Privacy Policy

Last Updated: July 1, 2026

Introduction

This Privacy Policy explains how ArchaeoMind Ltd., an Israeli company operating Agent Bayes, handles personal information in connection with the Services available at https://agentbayes.com, https://app.agentbayes.com, related subdomains, APIs, public share pages, and integrations, including the Zotero integration.

Agent Bayes began as an invite-only private beta. We may provision accounts manually, allow self-service registration with email and password, or use other account access methods we make available. We also operate waiting-list and launch-update forms on the marketing website for people who want to request an invitation or receive updates.

For convenience, we use the term "personal information" to mean information that identifies you or can reasonably be linked to you. "Research content" means the documents, text, citations, metadata, annotations, mindmaps, images, prompts, instructions, conversations, and other material you upload, sync, create, or generate inside Agent Bayes.

This Privacy Policy is incorporated by reference into the Agent Bayes Terms of Use at https://agentbayes.com/terms and should be read together with it. If you do not agree with this Privacy Policy, please do not use the Services.

1. Scope, Roles, and Beta Status

This Policy applies to:

  • The marketing website.
  • The authenticated web application.
  • Public mindmap share pages.
  • The API.
  • Emails we send about account access, password resets, beta updates, product updates, billing, security, or service notices.
  • The Zotero integration and other integrations you choose to use with the Services.

Agent Bayes acts as a controller, or similar role under applicable law, for information we use to operate our business and administer the Services. This includes website visitor information, waiting-list requests, account information, authentication records, payment and subscription records, security logs, support communications, and communications preferences.

For research content that you upload, sync, or create inside the Services, Agent Bayes primarily processes that content on your instructions to provide the product functions you request. If you use Agent Bayes on behalf of an organization, institution, research group, or other controller, that organization controls the content and is responsible for providing any required privacy notices, establishing a lawful basis, and handling certain rights requests. If you use Agent Bayes as an individual for your own research, you are the controller of the content you supply and are responsible for the lawful basis for it. In both cases the responsibility for any personal information inside your research content rests with you or your organization, not with Agent Bayes.

Because the Services are in private beta, features and data flows may change. If we make a material change to this Policy, we will update this page and, where appropriate, notify affected users.

2. Information We Collect

2.1. Information You Provide Directly

We may collect information you give us directly, including:

  • Waiting-list and launch-update information, such as full name, email address, role, institution or organization, use case, and marketing preferences.
  • Account information, such as first name, last name, username, email address, password, and password setup or reset information. Passwords are stored only in hashed form.
  • Research workspace information, such as project names and descriptions, knowledge base names and descriptions, document metadata, document tags, labels, bookmarks, annotations, uploaded images, citations, manual citations, mindmap content, public share titles and descriptions, custom instructions, conversation messages, and other edits you make within the Services.
  • Documents and files you upload or sync, including PDFs, images, bibliographic metadata, source metadata, and content imported through integrations such as the Zotero plugin.
  • API access information, such as API key names, expiry settings, revocation records, integration status, and related usage metadata. Full API keys are shown once and are not intended to be recoverable later.
  • Billing and subscription information, such as plan, subscription status, entitlements, credit grants, credit reservations, credit usage ledger entries, credit-adjustment records, payment and refund event records, operation types, timestamps, and payment status. We use PayPal as our payment processor. Payment card and funding details are handled by PayPal rather than by Agent Bayes directly, and we receive subscription and payment status information from PayPal rather than your payment credentials.
  • Communications and feedback, such as emails you send us, support requests, bug reports, beta feedback, and responses to product or research questions.

2.2. Information We Generate or Observe When You Use the Services

We may collect or generate operational information such as:

  • Login and account events, including last login time, token refresh events, password setup and reset events, account status, marketing opt-out events, and account deletion or restoration requests.
  • Research activity records, such as project and knowledge base assignments, mindmap version history, node provenance, edit history, conversation history, citation associations, AI verification runs, labels, annotation history, translation requests, terminology graph builds, and credit ledger entries.
  • Document processing metadata, such as content hashes, file names, file size, page count, processing status, chunking status, indexing status, OCR status, generated summaries, extracted terms, embeddings, timestamps, and derived metadata needed to run the Services.
  • Public share records, such as share slug, share status, publication time, revocation status, owner display name, public title, public description, public node tree, public citation references, public image URLs, and share payload metadata.
  • Technical information, such as IP address, user agent, request metadata, timestamps, browser type, device information, referrer URL, page URL, error logs, performance records, security logs, and abuse-prevention or debugging records.
  • Analytics information from the marketing website, such as page views, approximate location derived from IP address, device and browser information, traffic source, and interactions measured through Google Analytics.

