Privacy Policy
How we collect, use, share and protect your information across the app, the cloud, agents and services.
Last updated: 16 September 2026 · Effective: 16 September 2026
This Privacy Policy explains how CryptoBees LLC (“CryptoBees”, “we”, “us”, “our”) collects, uses, discloses and protects information in connection with the SchemAgentic application (the “App”) on all platforms it runs on (Windows, macOS, Linux, iOS, Android and the web), our related websites, our cloud and account backend, and the agent, service and AI features (together, the “Services”). By using the Services you agree to the practices described here and in our Terms & Conditions.
The short version
- A free account stores nothing with us. SchemAgentic works on files on your own device without an account at all. The cloud — sync, sharing, agents and services — is the paid part.
- Credentials you give a service are stored where nothing can read them back — not you, not us through the app, and never our AI provider.
- Agents keep a record. Unlike ordinary AI chat, what an agent did on each run is stored in your schema so you can see it, until you delete it.
- AI features send content to Anthropic to generate a response. We store usage counts, not the text of prompts or replies.
- We do not sell your personal information and we do not use your schemas or prompts to advertise to you.
- You control your data. Sign out of all devices, sign a service out of a connected account, remove an incoming address, delete a schema, or delete your account entirely from the app.
Contents
- Who we are
- Information we collect
- How we use information
- AI features & Anthropic
- Agents & what they record
- Service credentials & connected accounts
- Incoming addresses
- Cloud storage & collaboration
- MCP server & connected agents
- Third-party services we use
- How we share information
- Cookies & analytics
- Data retention
- Your rights & choices
- International transfers
- Security
- Children’s privacy
- Do Not Track
- Data-breach notification
- Changes to this policy
- Contacting us
1. Who we are
The Services are provided by CryptoBees LLC. For all privacy questions, requests and notices, contact us at cryptobees@gmail.com. For the purposes of the EU/UK GDPR, CryptoBees LLC is the “controller” of the personal data described in this policy, except where we act as a processor of the content you create (your schemas).
2. Information we collect
What we collect depends on how you use the Services. If you never create an account, we collect no account or content data at all — your schemas are files on your device.
a. Account & identity information
If you create an account or sign in, our authentication provider (Google Firebase Authentication) records the identifiers associated with your sign-in method. We support email/password sign-in and federated sign-in with Google, Apple and Microsoft. Depending on the method, this includes: your email address, display name, profile photo URL (if your provider supplies one), the provider’s user identifier, a unique SchemAgentic user ID, and whether your email is verified. We do not receive your password when you use a federated provider.
b. Purchase & subscription information
When you buy a Pro subscription, the purchase is processed by the relevant app store or reseller (see §10). We store the entitlement result linked to your account — which plan you are entitled to, the product (SKU) purchased, a purchase/transaction token used to verify and re-validate the purchase, verification timestamps, and, for web/desktop purchases, a Paddle customer identifier. We do not store your full card number or bank details; those are handled by the payment processor.
c. Content you create
Your schemas, nodes, node text, images and files you attach, and other content you author are “Content”. Content lives on your device by default. If you move a schema to the cloud, its nodes, connections and a snapshot file are stored in our cloud (see §8). You retain ownership of your Content.
d. Agent, service and AI usage data
If you use AI, agents or services, we record per-account usage metering: AI unit totals, compute time, service-call counts and storage bytes, per month, against your account and against each schema, together with your email for account support and abuse prevention. We do not store the text of your prompts or the AI’s responses on our AI-gateway servers — those are streamed to the provider and only counted. Agent runs are an exception and are stored in your schema; see §5.
e. Service configuration & credentials
For each service you connect we store its configuration — a name, which node it belongs to, which operations it may call, spending limits, and whether it is in test or live mode. The credential itself is stored separately and is never readable through the app; see §6.
f. Device, diagnostic & usage data
- Run information stored with your account: platform, device model, operating-system version, app version and the time of your most recent run.
