Privacy Policy
Last updated: September 28, 2026
This Privacy Policy describes how AUGLAB LLC, a Florida limited liability company (“we,” “us,” or “the Company”) collects, uses, and protects your information when you use the augLab platform (“the Service”). By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, and a hashed version of your password. If you join an organization, we also store your membership role and association with that organization.
Billing Information: Billing is managed through invoice-based agreements with your organization. We do not collect or store credit card numbers, bank account details, or other payment credentials on our servers.
Usage Data: We collect information about how you use the Service, including agent configurations, workflow definitions, run history, knowledge base metadata, and feature usage patterns.
Device & Log Data: We may collect your IP address, browser type, operating system, referring URLs, and access timestamps when you interact with the Service.
2. API Keys, Credentials & Data Encryption
API keys, agent run history, and file uploads stored in augLab are encrypted at rest using AES-256-GCM encryption. Keys and sensitive data are only decrypted in-memory during agent execution and are never logged, persisted in plaintext, or transmitted to third parties beyond the intended service provider (e.g., your chosen LLM provider). You are responsible for the security and rotation of your own API keys.
3. How We Use Your Data
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process billing and manage your account
- Send transactional emails (welcome emails, organization invitations)
- Manage platform access and organization memberships
- Monitor for abuse, fraud, and security incidents
- Improve the Service based on aggregated, anonymized usage patterns that do not include Protected Health Information
- Respond to your support requests and inquiries
We do not sell, rent, or trade your personal data to third parties.
4. Agent Execution & Data Processing
When your agents execute, they may send data to third-party LLM providers and other services using API keys you have configured. augLab acts as an intermediary and does not control how third-party providers process that data. We do not use the content of your agent inputs or outputs for training models or any purpose other than executing your requested operations.
Run history and agent outputs are encrypted at rest and may be stored to provide you with execution logs. You may delete this data at any time through the Service. Organizations with HIPAA mode enabled must have encryption configured; the platform will not store run data in plaintext for those organizations.
5. Protected Health Information
Do not submit Protected Health Information (“PHI”) unless HIPAA mode is enabled for your organization and AUGLAB LLC has executed a Business Associate Agreement with that organization. We do not request PHI for account, billing, or support purposes.
When those conditions are met, we process PHI only to provide the Service to that organization. We do not use it to train models, for marketing, or for product development. HIPAA mode adds enforced multi-factor authentication, encryption of stored run data, and restrictions on which model providers can be used. Notice of a breach or security incident involving that PHI is governed by the Business Associate Agreement.
If you submit PHI without HIPAA mode and an executed Business Associate Agreement, you do so in violation of the Terms of Service. We do not agree to act as a business associate for that information, and the HIPAA-mode safeguards are not applied to it. Saying that your organization does not need HIPAA does not change this.
The Service uses API keys you provide. You are responsible for having a business associate agreement with each LLM provider that will receive PHI under your key.
6. Cookies & Tracking
We use essential cookies and local storage to maintain your authentication session and preferences. We may use privacy-respecting analytics to understand aggregate usage patterns. We do not use third-party advertising trackers or sell data to advertisers.
7. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area or the United Kingdom, we process your personal data only when we have a legal basis under the GDPR and UK GDPR:
- Contract: to provide the Service, manage your account and organization membership, and process billing under our agreement with your organization.
- Legitimate interests: to secure the Service, prevent abuse and fraud, maintain audit logs, and improve the Service based on aggregated usage — balanced against your rights and expectations.
- Consent: for optional communications (such as marketing emails) and non-essential analytics. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: to retain records and respond to lawful requests where required by law.
8. Automated Decision-Making & Tracking Choices
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. Agents you build may perform automated processing of the data you direct them to; that processing is under your control and is governed by Sections 4 and 5, not by augLab.
We honor Global Privacy Control and browser Do Not Track signals for any analytics we operate. Because we use only essential cookies plus privacy-respecting analytics, no third-party advertising opt-out is applicable.
9. Third-Party Services
We share data with the following categories of third-party services:
- LLM Providers — only data you explicitly send through your agent configurations, using your own API keys
- Hosting Provider — our infrastructure provider processes data as needed to host the Service
- Email Provider — your email address and name for transactional emails
Each third-party service is governed by its own privacy policy. We require that all service providers maintain appropriate data protection standards.
10. Organizations & Shared Data
If you create or join an organization, other members of that organization may be able to see your name, email address, role, and shared resources within the organization workspace (such as agents, workflows, and knowledge bases). Organization administrators may have access to usage data and member activity within the organization.
11. Data Retention
Your data is retained as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal, tax, or compliance purposes. Anonymized, aggregated data that cannot identify you may be retained indefinitely for analytics. Where an executed Business Associate Agreement applies, PHI is retained or deleted as that agreement and the organization's configured retention period require.
12. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encryption at rest for credentials, run data, and file uploads (AES-256), hashed passwords (bcrypt), multi-factor authentication (TOTP), scoped download tokens for file access, and access controls on our infrastructure. Organizations with HIPAA mode enabled are subject to additional safeguards including enforced MFA for all members and mandatory encryption for all stored data. Those additional safeguards apply only while HIPAA mode is enabled. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Export: Request a portable copy of your data in a machine-readable format
- Objection: Object to certain processing of your data
- Restriction: Request that we limit how we process your data
To exercise any of these rights, contact us at contact@auglab.ai. We will respond to your request within 30 days. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office). Where our processing is based on consent, you may withdraw that consent at any time.
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to: (a) know what personal information we collect and how it is used, (b) request deletion of your personal information, (c) correct inaccurate personal information, (d) limit the use of sensitive personal information, (e) opt out of the sale or sharing of your personal information (we do not sell or share personal information for cross-context behavioral advertising), and (f) not be discriminated against for exercising your privacy rights. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. To make a request, contact us at contact@auglab.ai. We will verify your request before acting on it and respond within the timeframes required by law.
15. International Data Transfers
The Service is hosted in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Service, you consent to this transfer. We take appropriate safeguards to ensure your data is treated in accordance with this Privacy Policy regardless of where it is processed.
16. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly. If you believe we have collected information from a child, please contact us at contact@auglab.ai.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
18. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at contact@auglab.ai.