Legal · Last updated 3 September 2026

Delegent AI Privacy Policy

This Privacy Policy explains how Delegent AI LTD, a UK company registered in England and Wales under company number 17233711 ("Delegent AI LTD", "we", "us", "our"), collects, uses, shares, and protects your personal information when you use Delegent AI and its related mobile apps, websites, messenger integrations, subscriptions, files, AI coworker, and the private cloud computer we provision for you. We process personal information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Delegent AI is offered to people in the United Kingdom, the United States, Canada, Australia, and New Zealand; we do not target or offer the Services to people in the European Economic Area. If you access the Services from somewhere else, you do so on your own initiative, and this policy and UK data-protection law still govern how we handle your information.

1. Who controls your information

Delegent AI LTD is the data controller for personal information processed to provide Delegent AI. We are a private limited company registered in England and Wales under company number 17233711, with our registered office at 167-169 Great Portland Street, London, England, W1W 5PF.

For privacy questions, subject-access requests, opt-outs, and other data-protection matters, please contact admin@delegentai.co.uk. For general support, write to support@delegentai.co.uk. Our registered office is Delegent AI LTD, 167-169 Great Portland Street, London, England, W1W 5PF.

Where a third-party service such as a payment processor, authentication provider, messenger, cloud host, or AI inference provider processes information independently as its own controller, its privacy notice also applies. We are not responsible for how independent controllers process your information.

2. Information you provide

Account information: your email address, sign-in provider (for example, Google), profile name, the name you give your AI coworker, and any other details you choose to save in your profile.

Messages and instructions: the prompts, attachments, voice messages, files, and rules you send to your coworker through the Delegent AI app or a connected messenger such as Telegram.

Files and content: anything you upload, drafts you ask your coworker to prepare, and the files or notes your coworker creates and stores in your private cloud space (size depends on your plan).

Subscription and billing: when you choose a paid plan, you provide billing information to our payment processor. On the web and on Android this is Stripe. On iPhone and iPad, purchases go through Apple's In-App Purchase and Apple is the payment processor and merchant of record. Whichever processor you used shares the subscription and payment-status details we need to run your account with us. We do not store full card numbers, and on iOS we never see your card details at all.

Support, surveys, and feedback: if you contact us by email, support form, or in-app, we process the contact details and message content you submit so we can respond and improve the Services. Participation in any survey or research is voluntary and you can withdraw at any time.

3. Information we collect automatically

Device and technical data: device model, operating system, app version, browser type and language, IP address, time-zone, network or telecommunications provider, and similar technical fields.

Usage data: session identifiers, screens and features you use, timestamps, interaction patterns, error logs, and performance metrics. This information helps us keep the Services secure, debug issues, prevent abuse, measure capacity, and improve reliability.

Product analytics: the app uses Google Analytics to collect a small set of anonymised usage events, such as which screens are opened and where a sign-up or upgrade step is abandoned, using a random install identifier stored on your device. These events never include your name, email address, message content, or files, and the identifier is not used for advertising or shared across other apps or sites. You can object to analytics processing at any time by emailing admin@delegentai.co.uk.

Cookies and similar technologies: we use a small number of essential cookies and similar technologies (such as local storage and session identifiers) to keep you signed in and to operate the Services. On our website we also offer advertising and analytics cookies, described in section 15, and none of them is ever set unless you choose "Allow" on the cookie banner. Where any technology requires your consent under the Privacy and Electronic Communications Regulations (PECR), we ask for it first and set nothing until you agree. Separately, and without any cookie, we keep a count of how many people arrive from each of our adverts; that count is described in section 15 and holds nothing that identifies you.

Advertising measurement, only if you agree: the Delegent AI mobile app contains Meta's software development kit so that we can tell whether an advert we paid for actually led to someone installing the app. It is switched off when you install, and it stays off unless you say yes when we ask. If you agree, the kit reads your device's advertising identifier (the Android advertising ID, or on iPhone the identifier for advertisers) and tells Meta that an install or a sign-up happened, so that Meta can show our adverts to people more like you. On iPhone, Apple also asks for its own tracking permission, and we collect nothing unless you agree to both. It never sends Meta your name, your email address, your messages, or your files. You can change your mind at any time in the app's privacy settings, or by emailing admin@delegentai.co.uk, and we will stop the collection rather than simply stop asking. If you say no, or never answer, nothing at all is collected or sent.

