Privacy Policy
Privacy Policy
This English version is provided for convenience. If there is any discrepancy, the Japanese version prevails.
Delight, Inc. ("we", "us", or "the Company") establishes this Privacy Policy ("this Policy") regarding the handling of user information in Agentino ("the Service"), an AI work-execution service provided by the Company.
1. Service Operator
- Name: Delight, Inc.
- Representative: Ikumi Watanabe
- Address: Wind Ebisu Bldg. 8F, 2-4-8 Ebisu-Nishi, Shibuya-ku, Tokyo 150-0021, Japan
- Contact: support@agentinos.app
2. About the Service
The Service converts business procedures written in natural language into executable AI agents, and carries out work such as email handling, document preparation, and research, pausing for the user's approval at key points. By the nature of this work, the Service handles users' business data (email contents, document text, information from connected services, and similar data).
3. Information We Collect and Purposes of Use
3.1 Information We Collect
- Account information: name, email address, and other information required for login authentication
- Company and user information: information the user enters in the initial setup when starting to use the Service, such as the company name, organization name, company size, job role, and how the user learned about the Service
- Business data: business procedures created by the user, execution history, and information retrieved for executing work from external services the user has chosen to connect
- Google user data: information obtained when the user connects their own Google account to the Service (see Section 4)
- Access information: analytics information collected when this website or the Service console is viewed (see Section 6)
- Payment information: information about payments for paid plans and additional credits. Payments are processed through our payment service provider (Stripe), and card information such as card numbers is not handled on our servers. We retain only limited information provided by the payment service provider, such as customer identifiers, payment status, and the contracted plan
3.2 Purposes of Use
We use the information we collect for the following purposes:
- Providing and operating the Service: core functions such as assisting in creating business procedures, executing work, and displaying execution history
- Identity verification and authentication: account authentication and authorization when connecting external services
- Responding to inquiries: providing support and technical assistance
- Billing: aggregating usage and billing usage fees and additional credits
- Improving and developing the Service: investigating bugs, improving quality, and planning and developing new features
- Ensuring security: preventing abuse, and detecting and responding to security issues
- Important notices: notices about changes to the Terms of Service or this Policy, changes to the Service, maintenance, outages, and the like
- Complying with laws and regulations
- Information from us: providing information about the Service, and marketing and sales activities
- The purposes of use of Google user data are limited to those set out in Section 4.2 (it is not used for purposes 5 and 9 above)
- We use only account information and company and user information for purpose 9 above (we do not use business data or Google user data for it). You can stop receiving information from us at any time by contacting us via Section 12
- We do not use users' data for AI model training (see Section 5)
4. Handling of Google User Data
4.1 How and What We Access
The Service accesses Google user data only when the user chooses to connect their Google account, and only within the scopes explicitly presented on Google's OAuth consent screen:
- Gmail: reading emails, creating drafts, and organizing labels (e.g., marking items as processed, archiving, or moving to the trash)
- Google Drive: viewing, creating, and editing files (including moving files to and restoring from the trash)
- Google Calendar: viewing, creating, updating and deleting events
- Google Docs / Sheets: viewing, creating, and editing documents and spreadsheets
- Basic profile: account identifiers such as the email address
Due to the nature of the granted permissions, Google's consent screen may display wording that includes "send email" (Gmail) and "delete" (Drive); however, the Service's AI agents are not provided with an email-sending tool or a tool that permanently deletes files (moving files to and restoring from the trash is possible). For email, agents can only create drafts — sending is performed by the user.
4.2 Purpose of Use
Google user data is used solely to execute the business procedures defined by the user, and for the accompanying display of execution history and troubleshooting. We do not use it for advertising, nor repurpose it without the user's permission.
4.3 Compliance with Google's Limited Use Requirements
Agentino's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.4 Storage and Protection
- Google user data obtained for executing work is stored, as part of business data, on our servers (AWS Tokyo region) with encryption at rest
- Google account credentials (such as access tokens) are additionally encrypted at the application layer
- Credentials are never passed into the AI agents' execution environment; our deterministic program uses them on the agents' behalf, outside the execution sandbox
4.5 Sharing and Transfer
- We do not sell Google user data, nor provide it to third parties for advertising purposes
- To the extent necessary for executing business procedures, data may be sent — via our routing intermediary (OpenRouter, U.S.) — as input to the AI model providers described in Section 5. Providers are limited to companies whose published terms we have directly verified as not using customer data for AI training
- During execution, AI and tool inputs/outputs are stored as execution records in our own database (Amazon Web Services, Tokyo region) for verifying behavior, troubleshooting, and service improvement
- Except as required by law, no other third-party disclosure is made
4.6 Access by Our Staff
Our operating staff view business data, including Google user data, only for investigating bugs or abuse (security purposes), responding to a user's own request, or complying with applicable law.
