Skip to content
Agent Factory

Legal

Privacy Policy

Amended 26 August 2026

Agent Factory is a paid reference library of articles, prompts, and skill files for people building AI agents. We are committed to protecting your privacy. This policy sets out what personal data we collect when you visit or use the platform, why, who it is shared with, and the rights you have over it. It reflects how the service actually works - we have deliberately kept the amount of data we hold small.

1. Who is responsible

Agent Factory (https://www.skillagentfactory.com) is operated from Bulgaria by ADEN HOME, the data controller for the personal data described in this policy.

For any privacy question or request, contact business@skillagentfactory.com.

2. Information we collect

You give us some of this data directly, such as when you register an account or send us a support message. Some is recorded automatically as your browser interacts with the platform. We collect only what the service needs to function.

Your account consists of your email address, a securely hashed password, and timestamps for when the account was created and when you last signed in. Alongside it we record whether you hold lifetime access and a Stripe customer reference; we never receive or store your card details, which go directly to Stripe. If you write to us through the contact form or by email, we hold the name, email address, and message you sent.

If you sign up for report notifications we hold that email address, the date you confirmed it, which page you signed up from, and two random tokens - one that confirms the address, one that unsubscribes it. No name, and no link to your account: subscribing while signed in creates a separate record that knows nothing about you beyond the address you typed. Section 3 explains what it is used for and how to end it.

Two things are processed as you use the platform. Text you type into search is sent to our embedding provider to find matching content, and is not linked to your account. Separately, our host records technical request metadata such as IP address, browser type, and operating system for security and debugging.

The Agent Benchmark stores what you submit through it, and only that: the operational numbers you entered, four coarse labels you choose from fixed lists (what the agent does, team size band, deployment stage, and optionally an industry), which version of our thresholds produced the score, the score itself, and the month. Not the day, and not the time - an exact submission time alongside an unusual combination of labels would be enough to recognise someone, so it is not recorded.

There is no field in that record for a company name, an email address, a website, or free text of any kind, and no account is attached even if you are signed in. Values outside their possible range are refused rather than stored, and combinations that contradict each other are set aside for review rather than counted. We keep submissions because the comparisons are drawn from them - a percentile only exists if enough people have submitted one - and no comparison appears until a category holds at least 20 submissions for that metric. Read from the code rather than written out here, so this sentence cannot outlive the number it describes.

Your own past runs are grouped by a random key your browser generates and keeps locally. It is never sent to us: what reaches us is a hash of it, hashed again against a secret before storage. That is enough to show you your own history and to delete it on request, and not enough to identify you. It also means that if you clear this browser’s storage, those runs become unreachable by anyone, including us - which is the price of not asking who you are.

If you create a shareable link to a benchmark result, that page holds the score, the verdict, how many metrics you entered, and the per-group averages - and only those. It does not hold the numbers you entered, so sharing a score never publishes your cost per task or your margin. It carries no account reference and not even the hashed browser key, so a shared page cannot be traced back to you or matched against your other runs. The four coarse labels appear on it only if you tick the box asking for them, which is off by default. Anyone holding the link can open the page; nobody can find it without the link, and it is not indexed by search engines.

A small number of benchmark records were not submitted through the calculator at all. In the early period we asked teams for their operational numbers directly, in conversation, and entered what they told us ourselves — people will often share a figure in a call that they will not type into a form. Those records hold exactly the same fields as any other, which is to say nothing that identifies the team who gave them: no name, no company, no notes. They are marked in the dataset as entered by us rather than submitted, so any published figure can be recomputed with or without them, and the report says which it did. Because such a record carries nothing linking it to anyone, the person who gave us the numbers cannot delete it themselves — if you gave us figures this way and want them removed, write to us and we will delete the record.

We do not ask for your phone number or postal address, and we do not build behavioural profiles. We do count page views - which pages are read, and roughly where in the world from - using a measurement tool that stores nothing on your device and cannot follow you between visits or to other sites. Section 7 sets out exactly what it records.

There is one third-party script, and only with your consent: the Google Ads tag, which tells us whether an advert we paid for led to a purchase. It loads with all four Google consent signals set to denied, so no advertising cookie is written and nothing is sent to Google unless you accept. If you decline, or simply ignore the banner, it stays denied. Section 7 covers what it stores and how to change your mind.

You have choices about this. Where we ask for personal data you may decline - but an account cannot exist without an email address and a password, so declining those means you cannot use the platform.

3. What we use your information for

We use the data to operate the platform, keep it secure, and support you. That means creating your account, signing you in, and unlocking the content you have paid for; processing your purchase and keeping the transaction record; and sending the service emails that confirm your address and let you reset your password.

We also use it to diagnose problems and answer your enquiries, to fix faults and add content and features, and to detect and prevent abuse, fraud, and unauthorised access. Improvements come from aggregate behaviour and from what you tell us directly, not from profiling individuals.

