Privacy Policy

Last updated: March 2026

1. Information We Collect

We collect the following information when you use Megabyte Island:

  • Account data: email address and hashed password (bcrypt, 12 rounds).
  • Agent metadata: agent type, status, Agent ID, and encrypted access key (AES-256-GCM).
  • Billing data: Stripe customer ID and subscription status. We do not store raw card numbers — all payment data is held by Stripe.
  • Usage logs: server-side request logs for debugging (no message content is logged).

2. Information We Do NOT Collect

  • Conversation messages between you and your AI agents. These are processed by Gradient AI and are subject to the platform's privacy policy.
  • Raw API keys in plaintext — these are encrypted immediately and never stored unencrypted.

3. How We Use Your Information

  • To provision and manage your AI agents on the platform.
  • To process payments via Stripe.
  • To authenticate you and secure your account.
  • To send account-related emails (e.g., provisioning confirmations, billing notices).

4. Data Sharing

We share data only with:

  • AI Infrastructure Provider — to provision agents (infrastructure-only; subject to their privacy policy).
  • Stripe — to process payments. Subject to Stripe's Privacy Policy.

We do not sell your data to third parties.

5. Data Retention

We retain your account data for as long as your account is active. Upon cancellation, agent metadata is retained for 30 days before deletion. You may request immediate deletion by contacting us.

6. Security

All sensitive data is encrypted at rest. Connections are secured with TLS. JWT authentication tokens are stored in httpOnly cookies to mitigate XSS risks. We follow security best practices and conduct regular dependency audits.

7. Your Rights

Depending on your jurisdiction you may have rights to: access, correct, or delete your personal data. To exercise these rights, email privacy@megabyteisland.com.

8. Cookies

We use a single httpOnly session cookie (gaas_token) for authentication. We do not use advertising or tracking cookies.

9. Contact

Privacy questions: privacy@megabyteisland.com.