Privacy Policy

Last updated: 31 May 2026

This policy explains what Chloros Agent ("we", "the Service") collects, why, and your choices. We built a security product, so data minimization is a principle, not an afterthought.

The short version. We store your account details, the agents you connect, and a log of the actions those agents propose through the gate — so you can review and approve them. We don't sell your data, we don't use it to train models, and we don't read the contents of your agents' work beyond what's needed to assess and display each action.

1. Who is responsible

The operator of this deployment of Chloros Agent is the data controller. If you are using a self-hosted instance, the organization or individual running it is responsible for the data it holds. Contact: info@chloros.io.

2. What we collect

3. How we use it

We do not sell your data, share it with advertisers, or use your data or your agents' activity to train any machine-learning model.

4. The Claude assessment layer

If the operator enables the optional AI assessment layer, the summary and payload of an action may be sent to Anthropic's Claude API to produce a risk judgment. Anthropic processes this under its own commercial terms and does not train on API data. This layer is optional; with it off, all assessment is local pattern-matching and nothing leaves the server.

5. Sharing

We share data only with the infrastructure providers needed to run the Service — our hosting provider, our database, Stripe (billing), and (if enabled) Anthropic (assessment) and your chosen push/Telegram channels. Each processes data on our behalf under their own terms. We may disclose data if required by law.

6. Retention

Account and agent data persist while your account is active. Action records are retained to provide your audit history; you can delete your account to remove your data. Self-hosted operators control their own retention.

7. Your rights

Depending on your location (e.g. GDPR/CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these, contact us at the address above. You can delete your account at any time, which removes your associated data.

8. Security

Passwords are hashed with scrypt. Sessions are revocable server-side tokens. Each tenant's data is isolated by account. Agent access tokens can be rotated. No system is perfectly secure, but security is the core of what we do.

9. Children

The Service is not directed to anyone under 16, and we do not knowingly collect their data.

10. Changes

We'll update the date above when this policy changes and, for material changes, notify you in-app or by email.

Template notice. This is a practical starting template, not legal advice. Before relying on it for regulated data, have counsel review it and confirm the legal entity and jurisdiction. Contact: info@chloros.io.