CommandAGI
LearnPricingDocs
Log in
CommandAGI

Vision, intelligence, and control — intelligence you can see, specify, and trust, acting in real environments.

Platform

  • Product
  • Intelligence
  • Perception
  • Foresight
  • Robotics
  • Coordination
  • 3D printing
  • Services
  • Shop
  • Sites
  • Pricing

Explore

  • Worlds
  • Threads
  • Learn CommandAGI
  • Docs
  • Demos
  • Get the app
  • Start a business
  • The Command Economy
  • Ecosystem
  • The Opportunity Fund
  • Earn from your phone
  • Proof of reserves
  • Status

Company

  • Integrity
  • Trust & verifiability
  • About
  • Vision
  • Research
  • Blog
  • Brand
  • Contact

Legal

  • Privacy
  • Terms
  • SMS opt-in
  • Cookies
  • All legal
© 2026 CommandAGI INC. All rights reserved. · GDPR & CCPA aligned · SOC 2 in progress
TermsPrivacyCookiesStatus
← All legal documents

Privacy Policy

Last updated June 15, 2026

This Privacy Policy ("Policy") explains how CommandAGI INC ("CommandAGI," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with commandagi.com, our applications, APIs, and the agent, environment, and marketplace services we provide (collectively, the "Services"). It also describes the rights and choices available to you. This Policy applies to visitors, account holders, marketplace buyers and providers, and other individuals whose information we process. It does not apply to third-party products or websites that we do not control, or to data you process as an independent controller using the Services (for which you are responsible). By accessing or using the Services, you acknowledge that you have read and understood this Policy. Capitalized terms not defined here have the meaning given in the Terms of Service.

Contents

  1. 1. Who we are and scope
  2. 2. Definitions
  3. 3. Information you provide to us
  4. 4. Information we collect automatically
  5. 5. Thread and environment data
  6. 6. Connected accounts and credentials
  7. 7. Sources of information
  8. 8. How we use information
  9. 9. Model training, AI, and aggregated data
  10. 10. Legal bases for processing (EEA, UK, Switzerland)
  11. 11. How we disclose information
  12. 12. International data transfers
  13. 13. Data retention
  14. 14. Security
  15. 15. Data breach notification
  16. 16. Your rights and choices
  17. 17. United States state privacy disclosures
  18. 18. Cookies and tracking
  19. 19. Marketing communications
  20. 20. Children's privacy
  21. 21. Third-party links and services
  22. 22. Automated decision-making
  23. 23. EU/UK representative and DPO
  24. 24. Changes to this Policy
  25. 25. SMS messaging and mobile information
  26. 26. How to contact us

1. Who we are and scope

CommandAGI INC is the controller responsible for the personal information processed under this Policy, except where we act as a processor or service provider on your behalf (for example, when we process content within an agent thread you operate). Our registered address is CommandAGI INC, 1831 McAlpin Rd, Midlothian, TX 76065, USA.

Where you use the Services to process personal data about other individuals (for example, data captured in a thread, a connected account, or a marketplace data listing), you act as the controller of that data and we act as your processor; in that case our processing is governed by the Terms of Service and any applicable data processing addendum ("DPA"), and you are responsible for providing notices and obtaining consents.

2. Definitions

"Personal information" (or "personal data") means information that identifies, relates to, or could reasonably be linked with a particular individual or household. "Processing" means any operation performed on personal information. "Your Content" means the content, code, data, prompts, configurations, and outputs you provide or generate through the Services. "De-identified" or "aggregated" information is information that cannot reasonably be used to identify an individual. "Sell" and "share" have the meanings given under applicable U.S. state privacy laws.

3. Information you provide to us

Account and profile data: name, email address(es), username/handle, password or authentication credentials, profile image, and, for OAuth sign-in, the basic profile fields the identity provider releases to us.

Age and date of birth: we collect a date of birth only to confirm age eligibility and to gate age-restricted models and streams. It is optional at sign-up and is requested when you first try to use an age-restricted feature; we store it minimally, and once provided it cannot be unset. If you indicate an age below 13, we cannot keep your data and will delete the account.