We collect this information to operate the Services, secure accounts, debug failures, prevent abuse, maintain product state, support provenance and history features, administer subscriptions and credits, and understand how the marketing website is used.

2.3. Information Stored in Your Browser

The Services use browser storage for product functionality.

On the marketing website, we use local browser storage to remember limited client-side preferences or states, such as theme preference and whether the waiting-list form has already been submitted from that browser.

In the authenticated web application, we store access tokens, refresh tokens, basic account state, your preference for staying signed in, where to send you after sign-in, session timing data, theme preference, and selected client-side cache entries in local storage or session storage. If you disable browser storage, parts of the Services may not work correctly.

2.4. Information From Integrations

If you use the Zotero integration or another integration we make available, we may receive the content and metadata you choose to sync into Agent Bayes. This can include bibliographic metadata, Zotero item identifiers, selected PDF attachments, file metadata, sync status, orphaned-item status, and metadata conflict decisions.

The Zotero integration uses an Agent Bayes API key that you create and control. You can revoke the API key from your account settings.

3. How We Use Information

We may use personal information to:

  • Provide, maintain, secure, and improve the Services.
  • Provision invite-only beta accounts, support self-service registration, and support password setup, login, token refresh, account recovery, account deletion, and account restoration.
  • Operate research features, including document upload, Zotero sync, OCR, layout-aware extraction, semantic chunking, embedding generation, indexing, semantic search, citation tracking, PDF reading, annotations, labels, terminology graphs, translation, citation verification, mindmap editing, mindmap history, public sharing, and agent-assisted synthesis.
  • Generate and maintain bibliographic records, provenance links, citation references, confidence scores, version history, audit trails, and workspace history.
  • Provide API access, authenticate integrations, track API key lifecycle, and prevent unauthorized access.
  • Administer plans, subscriptions, entitlements, credits, reservations, usage history, invoices, receipts, payments, refunds, taxes, and related account status.
  • Send transactional emails, such as password setup, password reset, account access, account deletion, inactivity, billing, security, or service notices.
  • Send beta updates, product updates, launch updates, research updates, or other marketing communications where you have opted in or where the law otherwise permits, until you unsubscribe.
  • Respond to support requests, diagnose problems, resolve bugs, and process feedback.
  • Detect, investigate, and prevent abuse, security incidents, fraud, unauthorized access, scraping, excessive load, and violations of the Terms of Use.
  • Comply with legal obligations, preserve legal rights, enforce agreements, and respond to lawful requests.
  • Analyze marketing website performance and improve website content, onboarding, reliability, and product development.

Where applicable privacy law requires a legal basis, we rely on one or more of the following:

  • Contract necessity, when processing is needed to provide the Services, authenticate users, operate requested product features, respond to waiting-list and launch-update requests you submit to us, administer accounts, or deliver support.
  • Legitimate interests, when processing is reasonably needed for security, abuse prevention, service improvement, beta administration, product development, communications, and legal protection.
  • Consent, when you opt into marketing or launch communications, enable analytics cookies on the marketing website, choose an integration, publish a public share, or where consent is otherwise required.
  • Legal obligation, when processing is needed to comply with law, tax, accounting, legal process, or regulatory requirements.
  • Your instructions or the instructions of your organization, where Agent Bayes processes research content on behalf of a user, institution, organization, or other controller.

You may withdraw consent where processing depends on consent. Withdrawal does not affect processing that happened before the withdrawal.

5. AI Processing and Research Content

Agent Bayes is a research system. If you upload documents, sync from Zotero, create mindmaps, run semantic searches, verify citations, translate passages, generate terminology graphs, or ask the agent to synthesize material, your research content may be processed by automated systems and external model providers as needed to perform those functions.

This can include OCR, layout-aware extraction, semantic chunking, context rebuilding, idea and claim extraction, key term extraction, embedding generation, vector search, retrieval, summarization, translation, citation verification, confidence scoring, conversation compaction, response generation, and public share payload generation.

