This Privacy Policy applies to the Agent Outbox website, sign-up and sign-in flows, hosted application, caller API, command-line software, billing flows, and support interactions (collectively, the "Services").
"Conn Castle Studios," "we," "us," and "our" refer to Hardware Breakout LLC doing business as Conn Castle Studios. "You" refers to the person or entity using the Services.
The Services are controlled from the United States and intended for the U.S. market. We do not market or localize the Services for the European Union, European Economic Area, United Kingdom, or Switzerland. If you access the Services from another location, your information may be processed in the United States and in locations where our providers operate.
1. Information We Collect
Account and billing information
- Authentication information such as your email address and the user and session identifiers managed through Clerk.
- Agent Outbox account identifiers, membership, account tier, and account activity timestamps.
- Stripe customer, subscription, price, status, period, and webhook identifiers used to administer paid plans. Stripe, not Agent Outbox, collects and processes full payment-card details.
Caller registration and credential information
- Caller names, caller slugs, setup-request state, approval state, callback information, and timestamps used to connect, rotate, and revoke callers.
- Caller key identifiers, prefixes, last characters, keyed secret digests, status, activation, use, expiration, and revocation timestamps. Display-once caller secrets are not retained in plaintext by the hosted service.
Review queue, answer, and file content
- Review-item identifiers, titles, subtitles, summaries, details, safe HTML, links, icons, priorities, visual metadata, available actions, popup fields, caller-owned values, and timestamps submitted by authorized callers.
- Human answers such as action choices, free text, selections, dates, and file-upload responses, together with read and acknowledgement state.
- Uploaded filenames, MIME types, byte sizes, cryptographic digests, and file bytes. Uploaded files are part of a caller result, not a general-purpose file-storage service.
Usage, security, and diagnostic information
- Request timestamps, routes, response status, trusted source IP information used for narrow abuse controls, quota windows, rate limits, storage counts, and active limit state.
- Content-safe audit events containing lifecycle event types, internal identifiers, response kinds, byte counts, deletion reasons, and request or correlation identifiers. Audit events are designed not to contain review text, answer text, file bytes, or caller secrets.
- Content-safe application logs and Sentry error reports containing error class, operation, route, release, environment, and correlation identifiers. Runtime exception messages sent to Sentry are replaced with a fixed sanitized message.
- Cloudflare Web Analytics performance and page-view measurements. Its browser beacon does not use cookies, local storage, session storage, or fingerprinting and does not retain the visitor IP in its analytics data.
Information you send us
If you use our contact form or email us, we receive your name and email address, the topic and message you provide, and related delivery metadata. Do not send passwords, caller API keys, payment-card data, or unnecessary review content in a support message.
2. Sources of Information
- Directly from you when you create an account, use the review UI, subscribe, or contact us.
- From authorized caller software when it registers, authenticates, submits review items, reads outputs, downloads files, or acknowledges completed work.
- From Clerk and Stripe when they provide authentication and billing events needed to operate your account.
- Automatically from the application, API, command-line client, infrastructure, and observability systems when you use the Services.
3. How We Use Information
- Provide and authenticate the hosted application, caller API, command-line flows, account membership, and billing features.
- Store review items, deliver them to an authorized human, return answers and files to the correct caller, and delete acknowledged or expired queue content.
- Enforce account boundaries, caller credentials, product limits, quotas, rate controls, retention, and abuse protections.
- Process subscriptions, reconcile billing status, handle payment failure and cancellation, and provide the billing portal.
- Monitor, secure, debug, and improve the Services and investigate failures, suspicious activity, and support requests.
- Enforce our Terms, protect our rights and users, respond to lawful requests, and comply with legal, tax, accounting, and security obligations.
4. Cookies, Local Storage, and Local Credentials
- Clerk uses necessary cookies and browser storage to secure sign-up, sign-in, and authenticated browser sessions.
- Cloudflare Web Analytics is configured as cookie-free performance and page-view analytics and does not access browser storage.
- The Agent Outbox command-line client keeps connection configuration and caller credentials on your device or accesses credentials through a credential-management mechanism you provide. A credential is sent to the hosted caller API only to authenticate a request.
