Privacy Policy
Version: privacy-v1 · Effective: 10 September 2026
This policy explains what AGA collects, why, who it is shared with, and what you can do about it. It is written to be checked against the running platform rather than to sound reassuring. Where something is not yet built, it says so.
Who is responsible for your data
AGA (Artificial Guardian Angel) is operated by The N-Gine, which is the controller of the personal data described here.
The N-Gine
Suite 4, Level 6, Victoria House
29–31 High Street, St. Peter Port
GY1 2JX, Guernsey
Contact for any privacy question, request, or complaint: contact@myaga.org
What this policy covers
- The AGA website and installable web app at myaga.org, including organization sites published under it.
- The AGA mobile application for Android and iOS.
- The APIs behind both.
Organizations founded on AGA publish their own work and may operate their own sites under myaga.org. Their published material is public by design. This policy covers the personal data the platform holds about you.
The short version
- You can use most of AGA without an account. Reading published work needs nothing.
- Conversations with AGA are stored, because the stored conversation is the agent's memory. There is no hidden copy and no second transcript.
- Nothing about you becomes public unless you take an explicit action that says so.
- We do not sell personal data, we do not run advertising, and there is no advertising identifier in the mobile app.
- You can delete individual memories, delete conversations, and delete your account.
What we collect, and why
Account and sign-in
Email address, display name, authentication state, and sign-in timestamps. If you sign in with Google, we receive the account identifier and email from that sign-in and nothing more. Used to give you an account and keep it secure.
Conversations with AGA
The messages you send and AGA's replies are stored against your account. This is not incidental logging: the conversation history is what the agent reads to continue a conversation, so deleting it genuinely removes that context.
Conversations are private. They are not published, and they are not used as public profile data.
Personal memory
The platform distills bounded facts, preferences, and episodes from your conversations so that AGA can remember you between sessions. Each memory item is stored with its provenance — the conversation it came from.
Memory is private. You can inspect every memory the platform holds about you and delete any of them individually.
Journeys and guidance
Your ikigai record, meditation and dharma journeys, onboarding answers, chosen actions, and reflections. Used to give you continuity and personalised guidance. Private by default.
Public profile, matching, and connections
If — and only if — you choose to create a public profile: a username, a short bio, and the specific signals you approve one at a time. Matching ranks candidates from those approved signals; both people must independently accept before any connection exists. Messages inside a connection room are private to the two of you.
Email, contact details, raw conversations, raw memory, precise location, and wallet data are never public-profile fields.
Location
Optional and purpose-bound. If you grant it, a location record is stored with its precision, purpose, source, and any expiry you set. Device access is foreground and one-time — there is no background or continuous tracking.
Location records are private, are never copied to a public profile, and carry zero weight in people matching. Only the opportunity feed can use them, and only after a separate opt-in.
Opportunities
Saved, hidden, applied, and reported states for opportunities shown to you, plus private match evidence explaining why something was ranked for you. Private. AGA never applies or signs up on your behalf.
Voice
When you start a voice session, audio is streamed to the voice provider for the duration of that session in order to produce a reply. Sessions are started by you, never automatically.
Organizations, publications, campaigns, and votes
If you found or steward an organization, or vote on published work, we store those records. Organization and campaign records and published work are public by design. Votes are recorded against your account or, for a signed-out visitor, an anonymous cookie identifier, and are shown only as totals.
Treasury and campaign activity currently runs on the Solana devnet — a test network. Transaction records there are public by the nature of a blockchain.
Moderation and safety
Reports you file, cases about you, moderation decisions, and appeals. Retained for community safety and accountability. A reporter's private detail is never exposed on a public profile.
Technical and security records
IP address, user agent, request paths, timestamps, error traces, and rate-limit counters. Used to operate the service, diagnose faults, and defend against abuse.
When you use the AGA mobile app
The mobile app additionally involves:
| Surface | What happens |
|---|---|
| Camera | Requested only when you explicitly start a flow that needs it. No background capture. |
| Microphone | Requested only when you explicitly start a voice session. No background listening. |
| Notifications | If you allow them, a push token is registered. The server stores only a SHA-256 hash of that token plus platform and permission metadata — never the raw token. |
| On-device storage | A session cookie and non-secret account metadata in the platform's secure storage, plus a redacted offline snapshot so read-only screens work without a connection. Prompts, raw media, headers, keys, and session secrets are excluded from that snapshot. |
| Diagnostics | A redacted, allow-listed set of event summaries — such as a sync completing, a permission state, or a route failing. It excludes prompts, raw media, request and response headers, cookies, API keys, session secrets, and device identifiers. |
The app contains no advertising identifier, no advertising SDK, no third-party analytics SDK, and no crash-reporting SDK. It does not read your contacts, calendar, photo library, call logs, SMS, or installed-app list.
