Privacy Policy

Last updated: March 2026

1. Introduction

AgenticNode (“we”, “us”, or “our”) is a visual agentic coding platform operated by VeriduxLabs. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform at vibe-coding.academy and any related services.

By using AgenticNode, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please do not use our services.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and authentication credentials through Supabase, our authentication provider. If you sign in via a third-party OAuth provider (e.g., GitHub, Google), we receive the profile information you authorize that provider to share.

2.2 Workflow Definitions

When you save workflows, we store your workflow definitions (node graphs, YAML configurations, and associated metadata) in our database to enable persistence, sharing, and marketplace publishing features.

2.3 Project Context

AgenticNode lets you attach a project profile (tech stack, conventions, key files, notes) to your workflows so the agent always has consistent context. Project context is stored server-side in Supabase, scoped to your account via row-level security, and only accessed at prompt composition or legacy execution time. You explicitly consent to storage when you create a project context, and you can edit or delete it at any time from the Composer. We recommend you do not paste secrets, tokens, or personally-identifying customer data into project context.

2.4 Prompt Composition and API Keys

AgenticNode's prompt composition occurs locally in your browser. Standard prompt orchestration does not execute agents server-side or bill you for model usage. If you choose to configure API keys in Settings (to enable client-side rendering/validation or legacy runs), these keys are stored in an encrypted vault and only sent to model providers (such as Anthropic, OpenAI, or Google) when you explicitly request composition rendering or a legacy run. We do not use your prompts to train AI models.

2.5 Composition and Execution Logs

When you compose prompts or run workflows (optional), we generate logs that include timestamps, composition parameters, target platforms, token counts, and error messages. These logs are stored to provide composition and legacy run history. These logs do not contain your source code, API keys, or the full content of LLM responses beyond status and token counts.

2.6 Analytics Data

We use Veridux Analytics, our privacy-respecting analytics system, to collect anonymized usage data including page views, feature usage patterns, and session duration. This analytics system does not use cookies for tracking, does not collect personally identifiable information, and does not share data with third-party advertising networks. Analytics data is used solely to improve the platform experience.

3. How We Use Your Information

  • Service delivery: To authenticate you, save your workflows, compose your hand-off prompts, and provide composition and execution history.
  • Platform improvement: To analyze aggregated, anonymized usage patterns and improve platform features, performance, and reliability.
  • Billing: To process subscription payments through Paddle, our Merchant of Record.
  • Communication: To send essential service notifications (e.g., security alerts, billing confirmations) and, if you opt in, product updates and newsletters.
  • Security: To detect and prevent abuse, unauthorized access, and malicious use of the platform.

4. Prompt Composition and AI Processing

Standard prompt workflows are composed client-side on your local browser. The compiled prompts are run locally on your own machine under your own subscription or API keys (e.g. via Claude Code, Cursor, or Copilot). For optional prompt registry API lookups or legacy execution runs, processing occurs on our infrastructure hosted by Vercel using your configured API keys. We have DPA agreements with LLM providers and your prompts are not used for model training.

Non-AI prompt steps (referencing files, custom rules, conventions) are resolved client-side in your browser and are not shared with any third party.

5. Third-Party Services

We rely on the following third-party services:

  • Supabase — Authentication and database. Supabase processes your email and account data under their privacy policy.
  • Paddle — Payment processing and subscription billing. Paddle acts as Merchant of Record and handles all payment data, tax compliance, and billing under their privacy policy. We do not store credit card numbers or payment details.
  • Vercel — Application hosting and serverless function execution under their privacy policy.
  • Anthropic — Our managed LLM provider. Workflow prompts, curator reviews, and AI assist requests are sent to Anthropic Claude under our enterprise account. See our Data Processing Agreement for the full subprocessor list.

6. Data Retention

We retain your account information and saved workflows for as long as your account is active. Execution logs are retained for 90 days and then automatically purged. If you delete your account, all associated data (account information, workflows, API keys, and execution logs) is permanently deleted within 30 days.

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data at rest is encrypted in Supabase using AES-256.
  • All data in transit is encrypted via TLS 1.2+.
  • Database access is restricted via row-level security policies in Supabase.
  • Workflow executions run in isolated environments with no cross-user data access.
  • We conduct regular security reviews of our infrastructure and dependencies.

8. Your Rights

You have the right to:

  • Access your personal data stored on our platform.
  • Export your workflow definitions in YAML format at any time.
  • Delete your project contexts, workflows, run history, or your entire account.
  • Correct inaccurate personal information.
  • Opt out of non-essential communications.

To exercise any of these rights, contact us at privacy@vibe-coding.academy.

9. Cookies

AgenticNode uses only essential cookies required for authentication session management (provided by Supabase Auth). We do not use advertising cookies, tracking cookies, or any third-party cookie-based analytics.

10. Children's Privacy

AgenticNode is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and update the “Last updated” date at the top of this page. Your continued use of AgenticNode after changes are posted constitutes acceptance of the updated policy.

12. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

privacy@vibe-coding.academy

VeriduxLabs