We do not currently use advertising cookies, cross-site behavioral advertising, or a marketing session-replay product. Blocking required authentication storage may prevent protected parts of the Services from working.
5. How We Disclose Information
We disclose information only as reasonably necessary to operate the Services, fulfill your requests, secure the platform, or comply with law.
- Clerk: authentication, account identity, and browser session management.
- Stripe: hosted Checkout and Billing Portal, customer and subscription administration, payment processing, and billing events.
- Cloudflare: DNS, hosted application and API execution, contact-form email delivery, request security, structured runtime logs, and privacy-oriented Web Analytics.
- Supabase: managed Postgres storage for accounts, callers, queue content, answers, file bytes, usage state, and audit records.
- Sentry: sanitized application exception grouping, releases, and source-map-assisted diagnostics.
- Zoho Mail: receipt and storage of contact-form and email messages delivered to contact@agent-outbox.dev.
- Professional advisors and legal process: lawyers, auditors, insurers, regulators, courts, or law enforcement when required or reasonably necessary.
- Business transfers: parties involved in a merger, financing, acquisition, reorganization, or sale of all or part of the business, subject to applicable obligations.
We do not sell personal information and do not share it for cross-context behavioral advertising.
6. Data Retention
We retain information for as long as reasonably necessary to provide and secure the Services, satisfy legal and accounting obligations, resolve disputes, and enforce agreements. Primary queue content has these product-specific rules:
- Pending items on the hosted free tier are eligible for scheduled deletion after 60 days without an update. The hosted paid tier does not currently apply an automatic pending-item retention timeout.
- A caller can delete a pending item. A human answer remains linked to its output until the caller acknowledges it, the human undoes it before the first caller read, or timeout cleanup resolves it.
- Unacknowledged outputs, associated answers, matching input items, and uploaded file bytes are deleted no later than the 14-day output timeout. Acknowledgement deletes them earlier.
- Completed or abandoned caller setup requests and callers that never activate and have no meaningful history are generally eligible for cleanup after seven days.
- Processed Stripe webhook idempotency records are eligible for cleanup after 90 days. Billing and transaction records held by Stripe may be retained longer for tax, accounting, fraud, and legal purposes.
- Content-safe audit events are append-only operational history and do not currently have an automatic deletion window. Quota windows, temporary limit state, and IP rate-limit counters are pruned when their enforcement windows are no longer live.
- Logs, diagnostics, and contact messages are retained according to operational need and the configured retention of Cloudflare, Sentry, and Zoho Mail.
We may retain limited information longer when required for security, fraud prevention, legal compliance, accounting, dispute resolution, or enforcement. Deletion from active systems may not immediately remove data from provider backups maintained for disaster recovery.
7. Your Choices and Privacy Requests
Depending on applicable law, you may have rights to request access, correction, deletion, or information about personal information we maintain. You may also be entitled to object to certain processing or appeal a denied request.
- Manage your authentication session through the Clerk-powered sign-in and sign-out experience.
- Manage subscription renewal and payment methods through the Stripe-hosted billing portal.
- Delete pending queue items and acknowledge handled outputs through authorized caller workflows, which removes their live queue and file content.
- Revoke caller credentials through the authorized rotate and revoke flows.
Email privacy requests to contact@agent-outbox.dev. We may ask you to verify your identity and account authority before completing a request.
8. International Processing
Conn Castle Studios is based in the United States. The Services and their providers may process information in the United States and in other countries where those providers operate. Those locations may have data-protection laws different from the laws where you live.
9. Children's Privacy
Agent Outbox is not intended for anyone under 18. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and address the issue.
10. Security
We use administrative, technical, and organizational measures designed to protect information, including authenticated access, account and caller authorization, restricted provider credentials, encryption in transit, database row-level security, credential digests, product limits, and content-safe logging and audit controls.
No security measure is perfect. We cannot guarantee that information will always remain secure. You are responsible for protecting your devices, accounts, caller credentials, and connected systems.
11. Changes to This Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will post the revised version and update the last-updated date. If a change is material, we may provide additional notice through the Services or another appropriate means.
12. Contact
Conn Castle StudiosHardware Breakout LLC
3 Cressier Ct.
Fairport, NY 14450
For questions or privacy requests, email contact@agent-outbox.dev.