Gazebo
    ServicesAgentsDocsSpecWritingPricing
    Log inSign up
    Log in

    Privacy Policy

    Last updated: July 2026

    1. Who we are

    Gazebo ("we", "our", "us") is an identity and access management (IAM) platform for AI agents. This Privacy Policy explains how we collect, use, and protect information when you use Gazebo at gazebohq.com and any related services (collectively, the "Service").

    2. Information we collect

    Account data

    When you create an account, we collect your email address and a hashed version of your password. We never store your password in plaintext.

    Credentials vault

    When you connect external services (Stripe, GitHub, Vercel, etc.), we store the API keys and tokens you provide. These are encrypted at rest using AES-256-GCM. Plaintext credential values are never stored in our database and are never returned to the client after submission.

    Agent tokens

    When you create an AI agent, we generate and store a Bearer token for that agent. Each token is scoped to the services you permit. We store the token's metadata (name, permitted services, created date) and an audit record of every credential access made using that token.

    Workflow and chat data

    We store the workflow requests and chat messages you submit, the AI-generated execution plans, approval and rejection decisions, and the results of executed HTTP calls. This data powers your audit log and workflow history. Workflow descriptions and chat messages are sent to our AI provider (Anthropic) to generate plans and responses — see Section 4.

    Audit log data

    We record every credential access by an agent (which agent, which service, timestamp) and every HTTP call made by an executed workflow (method, URL, response status, timestamp). This log is stored for 12 months and is visible to you in the application.

    Session data

    We use server-side sessions to keep you logged in. Session identifiers are stored in an HTTP-only cookie.

    Email address for transactional messages

    We send transactional emails (email verification, magic sign-in links) via Resend. We do not send marketing emails without your consent.

    3. How we use your information

    • To provide, operate, and improve the Service
    • To authenticate your identity and keep your account secure
    • To execute workflow plans on your behalf using your connected service credentials
    • To provide AI agents with scoped credential access to services you have permitted
    • To maintain an audit log of all credential accesses and workflow executions
    • To send transactional emails (verification, sign-in links, billing notices)
    • To detect and prevent abuse, fraud, or security incidents

    4. Third-party services

    We share data with the following sub-processors to provide the Service:

    • Anthropic — AI model provider. Workflow descriptions and chat messages are sent to Anthropic's Claude API to generate execution plans and responses. We do not send raw credential values to Anthropic.
    • Resend — Email delivery. Your email address is shared with Resend to send transactional emails.
    • Replit — Cloud infrastructure and hosting. Our servers, database, and storage run on Replit's platform.

    We do not sell your data to any third party.

    5. Data retention

    • Account data is retained until you delete your account.
    • Vault credentials are deleted immediately when you remove a connected service or delete your account.
    • Agent tokens are invalidated and deleted when you revoke them or delete your account.
    • Workflow, chat, and audit log data is retained for 12 months by default, then automatically deleted.
    • Email verification tokens expire after 24 hours and magic link tokens after 1 hour.

    6. Your rights

    You have the right to access, correct, or delete your personal data at any time. You can delete your account and all associated data from your account settings page. To request a full data export or exercise any other data rights, contact us at [email protected].

    7. Security

    We take security seriously. Credentials are encrypted with AES-256-GCM, agent tokens are scoped to specific permitted services, sessions use HTTP-only cookies, and all workflow executions require explicit approval. For a full description of our security practices, see our Security page.

    8. Cookies

    We use a single session cookie to keep you logged in. This is a strictly necessary cookie — the Service cannot function without it. We do not use tracking, analytics, or advertising cookies.

    9. Changes to this policy

    We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top. For significant changes, we'll notify you by email.

    10. Contact

    Questions about this policy? Email us at [email protected].

    Gazebo

    IAM for AI agents. Scoped credentials, access policies, and audit trails — without rotating keys.

    Product

    • Pricing
    • Status

    Explore

    • Services
    • Agents
    • Workflows
    • Integrations

    Content

    • Writing
    • Topics
    • Blog
    • Docs

    Free Tools

    • Scanner

    Company

    • About
    • [email protected]
    • [email protected]

    © 2026 Gazebo. All rights reserved.

    PrivacyTermsSecurity