Current AI processing uses OpenAI for model, embedding, vision, and related AI processing. We also use Amazon Web Services for infrastructure or data processing. If additional model providers become available, the Services may send the content needed for the selected operation to those providers. When we add or change a model provider, we update the list in this Policy, and we select providers and configure them with the goal that your research content is not used to train their models.

We treat your research content as confidential. We do not use your research content for advertising or cross-context behavioral profiling. We do not use your research content to train our own general-purpose foundation models, and we do not use one user's research content to build, train, or improve models or features that expose that content to other users. Based on the OpenAI API terms and product controls we use, OpenAI does not use your API inputs or outputs to train its models. Your uploaded files and the indexes, embeddings, summaries, and other data derived from them are access-controlled to your account and are not shared with other users' workspaces. We use your research content only to carry out the operations you request, and to provide, secure, and support the specific features you are using.

Agent Bayes may store AI inputs, outputs, extracted text, citations, chunks, embeddings, generated summaries, term graphs, conversation history, verification results, and other derived data so that your workspace, search, citations, provenance, history, and audit features continue to work.

Human access to research content is limited to circumstances where it is reasonably needed, such as support, debugging, security, abuse investigation, legal compliance, or with your permission. Any such access is limited to authorized personnel and is subject to our internal access controls. We do not read your private research content for casual monitoring.

6. Public Shares and User-Directed Disclosure

If you publish a mindmap through the public sharing feature, the shared page may be available to anyone with the link and may be discoverable through search engines or other public indexing.

You control whether to publish or revoke a public share. Public shares are user-directed disclosures. If you include personal information about yourself or another person in a shared mindmap, that information may become public. You should not include personal information, sensitive information, confidential information, private research-subject information, or information about another person in a public share unless you have the right to do so and the disclosure is appropriate.

A public share may include:

  • The mindmap title and description.
  • Your owner display name.
  • Published date.
  • Node text, hierarchy, styles, collapsed state, confidence scores, and manual citations.
  • Public citation labels, bibliographic references, and page ranges.
  • Public image URLs for images included in shared nodes.
  • Share statistics such as node count, source count, and citation count.

Public shares are generated from an allowlist of fields and do not intentionally include private conversation history, full uploaded PDF content, private API keys, private account details, or private workspace metadata beyond the public payload described above.

If you revoke a public share, the public endpoint stops serving it. Copies, previews, caches, snippets, screenshots, search-engine records, or other records created before revocation may remain outside our control and may appear as stale entries after the share is unavailable.

7. How We Share Information

We do not sell your personal information.

We may share information only in the following circumstances:

  • With infrastructure and software providers that help us operate the Services, such as cloud hosting, object storage, database, vector database, workflow orchestration, email delivery, logging, security, and website analytics providers.
  • With AI and model providers, including OpenAI, when needed to perform OCR, embeddings, retrieval, synthesis, translation, verification, compaction, or other AI functions you request.
  • With integrations you choose to use, to the extent needed to complete the action you requested.
  • With PayPal, our payment processor, if paid subscriptions, refunds, disputes, or payment collection require it.
  • With service providers, contractors, advisors, or support personnel helping us support, secure, operate, or maintain the Services under appropriate confidentiality or data-protection obligations.
  • With other people when you choose to publish or share content, including through public mindmap share pages.
  • With an organization, institution, administrator, or research group if your account or content is provided through that organization and the organization controls or administers the workspace.
  • With law enforcement, regulators, courts, or other third parties when required to comply with applicable law, legal process, or a valid governmental request.
  • When reasonably necessary to investigate abuse, enforce the Terms of Use, protect the security or integrity of the Services, or protect users or the public from harm.
  • In connection with a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to appropriate protections.

Current external provider categories include OpenAI for model, embedding, vision, and related AI processing, Amazon Web Services for cloud infrastructure, object storage, email delivery, and data processing, PayPal for payment processing, and Google Analytics for marketing website analytics.

8. Cookies, Analytics, and Similar Technologies

The marketing website uses Google Analytics through the Google tag script to understand website traffic, page views, source attribution, device information, approximate location, and website performance. Google Analytics may set or read cookies and similar identifiers, and Google may process information according to its own policies.

