<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>AGL Connect Privacy Policy</title>
<meta name="description" content="What AGL Connect reads, keeps, and never does.">
<meta name="robots" content="index,follow">
<link rel="canonical" href="https://connect.agilegrowthlabs.com/pages/privacy">
<link rel="icon" href="https://connect.agilegrowthlabs.com/pages/favicon.svg">

<style>
  :root { --ink: #0A0A0C; --paper: #FAFAF7; --rule: #E6E5DF; --accent: #19E08F; --muted: #6B7280; --code-bg: #F2F1EC; --maxw: 720px; }
  * { box-sizing: border-box; }
  html, body { margin: 0; padding: 0; background: var(--paper); color: var(--ink); }
  body { font-family: 'Space Grotesk', system-ui, -apple-system, Segoe UI, Roboto, sans-serif; font-size: 17px; line-height: 1.6; }
  .wrap { max-width: var(--maxw); margin: 0 auto; padding: 56px 24px 96px; }
  header { display: flex; align-items: baseline; justify-content: space-between; margin-bottom: 40px; padding-bottom: 16px; border-bottom: 1px solid var(--rule); }
  .brand { font-family: 'Bebas Neue', Impact, sans-serif; font-size: 22px; letter-spacing: 0.04em; }
  .brand a { text-decoration: none; }
  .brand em { color: var(--accent); font-style: italic; }
  .meta { color: var(--muted); font-size: 14px; }
  h1 { font-family: 'Bebas Neue', Impact, sans-serif; font-size: 44px; letter-spacing: 0.02em; line-height: 1.05; margin: 0 0 24px; }
  h2 { font-size: 22px; line-height: 1.25; margin: 40px 0 12px; }
  h3 { font-size: 18px; margin: 28px 0 8px; }
  p, ol, ul { margin: 0 0 16px; }
  ol, ul { padding-left: 22px; }
  li { margin-bottom: 8px; }
  a { color: var(--ink); text-decoration: underline; text-decoration-thickness: 1.5px; text-underline-offset: 3px; }
  a:hover { color: var(--accent); }
  code { font-family: ui-monospace, SFMono-Regular, Menlo, monospace; background: #fff; border: 1px solid var(--rule); padding: 1px 6px; border-radius: 4px; font-size: 14.5px; }
  pre { background: var(--code-bg); border: 1px solid var(--rule); border-radius: 8px; padding: 16px; overflow-x: auto; font-size: 14.5px; line-height: 1.5; }
  pre code { background: transparent; padding: 0; border: 0; }
  .prompt { background: #0A0A0C; color: #F2F1EC; border-radius: 10px; padding: 18px 22px; font-family: ui-monospace, SFMono-Regular, Menlo, monospace; font-size: 14.5px; line-height: 1.6; white-space: pre-wrap; margin: 12px 0 20px; }
  .pill { display: inline-block; font-size: 12px; letter-spacing: 0.08em; text-transform: uppercase; background: #fff; border: 1px solid var(--rule); padding: 4px 10px; border-radius: 999px; color: var(--muted); margin-right: 8px; }
  .pill.accent { color: var(--ink); border-color: var(--accent); background: #E9FBF3; }
  .toc { background: #fff; border: 1px solid var(--rule); border-radius: 10px; padding: 18px 22px; margin: 0 0 32px; }
  .toc h4 { margin: 0 0 8px; font-size: 14px; letter-spacing: 0.08em; text-transform: uppercase; color: var(--muted); }
  .toc ol { margin: 0; padding-left: 20px; }
  .callout { background: #fff; border: 1px solid var(--rule); border-left: 3px solid var(--accent); padding: 16px 20px; border-radius: 8px; margin: 20px 0; }
  .card { background: #fff; border: 1px solid var(--rule); border-radius: 10px; padding: 16px 20px; margin: 0 0 14px; }
  .card h3 { margin: 0 0 4px; }
  .card p { margin: 0 0 6px; }
  footer { margin-top: 64px; padding-top: 16px; border-top: 1px solid var(--rule); color: var(--muted); font-size: 14px; }
  @media (max-width: 560px) { h1 { font-size: 34px; } .wrap { padding: 32px 18px 64px; } }
</style>
</head>
<body>
<div class="wrap">
  <header>
    <div class="brand"><a href="https://connect.agilegrowthlabs.com/pages/">AGL <em>Connect</em></a></div>
    <div class="meta">Privacy</div>
  </header>
<h1>AGL Connect Privacy Policy</h1><p class="meta">Last updated: September 12, 2026.</p><p>This is the privacy policy for AGL Connect, an MCP connector built by Agile Growth Labs. AGL Connect runs inside Claude, ChatGPT, and other clients that install MCP servers by URL. This page tells you what we read, what we keep, and what we never do.</p><p>Read it. If anything is unclear, email <a href="mailto:support@agilegrowthlabs.com">support@agilegrowthlabs.com</a> and a person will answer.</p>
<h2>Who we are</h2><p>AGL Connect is operated by Agile Growth Labs. Henry Kraus is the data controller. Contact: <a href="mailto:support@agilegrowthlabs.com">support@agilegrowthlabs.com</a>.</p>
<h2>What AGL Connect does in plain words</h2><p>AGL Connect helps 2 parties find each other. You raise a hand for what you offer or what you want. Other members do the same. The connector ranks the other side. When you ask for an intro, Henry reviews it and sends it by hand. Bots never get your email.</p>
