Privacy Policy
Last updated: September 17, 2026
This Privacy Policy explains how Aglyn LLC, a Texas limited liability company ("Aglyn," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with the Aglyn platform and related websites and services, including aglyn.com, app.aglyn.com (the console), the Besigner site builder, tenant sites on aglyn.app, docs.aglyn.com, our APIs, plugins, and the Aglyn marketplace (collectively, the "Services").
Two roles — please note the difference:
- When we act as a controller (business): For personal information of our account holders, prospective customers, and visitors to our own sites, Aglyn decides how and why the information is processed. This Policy governs that processing.
- When we act as a processor (service provider): When you (a customer) build a website, storefront, form, dataset, or CRM using the Services and collect personal information from your End Users, you are the controller of that information and we process it on your behalf under our Terms of Service and Data Processing Addendum. Your own privacy policy — not this one — governs your End Users, and you are responsible for it.
1. Information We Collect
1.1 Information you provide.
- Account & identity: name, email address, password or authentication credentials, and profile details, established through our identity provider (Google Firebase Authentication), which may include third-party sign-in identifiers (e.g., Google account identifiers).
- Phone number: a mobile or other telephone number, where you give us one — at signup, in your user or organization profile, or as a billing or support contact — or where your organization's single sign-on identity provider includes a phone number in the assertion it sends us when you sign in. Providing a phone number is optional. See Section 2 for how we use it and Section 11 for how to opt out of marketing calls and texts.
- Organization & membership: organization details, team member and invitee email addresses, roles, and permissions.
- Billing: plan selection, billing contact, subscription and transaction identifiers, and add-on/seat quantities. Payment card details are collected and processed directly by our payment processor (Stripe); Aglyn does not store full card numbers.
- Content & data you submit: websites, screens, layouts, media/assets, datasets, products, forms, contacts/CRM records, and other Customer Content — which may itself contain personal information about your End Users.
- Support & communications: messages, feedback, and information you share when you contact us.
1.2 Information collected automatically.
- Usage & device data: log data, IP address, browser and device type, pages/screens viewed, actions taken, timestamps, referring URLs, and similar analytics.
- Cookies & similar technologies: as described in our Cookie Policy.
- Security & anti-abuse: information used for authentication, session management, rate limiting, and bot protection (including Google reCAPTCHA), and audit/activity logs.
1.3 Information from third parties. We may receive information from authentication providers (e.g., Google), our payment processor (e.g., subscription status), and infrastructure providers, as needed to operate the Services.
Business contact information about prospective customers. We may collect business contact information about people who work at organizations we believe may benefit from Aglyn — such as name, job title, employer, work email address and public professional profile — from publicly available sources, including company websites and professional networking sites, and from business contact data providers. We use it only to contact you about Aglyn, and we do not sell it.
1.4 Data we process on your behalf (as processor). When End Users interact with your Hosts (e.g., submit a form, create an account/membership, make a purchase, or browse a storefront), the Services process personal information such as contact details, order and payment metadata, membership/subscription data, and site-analytics data on your behalf and under your instructions. See the DPA.
2. How We Use Information (as Controller)
We use personal information to:
- provide, operate, maintain, secure, and improve the Services;
- create and manage accounts, organizations, and authentication;
- process subscriptions, billing, and usage metering, and prevent payment fraud;
- provide support and respond to requests;
- send service, transactional, and administrative messages (via our email provider, Resend);
- contact you about your own account — including billing, invoicing, payment problems, and collection of overdue amounts, and service, security, and administrative notices — by email and, where you or your identity provider have given us a phone number, by telephone call or text message;
- with your consent where required, send product updates and marketing;
- contact you for sales and marketing purposes — including plan upgrades, add-ons, new features, and other product offers — by email and, where permitted by law and with your prior express consent where the law requires it, by telephone call or text message to a phone number we hold for you;
- monitor, analyze, and improve performance, reliability, and features, including developing new features;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms; and
- comply with legal obligations and enforce our agreements.
Legal bases (EEA/UK): performance of a contract; our legitimate interests (operating, securing, and improving the Services); consent (where required, e.g., certain cookies and marketing); and compliance with legal obligations.