Billing and payout data: payment card or bank details (processed and stored by our payment processor, not by us), billing address, tax identifiers, and Stripe/Stripe Connect identifiers and onboarding/KYC information.

Content and usage data: the prompts, threads, snapshots, agent configurations, listings, messages, reviews, and support communications you create or submit, and the credentials/tokens for third-party accounts you connect.

Communications: information you provide when you contact support, respond to surveys, apply for roles, or otherwise correspond with us.

You are responsible for ensuring you have the necessary rights, notices, and consents to provide any information about third parties, and for not submitting sensitive information except where the Services are designed to receive it.

4. Information we collect automatically

Device and connection data: IP address, device identifiers, browser type and settings, operating system, language, and network information.

Location data: when you use location-dependent features such as "nearby jobs" or worker mode (putting your device online for work) in our mobile app, and with your device permission, we collect your device's geographic location (which may be precise, to within roughly 100 meters) to match you with nearby jobs and suppliers and to set the geographic origin of a stream. We also infer approximate location from your IP address. You can decline or revoke location permission in your device settings, which disables location-dependent features.

Usage and diagnostic data: pages and features accessed, referring/exit pages, timestamps, clickstream, thread lifecycle, capacity and credit events, error and performance logs, and other telemetry.

Crash, diagnostics, and performance data: in our mobile and desktop applications we collect crash reports and stability data (such as the error message, stack trace, and whether the crash was fatal), diagnostic information (device model, operating-system and application version, and network connectivity), and application-performance metrics (such as start-up time, stream and frame health in worker mode, request latency, and web performance vitals). We collect this through our own first-party telemetry to keep the applications reliable; we do not use it for advertising and do not share it with third parties for their own purposes. Crash and diagnostic payloads are designed to exclude the content of your threads, prompts, messages, and credentials.

Cookies and similar technologies: we and our providers use cookies, local storage, and similar technologies for authentication, security, preferences, and analytics, as described in our Cookie Policy.

5. Thread and environment data

Agent threads run in single-tenant cloud virtual worlds or simulation slots that are provisioned for you, logically isolated during use, and torn down on release. Snapshots you create persist until you delete them or your account is closed.

Live screen, sensor, audio, and camera streams are processed in real time to deliver the thread and to provide features you enable (such as remote control or recording). We do not retain stream content beyond what you configure, except where reasonably necessary to provide the Services, investigate suspected abuse or security incidents, or comply with law.

We retain operational metadata (thread lifecycle, resource usage, and billing/earnings events) on an append-only basis for accounting, capacity management, abuse prevention, and audit.

6. Connected accounts and credentials

Tokens and credentials for third-party accounts you connect are encrypted at rest and in transit and are used solely to perform the actions you authorize through the Services. We do not use them for any other purpose. You may revoke any connection at any time, which invalidates the associated tokens on our side; revocation does not affect actions already taken.

7. Sources of information

We collect information directly from you; automatically from your use of the Services; from your devices and the environments you provision; and from third parties such as identity and OAuth providers, our payment processor, fraud-prevention and security vendors, analytics providers, and marketplace counterparties to the extent necessary to complete a transaction you initiate.

8. How we use information

Provide, operate, maintain, secure, and improve the Services, and develop new features.

Authenticate users, manage accounts, and remember preferences.

Meter usage and process credits, holds, escrow, settlement, payouts, refunds, and taxes.

Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms, and to enforce our agreements.

Provide support and send administrative, service, security, and transactional communications.

Comply with legal, regulatory, tax, accounting, and audit obligations, and to establish, exercise, or defend legal claims.

Develop, train, fine-tune, evaluate, and improve our models, features, and the Services, using de-identified or aggregated data wherever feasible (see Section 9).

With your consent where required, send product updates, newsletters, and marketing, from which you can opt out at any time.

9. Model training, AI, and aggregated data

We may use Your Content and usage data to develop, train, fine-tune, evaluate, and improve world-learning models and the Services. Wherever feasible we do this using de-identified or aggregated data.

You may opt out of the use of your identifiable content for model training using available account controls or by contacting privacy@commandagi.com. Opting out does not affect processing already performed, processing necessary to provide the Services you request, or our use of de-identified or aggregated data.

