agmsg.cloud — Privacy Policy
Last updated: August 14, 2026
Interpretation and Definitions
Interpretation — The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions have the same meaning whether they appear in singular or plural.
Definitions — For the purposes of this Privacy Policy:
- Company (referred to as “the Company”, “We”, “Us” or “Our”) refers to Jugemu Labs, Inc. (operating agmsg cloud).
- Service refers to agmsg.cloud — the Website and the hosted synchronization service that
relays messages between Your machines and agents — and Your access to it, including access
made programmatically or through the
agmsg-cloudcommand-line client. (This policy covers the hosted Service and Your access to it; the licensing of the client / OSS software itself, and any data it processes purely locally, are out of scope here — see the Terms of Service.) - Website refers to agmsg.cloud, accessible at https://agmsg.cloud/
- Personal Data is any information that relates to an identified or identifiable individual.
- Usage Data is data collected automatically, generated by the use of the Service or from the Service infrastructure itself.
- You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service.
The core commitment (end-to-end encryption)
The Service carries messages between Your machines and agents. The Service does not persist plaintext message content. The hosted service accepts only end-to-end-encrypted message writes, stores message bodies only as ciphertext, and we do not hold the keys required to decrypt them.
End-to-end encryption protects message contents, not traffic patterns. This policy is explicit about the non-content metadata we can see (which teams, devices, and wire identifiers are involved, how much, and when — not what).
Collecting and Using Your Personal Data
Types of data collected
Account and identity. You sign in with GitHub or Google; there is no password, and we never create or store one. From Your chosen provider we record a display name (Your GitHub login, or Your Google profile name), the provider and Your provider-specific user id, and — for Google sign-in — Your email address and whether the provider marked it verified. A GitHub sign-in stores no email address. We do not automatically link accounts across providers.
Message data (end-to-end encrypted). For each message we store an opaque encrypted envelope and the routing metadata needed to deliver it. The stored fields include the team identifier, a per-team sequence number, the receive time, an envelope/format version, a cipher and key identifier, the encrypted blob, and a digest. There is no plaintext message body.
Traffic and connection metadata. Because we route Your messages, the following is visible to us even though contents are not: team identifiers; message counts and per-message byte sizes; sequence numbers and timestamps; the team, device, and wire identifiers and per-machine read positions of members; and machine/device labels and device public keys You register.
IP address. When a machine requests a device credential, Your IP address is used for rate-limiting (abuse prevention), and a hashed form of it is stored with the device grant. We do not store the raw IP address in that record. We treat this hashed value as pseudonymous Personal Data, not as anonymized data.
Usage metrics. We record a small set of product events — account sign-in, organization creation, team creation, and access-token issuance — as counts. Separately, for capacity enforcement, we account for the retained-ciphertext byte totals per team. No message content is in either record.
Billing. Payment is processed by a third-party payment processor. Card details are entered directly with the payment processor; we do not collect or store full card numbers or security codes (CVC). To reconcile Your subscription we receive and store billing data from the processor, including: Your customer and subscription identifiers, plan, and paid-through date; a record of the processor’s webhook events (event id, type, organization, time); records of billing facts we could not immediately apply (with the reason and the claimed/stored plan and period); and checkout-attempt records (attempt id, plan, a processor-hosted checkout URL, and its expiry). Because the processor transmits whole signed events to us for verification, an event may incidentally include billing details the processor attaches (such as customer details); we do not use these beyond reconciling Your subscription.
Correspondence. When You contact us (for support, a rights request, or a legal matter) at
admin@jugemu.ai, we receive and process Your email address and the content of Your message
through our business email provider (see recipients, below).
Cookies and tracking
We set only functional cookies: a session cookie, a CSRF-protection cookie, and two short-lived cookies used during the OAuth sign-in exchange. We use no advertising, analytics, or cross-site tracking cookies, and we include no third-party analytics or tracking scripts.
Use of Your Personal Data
We use the data above to: provide, operate, and maintain the Service and deliver Your messages; authenticate You and manage Your account; process Your subscription and manage Your plan; enforce plan and capacity limits; secure the Service, prevent and investigate abuse, and troubleshoot and support the Service; and send You service and account notices. We do not use message contents for any purpose — we cannot read them.
Logs
Our application logs are restricted to a fixed allow-list of non-content fields (identifiers, a request id, a non-secret token prefix, status, latency, and byte counts). They cannot contain message bodies, email addresses, tokens, cookies, or URLs; secret headers are redacted. The synchronization gateway does not log requests at all, because the request URL carries a capability secret.
Service providers and other recipients
We rely on service providers to operate the Service, each receiving only what its function
requires: a payment processor (payment processing), sign-in providers (OAuth authentication),
a cloud infrastructure provider (hosting), and a business email provider (our operational
email, including our contact/support and legal correspondence address, admin@jugemu.ai;
when You email us, that provider processes Your sender address and the content of Your
message).
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, and to comply with our legal obligations, resolve disputes, and enforce our agreements. Usage Data is generally retained for a shorter period, except where it is used to strengthen the security or improve the functionality of the Service, or where we are legally obligated to retain it for longer. At present the Service does not automatically trim or delete message data by a retention window.
Data export. The Service does not currently offer a data-export feature.
Transfer, deletion, and Your rights
Your information, including Personal Data, is processed at the Company’s operating locations and in any other places where the parties involved in the processing are located. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy, and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
You may have rights to access, correct, delete, port, or restrict processing of Your Personal Data, and to object or withdraw consent, depending on where You live. Because message contents are end-to-end encrypted, we cannot produce their plaintext for a data request — only the encrypted envelopes and the metadata described above. To make a request, contact us (below).
Disclosure of Your Personal Data
We may disclose Personal Data in a business transaction (merger, acquisition, or asset sale, with notice), to comply with a legal obligation or valid request by public authorities, or in good faith to protect the rights, property, or safety of the Company, the Service, its users, or the public, and to protect against legal liability.
Security
Session tokens are stored only as hashes. Message contents are end-to-end encrypted and we do not hold the decryption keys. Traffic is served over TLS. No method of transmission or storage is 100% secure.
Children’s Privacy
The Service does not address anyone under the age of 13, and We do not knowingly collect Personal Data from children under 13.
Changes to this Privacy Policy
We may update this policy; we will post the updated version with a new “Last updated” date and, for material changes, provide notice through the Service.
Contact Us
If you have any questions about this Privacy Policy, contact us by email: admin@jugemu.ai.
Governing law: This Privacy Policy is governed by the laws of the State of California, United States, excluding its conflict-of-law rules.