Install source: separately from the above, and without any advertising identifier, we record how you found the app. When you install from the Google Play Store, Play tells us which advert or link brought you there. We keep that to understand which of our adverts work. It identifies the advert, not you, and it is not shared with anyone.

Push notification identifiers: if you allow notifications, your device gives us a notification token issued by Google's Firebase Cloud Messaging. We store one token per device so we can tell you when your coworker needs your approval, has a question, or has finished work while the app is closed. The token identifies a device installation, not you personally, and we do not use it for advertising. Notifications never contain the content of your messages or files. You can turn notifications off at any time in your device settings, and we delete the token when you delete your account.

4. Information we receive from others

Sign-in providers: if you choose Google sign-in, we receive your email address, basic profile information, and the authentication tokens needed to create and secure your account.

Connected messengers: when you connect Telegram (or another supported messenger), we receive the chat identifiers and messages needed to link the chat to your account and route tasks back to you.

Payment processors, Stripe on the web and Android, and Apple for purchases made on iPhone or iPad, send us subscription, customer, invoice, renewal, cancellation, and payment-status information so we can run billing correctly. We do not store full card details.

Security and fraud-prevention partners may send us risk signals, for example, device fingerprints, fraud scores, or lists of known-bad actors, so we can detect and respond to fraud, abuse, and other threats to the Services.

Publicly available sources: we do not buy personal information from data brokers. Some of the AI models that power our Services have been trained on publicly available data by third parties; that training is separate from your account and is governed by those third parties' own privacy notices.

5. How and why we use your information

To provide and run the Services (UK GDPR Article 6(1)(b), performance of a contract with you): authenticating you, provisioning your private cloud computer, routing messages and tasks, storing files, returning output, taking payments, and providing support.

To keep the Services secure (UK GDPR Articles 6(1)(c) and 6(1)(f), legal obligation and our legitimate interest): detecting and preventing fraud, abuse, spam, unauthorised access, and other security risks; investigating suspected breaches; and protecting our users and our infrastructure.

To improve and develop the Services (UK GDPR Article 6(1)(f), our legitimate interest, balanced against your rights): understanding how the product is used, fixing bugs, planning capacity, and improving prompts, features, and (where applicable) model performance. We use anonymised or minimised data where we can. You can opt out of having your Content used to improve the service or train models by emailing admin@delegentai.co.uk.

To comply with legal obligations (UK GDPR Article 6(1)(c)): including tax, accounting, anti-money-laundering, consumer-protection, and responding to lawful requests from authorities.

To communicate with you (UK GDPR Articles 6(1)(b) and 6(1)(f)): sending service notices, billing receipts, security alerts, and responses to your support requests. We send marketing messages only with your consent under PECR; you can withdraw consent at any time by using the unsubscribe link or contacting us. We do not sell your personal information.

6. AI processing and connected providers

To run your coworker, Delegent AI sends the relevant prompts, files, instructions, and context to the AI inference and cloud-compute providers that power the Services. We choose providers with strong contractual data-protection commitments, restrict their use of your data to operating the Services for us, and use access controls, secret separation, and tenancy isolation to keep your information bounded to your account.

Do not send personal information about other people, regulated personal data, or confidential third-party material unless you have the right to do so and are comfortable with it being processed by Delegent AI and the providers needed to fulfil your task.

Because AI output is generated probabilistically, it may not always be factually accurate. We are not responsible for decisions taken in reliance on AI output without independent human judgement. If you believe AI output contains inaccurate personal information about you and you would like it corrected or removed, please contact admin@delegentai.co.uk, we will respond in line with our legal obligations and the technical limits of the underlying models.

7. Connecting your other accounts

You can optionally connect third-party accounts so your coworker can work with them on your behalf. The services available today are AgentMail, Asana, ClickUp, Confluence, Dropbox, Facebook Pages, Figma, Firecrawl, FreeAgent, Freshdesk, GitHub, Gmail, Google Calendar, Google Docs, Google Drive, Google Sheets, Google Tasks, HubSpot, Instagram, Jira, LinkedIn, Notion, OneDrive, PDF.co, QuickBooks, Reddit, Salesforce, Shopify, Slack, Stripe, Trello, Webflow, YouTube, Zendesk, Microsoft Outlook and Microsoft Teams. You are never required to connect anything, and the Services work without it.