We rely on your consent as the legal basis for these analytics cookies and the related processing. Google Analytics is provided by Google LLC, which is based in the United States, so enabling analytics involves transferring website usage data to the United States. Google LLC self-certifies under the EU-US Data Privacy Framework, and Google also offers standard contractual clauses for international transfers. You can withdraw consent at any time through the "Cookie Preferences" link in the website footer, which stops further analytics collection and clears the analytics cookies.

To remember your cookie choices, our consent banner sets one strictly necessary first-party cookie. It does not track you and cannot be turned off:

CookieProviderDurationPurpose
cc_cookieAgent Bayes6 monthsRemembers your cookie preferences

Analytics cookies are loaded only after you consent through our cookie banner, and they are cleared if you withdraw consent. The analytics cookies we use are:

CookieProviderDurationPurpose
_gaGoogle6 monthsClient identifier
_ga_TEBEC8EE37Google6 monthsSession state

The Services are not operated as an advertising-supported site. We do not intentionally use advertising pixels, third-party advertising cookies, Google AdSense, session replay tools, or cross-context behavioral advertising.

The authenticated product relies primarily on browser storage rather than login cookies for authenticated web sessions. Some technically necessary cookies, headers, or similar identifiers may still be created by browsers, hosting providers, analytics scripts, security tools, or future service components.

You can clear cookies, local storage, and session storage through your browser settings. Doing so may sign you out, remove local preferences, clear local submission markers, or reduce functionality. You may also use browser tools or extensions to limit analytics, although some features may behave differently.

9. Retention and Deletion

We keep personal information for different periods depending on what it is and why we need it.

  • Waiting-list and launch-update requests are kept while the relevant invitation cycle, beta outreach, or launch communication remains active, unless you ask us to delete them earlier or unsubscribe from future outreach. We aim to delete or anonymize unused waiting-list submissions within 12 months if the person has not been invited to or onboarded onto the Services.
  • Account information is kept while your account is active.
  • A live subscription blocks an account deletion request. Cancel the subscription before requesting deletion. An eligible account enters a pending-deletion state for 14 days so you can restore it. If a subscription becomes live during that period, permanent deletion is canceled, the account is restored to active, and billing remains unchanged. Otherwise, after the pending-deletion period we aim to delete or de-identify account data from active systems, except where we need limited records for security, abuse prevention, audit integrity, billing, tax, legal compliance, dispute resolution, or enforcement.
  • Research workspace data, uploaded files, derived indexes, embeddings, citations, labels, annotations, images, terminology graphs, mindmap history, public share payloads, and conversation history are generally retained until you delete them, your account is deleted, or the private beta is discontinued.
  • Public shares are retained while active. Revoked shares are no longer served through the public endpoint, but related records may be retained as needed for security, audit, debugging, or legal reasons.
  • Password reset data is short-lived. Reset links are issued with a short validity period, and current reset emails state a 15-minute expiry window.
  • API key records are kept until they expire, are revoked, or are no longer needed for security, audit, and abuse-prevention purposes.
  • Credit ledger, subscription, payment event, refund, and credit-adjustment records are kept for as long as needed for account administration, accounting, tax, fraud prevention, dispute resolution, and legal compliance. When an account is permanently deleted, credit ledger and payment event records are retained for these purposes with a minimal identifying snapshot, while the account's subscription linkage records are deleted. PayPal keeps its own transaction records under its policies.
  • Operational logs and technical diagnostics are retained only for as long as reasonably needed for security, debugging, abuse prevention, and service reliability.
  • Backups and cached copies may persist for a limited period after deletion from active systems. We delete or overwrite them according to our backup lifecycle and operational needs.

If the private beta is discontinued, we will try to give users reasonable notice and an opportunity to export their data when practical. Because this is a private beta, we do not promise indefinite retention or uninterrupted availability.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information. Connections to the Services are encrypted in transit using TLS, and uploaded files and stored data reside on encrypted storage at rest. Uploaded files and their derived data are access-controlled to each account through ownership checks rather than shared across users, and the object storage holding uploaded files and images is configured to block public access. Our measures also include access controls, password hashing, signed tokens, API key revocation, separation between authenticated and public endpoints, user and resource ownership checks, private cloud infrastructure, logging, monitoring, and limited staff access.

No internet, AI, or storage system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your password, API keys, devices, Zotero environment, and browser sessions. Do not paste API keys into shared documents or send them to untrusted recipients.

