Legal
Privacy Policy
This policy explains how we process your personal data when you use our corporate site, our product site and the AgentScope.HyperAgent platform. We have written down what we measured, exactly as we measured it — including what we do not collect.
1. What this policy covers
This policy covers all three surfaces below. All three belong to the same legal entity and are operated by the same data controller:
- agentscope.ai — the company's corporate site (contact and newsletter forms)
- hyper.agentscope.ai — the AgentScope.HyperAgent product site (demo request form)
- platform.agentscope.ai — the AgentScope.HyperAgent platform (the application you use once you have an account)
Data processing terms agreed with enterprise customers prevail for their own data: if you use the platform on behalf of an organization, that organization is the data controller for its own data and we act as a data processor.
We meet our disclosure obligation under the Turkish Personal Data Protection Law in a separate document: the KVKK Notice. The rules for using the service are in the Terms of Use.
2. Data controller
The data controller is Agentscope Yapay Zeka Teknolojileri A.Ş., identified in the details at the top of this page. You can write to the e-mail address there with any question or request about this policy.
3. What data we process
What we collect depends on how you interact with us.
If you only browse our sites: the closed set of events listed below and your browser's country, and only if you have accepted analytics. Your IP address is not stored.
If you submit a form: your name, e-mail address, company name and the message you write; on the demo form, also your preferred date and time. If you arrived through a campaign link, the campaign parameters from that link are stored with your record.
Your IP address, browser details (user agent) and referring site are NOT written to the form record. Your IP address is only read to rate-limit bursts of submissions and to run the bot check, then discarded.
If you create an account on the platform: your first and last name, e-mail address, optional organization name and profile image; your last sign-in time; the content of your conversations and the files you upload; an audit record of actions taken in your account; and, if you purchase a plan, subscription and payment records. If you report a bug, the text of your report and an optional screenshot.
Sign-in is passwordless: a one-time code is sent to your e-mail address. We do not store passwords.
4. Why we process it
- To provide the service: create your account, run your conversations, process the documents you upload.
- To answer you: handling requests that arrive through the contact and demo forms.
- Security: preventing abuse, automated attacks and unauthorized access; keeping an audit trail.
- Billing and subscription management.
- Improving the product: measuring which screens are used. This purpose only runs if you have given permission.
- Meeting our legal obligations.
5. Cookies and browser storage
The table below is the complete set of cookies and browser storage used across the three surfaces. We use no advertising cookies, no tracking pixels and no social media cookies.
| Name | Type | What it does | Where | Lifetime |
|---|---|---|---|---|
| ph_…_posthog | Cookie (third party: PostHog) | Recognises the same visitor for analytics | All three surfaces | 365 days |
| ph_…_posthog | Browser storage (localStorage / sessionStorage) | The browser-side state of the same measurement | All three surfaces | Until you clear it / when the tab closes |
| agentscope_rt | Cookie (first party) | Keeps you signed in. HttpOnly, Secure, SameSite=Strict; sent only to the API address | Platform | 7 days, or 30 days if you chose 'remember me' |
| agentscope.utm | sessionStorage (first party) | If you arrived through a campaign link, carries the first-touch information into a form submission | The two marketing sites | Cleared when the tab closes |
| ui-storage, app-last-context, as_session_hint | localStorage (first party) | Theme preference, the app you last used, a session hint | Platform | Until you clear it |
| drafts-storage | localStorage (first party) | Message drafts you typed but did not send — they stay in your browser only | Platform | Until you clear it |
The analytics cookie is not written before you accept it. If you decline, no analytics event is sent at all and the rest of the service works exactly the same. You can change your choice at any time.
The session cookie is required for the service to work: without it you cannot sign in, so it is not subject to separate consent.
We use Cloudflare Turnstile for bot protection. We measured it: Turnstile writes no first-party cookie on our sites — during verification your IP address reaches Cloudflare and a script served by Cloudflare is loaded in your browser.
6. Analytics: what we measure and what we do not
For product analytics we use PostHog's European Union hosted service. Measurement is subject to your consent, and what is collected is limited to a closed list of named events.
Events collected: on the marketing sites, page views, page loads and which call-to-action was clicked; on the platform, named usage steps such as sign-in, sign-up, app selection, sending a message and completion of a response.
The fields that may accompany an event are also limited to a predefined allowlist. This is a mechanism rather than a preference: a field that is not on the list does not travel even if something tries to send it.
- Your e-mail address and your name are not sent to analytics.
- Your conversation content, the files you upload and the agent's answers are not sent to analytics.
- Identifiers in address bars are masked; for example, when a conversation address is recorded, a pattern is stored instead of the identifier.
- Automatic click capture, session recording, heatmaps, surveys and remote module loading are switched off — both in code and in the PostHog project settings.
Your IP address is not stored in analytics; however, your IP address is converted to a country code on ingest and that country is stored. So 'we do not collect IP addresses' is accurate, while 'we do not process location data' would not be.
Analytics events are retained by PostHog for 12 months. That period is a fixed property of the plan we use; no option to shorten it is offered.
Until 17 August 2026, automatic click capture was enabled on the two marketing sites; it was switched off on that date, both in code and in the project settings. Records from that period are still held: our analytics provider offers no way to delete events by type or date, so they will fall away when the 12-month retention period expires.