We run one email list, and it does one thing. If you ask for it, we will tell you when a new edition of The State of Production Agents is published - a few times a year, and nothing else. No product announcements, no offers, no reminders. That is not a statement of intent; it is the purpose you consented to, and consent given for one purpose does not cover another.

Signing up takes two steps on purpose. You give us an address, and nothing is stored as a subscription until you click a link we send to that address - so somebody typing in your email achieves nothing. The moment you click is the record of your consent. Every message carries an unsubscribe link, including the first, and unsubscribing deletes the record rather than moving you to a suppressed list: we would rather hold nothing than hold a list of people who asked us to stop. An address that never confirms is deleted within seven days.

Everything else we send is transactional and is not marketing: address confirmation, password resets, replies to your enquiries, and notice of significant changes to these documents. Those have no unsubscribe link because you cannot have an account without them.

We do advertise - which is what the Google Ads tag in section 7 is for - but we do not use your email address to do it, and we do not upload customer lists to any advertising platform. Subscribing to the report list does not put you in an advertising audience, and buying something does not put you on the report list.

4. Our lawful basis for processing

Most of what we do rests on performance of our contract with you: creating and running your account, granting access to purchased content, and sending the service emails that make those possible. Keeping transaction and tax records for the period the law requires is a legal obligation. Answering support requests, keeping the service secure, and preventing abuse rest on our legitimate interests; we have weighed your rights in each case and do not consider any of this processing intrusive.

Two things rest on your consent, and only on your consent. The advertising cookies described in section 7 are set only if you accept them, and stay off if you decline or ignore the banner. The report notification list in section 3 exists only for addresses that confirmed by clicking a link we emailed. Neither is necessary to use the platform, both are refusable at no cost to you, and both are withdrawable at any time - through “Cookie choices” in the footer, and through the unsubscribe link in every message. Withdrawing is as easy as giving it, and does not affect anything lawfully done beforehand.

Everything else rests on the bases above rather than on consent, so refusing these two leaves your account, your purchase, and your access entirely unaffected.

5. How we protect your information

All traffic is served over HTTPS, encrypted in transit with TLS. Data is stored encrypted at rest by our database provider. Passwords are hashed by our authentication provider and never stored in readable form, so nobody here can see yours.

Access to paid content is enforced at the database level with row-level security, not only in the interface. Administrative access is limited to a small number of named accounts. Payment card details never reach our servers.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the supervisory authority within 72 hours as the GDPR requires, and tell you directly where the breach is likely to present a high risk to you.

6. Keeping our systems confidential, resilient, and available

The platform runs on established infrastructure providers rather than hardware we operate ourselves: our host serves the application across a distributed, redundant network, and our database provider handles replication and automated backups. Their resilience and disaster recovery commitments are set out in the terms linked from their names in section 8.

On our side, we keep the number of people with production access to a minimum, apply security updates to our dependencies, and hold secrets such as API keys outside the codebase in the hosting platform’s encrypted environment settings.

7. Cookies and advertising

Cookies are small files a site stores in your browser so it can recognise you on your next request. There are two kinds here, and they are treated differently because the law treats them differently.

The cookies that keep you signed in are strictly necessary for the service to work, so we do not ask permission for them - there would be no service to consent to. Clearing them, or signing out, ends your session. Your browser can block them entirely, but you will not be able to sign in.

The Google Ads cookies are optional, and off until you say otherwise. We advertise, and this is how we learn whether an advert produced a purchase rather than guessing. The tag loads with all four of Google’s consent signals - advertising storage, advertising user data, personalisation, and analytics storage - set to denied, so no such cookie is written and no data reaches Google until you accept. Declining, or ignoring the banner entirely, leaves it denied.

We also count page views, and this one is not behind the banner. We use Vercel Web Analytics, which records the page visited, the site that linked you here, your country, and your browser and device type. It is not asked for your consent because it does not store or read anything on your device: no cookie, no local storage, no identifier you carry between visits. Repeat visits within a day are counted using a hash that Vercel rotates every day and cannot connect across days, so there is no profile, here or anywhere else. The script is served from this site’s own address rather than fetched from another company, and Vercel already handles every request as our host - so this sends your data nowhere it was not already going. We use it to see which articles are worth writing more of. It is the whole of our analytics; there is nothing else measuring you.

You can change your mind at any time. The Cookie choiceslink at the bottom of any page forgets your answer, stops the tracking immediately, and asks again - it does not silently switch you to the other option. Your answer is kept in your browser’s local storage, not in a cookie and not on our servers, so we hold no record of who consented; clearing your site data resets it.

Nothing about the paid content depends on this. Declining does not limit the site, the benchmark, or anything you have bought.

8. Who we share data with

We do not sell personal data and we do not share it for anyone else’s marketing. A handful of providers each handle one part of the service, under a data processing agreement and only for that purpose: Supabase - database and sign-in; Vercel - hosting, server logs, and page-view analytics; Stripe - payments; Resend - transactional email; Google (Ads) - advertising measurement, only with consent; and Google (Gemini API) - search embeddings. Each name links to that provider’s own privacy terms.

