Privacy Policy
What we collect on theagenticlab.net, why, where it lives, how long we keep it, and how you delete it.
The Agentic Lab® ("the Lab", "we") builds software for businesses. This policy explains what we collect when you use theagenticlab.net, why we collect it, where it is stored, how long we keep it, and how you can see it or delete it. It is written to be read, not skimmed.
1. Who we are
The Agentic Lab® is operated from New Jersey, United States. Contact us at sales@theagenticlab.net, or through the Legal notice page for our postal address.
2. What we collect, and when
When you build a brief. Your name, email, phone number with its country, company, current website, what you need, your market, budget range, timeline, how you found us, how you prefer to be contacted, and the text you write about your project. We create a reference number for the brief. We also record the country and IP address the brief came from and the browser you used, to protect the form against abuse.
When you book a Google Meet. The time you chose. We create an event on our Google Calendar with your name, email, and the brief's summary, and we send you an invitation file inside our confirmation email. Google receives the event details as our calendar provider.
When you look up a brief. The email or phone number you type. We match it against our records and either show the brief on the page (with the reference) or email your references to the address on file.
When you sign in to the client area. Your email address and the six-digit code we send it. We keep a session record so you stay signed in, plus the time of your sign-in, your browser type, and your country.
In the client area. The documents we place in your area, the files you send us with any note, and, if you choose, a photo for your profile. We record when you first open a document we sent you.
When you sign a document. The full name you type, the agreement statement you tick, the date and time, your IP address, your country, your browser, the result of the human check, the time you typed back the one-time code we emailed you, and a fingerprint (SHA-256) of the file you signed. We build a certificate from these and email it to you and to us.
When you end things. If you ask to delete everything, we record only that a deletion happened, with the brief references and counts, never your email. If a business asks to end our work together, we record the request, any note you add, and the outcome.
On every page. Standard server logs from our hosting provider (Cloudflare), which include your IP address and browser, kept by them for security.
3. What we do not collect
We do not run advertising trackers or analytics pixels. We do not collect card or bank details on the site; payment is arranged between us directly. We do not read your photo or files for any purpose other than showing them to you and to Lab staff working on your account.
4. Why we use it
To answer your brief and quote it; to hold the meeting you booked; to run the client area; to send you the emails you asked for (codes, confirmations, documents, receipts, signatures); to keep the site safe from bots and abuse; to keep records of agreements we have made with you; to meet our legal and accounting duties.
Where a law asks for a legal basis: we rely on the steps you take (your brief, your sign-in, your signature), on our contract with you, and on our legitimate interest in running a secure service and keeping business records.
5. Cookies and on-device storage
We use one cookie, tal_session, set only when you sign in to the client area. It keeps you signed in for up to 30 days, or until 7 days pass without a visit. It is HttpOnly and sent only to our site. We do not use advertising or analytics cookies.
We use browser storage on your device for convenience: the email you last typed at the sign-in and whether you are signed in, the tab you were on in the client area, your language choice on the legal pages, the reference and email of the last brief you sent (so Find my brief can offer it back to you), a short-lived copy of what the client area last showed you, and your scroll position on reload. These stay on your device, are cleared when you sign out or clear your browser data, and are not sent to us.
Cloudflare's Turnstile check on the brief and on document signing sets its own cookie to tell humans from bots, under Cloudflare's privacy policy.
6. Who else sees it
We use a small number of providers to run the site. Each one processes only what it needs, under its own terms:
- Cloudflare, Inc. hosts the site, its records (KV) and files (R2), and runs the human check and email routing. Data sits on Cloudflare's global network, with our primary storage in the United States.
- Resend, Inc. delivers our emails from hello@theagenticlab.net.
- Google LLC provides the calendar and Google Meet for booked meetings.
Lab staff who work on your account can see everything in your client area, including read receipts and the files you send. We do not sell personal data. We share it with nobody else unless the law requires it or you ask us to.
7. International transfers
We serve clients in Egypt, the Gulf, the United States and the United Kingdom, and our providers operate worldwide. Your data may be stored or processed in the United States. We choose providers with strong security and contractual commitments to protect your data.
8. How long we keep it
- Sign-in codes: 10 minutes.
- Sessions: 30 days from sign-in, or 7 days without a visit.
- Activity logs and email counters: 30 to 40 days.
- Briefs, meetings, documents and your photo: for as long as you have a brief or an account with us, until you delete them (section 9).
- Signed documents and their certificates: we keep our own copies for as long as the law requires us to keep contracts and accounting records, even after your area is removed.
- Our email copies of what we sent you: kept as business correspondence.
9. Your choices and your rights
Delete everything. If you sent a brief and have no active business with us, the client area has a single button, "Delete everything about me". It removes your briefs, your reference lookups, every file, your photo, your sessions and codes, and any future meeting on our calendar. You get one last email confirming it.
End the business. If you are a client with an active account, the client area has "End business with us". It opens an orderly close: we send the closing list within one working day, you receive every file you are owed, and your data is removed when both sides say done, 30 days later unless we agree otherwise.
See, correct, or export. Write to sales@theagenticlab.net and we will show you what we hold, fix what is wrong, or send you a copy.
Complain. If you believe we have handled your data badly, tell us first. You may also complain to the data protection authority where you live.
Depending on where you are, laws such as the EU and UK GDPR, Egypt's Personal Data Protection Law (Law 151 of 2020), Saudi Arabia's Personal Data Protection Law (PDPL), the United Arab Emirates' Personal Data Protection Law (Federal Decree-Law 45 of 2021) and US state privacy laws may give you specific rights. We honor them regardless of where you are.
10. Security
Sign-in is by short-lived code, never a password. Sessions are HttpOnly cookies. Every request that changes something is checked for origin. Files are served only to the account they belong to. Codes and rate limits protect the door. Signatures carry a cryptographic fingerprint of the file. No system is perfect; if we learn of a breach affecting you, we will tell you without undue delay.
11. Children
Our services are for businesses and the people who run them. We do not knowingly collect data from anyone under 18.
12. Changes
We will post changes here with a new date and version. If a change matters to you, we will tell you by email.
Version 1.0, September 7, 2026.