When you connect an account you are sent to that provider to sign in, and you choose which permissions to grant. We never see or store your password for that provider. What we receive and store is an authorisation token that lets us act within the permissions you granted.

How those tokens are held: the long-lived token is encrypted (AES-GCM, with a key held only by our server) and stored in our database. It is never given to your cloud computer and never sent to your device. When your coworker needs to perform one action, our server issues a short-lived access token for that single command. This means a compromise of your cloud computer cannot expose your connected accounts.

Gmail is held differently and we want to be plain about it. Gmail is brokered for us by Composio (Composio Inc.), a company whose business is holding connections like this one safely. You sign in at Google as normal, but the authorisation is held by Composio rather than by us, which is why the Google screen names them and not Delegent AI. Your coworker asks our server to carry out an action, our server asks Composio, and Composio performs it against your mailbox. We never hold your Gmail token and it is never placed on your cloud computer. Composio acts as our processor under contract, is not permitted to use your information for its own purposes, and disconnecting Gmail in the app removes the connection at Composio. You can also withdraw the grant at myaccount.google.com/permissions.

Gmail permissions. Connecting Gmail grants the https://mail.google.com/ permission, which Google classifies as restricted and which covers reading, composing, sending and permanently deleting mail. We ask for it because a coworker that can only read your inbox cannot reply on your behalf. In practice it reads and searches when you ask it to, and it sends or deletes only when you ask for that specific thing in that conversation. We do not read your mailbox in the background, we do not build a profile from it, we do not use it for advertising, we do not sell it, and we do not use it to train models.

Google Sheets and Google Docs. If you connect either, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Google screen names them. Your coworker uses the Google Sheets or Google Docs API to read and change the spreadsheets or documents you give it a link to, and the drive.file permission to create new ones and open the ones it created. It cannot see the other files in your Drive with this. It reads and changes a file only to carry out the task you asked for, and we do not use its contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also remove the grant at myaccount.google.com/permissions.

Notion. If you connect Notion, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Notion screen names them. Notion asks you at that point which pages to share, and your coworker can reach only those pages and databases and what sits under them. It reads and changes them only to carry out the task you asked for, and we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also change or remove the shared pages from the page menu in Notion.

Trello. If you connect Trello, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Trello screen names them. Trello does not offer a per-board permission, so the grant covers every board your account can open; your coworker reads and changes boards only to carry out the task you asked for, and we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it under Applications in your Trello account settings.

Asana. If you connect Asana, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Asana screen names them. Asana does not offer a per-project permission, so the grant covers every workspace and project your account can open; your coworker reads and changes tasks only to carry out the task you asked for, and we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it under Apps in your Asana settings.

ClickUp. If you connect ClickUp, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the ClickUp screen names them. ClickUp asks you at that point which Workspaces to authorise, and your coworker can reach only those. It reads and changes tasks only to carry out the task you asked for, and we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it under Apps in your ClickUp settings.

Google Tasks and Google Drive. If you connect either, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Google screen names them. Google Tasks uses the tasks permission to read, create, change and complete tasks on your lists. Google Drive uses the full Drive permission, so your coworker can find, open, create and change files across your Drive; it asks you before it deletes anything. Both are used only to carry out the task you asked for; we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also remove the grant at myaccount.google.com/permissions.

Slack, Dropbox, GitHub, Microsoft Outlook and Microsoft Teams. Until 2026-09-03 we brokered these five ourselves and held the authorisation on our own servers. They are now brokered by Composio like every other connection, which is why the permission screen names Composio and why you may be asked to connect again. If you connected one before that date, the old authorisation we held is no longer used. The permissions each grants are set out on its card in the app before you connect. Microsoft Outlook can now send email, which our own version could not; nothing is ever sent without you seeing it and agreeing first.

