Privacy Policy

Effective Date: August 12, 2026

TwelveAgents is a proprietary orchestration environment that brings twelve specialized AI agents together within a unified operating system for AI work.

TwelveAgents is a curated, integrated orchestration platform: one unified workspace where twelve specialized agents, each powered by a curated Agent Brain, get direct access to the tools, context, storage, execution environments, and workflow state needed to carry a task through to a finished, multi-step result. TwelveAgents' proprietary orchestration layer supplies that access — persona, tools, context, memory, and infrastructure — and each Agent Brain's own intelligence applies it to actually execute and complete the work, all within the same workspace, turn after turn.

The platform provides the agent personas, system instructions, tools, context management, storage, workflow state, execution environments, media processing, and consistency mechanisms that turn reasoning into completed, multi-step work. To perform specific capabilities, the orchestration layer may route requests through integrated AI model providers, cloud infrastructure, search services, media services, and execution environments, coordinated so they function as part of one unified experience.

TwelveAgents does not currently use customer data to train its own foundation models.


1. Information We Process

Depending on how you use TwelveAgents, we may process:

The information processed depends on the features, agents, models, tools, and services you choose to use.

1.1 Account Registration and Authentication

To create and maintain a TwelveAgents account, we may process:

TwelveAgents uses Amazon Cognito for account authentication and related identity-management functions.

Passwords, where used, are handled through the applicable authentication infrastructure and are not stored by TwelveAgents in plain text.

Amazon Cognito documents encryption of user-pool and identity-pool data at rest and requires TLS 1.2 or higher for network communications.

Amazon Cognito Data Protection Documentation

Amazon Cognito

1.2 Integrated Sign-In Services

Where TwelveAgents provides integrated sign-in options such as Google Sign-In or Sign in with Apple, the applicable provider may provide information necessary to authenticate and maintain your TwelveAgents account.

This may include:

TwelveAgents uses information necessary for account authentication and management. Information that is not required for these purposes is not intentionally retained by TwelveAgents.

For information about Google's privacy practices:

Google Privacy Policy

For information about Apple's Sign in with Apple privacy practices:

Sign in with Apple & Privacy

1.3 Prompts, Conversations, and Context

Depending on your use of the Services, we may process:

1.4 Files and Media

If you use features that support files or media, we may process:

Files may be transmitted to integrated AI, media, search, storage, or execution providers when necessary to perform the requested capability.

1.5 Generated Content

We may process and store content generated through the Services, including:

1.6 Purchases and Credits

Depending on the platform and payment method used, we may process:

Payment information such as full payment-card numbers is generally processed by the applicable platform or payment provider rather than stored directly by TwelveAgents.

1.7 Technical and Security Information

We may process technical information reasonably necessary to operate, secure, troubleshoot, and maintain the Services, including:

We do not use technical information for behavioral advertising or user profiling.


2. How We Use Your Information

We use information primarily to:

We do not use your information for:

We do not sell your personal information.


3. AI Model Providers and Integrated Services

The TwelveAgents orchestration layer provides the agent personas, system instructions, tools, context management, storage, workflow state, execution environments, media processing, and consistency mechanisms that turn reasoning into completed work. Certain capabilities are performed by routing requests through integrated AI models, specialized AI services, search services, cloud infrastructure, and execution environments, coordinated so they operate as part of one unified experience.

Depending on the agent, Agent Brain, tools, and capabilities selected, information may be processed by integrated providers such as:

The applicable provider receives the information required to perform the specific request or capability.

For example, a request involving an AI model may transmit the relevant prompt and context to the selected model provider. A voice-generation request may transmit relevant text or audio to the applicable voice provider. A web-search request may transmit the search query to the selected search provider. A code-execution request may transmit the required code, files, and inputs to the configured execution provider.

TwelveAgents coordinates these interactions but does not control the independent data-processing practices of integrated providers.

Integrated providers process information under their applicable terms, privacy policies, API agreements, and data-use practices.

