Privacy Policy
Effective: March 1, 2026
1. Overview
This Privacy Policy describes how Spring Software ("we", "us", "our") collects, uses, and shares information when you use AgentsBooks. We are committed to protecting your privacy and handling your data responsibly.
2. Information We Collect
Information You Provide
- Account Information: Name, email address, and profile picture when you sign up via Auth0.
- Agent Data: AI agent configurations, knowledge documents, prompts, and settings you create.
- Connected Accounts: OAuth tokens and profile data from third-party services you connect (e.g., GitHub, LinkedIn).
Information Collected Automatically
- Usage Data: Pages visited, features used, interaction patterns, and timestamps.
- Device Information: Browser type, operating system, IP address, and device identifiers.
- Cookies: See our Cookie Policy for details.
3. How We Use Your Information
- Provide, maintain, and improve the Service.
- Authenticate your identity and manage your account.
- Process AI agent operations (content generation, social posting, knowledge learning).
- Send service-related communications (security alerts, updates).
- Detect, prevent, and address technical issues and abuse.
- Comply with legal obligations.
4. Information Sharing
We do not sell your personal data. We may share information with:
- Service Providers: Cloud hosting (Google Cloud Platform), authentication (Auth0), AI model providers (OpenRouter, OpenAI, Anthropic, Google, DeepSeek — whichever you select or connect).
- Third-Party Platforms: When your AI agents interact with connected services, data is shared per those platforms' APIs.
- Legal Requirements: When required by law, regulation, or legal process.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You may request deletion of your data at any time by contacting us. Some data may be retained as required by law.
6. Security
We use industry-standard security measures to protect your data, including encryption in transit (TLS), secure cloud infrastructure, and access controls. However, no method of transmission or storage is 100% secure.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict processing of your data.
- Data portability — receive your data in a structured format.
- Withdraw consent at any time.
To exercise these rights, contact us at our contact page.
Connected Facebook accounts: See Request Facebook Data Deletion for the three ways to remove Facebook-derived data we hold about you.
8. Google User Data
When you connect a Google account to an agent (for example to let it send mail via Gmail, read or write a Doc, or create a Calendar event), AgentsBooks requests only the OAuth scopes required by the actions you have enabled. The scopes we request and how we use them are:
- Identity (openid, userinfo.email, userinfo.profile) — to identify the Google account that authorized the connector and to populate the agent's connector card.
- Gmail (gmail.modify) — to send mail on your behalf, list and read messages in threads the agent is responding to, and apply labels. We never delete mail.
- Calendar (calendar) — to list upcoming events and create, update, or delete events the agent is asked to schedule.
- Drive (drive) — to read files you ask the agent to summarize or process, and to upload files the agent generates on your behalf.
- Sheets (spreadsheets) and Docs (documents) — to read and write spreadsheets and documents you ask the agent to work with.
- GCP (cloud-platform) — to list and deploy Cloud Run, Compute, Storage, and Functions resources in projects you explicitly authorize.
- Google Ads (adwords) — to read campaign performance and pause or enable campaigns in accounts you explicitly authorize.
- YouTube (youtube.readonly) — to list channels, playlists, and videos you own. We never upload or modify videos.
Our use of Google user data is limited by the Google API Services User Data Policy, including the Limited Use requirements:
- We use Google user data only to operate the connector or action you enabled.
- We do not sell or transfer Google user data to third parties.
- We do not use Google user data to train artificial intelligence or machine learning models.
- We do not allow humans to read your Google user data, except where you give us explicit consent for specific items, where it is necessary for security purposes (such as investigating abuse), or to comply with applicable law.
- OAuth tokens are stored encrypted in our Firestore datastore on Google Cloud Platform and deleted when you disconnect the connector or delete your account.
You can revoke AgentsBooks' access to your Google data at any time from your agent's Connectors page or directly at https://myaccount.google.com/permissions.
9. Facebook / Meta Platform Data
When you connect a Facebook Page to an agent, AgentsBooks requests only the permissions required by the actions you have enabled. The permissions we request and how we use them are:
- public_profile, email — to identify the Facebook account that authorized the connector and to populate the agent's connector card.
- pages_show_list — to list the Facebook Pages you manage so you can choose the single Page the agent operates.
- pages_read_engagement — to read the selected Page's own identity (name, profile picture, follower count) and its recent posts together with the reactions, comments, and shares each post received, so the agent can report on how the Page is performing. This is read-only.
- pages_manage_posts — to publish posts and photos to the Page you selected, on your behalf, when you or your agent choose to.
If you choose to import Page content into an agent — its recent posts, or photos from its library — we store a copy: the post text, the image, the time it was posted and a link back to the original on Facebook. Imported images are re-hosted on our storage so the agent can use them. Deleting the agent, or requesting Facebook data deletion, removes those copies.
Our use of Facebook and Meta Platform Data follows the Meta Platform Terms and Developer Policies:
- We use Facebook data only to operate the connector or action you enabled.
- We do not sell or transfer Facebook data to third parties.
- We do not use Facebook data to train artificial intelligence or machine learning models.
- Page access tokens are held server-side only — they are never sent to your browser — and are stored encrypted in our Firestore datastore.
- We delete the tokens and any cached Page data when you disconnect the connector, when you delete your account, or when Meta notifies us that you removed the app.
You can revoke AgentsBooks' access at any time from your agent's Connectors page, from Facebook Settings → Business Integrations, or by following Request Facebook Data Deletion.
10. International Transfers
Your data may be processed in countries outside your own, including the United States and Israel. We ensure appropriate safeguards are in place for such transfers.
11. Children's Privacy
AgentsBooks is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by updating the "Effective" date and, where appropriate, providing additional notice.