Legal
Privacy Policy
Last updated September 27, 2026
In short: AgentPhone gives AI agents a real iPhone to use on your behalf. To do that we process what happens on that phone: screenshots, actions, and the messages your agent sends and reads. We use this data only to run, secure and support the service. We keep session recordings for 90 days. We don't sell your data, and we don't use it to train AI models.
1. Who we are
This policy covers the AgentPhone website, the AgentPhone service (our MCP server, the phones we operate and the related tools), and our communications with you. "AgentPhone", "we" and "us" mean the operator of the service. You can reach us through our support page.
2. What we collect
When you visit the site or join the waitlist
- What you type in the waitlist or support forms: name, email, company, how many phones you need, what you want your agent to do, and your message.
- Standard technical logs from our hosting provider, such as IP address, browser type and pages requested.
When you use the service
- Account information: your name and email, and the phones assigned to you.
- Credentials: API keys, sign-in codes, and the tokens issued when you connect an assistant. We store only one-way hashes of these, never the keys themselves.
- Session activity: when your agent uses a phone, we record the screenshots it sees, the actions it takes (taps, swipes, typed text), and what it opens.
- Messages: for messages your agent sends or reads, we record the content, the recipient, the delivery status and the time.
- Approvals and takeovers: approval requests and decisions, and actions you take in the live view.
- Usage records: which tools were called, when, on which phone, and whether they succeeded. We use these for billing and support.
About other people
Using a phone involves other people's information: the numbers and messages of people your agent texts, and anything that appears on the phone's screen. You're responsible for having the right to share it and to contact those people (see our Terms). If you received a message sent through AgentPhone and want it to stop, reply STOP or contact us.
What we don't collect
Agents never enter passcodes, Face ID or two-factor codes. Those screens are handed back to you, so we don't receive those secrets.
3. How we use it
- To run the service: carrying out your agent's requests on the phone and returning results to it.
- For safety: approval requests, sending limits, recipient allowlists, and detecting and stopping abuse such as spam.
- For support and reliability: investigating problems you report or that we detect.
- For billing and accounts: usage records and account management.
- To communicate with you: about your waitlist request, your account, or changes to the service.
We don't sell your personal information, and we don't share it for targeted advertising. We don't use your content to train AI models.
4. Your AI assistant
When you connect an assistant (for example Grok, Muse, Claude or your own agent), AgentPhone sends it the screenshots, messages and results it asks for. What that assistant does with them is governed by its provider's privacy policy, not this one. If you use AgentPhone's built-in agent, screenshots and your instructions are sent to Anthropic's API so it can decide each step.
5. Who we share it with
We share data only with the providers we need to run the service, and only for that purpose:
| Provider | Purpose | Data |
|---|---|---|
| Vercel | Website hosting | Site requests, form submissions in transit |
| Upstash | Storing waitlist and support requests | What you enter in those forms |
| Cloudflare | Secure network connection to the service | Service traffic, encrypted in transit |
| Apple and mobile carriers | Delivering the messages your agent sends | Message content and recipients |
| The assistant you connect | Acting on your requests | What your assistant requests |
| Anthropic (built-in agent only) | Deciding the agent's next step | Screenshots and instructions for that session |
We may also disclose information when the law requires it, to protect people from harm or abuse, or as part of a merger or acquisition (in which case this policy continues to apply).
6. How long we keep it
| Data | Kept for |
|---|---|
| Session recordings (screenshots, actions, messages) | 90 days, then deleted automatically |
| Approval requests | 90 days |
| Usage records | 13 months (billing and disputes) |
| Sending-limit log | 24 hours |
| Access tokens / refresh tokens | Expire after 1 hour / 30 days |
| Account information | While your account is open, and deleted within 30 days of closing it |
| Waitlist and support requests | Until you ask us to delete them, and at most 24 months |
Messages stay on the phone itself, like on any iPhone, until they're deleted there. We delete them when a phone is reassigned or when you ask.
7. Security
All connections to the service use HTTPS. Keys, codes and tokens are stored only as hashes. Each customer's access is limited to their own phones. Administrative tools can't be reached over the internet. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as the law requires.
8. Your choices and rights
- Access, correct, export or delete your data: ask through the support page. We'll verify it's you, then reply within 30 days.
- Disconnect an assistant: remove AgentPhone in the assistant, or ask us to reset your sign-in code. That also ends existing connections.
- California residents have the right to know, delete and correct personal information, and to not be discriminated against for exercising these rights. We don't sell or share personal information.
- EEA and UK residents: we process your data to provide the service you asked for (contract), to keep it safe and working (legitimate interests), and with your consent where required. You may object, restrict processing, or complain to your data protection authority.
9. Children
AgentPhone isn't for anyone under 18, and we don't knowingly collect their data.
10. Where data is processed
We operate in the United States. If you use AgentPhone from elsewhere, your data is transferred to and processed in the U.S.
11. Changes
We'll post any changes here and update the date above. If a change is significant, we'll notify customers before it takes effect.
12. Contact
Questions or requests: support page (choose "Privacy request").