Privacy Policy
Last updated: July 30, 2026
AgentFax stores account records, API key hashes, fax request metadata, delivery status, and billing identifiers required to operate the service. A newly issued API key is held in the activating browser's session storage until it is cleared or the session ends; AgentFax servers retain only its one-way hash. Stripe secrets are not stored in the public site.
Service providers
Cloudflare hosts the API and operational database, Stripe processes subscription billing, and Telnyx processes fax transmission. Information is shared with these providers only as needed to operate AgentFax.
Fax content
Customers host documents supplied through media_url; AgentFax stores the URL and transmission metadata and
sends the URL to the fax provider. AgentFax does not intentionally store document bodies. Provider-generated
event records may contain document URLs and delivery details. Do not submit protected health information unless
a separate written agreement expressly permits it.
Security and retention
API keys are stored as one-way hashes. Provider and billing webhooks are signature-verified, and customer webhooks are signed. Operational and billing records are retained while needed to provide the service, prevent abuse, resolve disputes, and meet legal obligations.
Customer responsibility
Customers are responsible for recipient authorization, lawful transmission, and protecting API keys. A customer may cancel billing through the Stripe customer portal; records may be retained where required for security, accounting, or legal purposes.