- Analytics: the App includes Google Analytics for Firebase (GA4), which collects standard app-usage and device information (e.g. app opens, platform, approximate region, and a Google-assigned instance identifier). This is used in aggregate and does not require you to sign in.
- IP address for AI region checks: when you make an AI request, your IP address is used transiently to determine your country for the availability check described in §4. We do not store your IP address for this purpose; only the resulting country verdict may be cached to your account.
- Presence: while you have a shared schema open, your display name, a colour and your cursor position are visible to the other people in that schema, and expire shortly after you leave.
- Storage usage: if you use cloud storage, we record how much you are using and your quota.
g. Communications
If you email us for support or opt in to product news, we keep your email address and the content of your message so we can respond and, if applicable, send updates you asked for.
3. How we use information
- To provide, operate and maintain the App, your account, cloud schemas and collaboration.
- To authenticate you and keep your account secure, including revoking sessions across devices.
- To process purchases, validate and re-validate subscriptions, and manage renewals and refunds.
- To run the agents you configure, make the service calls your schema makes, and record what happened.
- To provide AI features — sending your request to the AI provider and returning its response — and to meter usage against your plan’s limits.
- To enforce fair-use limits, detect and prevent abuse or fraud, and apply legal availability restrictions (see §4).
- To measure aggregate usage and improve the Services.
- To communicate with you about support requests, important service or security notices, and (where you opted in) product news.
- To comply with legal obligations and enforce our Terms.
Where required by law, our legal bases for processing are: performance of our contract with you (providing the Services), your consent (e.g. optional analytics, product emails, and using AI, agents and services), our legitimate interests (security, abuse prevention, aggregate product analytics), and compliance with legal obligations (including trade-sanctions compliance).
4. AI features & Anthropic
SchemAgentic’s AI features — agents, AI-drafted service definitions and AI chat — are powered by Anthropic’s Claude models. AI requests are routed through our secure cloud gateway to Anthropic; the App does not call Anthropic directly.
What is sent to Anthropic
- An agent run: the agent’s instructions and settings, the text of the node it belongs to, a description of the services on that node and the operations it may call, a description of that node’s connections, and anything delivered to the node that the agent reads.
- Drafting a service: the description you type of the API you want to connect to.
- AI chat: your typed message and the relevant schema context.
Credentials are never sent. An API key or token belonging to a service is used only in the outgoing request to that service, and is removed from anything that comes back before the result reaches the model.
What we retain
Our gateway does not persist the content of prompts or responses. We retain the usage counts described in §2(d), and operational logs containing metadata but not content. What an agent concluded, however, is written into your schema by design — see §5.
How Anthropic handles your data
Anthropic processes the content you send to generate a response. We access Anthropic’s API under commercial terms under which inputs and outputs are not used to train Anthropic’s models. Anthropic may retain data for a limited period for safety and abuse-prevention purposes in accordance with its own policies. Please review Anthropic’s Privacy Policy. You are responsible for the content you choose to submit; avoid sending sensitive personal information you would not want processed by a third-party AI service.
Regional availability
Because our AI provider does not serve certain sanctioned jurisdictions, AI features are unavailable in a small number of countries. To enforce this we determine the country of a request from network/geo signals or, as a fallback, your device’s locale (and, transiently, your IP address as described in §2(f)). If your location is restricted, the request is declined; the canvas continues to work.
5. Agents & what they record
An agent runs on our servers, on a schedule or when asked. For each agent we store what you configured — its name, instructions, settings, schedule, what it is allowed to reach, and its budget — and, for each run, a record of what it did: when it started and ended, why it ran, each step it took (including which service operations it called and whether they succeeded), what it concluded, and what the run cost.
These records live in your schema and are readable by everyone the schema is shared with. Unlike ordinary AI chat, they persist until you delete them or delete the schema. Values delivered between nodes are also stored on the receiving node, and a short history of deliveries is kept (see §13).