AI features. Some features use a third-party AI provider — currently Anthropic — to generate assistance or content. These include Aglyn Assist, the in-console helper that answers questions about using Aglyn, can carry out actions in the console that you confirm first, and can propose changes to the page, component, or layout you have open in the Besigner, which take effect only if you choose to apply or save them; the editor's writing and layout assistance; AI generation, which creates drafts and proposals for your site from a brief you write, such as copy, layouts, templates, search titles and descriptions, and theme changes; AI insights, which answer your questions about your own figures, such as your site's traffic, sales, bookings, forms, campaigns, A/B tests and datasets, and, if you ask for them, write a weekly summary of them; and AI assistance in the CRM, which summarizes a contact, company, deal, or lead for you and suggests a next step, drafts a one-to-one email for you to review and send yourself, and suggests how the columns of a spreadsheet you import match your CRM's fields.
What AI features send. When you use one of these features, we send the provider what that feature needs to return a result: your question, instruction, or brief, with the earlier messages of the same Aglyn Assist conversation, and the content of the page, element, post, or section you are working on; on some plans, your organization's name and the console page and site you are working in; for a change proposed in the Besigner, an outline of the page, component, or layout you have open — its elements, their names, their shortened settings and text, and the styles of the element you selected; for AI generation, a summary of your site — the names and addresses of its screens and collections, the names of its components, layouts, templates, forms, and datasets and of their settings and fields, and your theme's summary, colors, and fonts; for AI insights, your question and tables of totals, counts, and rates computed from your records — such as page views and your most viewed pages and referring sites, each form's views and submissions, revenue, orders, and your best-selling products, bookings by service, each campaign's delivery, open, and click rates, and each A/B test's conversions, and, for a dataset you can see, the names and types of its fields, its record counts and number ranges, and totals grouped by the values of one field that at least three records share — with email addresses and phone numbers removed, and never an individual visitor, contact, customer, order, booking, form submission, or dataset record; for a theme change, your site's current theme settings, and brand colors taken from your organization's brand settings, from your site logo in your media library, or from a public web page your brief links to, of which only the colors are sent; and, for features that review or write search information for your site, the text and structure of the pages concerned; for features that write product copy, your store's name, the product's name, type, description, tags, options, and search title and description, the names of your store's product categories, and the product's first photo from your media library, sent as a smaller copy (at most 768 pixels on its longer side) without the original file's embedded details such as the camera, date, or location — no other photo, file, or file name from your media library is sent, and no price, stock level, order, or customer information is sent; for features that propose products, categories, or discounts from a brief, your store's name and the names of your store's existing product categories; and, for AI assistance in the CRM, the contact, company, deal, or lead you open, as the CRM shows it to you — such as its name, job title, company, lifecycle stage, and tags, how the person was captured, the counts and dates of their captures, orders, and email engagement, a deal's stages, status, amount, and dates, its notes, its recent timeline entries with email subjects and the start of what was logged, and its open tasks and deals — with email addresses and phone numbers written in that text replaced, and never an email address, phone number, or postal address field, marketing consent, custom field value, or record identifier; for an email draft, also your request and the names of the merge fields the record can fill; and for an import, your file's column headers and the kind of values in each column, never a row of the file. When you ask AI to draft an automation, we also send which of the CRM, webhooks and bookings your plan includes. When you ask AI to explain an automation, we send an outline of how it is set up: what starts it, its conditions, and each step with the text you gave it and the names of the lists, campaigns, workflows, webhooks and datasets it uses. When you ask why a run failed, we also send when that run happened, what it did and the errors it recorded. We remove email addresses from the outline before sending it, and we never send the details of the event that started a run, such as what a visitor entered in a form. We do not send your account identifiers, email address, or authentication tokens to the provider. Do not submit sensitive personal information to AI features unless necessary, and review outputs before use.
Aglyn Assist conversations. We keep a record of your use of Aglyn Assist: the question you asked, the answer it gave, which console page you were on when you asked, and the number of tokens the exchange used. When an answer proposes changes in the Besigner, the record also notes how many changes it proposed and whether you applied them, and applying them is recorded in your site's activity log. If you rate an answer using the thumbs control, we keep that rating alongside the exchange. The record is stored against your Organization, is accessible to us, and is used for three purposes — to find what our documentation and our product fail to explain so we can improve both, to improve the assistant's answers, and to meter and price the feature. We do not use it to build a profile of you, we do not use it for advertising, and we do not sell it. Retention and deletion are described in Section 5.
