Privacy policy
Last updated: [Date of publication]
This policy explains what data One API for Agents ("we", "us") collects, how we use it, and the choices you have. One API for Agents is operated by [Legal entity]. Questions: [Contact email].
Summary
- We access Google data only with read-only scopes, and only when you or an agent you authorized makes a call.
- We do not sync data in the background, sell data, use it for advertising, or use it to train AI or machine-learning models.
- Credentials are encrypted (AES-GCM). Tokens, keys and auth headers are redacted from logs.
- You can disconnect an account at any time. Disconnecting revokes our access at Google and deletes the stored credentials.
Who this policy covers
- Workspace users: people who sign in to the dashboard at https://app.oneapiforagents.com and belong to a workspace, such as an agency team or a solo developer.
- Connecting users: people who connect their own Google account, either in the dashboard or through a connect link a workspace sent them. A connecting user does not need an account with us.
What we collect
Account and workspace data
- Your name and email address when you sign in with Google or with an email magic link.
- Workspace data you enter: workspace name, member roles, client names, connect links and API key names. API keys are stored only as a hash.
Google user data
When a Google account is connected, we receive OAuth tokens that let us call Google APIs on that account's behalf. We request only these scopes:
| Scope | Why |
|---|---|
https://www.googleapis.com/auth/webmasters.readonly |
Read Google Search Console data: properties, search analytics, sitemaps and URL inspection results. |
https://www.googleapis.com/auth/analytics.readonly |
Read Google Analytics 4 data: account and property lists, and reports. |
openid, email |
Know which Google account was connected, so the workspace can tell connections apart. |
Each connection asks only for the scope of the provider being connected. We never request permission to change Search Console or Analytics data.
Some workspaces connect Google properties with a service account instead of OAuth. In that case the property owner grants the service account read access in Google's own settings.
Call logs
For every API or MCP call we record: the time, the workspace, the connection used, the provider and endpoint or tool, the status, latency and cost, and a copy of the request and the response. Before storing, we remove tokens, API keys, authorization headers and any other credential we know about.
Technical data
Our hosting provider processes IP addresses and request metadata to serve the site and protect it from abuse. The marketing site does not use advertising or analytics cookies. The dashboard uses a session cookie to keep you signed in.
How we use Google user data
We use Google user data only to provide the features the workspace requested:
- to fetch Search Console or Analytics data when a workspace member, an API key or an authorized AI agent makes a call, and return the result to that workspace;
- to show which Google account is connected and whether the connection still works;
- to keep the call log described above, so the workspace can audit what its agents did;
- to cache a response for a limited time when the caller asks for it (see Retention).
We do not access Google user data at any other time. There is no background syncing and no monitoring of websites.
Google API Services User Data Policy
One API for Agents' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve user-facing features that are prominent in our product, as described above.
- We transfer Google user data to others only as needed to provide those features (see Sharing), to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized or interest-based advertising.
- We do not sell Google user data, and do not use it to determine credit-worthiness or for lending purposes.
- We do not use Google user data to develop, improve or train generalized or non-personalized AI or machine-learning models.
- Our staff do not read Google user data unless you give us permission for a specific item (for example, a support request), it is necessary for security purposes such as investigating abuse, or it is required to comply with law.
Sharing
- The workspace you connected to. When you connect an account, its data becomes available to that workspace's members, API keys and AI agents, within the client limits the workspace sets. If you connected through a connect link, that means the organization that sent you the link.
- AI agents chosen by the workspace. A workspace may connect AI tools such as Claude, ChatGPT, Codex or Cursor. Data an agent requests is returned to that agent and is then handled under the agent provider's own terms. Workspaces choose read-only or read-write access and which clients each agent can see.
- Service providers that process data on our behalf, under contract: Cloudflare (hosting, storage, email delivery), Google (sign-in) and, once billing launches, Stripe (payments). They may not use the data for their own purposes.
- Legal reasons: when required by law, or to protect the rights and safety of our users and the public.
We do not sell personal data.
Security
- OAuth tokens and service-account keys are encrypted with AES-GCM before they are stored. The encryption key is held in Cloudflare Workers Secrets and never leaves it.
- Credentials are decrypted in memory for the length of one call, and are never returned by our API or written to logs.
- Stored request and response bodies are redacted of tokens, keys and auth headers.
- API keys are stored hashed and shown once. Every query is scoped to the workspace and to the clients the caller may see.
- All traffic uses TLS.
No system is perfectly secure. If we learn of a breach that affects your data, we will notify you as required by law.
Retention
- Credentials are kept while the connection exists. Disconnecting deletes them.
- Call logs are kept for [log retention period, set per plan], then deleted.
- Cached responses are kept for at most 7 days.
- Account and workspace data are kept while the account or workspace exists, and deleted within [deletion window, e.g. 30 days] of a deletion request, except where law requires us to keep records (for example, invoices).
Your choices and deletion
- Disconnect an account: in the dashboard, disconnect the connection. We revoke the token at Google and delete the stored credentials.
- Revoke from Google: anyone who connected a Google account can remove our access at any time at myaccount.google.com/permissions. The connection then stops working and is shown as expired.
- Delete your data: email [Contact email] to delete your account, a workspace, or data about a Google account you connected. We confirm when it's done.
- Depending on where you live, you may have rights to access, correct, export or delete your personal data, or to object to its processing. Email us to use them. You may also complain to your data protection authority.
Children
One API for Agents is not directed to children under 16, and we do not knowingly collect their data.
International transfers
We use Cloudflare's global network, so data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
Changes
We will post changes here and update the date above. For material changes we will notify workspace owners by email before they take effect.
Contact
[Legal entity] · [Contact email]