AgentMail, Figma, Shopify and Webflow. AgentMail gives your coworker its own email inbox, separate from yours, which it can read and send from. Figma grants reading your design files, projects and comments, and posting a comment. Shopify grants reading and changing products, orders, customers and stock in the store you connect; your coworker treats it as read-only unless you ask for a change. Webflow grants reading and changing the content of the Webflow sites your token covers; nothing is published without you asking. AgentMail, Shopify and Webflow have no sign-in screen for apps like this, so connecting one means pasting a key from your own account into Composio's connection screen, and Shopify also asks for your store address. The key is held by Composio, encrypted, and never passes through the app, your chat or us.

Zendesk, Jira and Confluence. If you connect any of these, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the provider's screen names them. Each asks for the first part of your own address (for example yourcompany.zendesk.com or yourcompany.atlassian.net) so it can sign you in there. Zendesk grants reading tickets, users and organisations and creating tickets and replies. Jira grants reading and changing issues. Confluence grants reading and writing pages. Each is used only to carry out the task you asked for; we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it in the provider's own connected-apps settings.

OneDrive, HubSpot and Salesforce. If you connect any of these, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the provider's screen names them. OneDrive grants reading, creating and changing the files your Microsoft account can open. HubSpot grants reading and changing contacts, companies and deals, and nothing else in your HubSpot. Salesforce offers only full access to an app like this, so that grant covers everything your Salesforce user can reach; your coworker refuses to delete records regardless. Salesforce also asks for the first part of your own address so it can sign you in there. Each is used only to carry out the task you asked for; we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it in the provider's own connected-apps settings.

Stripe. If you connect Stripe, it is brokered by Composio in the same way as Gmail, and it is read-only in practice: Stripe grants read and write access because it does not offer a read-only grant to connections of this kind, and our server permits only read actions (balance, payments, customers, invoices and subscriptions) and refuses everything else before it reaches Stripe. Your coworker cannot take a payment, issue a refund, or change anything. Customer names, email addresses and amounts are visible to it when a job needs them, are used to answer your question and for nothing else, and are never used for advertising, sold, or used to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it under Installed apps in your Stripe dashboard.

YouTube, Reddit, LinkedIn, Instagram and Facebook Pages. If you connect any of these, it is brokered by Composio in the same way as Gmail, and the provider's screen names them. YouTube is read-only. Reddit, LinkedIn, Instagram and Facebook Pages can publish under your name or your Page, and your coworker never publishes or replies without your approval in that conversation. Instagram works with business and creator accounts only, and Facebook with the Pages you choose, never your personal profile. Each is used only to carry out the task you asked for; we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the connection at Composio, and you can also revoke it in each provider's own connected-apps settings.

PDF.co, Freshdesk and Firecrawl. These providers offer no sign-in screen for apps like this, so connecting one means pasting an API key from your own account into Composio's connection screen; Freshdesk also asks for the first part of your Freshdesk address. The key is held by Composio, encrypted, and never passes through the app, your chat or us. PDF.co and Firecrawl spend credits from your account and receive the files or pages your coworker sends them to process. Freshdesk grants reading, creating, updating and replying to tickets as you. Each is used only to carry out the task you asked for; we do not use their contents for advertising, sell them, or use them to train models. Disconnecting in the app removes the key at Composio, and you can also revoke the key in the provider's own settings.

QuickBooks. If you connect QuickBooks, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Intuit screen names them. Your coworker uses Intuit's accounting permission (com.intuit.quickbooks.accounting) to read your customers, suppliers, accounts and balance reports, and to create customers and suppliers when you ask it to, and for nothing else. We do not read your books in the background, we do not use them for advertising, we do not sell them, and we do not use them to train models. Disconnecting in the app removes the connection at Composio, and you can also remove the app under Apps in QuickBooks.

What we access: only what is needed for the task you asked for, within the permissions you granted, for example reading or writing a file you named. We do not scan or index your connected accounts in the background, and we do not use their contents to train models.

Disconnecting: you can disconnect a service at any time in the app, which deletes our stored token for it. Deleting your account deletes every stored token. Please also review the connected-apps or authorised-apps screen of the provider itself, because some providers, notably Microsoft, do not allow an application to revoke its own access remotely. Removing it there is the only way to withdraw the grant completely, and we will tell you this in the app.