When an agent asks a person to approve something, the question and what it says are stored with the schema, along with who answered and when.
6. Service credentials & connected accounts
A service needs a credential to reach the API it connects to. How we handle one:
- It is stored in Google Secret Manager, outside our database, under access controls separate from everything else.
- It is never readable through the app — not by you, not by the schema’s owner, not by anyone you share with. A service record says only whether a credential exists.
- It is never sent to our AI provider, and is removed from responses before they are recorded or shown, in case the API echoes it.
- It is used only to make the calls your schema’s operations define.
Connected accounts. Where a service signs in through the provider instead (OAuth), the access and refresh tokens are stored the same way. We receive only the permissions the provider showed you when you approved the sign-in. Signing the service out destroys the tokens we hold; you can also withdraw access at the provider.
7. Incoming addresses
You can give a service an address that the outside world can post to. If you do: we store the address identifier and, where you have signature checking on, a signing secret (shown to you once, then stored the same way as any other credential). What arrives is delivered to the node and may start its agents, and a short record of each delivery — its time, its size and its event type, not its full contents — is kept so you can see what has been arriving. Who you give the address to is your decision, and what they send is their data reaching your schema.
8. Cloud storage & collaboration
Cloud storage is part of the paid plan. When a schema is in the cloud, its nodes and connections are held in Google Firestore and a snapshot file in Google Firebase Storage, readable and writable only by the people it is shared with, according to the role each has.
If a subscription ends, the schema is disconnected, not deleted: it stays exactly where it is, everyone who had access can still read it, agents and services stop, and nothing new is written until the owner subscribes again.
Anyone you share a schema with can read its content, its agents' run records and its service configuration — though never a credential. Choose who you share with accordingly.
9. MCP server & connected agents
The optional MCP server lets you connect external AI agents and clients using personal access tokens. Sync is opt-in; access tokens are shown once and stored only as a SHA-256 hash with your user ID, email and a label, and can be revoked instantly. A token only ever reaches the content of the account that created it. Any external agent or client you connect operates under its own provider’s privacy terms.
10. Third-party services we use
We use the following processors and service providers to run the Services. Each receives only the data needed for its function.
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Authentication, Firestore, Storage, Cloud Functions) | Accounts, cloud schemas, backend | Account identifiers, entitlements, schema content, run records, usage |
| Google Secret Manager | Storing service credentials and tokens | API keys and OAuth tokens you provide |
| Google Analytics for Firebase (GA4) | Aggregate usage analytics | App/device usage events, approximate region, instance identifier |
| Anthropic | Agents, AI drafting and AI chat | Instructions, node text, service descriptions (see §4) |
| Apple App Store | Purchases on iOS & macOS | Purchase/transaction identifiers |
| Google Play | Purchases on Android | Purchase tokens/product identifiers |
| Paddle | Merchant of Record for Windows, Linux & web purchases | Buyer email, account ID, customer/subscription IDs |
| Services you connect (e.g. Stripe, Slack, GitHub, Google, Notion, Airtable, Twilio, Resend, or any API you add) | Whatever you configured them to do | Exactly what your operations send, at the times your agents call them |
We do not control, and are not responsible for, the privacy practices of third-party services you choose to connect. Please review their policies before sending them anything.
11. How we share information
We do not sell your personal information and we do not share it for cross-context behavioral advertising. We disclose information only:
- to the processors listed in §10, to provide the Services;
- to the payment processors and app stores needed to complete and verify your purchases;
- where you direct it — content you share, people you share a schema with, services you connect, and agents or addresses you enable;
- to comply with law, enforce our Terms, or protect the rights, safety and security of our users, the public or CryptoBees; and
- in connection with a merger, acquisition or sale of assets, subject to this policy.
12. Cookies & analytics
Our websites use a minimal set of cookies and similar technologies necessary to run the site and remember your choices. In-app analytics are provided by GA4 as described in §2(f). We do not serve third-party advertising in the App. If that ever changes, we will update this policy first.