AI generation jobs. When you, another member of your Organization, or a collaborator on one of your sites starts AI generation, we keep a record of the job: the brief and the options chosen for it, who started it and when, the plan it proposed and who confirmed it, its progress and the AI credits each step used, and what it produced — a link to each draft it created and, for a result that is not saved as a draft of its own, such as a piece of copy or a proposed theme change, the result itself. The record is stored against your Organization and is visible to its members and to us. Your Organization's activity log and our internal audit log record that a job was started and what it created, without the text of its brief or of what it wrote. Drafts a job creates become part of your site's content. For AI insights, the answer and the tables it was written from are kept beside the job record rather than on it, and are shown only to the member who asked or, for a weekly summary, to members who can access the site, and to us. If you turn on weekly insights for an Organization, we record that choice on your account and, each Monday, send you a summary for its busiest sites you can access, in the console and by email. You can turn it off in your notification settings. For AI assistance in the CRM, the result — a summary with its suggestions, an email draft, or a column matching — is kept beside the job record rather than on it. A summary is shown to members who can open the record in the CRM, and an email draft or a column matching only to the person who asked; each is also accessible to us. AI never sends an email; you review a draft and send it yourself. Retention and deletion are described in Section 5.
AI usage and allotments. For each person in each Organization, we keep a monthly record of their use of AI features: the AI credits they used and our estimated cost of serving them, how many requests they made and how many were refused, and how that usage divides by kind of request and by site. It can be seen by the person it is about, by members of the Organization who can view its billing or audit log, and by us. For an Organization on the Free plan, we also count AI usage against the account of its owner, so that the Free plan's limits apply across all the Organizations that account owns on the Free plan. The people who manage your Organization's billing, and a site's administrators for that site's collaborators, can set an AI allotment for a member, a site collaborator, or a site; an allotment records whom it applies to, its monthly limit, any models it allows, and who set it. When usage passes a notice threshold on an allotment, we tell your Organization's owners and administrators and, for an allotment that applies to a person, that person, in the console and by email. We use these records to operate, meter, and bill AI features, to show usage to you and your Organization, and to prevent abuse. Retention and deletion are described in Section 5.
3. How We Share Information
We do not sell personal information. We may share information with:
- Subprocessors / service providers who help us operate the Services (hosting, database, storage, payments, email, security, analytics, AI, video hosting). See our Subprocessors list. Current core providers include Google (Firebase/Cloud, including reCAPTCHA), Vercel, Stripe, and Resend, and our AI features use Anthropic, as described in Section 2. Films on our own marketing site are hosted and streamed by Wistia, whose player loads when you press play or, on a page built to show a single film, with the page if your privacy choices permit analytics.
- Payment processor (Stripe) to process subscriptions and, for commerce features, to facilitate your sales via Stripe Connect.
- Other organization members — information may be visible to members/administrators of your Organization.
- Legal & safety — to comply with law, legal process, or governmental requests; to enforce our terms; and to protect the rights, property, or safety of Aglyn, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction or consent.
"Sale"/"sharing" under U.S. state laws. We do not "sell" personal information for money. With your consent, we do "share" personal information for cross-context behavioral advertising as U.S. state privacy laws define that term: our own sites use advertising and measurement technologies from third-party advertising platforms, such as Google, Meta, and LinkedIn, so that we can show you Aglyn ads on other sites and services and understand whether they worked. The categories involved are online identifiers, device and browser information, and your activity on our own sites. Advertising technology runs on our own marketing site, console and documentation site; it does not run on customer Hosts unless the Host operator enables it themselves. Where the law requires us to ask first — the EU, the UK, and anywhere we cannot determine your region — it does not load until you accept. Elsewhere it runs from your first visit and you can turn it off whenever you like. You can withdraw at any time using the "Your Privacy Choices" control on any page, which stops the sharing, signals the platforms to stop, and clears the related cookies from your browser; clearing them stops future joins but cannot retract information a platform has already received. We also honor opt-out preference signals: if your browser sends Global Privacy Control, we treat that as an opt-out and no advertising technology loads at all. We use analytics on our own sites to understand how they are used; where analytics is connected to advertising it operates under the same consent and the same opt-out, and where it is not it is neither a "sale" nor a "share" as those laws define them. Our service providers process personal information only to provide the Services under contracts that restrict them accordingly.
4. Cookies & Tracking
We and our providers use cookies and similar technologies for authentication, security, preferences, and analytics. For details and choices, see the Cookie Policy.
