Privacy Policy

How TheAgent handles personal data across the website, newsletter, podcast, TheAgent Vendors and TheAgent Pro.

Last updated: October 7, 2026.

This policy covers theagent.bz, the newsletter, the podcast, the TheAgent Vendors catalog and TheAgent Pro (the tool connected to Claude and ChatGPT). Here you can find what data we use in each service, why we use it, who we share it with, how long we keep it and how to exercise your rights. The Portuguese version prevails if it differs from this English translation.

1. Who is responsible for your data

TheAgent is operated by RX Investimentos e Participações Ltda (trading as Rx Venture Studio), CNPJ 48.095.059/0001-37, Av. Brasília, 6690, Conj. 06, Capão Raso, Curitiba/PR, CEP 81020-010. Cassyano Correr is the contact responsible for data protection. To discuss your data, write to cassyano@theagent.bz or use the Contact us form on the website.

2. What data we use in each service, and why

Each processing activity below states its legal basis under the Brazilian General Data Protection Law (LGPD, Law 13,709/2018) and its purpose. We use only the data needed for each purpose.

2.1 Website, newsletter and podcast

Data: email address and name provided when subscribing to the newsletter; email open and click records; for website visits, IP address, browser, device, pages visited, duration and referral source; aggregate metrics for episode plays on the website.

Purpose: deliver the newsletter you subscribed to; understand interest in the content and improve what we produce; measure website and podcast audience.

Legal basis: consent to send the newsletter (you can unsubscribe using the link in the footer of each email, effective immediately); legitimate interest in measuring audience, always respecting your choice in cookie notices.

2.2 TheAgent Vendors catalog

Data: audience measurement by Google Analytics depends on your choice in the catalog's notice. Technical server records include IP address, browser and referring page for 14 days, for security and troubleshooting. For searches, we keep the text entered after removing passages that appear to be an email address, phone number or identity document, together with the number of results and the referring page, without the IP address, to improve search. In contact, correction, company inclusion and dossier interest forms, we receive the fields submitted, date, IP address and browser. The catalog brings together company data from public sources, including partners' names and roles disclosed by the Brazilian Federal Revenue Service.

Purpose: operate the catalog, respond to your requests, publish business information from public sources and improve search.

Legal basis: legitimate interest in operating the catalog and publishing business data from public sources; performance of contract or precontractual steps when you submit a contact, correction or dossier interest form; consent to audience measurement when you accept it.

2.3 TheAgent Pro — account and subscription

Data: when you sign in to your account with Google, Microsoft or email, we receive your email address, name, language and the identifiers needed for login and billing. Stripe sends us subscription status and dates. You enter card details directly with Stripe; your full card details stay outside our servers.

Purpose: create and maintain your account, control access to the tools and charge for the subscription.

Legal basis: performance of contract.

2.4 TheAgent Pro — tool usage and saved questions

Data: records of the date, tool used, outcome, duration and number of results. To control access by connected agents, the app name and dates of first and last use. Tool usage records are separate from question text.

The option to save the text of questions asked by your agent is on by default. Your name is left out of the record, and we mask passages recognized as an email address, CPF, CNPJ or phone number. The text remains linked to your account through an internal code so that you can delete it; it may therefore still be considered personal data. Answers are not kept in this record, and other subscribers cannot access saved questions.

In your account, you can turn off saving for future questions and delete those already saved. The text is used to test and improve answers.

Purpose: operate the tools securely, provide support and improve answers.

Legal basis: performance of contract for operation and security; consent (given when you accept the Terms of Use and this Policy at sign-up) to save question text, with an option to turn saving off and delete the text at any time.

2.5 TheAgent Pro — your company's memory

For each client company, TheAgent maintains a memory made up of:

  • Company profile: registration details (name, CNPJ, sector, size and related information), what was collected from the website, LinkedIn, social media and the Brazilian Federal Revenue Service's public records, and what the client confirmed directly.
  • Work and decision history: each requested work product, the context needed to produce it (answers, assumptions and fields extracted from documents), and a short summary of decisions recorded for each delivery.
  • Deliveries: the content of delivered work products, with versions and revisions.

