# Privacy Policy — Agent Rails

**Last updated:** 2026-08-05  
**Service:** https://agent-rails.onrender.com  
**Contact:** federico.celico87@gmail.com  
**GitHub:** https://github.com/federicocelico/agent-rails

## What Agent Rails is

Agent Rails is a shopping API and MCP server for AI agents. It returns product search results and Amazon purchase links that may include an Amazon Associates affiliate tag (`agentrails-20`).

## Data we collect

- **Agent registration:** optional agent name, optional owner email, generated API key hash, plan, quotas.
- **Usage logs:** endpoint, query text, status code, latency, agent id, approximate request time.
- **Click tracking:** opaque click ids for affiliate redirects (`/v1/go/{clickId}`), hashed IP for abuse limits.
- **MCP HTTP:** same commerce calls under a shared MCP agent id; no conversation transcripts from ChatGPT/Claude/etc. are stored by Agent Rails.

We do **not** sell personal data. We do not intentionally collect payment card data.

## How we use data

- Provide search, compare, and buy-link features
- Enforce free/anonymous daily quotas and rate limits
- Measure aggregate traffic (`/v1/stats`)
- Improve reliability and prevent abuse

## Third parties

- **Hosting:** Render (or successor) processes HTTP traffic and may log standard server metadata.
- **Amazon Associates:** when a user opens a `buy` link, Amazon may set cookies and process the purchase under Amazon’s policies. Agent Rails may earn a commission.

## Retention

API keys and usage/click records are kept while the service operates and for a reasonable period afterward for abuse investigation, then deleted or anonymized when practicable.

## Your choices

- Use anonymous quota without registering.
- Register without providing an email.
- Contact us to request deletion of an agent id / email association when feasible.

## Children

Not directed at children under 13.

## Changes

We may update this policy; the date above will change. Continued use means acceptance of the updated policy.
