, prompts, assessments, or Generated Output to train or fine-tune AI models.

Where Customer uses Customer-provided AI credentials, Customer's provider configuration and agreement may independently affect provider retention and data-use practices.

10. Data Minimization

Agiloop seeks to Process information reasonably necessary to provide the functionality selected by Customer.

The amount and type of Customer Personal Data Processed depends substantially on Customer's use and configuration of the Service.

11. Personnel Confidentiality

Personnel authorized to access Customer Personal Data are subject to appropriate confidentiality obligations.

Access is intended to be limited to personnel with a legitimate operational, support, security, or other authorized business need.

12. Subprocessor Management

Agiloop evaluates and uses service providers appropriate to the functions they perform and enters into contractual arrangements designed to protect Customer Personal Data as required by applicable law.

Agiloop's current material Subprocessors and service providers are identified in Section 14 of this DPA.

13. Incident Response

Agiloop maintains processes designed to identify, investigate, mitigate, remediate, and document security incidents.

Where a Personal Data Breach affects Customer Personal Data, Agiloop will notify Customer in accordance with the DPA.

14. Vulnerability Management

Agiloop uses reasonable processes designed to identify, evaluate, and remediate vulnerabilities in the systems and applications used to provide the Service.

15. Data Retention and Deletion

Agiloop maintains processes for deleting Customer Personal Data in accordance with the DPA and Privacy Policy.

Following account deletion or termination, Customer Personal Data may remain in Agiloop systems, backups, or deletion workflows for up to 30 days, subject to permitted legal and operational retention requirements.

16. Business Continuity and Availability

Agiloop uses cloud infrastructure and operational practices designed to support the availability and resilience of the Service.

Unless expressly agreed in a separate written agreement, these measures do not constitute a service-level or uptime guarantee.

17. Ongoing Review

Agiloop may update its technical and organizational measures to reflect changes in technology, threats, infrastructure, or the Service, provided that Agiloop does not materially reduce the overall level of protection provided to Customer Personal Data during the applicable contractual term.