TwelveAgents uses applicable API, account, and configuration controls available for the services it operates.


4. AI Model Training

4.1 Does TwelveAgents Use My Data to Train TwelveAgents Models?

TwelveAgents focuses on orchestrating and augmenting AI models rather than training its own foundation models.

Your data is processed to provide the capabilities and Services you request and is not currently used by TwelveAgents to train TwelveAgents foundation models.

TwelveAgents provides the surrounding intelligence and infrastructure that enables different AI models and services to operate as part of a consistent system, including:

If TwelveAgents introduces a future feature that uses customer data to train or improve a TwelveAgents model, that use will be clearly disclosed and, where consent is legally required or otherwise provided as part of the feature, will require your explicit consent before your data is used for that purpose.

4.2 AI Model Providers

TwelveAgents uses paid API and cloud services from AI model providers and specialized services.

Where the applicable provider's API or service terms state that customer inputs and outputs are not used to train or improve its underlying models, TwelveAgents relies on those applicable terms.

Where a provider offers account-level or API-level controls that restrict training or model-improvement use, TwelveAgents configures and uses those controls where available and applicable to the services configured for TwelveAgents.

For example, TwelveAgents has configured the applicable account or API controls available for ElevenLabs and Stability AI to disable training where supported by those services.

For providers or services where data-use practices depend on the applicable API, account, service, model, or processing mode, TwelveAgents does not make a broader representation than the provider's applicable terms and configuration support.

Provider policies, available controls, models, APIs, and service configurations may change over time. TwelveAgents will continue to use applicable controls and configurations available to the platform as those services evolve.


5. AI Provider Data & Training Overview

The TwelveAgents orchestration layer connects multiple AI model providers and specialized services. The applicable Agent Brain, media service, search service, or other provider processes the information required for the capability being used.

Provider Services Used TwelveAgents Position
OpenAI GPT models through API services OpenAI states that, by default, inputs and outputs submitted through its API platform are not used to train or improve its models. TwelveAgents relies on the applicable OpenAI API terms and configuration.
Google Cloud / Vertex AI Multiple AI services Google Cloud's applicable privacy commitments and service terms govern customer data. TwelveAgents relies on the applicable Google Cloud / Vertex AI terms and configuration.
AWS / Amazon Bedrock Multiple AI services Amazon Bedrock's applicable data-protection and service terms govern customer inputs and outputs. TwelveAgents relies on the applicable AWS / Bedrock terms and configuration.
ElevenLabs Media AI services TwelveAgents configures the applicable account or service controls to disable training where supported by the ElevenLabs service and account configuration.
Stability AI Media AI services TwelveAgents configures the applicable Platform API training opt-out where supported. Stability AI documents an account-level Platform API training control.
Runway Media AI services Runway processes requests according to the applicable API, service, model, and data-use terms. TwelveAgents does not represent that Enterprise-level protections apply unless separately contracted.

Provider policies, terms, available controls, and service configurations may change over time. The applicable provider's current documentation and contractual terms govern that provider's processing of information.

TwelveAgents configures available account-level and API-level data-use controls where applicable to the services it uses.

Provider Documentation


6. Web Search

TwelveAgents may route web searches through the Brave Search API.

Brave operates its own independent web index and describes Brave Search as a privacy-focused search service.

For the Brave Search API specifically, Brave states that a record of search queries submitted through a customer's Search API account may be retained for a maximum of 90 days, including for billing and troubleshooting purposes, subject to its legal obligations.

Accordingly, users should not assume that a web-search request made through TwelveAgents is automatically zero-retention.

Information necessary to perform a search may be transmitted to Brave.

Brave's applicable terms and privacy documentation govern information processed through its service.

Brave Search API Privacy Notice

Brave Search API Terms of Use


7. Code Execution

Some TwelveAgents agents may execute code in an isolated execution environment when a task requires it.

Where enabled, code execution may use E2B or another execution infrastructure provider configured for the relevant capability.