FreeAgent is different from the others and we want to be plain about it. FreeAgent does not offer partial permissions, so connecting it grants access to your whole accounting record, including the ability to create, change and delete entries. That is not a choice we made; it is the only level of access FreeAgent offers. We ask you before creating or deleting anything in your books, and we check the entry really exists in your account before telling you it is done. Connect it only if you want your coworker actually keeping your books, and you can disconnect it at any time.

Google Calendar. If you connect Google Calendar, it is brokered by Composio in the same way as Gmail: the authorisation is held by Composio, not by us, and the Google screen names them. Your coworker uses the Google Calendar API under the calendar.events permission, and nothing wider, to view, create, change and delete events on the calendars in your Google Account, and only to carry out the scheduling you have asked it for. We do not read your calendar in the background, we do not build a profile from it, we do not use it for advertising, we do not sell it, and we do not use it to train models. Calendar data is used to complete your request and is not retained beyond what that requires. Disconnecting in the app removes the connection at Composio, and you can also remove the grant at myaccount.google.com/permissions.

Our use of Google user data. Delegent AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This applies to every Google service you choose to connect, currently Gmail, Google Drive, Google Calendar, Google Sheets, Google Docs, Google Tasks, Google Photos and YouTube. Information obtained through Google APIs is used solely to carry out the task you asked for. It is never used to create, train or improve any artificial-intelligence or machine-learning model, whether ours or anyone else's, and our AI providers process it under zero-data-retention API terms that prohibit them from training on it.

8. Subscription and payment information

On the web and on Android, payments are processed by Stripe under its own privacy notice. We receive transaction metadata (customer ID, subscription ID, status, billing dates, amounts, currency, country, and similar fields) so we can run subscriptions, send receipts, and provide support. We never store your full payment card details on our servers.

On iPhone and iPad, subscriptions are sold through Apple's In-App Purchase and Apple is the merchant of record and payment processor, under Apple's own privacy policy. We receive a transaction identifier and subscription status from Apple's App Store Server API so we can activate and run your account; we do not see or store your card details, and Apple does not share your name or Apple Account email with us for this purpose. Cancellation, refunds, and payment method changes for an App Store subscription are handled entirely by Apple, in Settings on your device or at reportaproblem.apple.com; we cannot access or change your payment details in those cases.

If your subscription is bought through the Google Play Store, cancellation and refund rules are similarly governed by that store's terms, and we do not access your full payment details there either.

We retain transaction-related information (receipts, billing records, refund history) for as long as needed to meet our tax, accounting, audit, fraud-prevention, and other legal obligations, typically at least six years under UK tax law, even after your account is deleted.

9. When we share information

We share personal information with service providers (processors) acting on our behalf, strictly under our instructions and only for the purposes set out in this policy. These include our cloud infrastructure host, AI inference providers, the provider that operates your cloud computer, our authentication provider, Stripe (payments on the web and Android), Apple (payments and subscription status for purchases made on iPhone or iPad), Telegram (messenger), Google Firebase Cloud Messaging (push notifications), our email and notification providers, monitoring and analytics tools (including Google Analytics), Composio (which brokers every connected account except FreeAgent: your Gmail, Google Calendar, Google Sheets, Google Docs, Google Tasks, Google Drive, YouTube, Notion, Trello, Asana, ClickUp, Zendesk, Jira, Confluence, OneDrive, HubSpot, Salesforce, Stripe, Reddit, LinkedIn, Instagram, Facebook Pages, PDF.co, Freshdesk, Firecrawl, QuickBooks, Slack, Dropbox, GitHub, Microsoft Outlook, Microsoft Teams, AgentMail, Figma, Shopify and Webflow connections), Meta (advertising measurement, only where you have agreed to it), and security partners. Where you have chosen to connect one of your own accounts, we also exchange information with that provider, currently AgentMail, Asana, ClickUp, Confluence, Dropbox, Facebook Pages, Figma, Firecrawl, FreeAgent, Freshdesk, GitHub, Gmail, Google Calendar, Google Docs, Google Drive, Google Sheets, Google Tasks, HubSpot, Instagram, Jira, LinkedIn, Notion, OneDrive, PDF.co, QuickBooks, Reddit, Salesforce, Shopify, Slack, Stripe, Trello, Webflow, YouTube, Zendesk, Microsoft Outlook or Microsoft Teams, but only to carry out the tasks you ask for and only within the permissions you granted. See section 7. They are contractually required to protect your information and may not use it for their own purposes.

