Legal

Privacy Policy

Last updated September 27, 2026

In short: AgentPhone gives AI agents a real iPhone to use on your behalf. To do that we process what happens on that phone: screenshots, actions, and the messages your agent sends and reads. We use this data only to run, secure and support the service. We keep session recordings for 90 days. We don't sell your data, and we don't use it to train AI models.

1. Who we are

This policy covers the AgentPhone website, the AgentPhone service (our MCP server, the phones we operate and the related tools), and our communications with you. "AgentPhone", "we" and "us" mean the operator of the service. You can reach us through our support page.

2. What we collect

When you visit the site or join the waitlist

When you use the service

About other people

Using a phone involves other people's information: the numbers and messages of people your agent texts, and anything that appears on the phone's screen. You're responsible for having the right to share it and to contact those people (see our Terms). If you received a message sent through AgentPhone and want it to stop, reply STOP or contact us.

What we don't collect

Agents never enter passcodes, Face ID or two-factor codes. Those screens are handed back to you, so we don't receive those secrets.

3. How we use it

We don't sell your personal information, and we don't share it for targeted advertising. We don't use your content to train AI models.

4. Your AI assistant

When you connect an assistant (for example Grok, Muse, Claude or your own agent), AgentPhone sends it the screenshots, messages and results it asks for. What that assistant does with them is governed by its provider's privacy policy, not this one. If you use AgentPhone's built-in agent, screenshots and your instructions are sent to Anthropic's API so it can decide each step.

5. Who we share it with

We share data only with the providers we need to run the service, and only for that purpose:

ProviderPurposeData
VercelWebsite hostingSite requests, form submissions in transit
UpstashStoring waitlist and support requestsWhat you enter in those forms
CloudflareSecure network connection to the serviceService traffic, encrypted in transit
Apple and mobile carriersDelivering the messages your agent sendsMessage content and recipients
The assistant you connectActing on your requestsWhat your assistant requests
Anthropic (built-in agent only)Deciding the agent's next stepScreenshots and instructions for that session

We may also disclose information when the law requires it, to protect people from harm or abuse, or as part of a merger or acquisition (in which case this policy continues to apply).

6. How long we keep it

DataKept for
Session recordings (screenshots, actions, messages)90 days, then deleted automatically
Approval requests90 days
Usage records13 months (billing and disputes)
Sending-limit log24 hours
Access tokens / refresh tokensExpire after 1 hour / 30 days
Account informationWhile your account is open, and deleted within 30 days of closing it
Waitlist and support requestsUntil you ask us to delete them, and at most 24 months

Messages stay on the phone itself, like on any iPhone, until they're deleted there. We delete them when a phone is reassigned or when you ask.

7. Security

All connections to the service use HTTPS. Keys, codes and tokens are stored only as hashes. Each customer's access is limited to their own phones. Administrative tools can't be reached over the internet. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as the law requires.

8. Your choices and rights

9. Children

AgentPhone isn't for anyone under 18, and we don't knowingly collect their data.

10. Where data is processed

We operate in the United States. If you use AgentPhone from elsewhere, your data is transferred to and processed in the U.S.

11. Changes

We'll post any changes here and update the date above. If a change is significant, we'll notify customers before it takes effect.

12. Contact

Questions or requests: support page (choose "Privacy request").