For this provider's own privacy policy, see PostHog Privacy.
7. Who we share it with
We do not sell your personal data and we do not share it for advertising. The providers we use to deliver the service are listed below; each one only has access to the data its function requires.
| Provider | What for | Data that reaches it |
|---|---|---|
| Google Cloud | Servers, database, file storage, logging | All data processed on the platform |
| Google Cloud Vertex AI | Running the AI models | The messages and documents you send to the agent |
| PostHog | Product analytics | The named set of events and the country code |
| Cloudflare | Bot protection on forms and sign-in screens | Your IP address at the moment of verification |
| Resend | One-time sign-in codes and invitation e-mails | Your e-mail address and your name |
| Slack | Notifying the team of a new form submission | The e-mail address and company name from the form |
| Firebase Hosting (Google) | Serving the marketing sites | Server access logs |
Beyond these, data is shared with public authorities only where we are legally required to do so.
8. Where your data is processed
The platform's database, file storage and application servers are in Google Cloud's Frankfurt (Germany) region. Search indexes are in the Netherlands region. In other words, the core of the service runs inside the European Union.
There are two exceptions to this, and we state them plainly:
| Where | What for | Which data |
|---|---|---|
| Google Cloud — multi-region endpoint | Running the default AI models | The messages and documents you send to the agent |
| Google Cloud — United States (Iowa) | Running one higher-tier model, only when it is selected | The messages and documents you send to the agent |
| Cloudflare — global network | Bot protection | Your IP address at the moment of verification |
| Resend — United States | Sign-in codes and invitation e-mails | Your e-mail address and your name |
| Slack — United States | Form notification | The e-mail address and company name from the form |
We deliberately chose PostHog's European Union service; analytics data does not leave the European Union.
For the legal framework and basis of international transfers, see the KVKK Notice.
9. How long we keep it
We write our retention periods as they are — some run automatically, others are deletion on request.
| Data | Period | How it is deleted |
|---|---|---|
| One-time sign-in code | 2 minutes | Automatic |
| Session refresh records | 30 days | Automatic |
| Screenshot attached to a bug report | 90 days | Automatic |
| The agent's long-term memory (if enabled) | Depends on the setting; 30–180 days by default | Automatic |
| Form records | 24 months from last contact | Manual; immediately upon your request |
| Your account and conversation content | For as long as your account is open | You can delete it yourself from within the application; also deleted upon your request |
| Subscription and payment records | The period required by tax legislation | When the statutory period ends |
| Audit records | Kept for security and as legal evidence | On request, the link to your identity is severed |
For analytics events the period is 12 months on PostHog's side, and no option to shorten it is offered.
10. Security
The measurable technical safeguards we apply:
- All traffic is encrypted with TLS; our sites instruct the browser to keep the connection secure.
- The database and cache are closed to the public internet and reached over a private network; the cache connection is encrypted as well.
- Sign-in and forms are rate limited per e-mail address and per IP address, with bot protection on top.
- A web application firewall runs in front of the application.
- Only signed application builds may run; creation of long-lived access keys is disabled by organisation policy.
- Secrets such as provider and model access credentials are additionally encrypted at the application layer inside the database.
- Session information is held in a cookie that scripts cannot read, and it is rotated on every use.
- Actions taken in your account are written to an audit record.
If a support request requires our team to look inside your account, that is only possible through a time-boxed support session with a written reason: the session closes by itself after 30 minutes, every access is written to the audit record, and activity during that period is not counted as your usage.
We should also state that data is encrypted at rest by the cloud provider; beyond that, conversation content is not separately encrypted at the application layer.
11. AI and your data
When you talk to the agent, your message and any documents you attach are sent to the model provider to produce the answer. The provider we use is Google Cloud Vertex AI, which under its terms does not use customer data to train its own models. We do not use your data for model training either.
The platform has an optional content safety layer: when enabled, patterns such as Turkish national identity numbers, IBANs, tax numbers and phone numbers are masked in messages before they reach the model. This layer is enabled per application and is off by default; it does not cover personal data in free text such as names and addresses.
AI output can be wrong. You need to verify results before relying on them; see the Terms of Use for detail.
12. Your rights
You have the rights the law grants over your personal data: to learn whether your data is processed, to request information, to learn whether it is used for its purpose, to request that it be corrected, deleted or destroyed, to object to the outcome of processing, and to claim compensation for damages.
You can send your request to the e-mail address in the details above; for the application channels and time limits see the application section of the KVKK Notice.
Your request is concluded within thirty days at the latest. On a deletion request, the personal content in your account is deleted; in records we are legally required to keep, such as invoice records and the audit trail, the link to your identity is severed.
You can also delete your account and its content yourself from within the application, via the account deletion step in settings; deletion takes effect immediately and cannot be undone. You can likewise view and delete what the platform's agent memory holds about you from within the application.
13. Children
Our services are not designed for people under eighteen and we do not knowingly collect data from anyone below that age. We should state plainly that we do not verify age: this rests on your declaration. If we learn that we process data belonging to someone under eighteen, we delete the record; you can report such a case to the address in the details above.
14. Changes
We may update this policy from time to time. The effective and last-updated dates at the top of the page show which text applies; when a significant change is made we also notify you through the platform.
Agentscope Yapay Zeka Teknolojileri A.Ş.