Every field records where it came from (you provided or confirmed it, or it came from the website, the Brazilian Federal Revenue Service or a document), when and in which version. A correction creates a new version; nothing is silently overwritten. The memory belongs to the company, and the client who owns the account relationship controls correction and deletion (as described in section 6).

Purpose: provide work products grounded in your company's history, avoid repeating questions already answered and maintain traceability for every item of information used.

Legal basis: performance of contract.

2.6 Collection from your company's website

When you provide your company's website, TheAgent reads up to 12 public pages (home, about, products, solutions, segments, prices, cases, contact, careers, terms, privacy policy and blog) and fills profile fields with what it finds. The website provided is read only if it is public: a regular web address, accessible on the open internet, subject to size and time limits per collection. The full text of the pages is not kept: only the extracted fields, with the page URL as their source, remain. The client is invited to confirm or correct the most important points for the request, and the client's confirmation prevails over what the website said.

Purpose: fill the company profile automatically to reduce what you need to enter.

Legal basis: performance of contract; legitimate interest in using business data published by the company itself.

2.7 Collection from the company's LinkedIn and social media

TheAgent reads your company's public LinkedIn and social media profiles that you provide or that are found in the website footer: public description, employee range, headquarters and sector, titles and dates of recent posts, and public activity (frequency and topics). We read only what is visible without logging in, always respecting each platform's automated access rules and terms of use; we keep a record of the pages read. When a platform prohibits automated access, the field remains empty and is declared as a gap, and you can fill it in manually.

Purpose: complete the company profile with public information that the company itself has published about itself.

Legal basis: legitimate interest in processing business data published by the company itself. You may object to this processing at any time through the channels in section 6.

2.8 Documents submitted by the client

Your document is submitted as pasted text, a public link or a file. It goes through local automated screening, before any AI model, with size limits and accepted formats. We reject five categories of content at the outset: health data, minors' data, biometric data, credentials (including passwords) and card numbers. The rejection returns only the category name (no one reads the passage), and none of the rejected content is saved.

For an accepted document, before any processing outside TheAgent's environment, natural persons' names, CPF numbers, personal email addresses and phone numbers are replaced with role markers (for example, "signatory 1"); the original passage containing those details is not sent to any external provider. Exception: when the work product requires the data and you expressly confirm its transmission.

We never keep the document file or its text: the content is discarded at the end of the same execution that read it, and the disposal is recorded. What remains is the extract: only the fields extracted (for example, dates, amounts and tax burdens in a contract), with source and date, linked to the work. If a document is submitted again, the previous extract remains valid.

If you decline to submit a document, the work continues without it, with the gaps declared.

Purpose: extract from the document the data used by the requested work product, without keeping the document.

Legal basis: performance of contract. Removing third parties' personal data (data subjects without accounts) before external transmission is a data minimization measure (LGPD art. 6, III) and mitigates the processing of those third parties' data.

Work products are available on a private page in your account, protected in two layers: the link is signed and individual, and the page requires, in addition to the link, a signed-in session in the account linked to the company. The link opens only if both conditions are met. The page has a watermark with the company name and date, allows PDF export, and blocks external scripts and images. Ending the relationship, a deletion request or the end of the retention period revokes access immediately.

When you request a copy of your company's data (section 6), it is delivered through the same type of link, with the same protection.

Purpose: deliver work products securely, with revocable access and an audit trail.

Legal basis: performance of contract.

2.10 Professional contacts

To present TheAgent products to companies, we may use professionals' names, job titles, companies, work email addresses and public profiles obtained from public sources or commercial databases such as Apollo and Hunter. Each message offers a way to stop future contact, and we honor that request immediately.

Legal basis: legitimate interest, subject to your right to object at any time.

