[ LEGAL ]

Privacy Policy

Last updated: September 20th, 2026

This policy explains what QuietOffer LLC (”AgentCents,” “we,” “us”) collects, why we collect it, and the choices you have. It applies to the AgentCents website, app, API, and MCP server (the “Service”).

The short version: your expenses are yours. We use them only to run AgentCents for you. We don’t sell your data, we don’t use it for advertising, and we don’t use it to train AI models. Agents see your data only when you connect them.

1. What we collect

Account information. Your email address and, if you choose to add them, your name and workspace name.

Expense data you or your agents submit. This includes amounts, currency, merchants, categories, dates, notes, budgets, and receipt images. We also record the source of each entry: you, or which API key or agent connection created it.

Household data. Email addresses of people you invite, their roles, and the workspaces they belong to.

API key data. For API keys, we store only a hashed version of the key, the key’s name, its prefix, and when it was created and last used. We never store the full key after you’ve seen it once.

OAuth connection data. When you approve an agent through our OAuth consent screen, we store the connecting application’s name, its redirect address, the scopes you granted, your per-connection spending cap, and when it was connected, last used, and (if applicable) revoked. We never see or store the agent’s own credentials — access tokens are short-lived and issued directly by our authorization server.

Agent and API request logs. For each API key or OAuth-authenticated request, we log the key or connection identifier, endpoint, response status, IP address, user agent, and timestamp. We never log request bodies or the values of keys or tokens.

Billing information. Stripe processes payments. We receive your plan, billing status, and the last four digits and brand of your card. We never see or store full card numbers.

Usage and device data. Basic information such as browser type, device type, pages visited, and error reports, which we use to keep the Service working.

Cookies. We use essential cookies to keep you signed in.

2. How we use it

We use your information to:

  • provide the Service, including dashboards, budgets, exports, shared access, and API/MCP responses;
  • secure the Service, which includes authenticating requests, enforcing rate limits, and detecting abuse;
  • send transactional emails, such as magic links, invites, receipts, and important notices;
  • process payments;
  • provide support when you ask for it;
  • improve the Service using aggregated or de-identified usage data;
  • meet our legal obligations.

We send product updates or marketing emails only if you opt in. You can unsubscribe at any time.

3. What we don’t do

  • We don’t sell or rent your personal data.
  • We don’t share your data with advertisers.
  • We don’t use your expense data or receipts to train AI models.
  • We don’t look at your expenses, except when you ask for support, when investigating abuse, or when the law requires it.

4. Connected AI agents

When you give an API key or OAuth connection to an agent — for example Meta Muse, Grok, Grok Bot, Claude, Cursor, ChatGPT, Gemini, or your own software — that agent can read and write the data the connection allows. This includes expenses, summaries, budgets, and categories. We return data only in response to requests made with your key or an authorized connection. You can stop access at any time by revoking the key or connection in Settings — this takes effect immediately, on every session using it.

The current list of agents we document setup for is at agentcents.com/connect; new ones may be added over time.

Once an agent receives your data, its handling of that data is governed by the agent provider’s own privacy policy. Review it before you connect.

5. Team sharing

Expenses in a shared workspace are visible to all members of that workspace. Your personal workspace is visible only to you. A workspace owner can see and revoke any API key or OAuth connection in their workspace, not only ones they created themselves; a member can see and manage only their own.

6. Who we share data with

We share data only with service providers who help us run AgentCents. They are contractually bound to use it only on our behalf.

ProviderPurpose
SupabaseDatabase, authentication, OAuth server, file storage (receipts), edge functions
StripePayments and subscription billing
AgentMailMagic link and transactional emails
VercelWebsite and app hosting
GoogleAnalytics
VercelError reporting

We may also disclose information:

  • to comply with valid legal process;
  • to protect the rights, safety, or security of our users or the Service;
  • to a successor company if we are involved in a merger, acquisition, or sale of assets. If that happens, we’ll give you notice before your data becomes subject to a different privacy policy.

7. How long we keep it

  • Expenses, receipts, and budgets: kept until you delete them or delete your account.
  • Deleted accounts: permanently deleted from live systems within 30 days. Removal from backups can take up to 90 days.
  • API and agent request logs: 90 days.
  • Revoked API keys and OAuth connections: the connection record (name, scope, cap, dates) is retained for your own audit history; only the ability to authenticate is revoked immediately.
  • Billing records: kept as long as tax and accounting laws require.

8. Security

We protect data with encryption in transit (TLS) and at rest, row-level security that isolates each workspace, hashed API keys, audience- and issuer-validated OAuth tokens, and access controls on receipt storage. No system is perfectly secure. If a breach affects your personal data, we’ll notify you as required by law.

9. Your choices and rights

You can:

  • access and export your expenses at any time (CSV export in the app);
  • correct your data directly in the app;
  • delete individual expenses or your entire account in Settings;
  • revoke any API key or OAuth connection;
  • opt out of marketing emails.

US state privacy rights (including California). Depending on where you live, you may have the right to know, access, correct, delete, and receive a copy of your personal data, and the right not to be discriminated against for exercising these rights. We don’t sell or “share” personal data for cross-context behavioral advertising.

EEA/UK users. We process your data to perform our contract with you, based on our legitimate interests in securing and improving the Service, and with your consent where required. You may also object to or restrict processing, and you can complain to your local data protection authority.

To make a request, email support@agentcents.com. We may need to verify your identity before we respond.

10. International transfers

We are based in the United States, and our providers may process data in the US and other countries. Where required, we use appropriate safeguards for international transfers.

11. Children

AgentCents is for adults 18 and over. We don’t knowingly collect data from children. If you believe a child has given us data, contact us and we’ll delete it.

12. Changes

If we make material changes to this policy, we’ll notify you by email or in the app before they take effect.

13. Contact

AgentCents is owned and operated by QuietOffer LLC | Email: support@agentcents.com