Information necessary to execute the requested code may be transmitted to the applicable execution provider. This may include:

Where E2B is used, execution takes place within an isolated Firecracker microVM environment designed to provide a security boundary between the code being executed and the surrounding infrastructure.

Execution environments are designed to be isolated and may be ephemeral, subject to the capabilities and configuration of the underlying provider.

This provides an important isolation layer, but no execution environment can guarantee absolute security.

Users should avoid providing highly sensitive information to code-execution environments unless that information is necessary for the requested task.

The applicable E2B terms, privacy policy, and security documentation govern information processed by E2B.

E2B Privacy Policy

E2B official website


8. Prompt Protection

TwelveAgents includes an optional, on-device sensitive-data redaction feature called Prompt Protection.

When enabled, content pasted into a chat is scanned locally for supported sensitive-data patterns before submission.

Depending on the selected protection level, the system may detect patterns such as:

The scan occurs locally on the device. The content is not uploaded to a remote service solely to perform this local detection.

Prompt Protection is a pattern-based safeguard and is not a guarantee that every sensitive item will be detected.

Users remain responsible for reviewing information before submitting it to an AI provider or other integrated service.


9. Storage

9.1 Local Storage

TwelveAgents may maintain supported conversation history locally on the device where the conversation was created.

Local application data is stored using the application's configured local-storage and encryption mechanisms.

9.2 Cloud Storage

TwelveAgents also stores certain information server-side to provide functionality such as:

Cloud storage is not intended to represent a complete mirror of every piece of locally stored application data.

Each account is subject to a cloud storage allowance and a maximum number of active chat rooms, as described in the App or applicable documentation.

9.3 Files

Uploaded and generated files may include images, audio, video, documents, and other supported formats.

Files are stored in cloud infrastructure so that the Services can process and retrieve them when required.

Generated media retention: AI-generated media is retained on TwelveAgents' servers for 7 days from the date of generation. This limit exists mainly to keep recent conversation context manageable, ensuring that media associated with your recent chats stays readily accessible for that period. After 7 days, the server copy is automatically removed, regardless of subscription tier. If you wish to edit, update, or perform any further action on generated media after this period, you will need to re-upload it from your local copy for processing or analysis. We recommend downloading any media you wish to keep to your device before it expires — once downloaded, it remains on your local storage and is unaffected by server-side deletion.

Storage-based media cleanup: If your account's cloud storage usage reaches its allowance before the 7-day period has elapsed, TwelveAgents may automatically remove media files from your oldest chat rooms to free up space, so that new generation requests are not interrupted. This process removes stored media only — the text-based conversation history of the affected chat rooms is not deleted by this process. As with standard 7-day expiry, we recommend downloading media you wish to keep before your storage usage approaches the limit.

Deleting a chat is intended to remove its associated files from active TwelveAgents storage, subject to applicable deletion processes, backups, legal requirements, and security retention requirements.


10. Data Security

TwelveAgents uses reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction.

Depending on the feature, these measures may include:

However, no method of transmission, storage, or processing can be guaranteed to be completely secure.

Amazon Cognito Data Protection Documentation


11. Data Retention

We retain information for as long as reasonably necessary to:

Retention periods vary depending on the type of information and how it is used.

Information transmitted to integrated providers is subject to the applicable provider's retention policies and terms.

Integrated services may retain limited information for security, abuse prevention, troubleshooting, billing, or other legitimate operational purposes even after a TwelveAgents request has completed.

Where available and applicable, TwelveAgents uses provider controls designed to limit unnecessary retention.


12. Account Deletion

You may delete your TwelveAgents account through the available account-management controls.

Account deletion is intended to remove associated information from active TwelveAgents systems.

Depending on the nature of the information, deletion may include:

Certain information may remain temporarily in backups or be retained where required for:

Integrated providers may have separate retention schedules for information processed through their services.