What we never do
- We do not sell or rent personal data.
- We do not serve advertising or build advertising profiles.
- We do not publish your conversations, memory, guidance, or reflections.
- We do not connect you to another person without both of you accepting.
- We do not track your location in the background.
Legal bases for processing
Under the Data Protection (Bailiwick of Guernsey) Law, 2017 and, where it applies, the EU General Data Protection Regulation:
- Performance of a contract — running your account and the features you ask for.
- Consent — voice sessions, location, notifications, anything published to your public profile, and any optional feature presented as an opt-in. You can withdraw consent at any time; withdrawing it does not undo processing already carried out.
- Legitimate interests — security, abuse prevention, and keeping the service working, balanced against your interests.
- Legal obligation — where we are required to retain or disclose something.
Who we share data with
We use service providers ("processors") who handle data on our behalf under contract. By category, and naming those the platform currently uses:
| Purpose | Providers |
|---|---|
| AI model inference for conversation and generation | Anthropic, OpenAI, OpenRouter, and NVIDIA NIM, depending on the feature |
| Text embeddings for conversation memory | Voyage AI |
| Voice sessions | ElevenLabs; OpenAI Realtime in the mobile app |
| Video and scheduled calls with organizations | Tavus, SmartMeet |
| Transactional email | Resend, Mailgun |
| Push notifications | OneSignal on the web app; the platform's own hash-only registration in the mobile app |
| Optional sign-in | |
| Opportunity listings | Adzuna |
| Hosting and network protection | Our hosting provider and Cloudflare |
| Devnet treasury records | Solana devnet and the configured RPC provider |
We share data with a provider only for the purpose listed, and only the data that purpose needs. We also disclose data where the law requires it, and to protect the rights or safety of people.
Two honest limits: the exact model provider used for a given feature can change as we route work between them, and we do not yet publish each provider's own retention terms here.
International transfers
The N-Gine is in the Bailiwick of Guernsey, which the European Commission recognises as providing an adequate level of data protection. Several of the providers above operate in the United States or other countries outside the Bailiwick and the EEA. Where personal data is transferred out, we rely on the receiving country's adequacy recognition or on standard contractual clauses approved for use by Guernsey controllers.
How long we keep data
- Account, conversation, memory, and journey data — while your account exists, and then per the deletion process below.
- Anonymous vote cookies — until the cookie expires or is cleared.
- Security, audit, and abuse records — retained for a bounded period after the event, and after account deletion where we are required to keep them.
- Published work, organizations, and campaigns — kept as a public record, because the point of a published record is that it stays checkable.
A complete category-by-category retention schedule is still being written. That is a known gap, stated here rather than glossed over.
Deleting your account and your data
You can delete your account from Profile → Account in the app, or on the web at myaga.org/profile. Full instructions, including how to make a request without signing in, are on the Account and Data Deletion page.
In summary: deletion is confirmed with your email address, then held for a 30-day recovery window during which signing in restores the account. After that, identifying data is erased or pseudonymised. A privacy-safe deletion receipt and any records we are required to keep for security or financial reasons remain. Published work already in the public record is not retracted by account deletion.
You can also delete individual memories and individual conversations at any time without deleting your account.
Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct data that is wrong.
- Delete your data.
- Restrict or object to processing.
- Receive a copy of data you provided, in a portable form.
- Withdraw consent for anything you consented to.
- Not be subject to a decision made solely by automated means with a significant effect on you. AGA suggests; it does not decide anything about your rights or obligations on its own.
To exercise any of these, write to contact@myaga.org. We answer within 30 days.
If you are not satisfied, you can complain to Guernsey's Office of the Data Protection Authority (ODPA) at odpa.gg, or, if you are in the EEA, to your local data protection authority.
Children
AGA is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to contact@myaga.org and we will delete it.
What AGA cannot promise
AGA is an AI system. Its replies, summaries, memory items, match explanations, and suggested actions can be incomplete or wrong. Treat them as fallible suggestions, not verified facts.
AGA is not a doctor, lawyer, therapist, or financial adviser, and nothing it says is professional advice. If you are in danger or in crisis, contact your local emergency services.
If the AI runtime behind AGA is unavailable, the platform returns an error. It does not generate a substitute reply and present it as AGA.
Changes to this policy
When this policy changes materially, we update the version and effective date at the top and record the change in the version history on the Trust Center. Continuing to use AGA after a change means the updated policy applies to you.
Contact
The N-Gine
Suite 4, Level 6, Victoria House
29–31 High Street, St. Peter Port
GY1 2JX, Guernsey
Privacy contact: contact@myaga.org
A fuller, system-by-system account of what is automated, what a person reviews, what is logged, and what remains unbuilt is published at myaga.org/trust.