3. Who we share data with, in which country and with what protection

We do not sell or trade your personal data. Service providers receive only what they need to perform their functions. When a provider is outside Brazil, the international transfer relies on the contractual data protection safeguards offered by that provider, under article 33 of the LGPD.

Recipient What they receive Purpose Country / mechanism
Clerk email address, name, language, login identifiers account authentication United States; provider's contractual safeguards
Stripe necessary subscription and payment data billing United States; provider's contractual safeguards
OpenRouter prompts with document or website content, already minimized (identified personal data replaced with markers) run the models that generate the work product; routing exclusively to providers committed to zero data retention, with a price cap per call United States; provider's contractual safeguards; the zero retention requirement is enforced in the call itself, and the call is aborted if no provider with that protection is available
Final model providers (via OpenRouter) the same content, already minimized, with a zero retention requirement generate the work product; without an eligible provider, the work pauses depending on the provider selected for each call, including the United States and China; contractual safeguards and zero retention requirement
Hostinger hosting for the VPS running the service and database operation United States (server in Boston); provider's contractual safeguards
Vendors (catalog) the vendor dossier is generated in the catalog; MCP only reads the delivered edition dossier production Hostinger servers outside Brazil; provider's contractual safeguards
Mailgun operational alerts monitoring United States; provider's contractual safeguards
Ghost, Mailgun (website/newsletter), Mautic, Google Analytics, Google Tag Manager, Meta Pixel website and newsletter processing (described above) website and newsletter United States; providers' contractual safeguards and applicable cookie notices
Apollo, Hunter professional contact data outreach United States (Apollo) and France (Hunter); providers' contractual safeguards

Competent authorities may also receive data to comply with legal obligations, as may contracted hosting and operation providers acting under our instructions.

4. How long we keep data

TheAgent Pro rule: everything the product keeps about the client — profile, work and decision history, context and deliveries — remains available while the subscription lasts, for as long as any account linked to the company has a subscription granting access. When the last subscription stops granting access, the day count begins; all data is deleted 365 days after the subscription ends. If any company account subscribes again within that period, the counter resets to zero and nothing is lost. Immediate deletion may be requested at any time (section 6).

Specific TheAgent Pro cases:

What Retention period
Company profile, decisions and account relationships while the subscription lasts + 365 days, or immediate deletion on request
Work history, context and document extracts same
Deliveries (work product content) same
Intermediate drafts and engine checkpoints 7 days after the work ends
Document content discarded at the end of the execution that read it; no file or text is kept
Raw text of website and social media pages read discarded at the end of collection; only extracted fields remain
Saved questions (text) while the subscription lasts + 365 days; saving can be turned off and the text deleted at any time in the account
Vendor dossiers (request history and metadata) same "while the subscription lasts + 365 days" rule; the page opens only while the edition exists in the catalog
Cost entries 5 years (accounting record, without client content)
Access records with IP address 6 months (Brazil's Internet Civil Framework), confidential
Security incident records 5 years
Login account and subscription while they exist; after closure, we keep for 5 years only the email address, payment identifier and dates needed to document the contractual relationship (retained from the published policy)

Other services:

  • Newsletter: keeps your email address while you are a reader. After cancellation, it leaves the mailing list, and the minimum record needed to respect your decision remains.
  • Vendors catalog: technical access records for 14 days; data measured by Google and Meta follows those platforms' retention periods.
  • Technical payment records: 30 to 90 days.
  • Connected agent data: up to 6 months after disconnection.

Backups

Backups of the TheAgent Pro database are kept for up to 90 days. Before any restored backup goes live, it reapplies the record of deletion requests already fulfilled; if the restoration uses an older copy, data covered by that record is deleted again, automatically and with proof. Thus, deletion requested by a client is carried out in backup copies within 90 days as well.