Deleting your TwelveAgents account does not necessarily cause integrated providers to immediately delete information already processed by them. Their applicable retention and deletion policies govern such information.


13. Purchases and Payments

Credits, subscriptions, or other purchases may be processed through supported platform stores or payment providers, such as:

Payment information is generally processed by the applicable platform rather than being stored directly by TwelveAgents.

Purchase and transaction information may be retained as necessary for:

Integrated payment providers operate under their own privacy policies and terms.


14. Children's Privacy

TwelveAgents requires all users to be at least 18 years old, or the minimum age required to consent to use the Services in their jurisdiction, whichever is higher, as set out in our Terms & Conditions.

TwelveAgents is not directed at, and is not intended for use by, children.

We do not knowingly collect personal information from anyone below this minimum age.

If we become aware that we have collected personal information from someone below this minimum age, we will take reasonable steps to delete that information and, where applicable, suspend or terminate the associated account.


15. Integrated Services

TwelveAgents integrate multiple services to provide certain capabilities.

These may include:

Amazon Cognito

Account authentication and related identity-management services.

Amazon Cognito

Amazon Cognito Data Protection Documentation

Amazon Web Services / AWS

Cloud infrastructure and other backend services used by TwelveAgents.

AWS Privacy Notice

OpenAI

AI model and API services.

OpenAI Business Data Privacy

Google Cloud / Vertex AI

Gemini and other AI services.

Google Cloud Privacy Resource Center

Google Cloud Generative AI Data Governance

Amazon Bedrock

Foundation-model and AI services.

Amazon Bedrock Data Protection

ElevenLabs

Media-generation.

ElevenLabs Privacy Policy

ElevenLabs Zero Retention Mode

Stability AI

Media-generation.

Stability AI Privacy Center

Stability AI Platform API Training Opt-Out

Runway

Media-generation.

Runway Privacy Policy

Brave Search

Web-search services.

Brave Search API Privacy Notice

Brave Search API Terms of Use

E2B

Code-execution infrastructure where enabled.

E2B Privacy Policy

These providers receive information only as necessary for the capabilities in which they participate.

TwelveAgents does not control integrated providers and cannot independently guarantee their privacy, security, retention, or data-handling practices.


16. International Data Processing

Because TwelveAgents uses international cloud, AI, search, media, payment, and execution infrastructure, information may be processed or stored in countries other than the country where you live.

These countries may have data-protection laws that differ from those in your country.

Where required by applicable law, TwelveAgents will take appropriate steps concerning international transfers of personal information.


17. Your Privacy Rights

Depending on your location and applicable law, you may have rights concerning your personal information.

These may include:

The availability and scope of these rights depend on applicable law.

Exercising Your Rights

To exercise applicable privacy rights or ask questions about our privacy practices, contact:

Email: support@twelveagents.ai

We may need to verify your identity before processing certain requests.

We will respond within the period required by applicable law.


18. Your Choices

Depending on the features available in your version of TwelveAgents, you may be able to:

Some processing is necessary to provide a requested feature and cannot be disabled while that feature is being used.

For example, selecting an integrated AI model necessarily requires the relevant information to be transmitted to that provider so that the requested capability can be performed.


19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

When we make material changes, we may update the "Last Updated" date and provide additional notice where appropriate.

Your continued use of the Services after an updated Privacy Policy becomes effective constitutes acceptance to the extent permitted by applicable law.


20. Contact

If you have questions about this Privacy Policy, our privacy practices, or how TwelveAgents processes information, contact:

Email: support@twelveagents.ai

Website: twelveagents.ai

We will respond to privacy inquiries within the period required by applicable law.


Important References

The following are the principal integrated providers and official documentation relevant to TwelveAgents' authentication, AI processing, search, execution, privacy, security, and data-use practices:

Integrated services policies, terms, models, APIs, retention practices, security practices, and available controls may change independently of TwelveAgents. The applicable provider's current documentation and contractual terms govern that provider's processing of information.


Last updated August 12, 2026.