5. Data Retention
We retain personal information for as long as needed to provide the Services, maintain your account, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and context. Some specific periods we operate today: when you request deletion of your organization, a 7-day reversible hold precedes the permanent erasure, so an accidental or malicious request can be canceled; after the hold, the erasure is a genuine recursive delete and we keep no copy of the erased content — only an internal record that the erasure happened, retained for a limited period. Database backups are kept on a 14-week cycle and deleted media is recoverable for 7 days, so residual copies of deleted data can persist in backups for up to that period before expiring. For data we process on your behalf, retention is governed by your instructions and the DPA. You may request deletion as described in Section 7, subject to legal and operational limits. You are responsible for maintaining your own backups of your content.
AI features. The questions you ask Aglyn Assist and the answers you receive, including answers that propose changes in the Besigner, are deleted automatically 180 days after the exchange. We keep a record of each exchange for longer — which documentation it drew on, which model answered, what it cost, any rating you gave, and how many changes it proposed and whether they were applied — but that record contains neither your question, your answer, nor your user identifier, and we use it only to improve our documentation and the assistant and to operate and meter the feature. The record of an AI generation job — its brief and options, its plan, and any result kept on it, or kept beside it for AI insights with the tables it was written from — is deleted automatically 180 days after the job is started, and the result of AI assistance in the CRM, which is kept beside that record, is deleted automatically 14 days after it is produced; drafts a job creates are part of your site's content and are kept until you delete them. Monthly records of each person's AI usage are deleted automatically 13 months after the end of the month they describe. AI allotments are kept until they are changed or removed. Your choice to receive weekly insights is kept with your account until you change it. All of this is erased with your Organization in any case, under the 7-day reversible hold described above. The monthly count of AI usage we keep against an account for the Free plan's limits is kept with the account. When a person's account is erased, the erasure also deletes that count, their monthly AI usage records in every Organization, and the AI allotments set for them in the Organizations they belong to when the erasure runs. You may request deletion sooner as described in Section 7.
6. Security
We use reasonable technical and organizational measures designed to protect personal information, including authentication controls, access restrictions, encryption in transit, and infrastructure provided by reputable vendors. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and configuring your Hosts securely. See our security-disclosure process at security@aglyn.com.
7. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent.
- EEA/UK (GDPR): rights of access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with a supervisory authority.
- California (CCPA/CPRA) and similar U.S. state laws: rights to know, access, delete, correct, and to opt out of "sale"/"sharing" and certain targeted advertising. Because we share for cross-context behavioral advertising where you have consented, that right is live: use "Your Privacy Choices" on any page, or send Global Privacy Control, and we will stop. We do not sell personal information for money. You also have the right not to be discriminated against for exercising these rights.
To exercise rights, contact privacy@aglyn.com. We will verify your request as required by law. If your request concerns personal information we process on behalf of a customer (as processor), please contact that customer directly; we will assist them as required by the DPA. You may authorize an agent to act on your behalf where permitted by law.
8. International Data Transfers
We and our providers may process and store information in the United States and other countries where our providers operate. These countries may have different data-protection laws than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers. By using the Services, you understand your information may be transferred to and processed in such countries.
9. Children's Privacy
The Services are not directed to children under 13 (or the applicable minimum age), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@aglyn.com and we will take appropriate steps. If your Host collects information from children, you are responsible for compliance with applicable children's-privacy laws (e.g., COPPA, GDPR-K).
10. Third-Party Sites & Services
The Services link to and integrate with third-party sites and services that we do not control. Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
11. Marketing Communications
You may opt out of marketing emails using the unsubscribe link or by contacting us. If we emailed you as a prospective customer, you can also opt out by replying to that message; we will stop contacting you and keep only your email address on a limited internal do-not-contact list used for nothing else. You may opt out of marketing telephone calls and text messages at any time — reply STOP to any marketing text to stop texts, tell us during a call, or email privacy@aglyn.com to stop calls, texts, or both — and you may ask us to delete the phone number we hold for you. If you do, we will delete it from your account and keep it only on a limited internal do-not-contact list, used for nothing else: that record is the only way we can recognize your number and avoid contacting it again. We may still send you non-promotional, service-related messages, including account, billing, payment, security, and administrative notices, by email and, where we hold a phone number for you, by call or text.
12. Changes to this Policy
We may update this Policy at any time. Material changes will be indicated by updating the "Last updated" date and, where appropriate, by additional notice. Your continued use of the Services after changes take effect constitutes acceptance.
13. Contact Us
Aglyn LLC (a Texas limited liability company)
Privacy: privacy@aglyn.com
General: info@aglyn.com
© 2026 Aglyn LLC. All rights reserved.