Skip to main content

Privacy Policy

Effective date: 8 August 2026 · Last updated: 8 August 2026

1. Who we are

The Agentic Architecture Framework site at agenticaf.io (the "Site") and paid MCP Access (the "Service") are enabled and operated by:

  • WrangleAI Ltd ("WrangleAI", "we", "us", or "our")
  • Company number: 16670149
  • Registered office: 11a Abbey Road, Malvern, England, WR14 3ES
  • Privacy: privacy@wrangleai.com
  • Data Protection Officer: dpo@wrangleai.com

WrangleAI Ltd is the data controller for personal data processed through this Site and Service. The broader WrangleAI platform at wrangleai.com is covered by the WrangleAI Privacy Policy. This policy applies only to agenticaf.io and AAF MCP Access.

2. Scope

This Privacy Policy covers:

  • Visitors to the Site (including framework documentation and community pages)
  • Customers who subscribe to MCP Access
  • People who contact us about the Site or Service

3. Personal data we collect

3.1 Account and billing (MCP Access)

  • Email address — required for checkout, receipts, magic-link sign-in, and support
  • Stripe identifiers — customer ID, subscription ID, and related billing metadata
  • Subscription status — active/cancelled, period end, included call allowance, calls used
  • API key material — we store a cryptographic hash of your API key, not the plaintext key after initial reveal

Payment card details are collected and processed by Stripe. We do not store full card numbers on our systems.

3.2 Authentication

  • Short-lived magic-link tokens (emailed via Resend)
  • Session cookies used to keep you signed in on Manage Access

3.3 Service usage

  • MCP tool-call counts against your monthly allowance
  • Aggregate, non-identifying telemetry used for public Site stats (for example total tool-call counts), where enabled

We do not intentionally store the content of your MCP tool arguments, prompts, or document payloads as part of the paid Service.

3.4 Technical data

Standard server and edge logs may include IP address, User-Agent, timestamps, and request paths as needed to operate, secure, and debug the Site and Service (hosted on Vercel and related infrastructure).

3.5 Communications

If you email us for support, we process the content of that correspondence and your email address.

3.6 Community / third-party embeds

Some pages may embed GitHub Discussions via Giscus. Interaction with those embeds is also subject to GitHub's privacy practices.

4. How we use personal data

  • Provide MCP Access, authenticate you, and enforce the monthly tool-call limit
  • Process payments and manage subscriptions via Stripe
  • Send transactional email (magic links, billing-related notices, security notices)
  • Provide email support
  • Secure the Service, prevent abuse, and investigate incidents
  • Comply with legal and accounting obligations
  • Improve reliability using aggregate usage statistics

We do not use your MCP Access email for marketing unless you separately opt in. Transactional messages required to run the Service may still be sent.

5. Legal bases (UK GDPR / EU GDPR)

  • Contract — providing MCP Access, billing, authentication, and support
  • Legitimate interests — security, abuse prevention, service improvement, essential cookies/sessions
  • Legal obligation — tax, accounting, and regulatory requirements
  • Consent — where required for optional cookies or marketing (if introduced later)

6. Sharing and processors

We do not sell personal data. We share data with processors who help us run the Service:

  • Stripe — payments and subscription management
  • Resend — transactional email delivery
  • Vercel — hosting, serverless APIs, and related infrastructure
  • Upstash (Redis/KV) — subscription and auth records
  • GitHub / Giscus — optional comments and community features

We may also disclose data if required by law, to protect rights and safety, or in connection with a business transfer (merger, acquisition, or asset sale), with notice where appropriate.

7. International transfers

We serve users in the UK, EU, US, and elsewhere. Some processors (including Stripe and US-based cloud providers) may process data outside the UK/EEA. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum, and on adequacy decisions where applicable.

8. Retention

  • Active subscriptions — retained while your subscription is active
  • After cancellation — access records may be retained for a limited period for support, fraud prevention, and accounting, then deleted or anonymised when no longer needed
  • Billing / financial records — typically up to 7 years where required for tax and accounting
  • Magic-link tokens — short-lived; deleted after use or expiry
  • Support emails — retained as needed to resolve your request and for legitimate business records

9. Cookies

We use strictly necessary cookies/session storage for Manage Access authentication. Theme preferences may also be stored locally in your browser. We do not currently rely on advertising cookies on this Site. If we add non-essential analytics cookies, we will update this policy and obtain consent where required.

10. Security

We use industry-standard measures appropriate to the Service, including TLS in transit, hashed API keys, access controls, and processor security commitments. No method of transmission or storage is perfectly secure.

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected individuals without undue delay (target: within 48 hours of becoming aware, where feasible) and notify the ICO within 72 hours where required by UK GDPR.

11. Your rights

Depending on where you live (UK, EEA, California, and other jurisdictions), you may have rights to access, rectify, erase, restrict, object to processing, port your data, and withdraw consent. California residents may have CCPA/CPRA rights including the right to know, delete, and opt out of "sale" or "sharing" (we do not sell personal information).

To exercise rights, email privacy@wrangleai.com or dpo@wrangleai.com. We may need to verify your identity. You may also lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority.

12. Children

The Site and Service are not directed to children under 18. We do not knowingly collect personal data from children under 18.

13. Changes

We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of the Site or Service after changes take effect constitutes acceptance of the updated policy where permitted by law.

14. Contact

WrangleAI Ltd, 11a Abbey Road, Malvern, England, WR14 3ES
Privacy: privacy@wrangleai.com
DPO: dpo@wrangleai.com
Support: support@agenticaf.io

Related: Terms of Use