We may create, use, retain, and commercialize aggregated, anonymized, and de-identified information, statistics, and insights derived from use of the Services. Such information does not identify you, is not personal data, and is not subject to the no-sale commitment in Section 11.

The Services include AI systems that can produce inaccurate or incomplete output and can act with a degree of autonomy. We do not use the content of your threads to make legal or similarly significant decisions about you. You are responsible for reviewing AI output and for the actions you direct agents to take.

10. Legal bases for processing (EEA, UK, Switzerland)

Where the GDPR, UK GDPR, or Swiss FADP applies, we process personal data on one or more of the following bases: performance of a contract (to provide the Services you request); our legitimate interests (to secure, operate, analyze, and improve the Services, prevent abuse, and pursue our business, balanced against your rights and freedoms); compliance with a legal obligation (including tax, accounting, and KYC/AML obligations handled through our payment processor); the protection of vital interests or the public interest where applicable; and consent (for optional cookies, certain marketing, and any processing for which we ask for it), which you may withdraw at any time without affecting prior processing.

11. How we disclose information

We do not sell your personal data and do not share it for cross-context behavioral advertising. This commitment does not restrict our use of aggregated or de-identified information, which is not personal data (Section 9).

Service providers and sub-processors: vendors who process information on our behalf under contract, such as cloud infrastructure, payment processing, identity/authentication, communications, analytics, and security providers (see our Sub-processors page).

Marketplace counterparties: information shared only to the extent necessary to complete a transaction you initiate (for example, between a buyer and a provider).

Legal and safety: authorities, courts, and other parties where we believe disclosure is required by law, regulation, legal process, or governmental request, or is reasonably necessary to protect the rights, property, safety, or security of CommandAGI, our users, or the public, or to detect or prevent fraud, security, or technical issues.

Corporate transactions: in connection with, or during negotiations of, a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, in which case personal data may be transferred subject to this Policy.

With your direction or consent: any other disclosure you authorize.

12. International data transfers

We are based in the United States and may process and store information in the United States and other countries whose data-protection laws may differ from those in your jurisdiction. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms, and we take additional measures where required. You may request a copy of the relevant safeguards by contacting us.

13. Data retention

We retain personal information for as long as your account is active and thereafter only as needed to provide the Services, comply with our legal, tax, accounting, and audit obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. Append-only billing and earnings ledgers are retained for the period required by applicable financial-records law. Retention periods vary by data type and purpose; when information is no longer needed, we delete, anonymize, or de-identify it. We may retain de-identified or aggregated information indefinitely.

14. Security

We maintain technical and organizational measures designed to protect personal information appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege credential handling, tenant isolation for threads, logging and monitoring, and security testing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for the security configuration of the environments and agents you operate.

15. Data breach notification

If we become aware of a security incident affecting your personal information, we will investigate and, where required by applicable law, notify the relevant supervisory authorities and affected individuals within the timeframes the law requires. Notification or response is not an acknowledgment of fault or liability.

16. Your rights and choices

Subject to applicable law, you may have rights to access, correct, update, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; to opt out of the "sale" or "sharing" of personal information or targeted advertising (we do not sell or share); to limit the use of sensitive personal information; and to withdraw consent.

You can exercise many choices directly in your account settings (including the model-training opt-out), unsubscribe from marketing via the link in our emails, and control cookies as described in our Cookie Policy. To make a request, contact privacy@commandagi.com.

We will verify your identity before acting on a request and will respond within the timeframe required by law. You may use an authorized agent where the law permits. We will not discriminate or retaliate against you for exercising your rights. If we decline a request, you may appeal by replying to our response; you also have the right to lodge a complaint with your data-protection authority.

17. United States state privacy disclosures

California (CCPA/CPRA): in the preceding 12 months we may have collected the categories of personal information described in Sections 3–4 (identifiers, customer records, commercial information, internet/network activity, geolocation inferred from IP, audio/visual information from threads you configure, professional information, and inferences). We collect this information for the business and commercial purposes in Section 8, from the sources in Section 7, and disclose it to the categories of recipients in Section 11. We do not sell or share personal information and do not use or disclose sensitive personal information for purposes that would trigger a right to limit. California residents have the rights to know, access, correct, delete, opt out of sale/sharing, and limit, and the right to non-discrimination.