We may also disclose data where we are legally required to, for example in response to a valid legal request, or where necessary to establish or defend legal claims.

9. International transfers

Some of the providers named above operate outside the European Economic Area. Where data is transferred out of the EEA, it is covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard under that provider’s data processing terms.

11. Your rights as a data subject

You have guaranteed rights under Regulation (EU) 2016/679 (the “GDPR”). You can learn more about the GDPR and your rights on the European Commission’s website.

Two of these you can exercise yourself, immediately, from your account page: download a machine-readable copy of your data, and delete your account outright. For anything else, email business@skillagentfactory.com and we will respond within one month.

Right to information and access

You have the right to be told how your personal data is processed - which is what this policy is for - and to obtain a copy of the data we hold about you. To protect your account we may need to verify your identity before disclosing it.

Right to rectification

You have the right to have inaccurate personal data corrected and incomplete data completed. Your email address is the only personal detail we hold that you might need to change; contact us and we will update it.

Right to erasure (the right to be forgotten)

You may request erasure of your personal data where it is no longer necessary for the purpose it was collected for, where you withdraw consent and no other legal basis applies, where you object to processing for direct marketing purposes, where we have processed it unlawfully, or where erasure is required to comply with a legal obligation that applies to us.

You can do this yourself from your account page, and it takes effect immediately. We will comply with a written request without undue delay unless continued retention is necessary for exercising freedom of expression and information, complying with a legal obligation, performing a task in the public interest, archiving or research purposes, or establishing, exercising, or defending legal claims.

In practice one exception applies to us: transaction records are retained after deletion where tax and accounting law requires it. That is a legal obligation we cannot waive, which is why deleting your account does not erase your invoices.

Right to restrict processing, and to object

You may ask us to restrict processing where you contest the accuracy of the data, where processing is unlawful and you would prefer restriction to erasure, or where we no longer need the data but you need us to keep it to establish, exercise, or defend a legal claim.

You may also object to processing carried out on the basis of our legitimate interests. Where an objection would prevent us from providing the service you have paid for, we will explain that before acting on it.

Right to data portability

Where processing is based on your consent or on performance of a contract with you, you may receive the data you provided in a structured, commonly used, machine-readable format, or ask us to send it to another controller. The export on your account page produces exactly this, as JSON, with no need to ask.

Right to freedom from automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects or otherwise significantly affects you. Were that ever to change, you would have the right to express your point of view, to contest the decision, and to require that it be taken by a person rather than by software alone.

Right to object to direct marketing

The only list we run is the report notification list in section 3, you are on it only if you confirmed by email, and you can leave in one click from the link in any message. Leaving deletes the record outright, so there is nothing left to object to afterwards. Note that administrative and service messages - confirming your address, resetting your password, notifying you of changes to these documents - are necessary to provide the service and are not marketing, so they do not carry an unsubscribe option.

Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time by contacting us. As set out in section 4, we currently rely on contract, legal obligation, and legitimate interests rather than consent.

Right to complain

If you believe we have handled your data improperly, please tell us first - most issues are resolved quickly by email. You also have the right to lodge a complaint with the Commission for Personal Data Protection (Bulgaria), our lead supervisory authority, or with the supervisory authority in the EU or EEA country of your habitual residence, your place of work, or the place where you believe the infringement took place.

12. How long we keep it

We keep your account data for as long as your account exists; delete your account and it is removed immediately. Transaction records are kept after deletion for the period tax and accounting law requires. Support messages are kept while needed to resolve your enquiry and for a reasonable period afterwards, and server logs are retained short-term by our host according to their policy.

Benchmark submissions are kept for 24 months and then deleted automatically. Twenty-four months is what year-on-year comparison needs and nothing beyond it. Records used only for rate limiting hold no submission data and are deleted after a day.

Shared result pages expire after 12 months and are then deleted automatically - shorter than submissions, because a submission is an anonymous data point and a shared page is public. A score from three years ago presented as current says something untrue about a team that has probably moved on.

Deletion is available and immediate. The benchmark page has a control that removes every run submitted from that browser’s key, and it deletes the rows outright rather than marking them hidden - a record flagged as deleted is a record still held. Because submissions carry no identifier, that control is the only route: we cannot find your rows from your name or your email, because we never had either. Submitting is optional and separate from using the tool, which calculates your score in your browser whether or not you ever submit anything.

13. Children

The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

14. Changes to this policy

We will update this policy when necessary to reflect changes to the platform or to the law, and will revise the “Amended” date at the top. We encourage you to review it periodically. Significant changes affecting registered users will be notified by email.

15. How to contact us

For any privacy concern, complaint, or question, write to business@skillagentfactory.com. We respond to privacy requests within one month, as the GDPR requires, and to ordinary questions within 2 working days.

See also our Terms and Conditions and Contact page.