Privacy
Last updated 30 September 2026
Agent Graph is built to keep what it records to a minimum, and to keep it on your computer unless you choose to share it. This page says what the agent-graph command records, what this site (agentgraph.chofter.com) stores, who can see it, and how long it’s kept. The site is run by HumTech Ltd, in Ireland, which is the controller of the personal data it holds. For questions, email support@chofter.com.
On your computer
The agent-graph command records your AI coding agents’ sessions in ~/.agent-graph on your own computer. By default it keeps short labels (task names, agent descriptions, summaries of messages between agents), not your prompts, what tools return, or agents’ replies, unless you turn that on with AGENT_GRAPH_CAPTURE_BODIES=1. Recording sends nothing anywhere, and agent-graph view shows it on your computer only. Nothing reaches this site unless you paste or upload a log, or run agent-graph watch-remote.
Logs you share
- Pasted or uploaded logs can be opened by anyone who has their link, unless you set a password when you share one; then they need that too. The password is stored only as a scrypt hash.
- Live shares (
agent-graph watch-remote) belong to your account, and only you, logged in, can see them. - Every log is stored encrypted (AES-256-GCM, with a key of its own), under a name derived from its link, so the database holds neither the link nor the log in the clear.
- A log that has had no new events for a week is deleted, by a job that runs every day. A live share keeps only its most recent events (the site deletes older ones as new ones arrive).
Your account
You need an account only to share live. You log in with Google, or an email address and password, through Firebase Authentication (Google), which holds your login. This site stores, for your account:
- your email address, when the account was made, and when you last logged in and last shared live;
- which live share is your latest (encrypted);
- each computer you’ve logged in from with
agent-graph watch-remote: its name (the computer’s hostname), when it logged in and was last used, and a hash of its login (never the login itself). You can log any of them out on your account page; - whether you’re subscribed, if the site charges for sharing live (below).
While watch-remote is running it tells the site so every minute or so: which computer it’s on (its name), and a summary of each session it’s watching (its name, folder and state), so the home page and /watch can show them, from all your computers together. Like your logs, it’s stored encrypted.
Payments
Subscriptions are handled by Stripe. Your card details go to Stripe, never to this site. The site gives Stripe your email address and an account id, and keeps Stripe’s customer id, and your subscription’s plan, status and renewal or end date. Stripe’s own privacy policy covers what it does with your payment details.
Cookies and counting visits
- Logged in, the site sets a session cookie (
__session, for 14 days) and a cookie that just says you’re logged in, so pages can show the right links. Having opened a log with a password, a cookie remembers that for that log (for 30 days). - The site counts page views, visitors, downloads, sign-ups and live shares, as totals per day and per month, in its own database. It uses no analytics service and no tracking cookies, and stores no IP address, browser details or identifier with them: a visitor is counted using your browser’s own storage, which holds only the date of your last visit. Daily totals are deleted after a year.
- To limit password guessing, the site counts wrong guesses for a short while, by a keyed hash of your network address, not the address itself.
Who else handles it
- Vercel hosts the site.
- Google (Firebase and Google Cloud) holds accounts, logs and the site’s database, and serves downloads of the command.
- Stripe takes payments.
- The home page shows a video from YouTube (Google), from its privacy-enhanced domain: it sets no cookies until you play the video yourself, but your browser does fetch it from YouTube.
We don’t sell your data, share it with advertisers, or use it to train models. The site’s own admin pages show only totals (the counts above), and we don’t look at your logs or live shares.
Your choices
- Don’t share: everything stays on your computer.
- Log a computer out on your account page, or with
agent-graph watch-remote --logout. - Stop sharing live, and your share is deleted after a week without new events.
- Cancel a subscription from your account page.
- Delete your account, with your live shares and your computers’ logins, on your account page. It cancels any subscription too.
- To ask what we hold about you, email support@chofter.com from the address you log in with.
Your rights
Under data protection law (the GDPR) you can ask for a copy of the personal data we hold about you, have it corrected or deleted, object to or restrict how it’s used, and take it elsewhere. We use it to provide the service you’ve asked for (your account, your live shares, your subscription), to keep the site secure, and to count its use in aggregate. Email support@chofter.com, and we’ll reply within a week. If you’re not happy with how we handle it, you can complain to Ireland’s Data Protection Commission, at dataprotection.ie, or the authority where you live.
The services above may process data outside the European Economic Area (in the United States, say); where they do, it’s under the safeguards data protection law requires, such as the European Commission’s standard contractual clauses.
Changes
If this changes, we’ll update this page and the date at the top. Agent Graph is open source, so you can always check what it does: github.com/shaneosullivan/agent-graph.