Skip to content

Afora Privacy Policy

Effective date: July 10, 2026 · Last updated: August 29, 2026

Afora LLC ("Afora," "we," "us") provides a hosted personal AI agent: your own agent, running around the clock on its own dedicated instance, that you reach from a browser console and the Afora Mac app, and that runs on the AI subscription you already have (Anthropic Claude or OpenAI ChatGPT). This policy explains what data we handle, how we use it, and the choices you have. It is written to be read; if anything is unclear, email privacy@aforademo.com and we will answer plainly.

This policy is incorporated into our Terms of Service. Our Security page describes how we protect data; our Subprocessor list names every vendor that touches customer data.

1. What Afora is, in data terms

When you subscribe, we provision an agent instance for you: an isolated environment on infrastructure we operate, with its own workspace. Your conversations with your agent, the files in its workspace, its memory, and its activity all live on that instance. The web app at aforademo.com is the front door — signup, billing, and the handoff into your console.

You are our customer directly. If you use Afora inside a company, your use may also be governed by your company's own policies; data your agent touches in accounts you connect (for example, your email) remains governed by your relationship with those account providers.

2. Information we collect

CategoryExamplesSource
Account & contact dataName, email, authentication identifiersYou, via signup (authentication is provided by Clerk)
Billing dataSubscription status, invoices; card details stay with StripeYou, via checkout (Stripe)
AI provider sign-inAn access token for the Claude or ChatGPT account you connect (never your password)You, via your provider's own sign-in flow
Agent workspace dataYour conversations with your agent, files in its workspace, its memory and task stateYou and your agent, on your instance
Connected accountsOAuth tokens and the data your agent accesses in services you choose to connect (for example GitHub, Google, Microsoft, Slack, Linear, Telegram)The services you connect, only after you authorize them
Usage & log dataPages viewed, actions taken, device/browser type, IP address, error logsAutomatic

We do not collect: passwords for your AI provider or connected accounts (sign-in happens with the provider and we receive only a token), biometric data, precise geolocation, or data about children. Afora is not directed at anyone under 18.

3. How we use information

We use data only to provide and secure the service:

We do not use your data for advertising of any kind, and we do not sell personal information — to anyone, for anything.

4. Artificial intelligence — your own subscription

This is the most important section of this policy, because it is different from most AI products: your agent thinks with the AI subscription you connect — your Anthropic Claude account or your OpenAI ChatGPT account (or an Anthropic API key you provide).

5. Connected accounts — Google and Microsoft commitments

Connecting any outside account is optional and uses OAuth: you grant access from the provider's own consent screen, and you can revoke it at any time from the provider's security settings or from within Afora.

Google. Afora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

Microsoft. We apply the same commitments to Microsoft 365 / Outlook data accessed through Microsoft Graph: minimum necessary permissions, no advertising or marketing use, no use outside the permissions you granted, and retention and deletion per Section 8.

Other connections (for example GitHub, Slack, Linear, Telegram) follow the same pattern: your agent accesses them only with the token you granted, only to do the work you direct, and you can disconnect at any time.

6. Your agent acts for you

Afora is an agent, not just a chat window: when you direct it to (and within the connections you have granted), it can send messages, edit files, and act in your connected accounts. Content it produces and actions it takes are attributed to you. The console shows its activity; review what matters. Content your agent encounters in the outside world (web pages, inbound messages) is treated as data, and manipulation attempts (prompt injection) are a threat we design against — see the Security page.

7. When we share information

We share personal information only with:

We never sell or rent personal information, and we never share it with data brokers or advertising platforms.

8. Retention and deletion

9. Your rights and choices

10. Security

Traffic is encrypted in transit (TLS 1.2+). Each customer's agent runs in its own isolated instance with its own operating-system identity and data directory — one customer's agent cannot read another's data. Credentials and tokens are encrypted at the application layer where our web app stores them, and held on your instance under its own isolation elsewhere. Full details, including how to report a vulnerability, are on our Security page. No system is perfectly secure; if a breach affects your data, we will notify affected customers without undue delay, and within 48 hours of confirmation for personal-data breaches.

11. Changes to this policy

We will post changes here with an updated date. If a change materially expands how we use personal information, we will notify affected customers in advance and, where the change involves using existing data for a new purpose, obtain consent before applying it. We will never quietly repurpose your data through a policy edit.

12. Contact

Afora LLC · privacy@aforademo.com