13. Data retention
- Account data is kept while your account is active and for a reasonable period afterward for legal, accounting and anti-fraud purposes.
- Purchase/entitlement records are retained after a subscription ends so we can honor prior purchases and meet tax/audit obligations.
- Usage counters reset each month; the usage document persists for support and abuse prevention.
- Cloud schemas, agent run records and approvals remain until you delete them or delete your account — including while a subscription is lapsed, because a disconnected schema is not a deleted one.
- Delivery records between nodes are kept for about seven days.
- Service credentials and OAuth tokens are kept until you replace them, sign the service out, delete the service, or delete your account.
- MCP tokens are stored only as hashes and are removed when revoked.
- AI prompt/response content is not retained by us (see §4).
- When you delete your account, we erase the data associated with it as described in §14, except records we are required to keep by law.
14. Your rights & choices
Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act, as amended), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. Because we do not sell or “share” personal information as those terms are defined, there is no sale to opt out of.
You can exercise many choices directly in the app:
- Sign out of all devices to revoke active sessions.
- Turn an agent off, narrow what it may reach, or delete it.
- Replace or remove a service’s credential, sign a service out of a connected account, or delete the service.
- Stop receiving on an incoming address, which destroys its signing secret.
- Stop sharing a schema, or delete it entirely.
- Update your display name and manage email verification and password reset.
Deleting your account. You can permanently delete your account and its associated data from Manage Account on this site, or from within the app: open Account, choose Manage Account, then Delete account. To protect you against accidental or unauthorized deletion, we first re-verify your identity and then ask you to confirm once more — on this site, by typing your exact account email. When you confirm, we delete your account and the personal data associated with it — including your profile, entitlement and usage records, cloud schemas and their snapshots, agent run records, service configurations and their stored credentials and tokens, and MCP tokens — and sign you out. Some records may be retained where we are required to keep them by law or to resolve disputes or prevent fraud; and while we cancel a subscription billed through our web checkout, we cannot cancel one billed by Apple or Google Play — only they can, so cancel that separately in the App Store or Google Play before deleting, or you will keep being charged. If you prefer, you can request deletion by emailing cryptobees@gmail.com from your account email. To exercise any other right, contact us at the same address; we will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data-protection authority.
15. International data transfers
We and our processors operate in the United States and other countries. Where we transfer personal data across borders, including from the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms offered by our processors.
16. Security
We take reasonable and appropriate technical and organizational measures to protect your information, including: storing service credentials and OAuth tokens in a dedicated secrets manager with no read path back to any client; removing credentials from responses before they are recorded; requiring a person to approve any action that spends money, messages someone outside a schema, or deletes data; refusing outbound calls to private network addresses, checked again on every redirect; verifying incoming webhook signatures with a constant-time comparison; per-user and per-role access rules on cloud data and storage; hashing MCP access tokens; and transport encryption throughout. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and any API or access tokens confidential.
17. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Some features (such as AI and purchases) may have a higher minimum age under the applicable app store’s or provider’s terms. If you believe a child has provided us personal information, contact us and we will delete it. This is consistent with the U.S. Children’s Online Privacy Protection Act (COPPA).
18. Do Not Track
Some browsers offer a “Do Not Track” signal. There is no common industry standard for how to respond to it, and our websites do not currently respond to DNT signals. We limit tracking as described in this policy regardless.
19. Data-breach notification
If a data breach affecting your personal information occurs, we will notify affected users and any relevant authorities without undue delay and as required by applicable law, describing the nature of the incident and the steps we are taking.
20. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Services, our practices, or legal requirements. When we make material changes we will update the “Last updated” date above and, where appropriate, provide additional notice. Please review this page periodically.
21. Contacting us
For any privacy question, request or notice:
cryptobees@gmail.com
CryptoBees LLC