If we become aware of a data breach affecting personal information, we will investigate it and take reasonable steps to contain and remediate it. We will notify affected users and the relevant authorities without undue delay where applicable law requires. Even where notice is not legally required, we may still tell you about an incident that affects you when we believe that is the right thing to do.

11. Your Choices and Rights

Depending on your relationship with the Services and applicable law, you may have the ability to:

  • Access, correct, update, or request a copy of certain account information or personal information we hold about you.
  • Request deletion of your account or other personal information.
  • Ask us to restrict or object to certain processing.
  • Request portability of information you provided to us, where technically feasible and legally required.
  • Withdraw consent where processing depends on consent.
  • Unsubscribe from marketing emails using the unsubscribe link or by contacting us.
  • Revoke API keys and integrations from account settings.
  • Delete or remove projects, knowledge bases, documents, mindmaps, labels, annotations, images, and public shares through available product controls where supported.

Some requests may be limited where we need to protect other users, preserve security, prevent fraud or abuse, keep required records, complete transactions, comply with law, or maintain the integrity of research history, citations, provenance, public shares, billing records, and audit trails.

If your account or research content is administered by an organization, institution, research group, or other controller, we may direct your request to that organization or need its instructions before acting.

We do not offer a general privacy-controls page at a public settings URL. For privacy requests, contact us at contact@agentbayes.com, and we will respond within a reasonable time. Institutional users with specific data-protection requirements are welcome to contact us to discuss them.

We do not sell personal information or use it for cross-context behavioral advertising. Agent Bayes does not respond to browser "Do Not Track" signals.

12. Regional Privacy Notices

If you are in the European Economic Area, the United Kingdom, Switzerland, Israel, California, or another region with privacy rights, you may have additional rights under applicable law. These may include rights to know, access, correct, delete, port, restrict, object, withdraw consent, and complain to a privacy regulator.

California residents may have rights to know categories of personal information collected, sources, purposes, categories of recipients, retention periods, and rights to access, delete, correct, and opt out of certain sales or sharing. We do not knowingly sell personal information or use it for cross-context behavioral advertising.

We do not knowingly collect sensitive personal information for purposes of inferring characteristics. Agent Bayes does not need special category data, as defined in Article 9 of the GDPR, to provide the Services, and we do not rely on any Article 9 condition to process it. You must not upload special category data, criminal-offence data, personal information about other people, confidential information, or other regulated information unless you are the controller of that data, you have your own lawful basis for it, and the upload is appropriate for your research use. Where you provide such content, you remain responsible for the lawful basis and any required notices or consents.

To exercise rights, contact us at contact@agentbayes.com. We may need to verify your identity and may ask for information needed to locate your account or request.

13. International Processing

Agent Bayes is operated by ArchaeoMind Ltd. from Israel. Personal information may be processed in Israel, the United States, and other countries where our infrastructure, service providers, payment providers, identity providers, model providers, analytics providers, or support providers operate.

Our production cloud infrastructure is currently configured in the AWS us-east-1 region in Northern Virginia. Some processing may occur outside those locations when a service provider, payment provider, identity provider, model provider, analytics provider, email provider, integration, or user action requires it.

Where cross-border transfers are involved, we aim to use reasonable contractual, technical, and operational safeguards appropriate to the circumstances and required by applicable law. Several of our main service providers, including OpenAI, Amazon Web Services, and Google, offer standard contractual clauses or operate under recognized data transfer frameworks as part of their terms.

14. Children

The Services are intended for adults. You may not use the Services if you are under 18 years old. If we learn that we have collected personal information from a child under 18, we will take reasonable steps to delete it.

Agent Bayes is not designed as a school-directed service for children, and it should not be used to collect student records from minors unless Agent Bayes has separately agreed to appropriate terms.

The Services may link to third-party websites, academic publishers, Zotero, payment processors, model providers, analytics providers, repositories, journals, libraries, or other services that we do not control. Their privacy practices are governed by their own policies, not this one. If you follow those links or use those services, you do so subject to their terms and policies.

16. Changes to This Policy

We may update this Privacy Policy from time to time, especially as the private beta evolves. When we make material changes, we will update the "Last Updated" date above and may provide notice through the Services, by email, or through another reasonable method where appropriate.

17. Contact

If you have questions, requests, or concerns about this Privacy Policy or our handling of personal information, contact us at contact@agentbayes.com.