Data handling / updated August 28, 2026

Know where your test data goes.

This operational guide describes the product as it works today. It complements Agentzia's formal Privacy Policy with a concise view of the current beta.

Stored by Agentzia

Account, run, and billing records.

Account Email address, plan and credit balance, subscription status, account creation time, and hashed MCP-token metadata when a manual token is used.

Run input The submitted public URL or content, optional competitor names, source, status, and timestamps.

Run output Participant decisions, citations, reported research traces, observer synthesis, usage, and error details.

Billing Credit events and checkout identifiers. Stripe processes card details; Agentzia does not store card numbers.

External processing

Models and research services receive what they need to run the study.

OpenRouter Routes the current participant and observer model requests and reports model usage and cost telemetry.

OpenAI GPT-5.6 Luna and Sol process declared high-volume and flagship OpenAI participant proxies. GPT-5.6 Terra produces the observer synthesis.

Google Gemini 3.7 Flash processes Gemini Spark category-discovery and implementation-readiness journeys.

Anthropic Claude Sonnet 5, the Claude Free and Pro default, processes the trust-and-risk journey.

xAI Grok 4.6 processes the Grok Bot market-reputation proxy. A direct xAI route can use web and X search; the OpenRouter fallback supplies web research only.

Research tools Provider-native routes and OpenRouter provide model-directed research using provider defaults. Agentzia does not impose search-result, page-count, or fetched-page token limits.

Firecrawl The submitted public URL is used for the separate visibility and page-inventory track.

Infrastructure Vercel runs the web application and Supabase stores account and report records.

Access and retention

Private by account. Retained during beta.

Access Signed-in reports are restricted to their owning account. Guest reports use an unguessable claim token until they are attached to an account.

Database Row-level security blocks users from reading another account's records. Server credentials are kept outside browser code.

Retention There is currently no automatic expiry. Account and report records remain stored during the beta until they are manually deleted.

Deletion Self-serve deletion is not available yet. This is a known beta gap and must be resolved before a broader launch.

What to submit

Use public pages and non-sensitive content.

Public URL URL analysis is designed for pages that the model and research tools can reach without credentials.

Direct content MCP can analyze supplied content, but that content becomes part of the stored run.

Avoid Do not submit secrets, personal data, confidential drafts, authenticated pages, or regulated information during the beta.

OAuth MCP authorization requests the email scope. Manual MCP tokens are stored only as hashes and can be rotated.

Accountability

Agentzia is operated by Morphologic AI Inc. Read the complete policy before submitting content.

Read the privacy policy