5. How we protect data

  • Separation between clients by design: each company can read and write only its own data, and no data from another company is returned, even if an identifier is supplied. This is checked by permanent automated tests of reading and writing.
  • Two layers of access for deliveries: a signed link and a signed-in session in the account linked to the company. When the relationship ends or access is deleted, the link stops opening immediately.
  • Documents: automated screening before any model, rejection of the five sensitive categories, minimization of third parties' personal data before external transmission, disposal of content at the end of execution and a ban on storing the file in any log.
  • Providers committed to zero data retention, enforced in the call itself; without a provider offering this protection, external processing is aborted instead of continuing without it.
  • Network and size limits when reading websites and documents provided by the client, with internal and cloud addresses blocked so that a URL cannot be used to reach data other than public data.
  • No client data goes to an external tracking or telemetry service; technical monitoring stays entirely within our environment.
  • General technical and administrative measures: secrets kept out of code, database access controls and incident records. We apply the security measures required by the LGPD (art. 46) and Brazil's Internet Civil Framework.

Incidents: if an incident involving personal data could cause relevant risk or harm, we will notify the affected people and the ANPD under the applicable rules and deadlines, and document the measures taken.

6. Rights of data subjects and those without accounts

Under the LGPD, you may confirm whether we use your data, access it, correct incomplete or outdated data, request anonymization, blocking or erasure of excessive data, request portability where applicable, learn who we share data with, obtain information about the choice to consent, withdraw consent, request erasure of data associated with that consent and object to unlawful processing. You may also complain to the ANPD. Some deletions are subject to the statutory retention periods explained in section 4.

If you are a TheAgent Pro client:

  • Access and copy: request it through your account (Account page) or the export tool in your app; you receive a private link, protected like the deliveries, to a readable copy (JSON) of your company's profile, context, decisions and deliveries.
  • Correction: any field can be corrected in conversation with the agent; the correction creates a new version and preserves the history.
  • Deletion: you can delete a delivery, a work item, a recorded document, a profile field or the entire company (the last option requires express confirmation by the owner of the account relationship and is irreversible, with a list of what will be deleted before confirmation). The effect on access is immediate: the content becomes unavailable at once, and permanent deletion takes place within 24 hours, including previous versions and derived data. Backups remain for up to 90 days, with deletions reapplied automatically.
  • Saved questions: turn off saving and delete the history on the Account page at any time.

If you do not have a TheAgent account but are a data subject whose data appears in a client's documents or pages (for example, your name appears in a contract your supplier used to produce a work product): write to cassyano@theagent.bz, use the Contact us form, or use the same channel as the Privacy Policy. The responsible person verifies your identity and responds within 15 days. Whenever the response concerns data belonging to the client's work memory, the request is handled with care to preserve the confidentiality of the client's own content; you are informed about the use and status of your personal data. The client who owns the documents is also notified of the request where appropriate.

Other services (website, newsletter, catalog): write to cassyano@theagent.bz or use the Contact us form; we respond within 15 days. Unsubscribing from the newsletter through the link in the email footer takes effect immediately. In the catalog, the Report an error button lets you request a correction to company data.

7. Limits: what is outside our control

Files you have already downloaded. When you export or download a work product, a report or a copy of your data, the file on your computer is under your control: we delete what is on our side, but the file that has already left us stays with you. This is a known technical limitation stated here clearly: deletion at TheAgent covers content served by us and all copies we make, but does not reach local copies kept by you or by anyone you have shared them with.

8. Cookies

The website uses cookies for audience measurement and ads. On TheAgent Vendors, measurement cookies depend on your acceptance. On TheAgent Pro, cookies maintain access to the account. You can control them in your browser; blocking login cookies prevents you from signing in to the account.

9. Changes to this policy

When this policy changes, we will update the date on this page. Relevant changes will be communicated by email to newsletter readers and TheAgent Pro clients. See also the Terms of Use.

criado por: RX Venture Studio
RX Investimentos e Participações Ltda · CNPJ 48.095.059/0001-37
Avenida Brasília, 6690, Conj 06, Capão Raso, Curitiba/PR, 81020-010 · Brasil
RX Venture Studio