Other states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana): residents have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling, and may appeal our decisions. We honor recognized universal opt-out signals where required.

Nevada: we do not sell covered information as defined under Nevada law; you may still submit a request regarding sale.

18. Cookies and tracking

We use cookies and similar technologies as described in our Cookie Policy. We currently do not respond to browser "Do Not Track" signals because no common standard exists, but we honor legally recognized opt-out preference signals where applicable.

19. Marketing communications

Where permitted, we may send you product and marketing communications. You can opt out at any time using the unsubscribe link in those messages or by contacting us. We may still send you non-promotional administrative, service, security, and transactional messages about your account and the Services.

20. Children's privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from them. The minimum age to hold an account is 13 (or the minimum age of digital consent in your jurisdiction, where that is higher — for example, 16 in parts of the EEA). If a user indicates an age under 13, or we otherwise learn that an account belongs to a child under 13, we will delete the account and its associated personal data. A user who tells us their date of birth is under 13 is shown a clear, confirmable notice and, on confirmation, the account and data are deleted; financial records we are legally required to retain are de-identified.

If you believe a child under 13 has provided us personal information, contact us and we will take steps to delete it. We do not knowingly "sell" or "share" the personal information of consumers under 16. Certain models and streams are further restricted to users 18 and older (see the Terms of Service and Acceptable Use Policy).

21. Third-party links and services

The Services may link to or interoperate with third-party websites, products, and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Review their policies before providing information.

22. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement, except where permitted by law (for example, automated fraud and abuse prevention). Where such processing occurs and the law grants you rights, you may request human review and contest the decision.

23. EU/UK representative and DPO

Where required, we will designate a representative in the EU and/or the UK and a data protection officer, whose contact details will be published here. Until then, you may reach our privacy team at privacy@commandagi.com.

24. Changes to this Policy

We may update this Policy from time to time. We will post the updated Policy here with a revised "Last updated" date and, for material changes, provide additional notice (for example, by email or in-product notice) and, where required, obtain your consent. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

25. SMS messaging and mobile information

SMS is an optional convenience. You can use CommandAGI fully without it, and the same information SMS provides is always available in your account on the website and apps. Enrolling in or staying enrolled in SMS is never required to create an account, purchase credits, run agents, or complete any task. If you provide your mobile phone number and opt in, CommandAGI may send you customer-care and conversational SMS text messages relating to the agents and tasks you operate — for example task updates, clarification requests, approval requests, status updates, and responses to your inquiries. This is account-related, customer-care messaging; we do not send marketing or promotional SMS under this program.

No mobile information sharing for marketing: mobile phone numbers and SMS consent data are not sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. We may use vendors and service providers (such as our SMS/telecommunications provider) only as needed to operate, deliver, secure, support, or improve the messaging service, and those providers are not permitted to use mobile information for their own marketing. No mobile information is shared with third parties or affiliates for marketing or promotional purposes under any circumstances.

Message frequency varies based on your activity, the agents you authorize, and the tasks you request. Message and data rates may apply. You can opt out at any time — reply STOP to opt out, and reply HELP for help. For support you can also contact us at hello@commandagi.com.

We retain SMS consent records (including the mobile number, the consent text and version, the source of the opt-in, and a timestamp) as an audit record of your consent and to operate the messaging program, as described in Section 13 (Data retention).

26. How to contact us

For privacy questions or requests, contact privacy@commandagi.com. For SMS or general support, contact hello@commandagi.com. For other legal matters, contact legal@commandagi.com. You may also write to us at CommandAGI INC, 1831 McAlpin Rd, Midlothian, TX 76065, USA.

Privacy Policy forms part of the agreements governing your use of CommandAGI and should be read together with our other policies. If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will remain in full force and effect. This document is provided for transparency and does not constitute legal advice. Questions may be directed to legal@commandagi.com. © 2026 CommandAGI INC. All rights reserved.