Security
Last updated July 2026
Agenta connects to your inbox and calendar, so we treat that access as sensitive by default. This page describes what Agenta can and cannot do, and how your data is protected.
What Agenta can access
We request the narrowest scopes that make the product work, and no more:
- Mail, read plus send. Agenta reads messages to detect the requests aimed at you, and can send the emails you write in Agenta. It cannot delete or modify anything already in your mailbox. Sending is never automatic: you write or approve every message, confirm it, and it goes from your own address.
- Sending is opt-in per account. Permission to send is a separate grant. An inbox connected before sending existed stays read-only until you reconnect it, and Agenta tells you so rather than failing silently.
- Calendar, read plus create and edit events. Read access lets Agenta show your schedule alongside your tasks. Write access is used only to add or update events you ask it to create; it does not touch unrelated events.
No other Google, Microsoft, or Apple data is requested. Google and Microsoft show the exact permissions on their consent screens. Apple Calendar uses an app-specific password that can access iCloud Calendar without exposing your main Apple Account password.
When Agenta processes your mail
Free-plan task scans happen only when you press Scan. Paid plans may run the disclosed daily background scan, and connected messaging webhooks are processed when the provider delivers them. Opening Inbox fetches the mail you are about to read, which is the read your click asked for. Agenta does not run a hidden page-load scan.
AI sorting is off until you switch it on. Once enabled, it judges the messages your own keyword rules did not already decide, and caches that decision so each message is judged once rather than every time you open the page. Turning it off stops it entirely; your keyword rules keep working without sending anything to a model.
A task scan may also identify a short, durable fact that could improve future communication. It is stored as a reviewable suggestion with bounded evidence and does not influence a draft until you accept it. When drafting is enabled, Agenta can use the editable context for one recipient and the selected workspace. The composer shows what context was used and lets you turn saved context off for that draft. Person-specific context is not applied to group mail.
Credentials at rest
The provider tokens and Apple app-specific passwords that let Agenta reconnect are encrypted with AES-256-GCMbefore they are written to the database. The encryption key lives in the application environment, never in the database, so a database dump alone yields ciphertext only, not usable credentials.
In transit & isolation
All traffic is encrypted in transit over TLS. Stored tasks, updates, calendar data, relationship context, and context suggestions are protected by row-level access rules enforced in the database: a person only ever sees their own data, and a collaborator only sees what was explicitly shared with them. Isolation is enforced by policy, not by convention in application code.
Revoke and delete, any time
Disconnecting an account deletes Agenta's encrypted credential and cached calendar data. Google tokens are also revoked upstream when possible. Apple app-specific passwords can be revoked from Apple Account settings. You can review Google access from your Google account permissions, or manage Apple app-specific passwords at account.apple.com. To remove everything, delete your account and Agenta-owned data from Settings. See the Privacy Policy for what is stored and shared.
Reporting an issue
Found a vulnerability? Submit a Security report through the Contact page. Please avoid including live credentials or unnecessary personal data in your report.
Agenta is currently an alpha product and has not yet been independently audited. Avoid connecting regulated or business-critical accounts until that review is complete. This page is a description of current practices, not a contractual guarantee.