We may share information with corporate affiliates (entities under common ownership or control) where this is needed for internal administration, security, or to provide consistent product experiences. Affiliates are required to honour this policy or equivalent protections.

If we are involved in a corporate transaction (merger, acquisition, asset sale, or restructuring), personal information may be transferred as part of the transaction. We will require recipients to honour this policy or equivalent protection and will notify you where required by law.

We may disclose information to regulators, courts, or other authorities where we believe in good faith it is reasonably necessary to: comply with a legal obligation; respond to a valid lawful request; enforce our Terms; protect rights, safety, or property; or investigate suspected fraud, abuse, or security incidents.

We do not sell your personal information.

10. International transfers

Some of our providers operate outside the UK, including in the European Economic Area and the United States. When we transfer personal information out of the UK, we rely on the UK Government's adequacy decisions where available; otherwise, we use the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard, and apply additional measures such as encryption in transit and access controls where appropriate.

You can ask us for a current list of the providers we use and the safeguards in place by emailing admin@delegentai.co.uk.

11. Retention and deletion

We keep personal information only for as long as we need it for the purposes set out above. As a guide: account and profile data are kept while your account is active and for a short reasonable period afterwards; security and audit logs are kept for up to 12 months; transaction and billing records are kept for at least six years to meet UK tax and accounting requirements; and the Content stored in your private cloud space is kept until you delete it or close your account.

You can ask us to delete your account and the personal information we hold about you by emailing admin@delegentai.co.uk. Account deletion is permanent, please export anything important first.

When you delete your account, your personal information is erased and your private cloud space is decommissioned without undue delay, other than the limited records we are required to keep for the legal reasons described below.

Some records may need to be retained where the law requires (for example, tax records) or where there is an active dispute, security incident, or fraud investigation; in those cases we keep the minimum amount of information needed and we delete the rest.

12. Your rights under UK GDPR

Depending on your circumstances, you have the right to: access the personal information we hold about you and receive a copy; ask us to correct information that is wrong or incomplete; ask us to delete personal information (the "right to be forgotten"), subject to legal exceptions; restrict or object to certain processing; request portability of certain data in a structured, machine-readable format; and withdraw consent at any time where processing is based on consent (without affecting earlier processing).

You can exercise these rights by emailing admin@delegentai.co.uk. We will respond within one calendar month, as required by UK GDPR. If your request is unusually complex or you make several requests, we may extend the response time by up to two further months and will tell you why.

If we cannot verify your identity using the information we already hold, we may ask for additional information to make sure we don't act on a request from someone impersonating you.

You have the right to complain to the UK Information Commissioner's Office (ICO) at https://ico.org.uk. If you are in another country where Delegent AI is offered, you may also have rights under your local privacy law and the right to raise concerns with your local privacy regulator, for example the Office of the Australian Information Commissioner, the Office of the Privacy Commissioner of Canada, or the Office of the Privacy Commissioner in New Zealand. We'd appreciate the chance to put things right first, so please contact us at admin@delegentai.co.uk before you do.

13. Children’s privacy

Delegent AI is not designed for, marketed to, or intended to be used by children. You must be 18 or older to use the Services. If you believe that a child has provided personal information to us, please contact admin@delegentai.co.uk so we can investigate and, where appropriate, delete the information.

14. How we protect your information

We use technical and organisational measures designed to keep your information secure, including: encrypted transport between you, our servers, and our providers; access controls and least-privilege internal access; tenancy isolation between users; provider-secret separation; security monitoring; routine software updates; and incident-response procedures.

We restrict employee access to user data to those who genuinely need it for their work, and we train staff on data-protection responsibilities. We monitor administrative access and take action if we detect improper behaviour.

No online service can be made perfectly secure. Please keep your sign-in details safe, use a strong password where applicable, never share verification codes, and avoid sending Delegent AI information you would not want processed by an AI service.