<h2>What data we collect</h2><p>We collect 3 things, and only when you act.</p><ol><li>Your verified email when you sign in with a 6-digit code. From it we derive your domain. We also keep the name you give us, or the part of your email before the @ if you give none.</li><li>The hands you raise. Each hand has: side, category, headline, details, segment, criteria, and a public flag. You choose every value.</li><li>The intro requests you make. Each has 1 to 2 lines of context you wrote, plus the draft note we write for Henry to review.</li></ol><p>If your assistant stages feelers to people found on the public web, we store their name, company, and public URL as a feeler draft. We do not store them as members. They become members only if they raise a hand.</p>
<h2>What we do not collect</h2><div class="callout"><p style="margin:0"><strong>We do not store the conversation.</strong> Not your prompts. Not the assistant replies. Only the fields named above. If you ask a question and never raise a hand, we keep nothing about that conversation.</p></div><p>We do not run analytics pixels or third-party trackers. The connector serves JSON and nothing else.</p><p>We do not buy, rent, or enrich data. We do not sell or share your data with advertisers or data brokers. Ever.</p>
<h2>Where it goes</h2><p>Your data sits in 1 Postgres database hosted on Supabase in the United States. Only the connector and Henry can read it. The connector never returns another member's email to any caller.</p>
<h2>How we use it</h2><p>1 thing: to match hands and to draft intros for Henry to approve. If Henry sends an intro, both sides get 1 short email with the other side's name, company, and headline. If he does not send it, nothing goes out.</p>
<h2>How long we keep it</h2><p>Your hands stay open until you withdraw them or delete your data. Server logs (timestamp, tool name, your email, response code) are kept for 30 days, then deleted. Logs do not contain tool arguments or assistant outputs.</p>
<h2>How to delete your data</h2><p>2 ways.</p><ol><li>Ask your assistant to call <code>delete_my_data</code>. Your member record and everything tied to it is deleted at once.</li><li>Email <a href="mailto:support@agilegrowthlabs.com">support@agilegrowthlabs.com</a> from the address you signed in with. Subject line: "delete my AGL Connect data." We confirm and delete within 3 business days.</li></ol>
<h2>How to see what we have on you</h2><p>Ask your assistant to call <code>my_hands</code>. Or email support and we send the rows as JSON within 3 business days.</p>
<h2>How to fix what we have on you</h2><p>Withdraw the hand with <code>withdraw_hand</code> and raise a new one.</p>
<h2>Who can see your hands</h2><ol><li>You.</li><li>Other signed-in members who run <code>find_matches</code>. They see your company, headline, and segment. Not your email.</li><li>Anyone on the web, if you set a hand to public. Public hands show on the <a href="https://connect.agilegrowthlabs.com/pages/members">members page</a> with your name and company. Want hands on the <a href="https://connect.agilegrowthlabs.com/pages/wants">open wants page</a> show headline, segment, and category only. No name.</li><li>Henry Kraus and any AGL engineer doing security or debugging work, under a written confidentiality obligation, only when needed.</li></ol>
<h2>Children</h2><p>AGL Connect is for business use. Do not use it if you are under 18.</p>
<h2>Security</h2><p>All traffic is TLS. The database is encrypted at rest. Sign-in uses OAuth 2.1 with PKCE and an email one-time code. Access tokens last 24 hours. Refresh tokens last 30 days and rotate on use.</p><p>We are a small team. We do not claim SOC 2 today. If a breach happens, we notify affected members by email within 72 hours of discovery.</p>
<h2>Your rights</h2><p>If you live in the EU, UK, California, or any other place with a privacy law, you have the rights that law gives you: access, correction, deletion, portability, and the right to complain to your regulator. Use the contact above.</p><p>We do not sell personal data, so the opt-out-of-sale right does not apply.</p>
<h2>Changes to this policy</h2><p>If we change this policy in a way that affects you, we post the new version at this URL, change the date at the top, and email everyone with an open hand.</p>
<h2>Contact for data requests</h2><p>Email: <a href="mailto:support@agilegrowthlabs.com">support@agilegrowthlabs.com</a><br>Subject lines we recognize: "access my data", "delete my data", "correct my data", "complaint."<br>We answer within 3 business days.</p>

  <footer>
    AGL Connect is operated by Agile Growth Labs.
    <a href="https://connect.agilegrowthlabs.com/pages/docs">Docs</a> &middot;
    <a href="https://connect.agilegrowthlabs.com/pages/members">Members</a> &middot;
    <a href="https://connect.agilegrowthlabs.com/pages/wants">Open wants</a> &middot;
    <a href="https://connect.agilegrowthlabs.com/pages/privacy">Privacy</a> &middot;
    <a href="https://connect.agilegrowthlabs.com/pages/terms">Terms</a> &middot;
    <a href="https://connect.agilegrowthlabs.com/pages/data-handling">Data handling</a> &middot;
    <a href="mailto:support@agilegrowthlabs.com">Support</a>
  </footer>

</div>
</body>
</html>