4.7 Deletion and Disconnection
- Users can disconnect their Google account from the Service's interface at any time, and can also revoke the Service's access from their Google Account settings
- Upon disconnection, the stored credentials become unusable; upon termination they are made unusable together with the suspension of the organization and are included in the deletion described in Section 7
5. Input to AI Models
The Service does not host AI models on its own servers; business data is sent as input to external AI model providers. We only adopt providers whose published terms we have directly verified as not using customer data for AI training. This standard is not relaxed by user consent.
Details on the providers that receive data, their training and retention practices, and the settings of our routing intermediary are published on AI Models and Data Handling (in Japanese).
6. Analytics (Cookies)
This website and the Service console use Google Analytics to understand usage. Google Analytics collects anonymous traffic data using cookies. You can opt out via your browser settings or the Google Analytics Opt-out Add-on.
7. Retention and Deletion
- Business data is retained for as long as necessary to provide the Service
- Upon termination, we suspend the user's organization and stop using the stored data (including account information) for the Service (no new workflow runs and no agent access). The data is retained securely by us and deleted upon the user's request (see Section 10; contact in Section 12); a retention limit will be defined and this policy updated accordingly
- Server logs are automatically deleted after 30 days
- Information that we are required by law to retain (such as tax records) is retained for the period prescribed by law
8. Security Measures
- TLS encryption in transit, encryption at rest, and application-layer encryption of credentials
- Isolation of the AI agents' execution environment (the credentials themselves are not placed inside the execution environment)
- Per-organization data separation and access control
9. Provision to Third Parties and Outsourcing
9.1 Provision to Third Parties
We do not provide users' personal data to third parties except in the following cases:
- With the user's consent
- As required by law
- When necessary to protect a person's life, body, or property and it is difficult to obtain the user's consent
- When specially necessary to improve public health or promote the sound growth of children and it is difficult to obtain the user's consent
- When necessary to cooperate with a national or local government agency, or a party entrusted by one, in carrying out duties prescribed by law, and obtaining the user's consent would likely impede those duties
- When our business is succeeded due to a merger, company split, business transfer, or other reasons
The provision and transfer of Google user data to third parties is limited to what is set out in Section 4.5.
9.2 Outsourcing
To the extent necessary to provide the Service, we entrust the handling of personal data to external service providers, and we supervise them as necessary and appropriate under the Act on the Protection of Personal Information. The list of these providers (company name, country, and processing) is published on Subprocessors and Cross-Border Data Transfers (in Japanese).
9.3 Provision to Third Parties in Foreign Countries
In providing the Service, users' personal data may be provided to third parties in foreign countries. The countries concerned, the personal information protection systems of those countries, and the measures taken by the recipients to protect personal information are published in Section 4 of Subprocessors and Cross-Border Data Transfers (in Japanese).
9.4 External Services Connected by the User
Data is sent to external services that users themselves have connected for use in their business procedures, according to the content of those procedures. Connections are set up by the user's own actions, and data is never passed to external services that the user has not connected.
10. Your Rights and Request Procedures
Users may request disclosure, correction, or deletion of their information held by the Company. Please contact us via Section 12.
10.1 What You May Request
Under the Act on the Protection of Personal Information, you may request:
- Notification of the purposes of use
- Disclosure of retained personal data (including by provision of electronic records)
- Correction, addition, or deletion of the content
- Suspension of use or erasure
- Suspension of provision to third parties
10.2 Procedures
We will respond within the period prescribed by law after verifying your identity. Identity is verified by contact from your registered email address. A fee of JPY 1,100 (including tax) per request applies to requests for disclosure and for notification of the purposes of use; we will explain how to pay when we receive the request. No fee is charged for requests for correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties.
11. Changes to This Policy
This Policy may be revised in response to legal changes or service improvements. For material changes, we will provide notice on this website or by other appropriate means.
12. Contact
For inquiries about this Policy or the handling of your information, please contact support@agentinos.app.
Established: October 6, 2026