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office within 72 hours where required, and we will tell you in line with our legal obligations.

15. Cookies and tracking technologies

We use a small number of essential cookies and similar technologies (including local storage and session identifiers) to keep you signed in, to remember your preferences, and to operate the Services. These are necessary for the Services to work and do not require your consent.

Advertising and analytics cookies on our website, only if you agree. Our website delegentai.co.uk uses two technologies that need your consent: the Meta Pixel, which tells us whether an advert we paid for actually led someone to go and get the app, and Google Analytics, which tells us which parts of the site people read and where they stop. Nothing is loaded and no cookie is set by either unless you choose "Allow" on the cookie banner. If you choose "No thanks", or ignore the banner entirely, neither is ever loaded at all. It is not a case of loading them and asking them to behave.

If you do agree, the Pixel sets a cookie called "_fbp" in your browser, which holds a randomly generated browser identifier and lasts up to about 90 days. If you arrived by clicking one of our adverts on Facebook or Instagram, it also sets a second cookie, "_fbc", which records that click and lasts a similar time. If you came to us any other way, by search, a link, or typing the address, only "_fbp" is set. Some browsers, Safari in particular, shorten these lifetimes considerably. It records that you visited the site and whether you tapped through to an app store. It never receives your name, email address, messages or files, because you do not give us any of those on the website. Meta acts as an independent controller for its own advertising purposes when it receives this, which is why we ask rather than assume.

If you agree, Google Analytics sets cookies beginning "_ga" in your browser, which hold a randomly generated browser identifier and last up to about two years, though some browsers shorten that considerably. We use it only to understand how the site is used in aggregate. We have switched off Google Signals and advertising personalisation, so this information is not used to build an advertising profile of you and is not combined with data from other sites. It never receives your name, email address, messages or files, because you do not give us any of those on the website.

Counting advert clicks, which needs no cookie. When you arrive from one of our adverts, the link you followed already carries a label identifying the advert and the campaign. Our own server keeps a count of those labels, together with whether the visit came from an Android or an iPhone device, which app store we sent you to, and the country your connection is in. This lets us tell whether the money we spend on advertising reaches anyone at all. It stores nothing on your device and reads nothing from it, so it does not require consent under PECR, and it does not use a cookie or any advertising identifier. We do not record your IP address, your browser details, or anything else that identifies you, and there is nothing in these records that can be traced back to a person. If you would still rather we did not count your click, email admin@delegentai.co.uk.

You can change your mind at any time. The simplest way is the "Cookie choices" link in the footer of this website, which clears the answer and asks you again, so you can withdraw a yes or give one after saying no. You can also delete these cookies directly in your browser settings, or write to admin@delegentai.co.uk with any question about them.

The other advertising technology in the Services is Meta’s measurement kit in the Delegent AI mobile app, described in section 3. That is a separate thing on a separate device, is off by default, and runs only if you agree to it there as well. Agreeing on the website does not switch it on in the app, and agreeing in the app does not switch it on here.

The mobile app also uses Google Analytics, separately from the website, with a random install identifier to measure feature usage, as described in section 3. That identifier is separate from the advertising measurement described in section 3, is not used for advertising, is not shared across other apps or sites, and is removed if you clear the app's data or delete your account. Agreeing on the website does not switch anything on in the app, and agreeing in the app does not switch anything on here. You can object to analytics at any time via admin@delegentai.co.uk.

If we add analytics that require your consent under PECR, we will ask for it through a clear in-app prompt and give you a way to change your mind. You can also manage device-level identifiers through your device settings.

16. Changes to this policy

We may update this policy when our product, our providers, or the law changes. When a change materially affects how we handle your personal information we will take reasonable steps to bring the update to your attention, typically by an in-app notice or email, before the new version takes effect. Continued use of the Services after the new version takes effect means you accept the updated policy.

17. Contact us

Privacy queries and data-subject requests: admin@delegentai.co.uk. General support: support@delegentai.co.uk. Registered office: Delegent AI LTD (company number 17233711), 167-169 Great Portland Street, London, England, W1W 5PF.

UK regulator: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom, https://ico.org.uk.


Questions? Email admin@delegentai.co.uk or support@delegentai.co.uk.