This policy states what information the Agentbox application for macOS and the Agentbox website collect, why they collect it, who receives it, how long it is held and what you can require of us. It is given by Astral AI Inc. and covers no other company.
Last changed 5 October 2026. This version replaces every earlier version.
Astral AI Inc. makes Agentbox and is the company responsible for the information described in this policy. Where the words we, us and our appear here they mean Astral AI Inc. Where the words you and your appear they mean the person using Agentbox.
Claude and Claude Code are made by Anthropic, which is a separate company. We are not Anthropic, we do not act for Anthropic, and what Anthropic does with what you send it is governed by your own agreement with Anthropic and not by this policy.
Agentbox runs on your own computer. Your files, your code, the prompts you write, the replies your agents write, your keys and your file paths are not sent to us and we have no way to read them. What we receive is a small amount of information about how the application is used, how it is configured and how it fails. It is not attached to your name or your email address, because Agentbox has neither.
This section is a summary and nothing more. Sections 3 to 17 are the policy, and where the summary is less precise than they are, they govern.
Agentbox is a layer over the copy of Claude Code already installed on your computer. It reads your sessions from your own disk and runs them under your own user account. No server of ours stands between your computer and Anthropic, so your prompts reach Anthropic in the same way they do when you run Claude Code in a terminal, and we cannot see them at any point.
Agentbox also supports Codex using your own Codex account. When you request conversation compaction, the installed Codex summarizes the existing conversation through its configured provider. That provider processes the conversation under your agreement with it. Agentbox keeps the command status on your computer and does not send the conversation or its summary to us. Compaction does not grant an agent any additional permissions.
Agentbox managed Codex workers disable automatic loading of Codex apps and plugins. A project worker may still use the local Agentbox store connection supplied for that task. This does not change the integrations in your separate native Codex sessions.
Messages you send while an agent is working are forwarded to the existing Claude Code or Codex conversation through your configured provider account. Agentbox keeps the reply and delivery state locally. Your provider processes these messages under your agreement with it. The messages and their contents are not sent to us.
The built-in terminal runs a local shell under your computer account in the selected task folder. Terminal input and output are not sent to us. Agentbox retains a limited amount of output in memory while it runs. Your shell and the programs you run may keep their own history, write files or communicate with services you choose. Those services process information under their own policies.
In personal Claude Code conversations, requests that need your approval can be shown in Agentbox. The request and your decision are kept locally so the waiting agent can receive your answer. This approval channel does not give the conversation access to Agentbox task store tools and does not send approval records to us.
Commands you invoke can also request code review, manage conversation goals, or inspect the connected provider and local project. Provider commands use your existing provider account. Review may send project content to that provider as part of its normal operation. Command results, model and effort choices, and the available Claude Code command names are kept locally. These results and command names are not sent to us.
When you enable Remote Control for a Claude Code conversation, the installed Claude Code connects that conversation to Anthropic so you can continue it in Claude on another device. Anthropic receives the conversation history and subsequent messages under your agreement with it. Tool execution remains on your computer. Agentbox stores remote replies and connection state locally and does not receive a cloud copy of the conversation. Turning Remote Control off disconnects access through this local session. It does not promise deletion of records held by Anthropic.
Agentbox has no sign in, no user account and no cloud copy of your work. We therefore hold no name, no password and no profile of you, and nothing in this policy should be read as saying otherwise. We hold no email address for you either, and the feedback box described in section 5.4 has nowhere to type one.
Agentbox can also use the services you have connected to Claude Code, such as Slack or Linear. When an agent reads from one of them, the request goes from your computer to that service through Claude Code, signed in as you, under your own account with that service and its own terms. Agentbox holds no password, key or token for any of them, and nothing an agent reads there reaches us. In this version an agent can only read from a connected service. It cannot send or post anything through one, and a version that can will change this policy and section 7 of the terms before it is released.
We do not receive, and no future version of Agentbox will send us, any of the following.
This section is the binding limit of the whole policy. Every other section describes information received inside it, and section 5 may grow only inside it. If we ever intend to send anything named above, we will change this section before doing so and we will say in the application that it has changed.
A count records that something happened once. It carries no text that you or an agent wrote, no name, no path and no title. Agentbox sends the following counts today.
Agentbox is early and it changes quickly. We expect to measure more of how it is used than this over time, and when we do, this list is changed in the same release that changes the application. What may never grow is section 4, which is the promise this policy is built on. A new count tells us that a part of Agentbox was used. It will not tell us what you were working on.
The first time Agentbox runs it generates a random identifier and stores it in a file on your computer. Its only purpose is to let counts from one installation be read as one installation rather than as many. It is not your name, your email address or an account, it is not derived from anything about you or your hardware, and we hold nothing that would let us connect it to you. Removing Agentbox and its application data ends it. A fresh installation generates a new one, and we cannot tell that the two are the same person.
When Agentbox fails it prepares a report. The report says which of the ways the application can fail happened, when it happened, the installation identifier, the version of Agentbox, the release of macOS and the processor architecture, how long the application had been open, and the error itself, which is its name, its error code, the name of the system call that failed, its cleaned message and the failing lines of our own code.
Errors normally carry your home directory, your username and your folder names inside them. Reports are therefore cleaned on your computer, before anything is sent, rather than after they arrive. Paths are removed and only their depth is kept, the arguments to the failed system call are dropped in full, and stack frames outside our own application are counted and discarded. The finished report is then checked again, and a report that still contains anything private is not sent with the offending field removed, it is discarded in full and replaced by a note that a crash happened.
We tested this by breaking a real copy of Agentbox three ways on purpose and reading what came out. None of the three carried a path, a folder name or a task title.
Agentbox has a box for telling us what broke, what is missing or what you wish it did. Nothing in it is collected. It is sent only when you write something and press send, and if you never open it we receive nothing from it at any point.
What we receive when you do press send is this.
There is nowhere to type an address, so nothing you send from the box tells us who you are unless you write it in the box yourself. The installation identifier described in section 5.2 is not sent with a feedback message.
Your message is not written to a file and it is not held anywhere for sending later. It is sent when you press send, and if it cannot be sent, Agentbox says so and leaves what you wrote in the box so you can send it again. Nothing is tried again on its own, and closing the box without sending discards what is in it.
Section 4 governs this section as it governs every other. We do not attach your files, your code, your prompts, your keys or your paths to a feedback message, and a file you attach yourself is sent by its contents and its name, never by where it was on your computer. If you write any of those things into the box yourself, they reach us because you chose to send them.
Agentbox keeps itself up to date. A few times a day it asks GitHub whether a newer version has been released, and if there is one it downloads it in the background and waits for you to restart. Nothing is installed until you say so, and restarting is a button you press.
That question goes to github.com, which is a separate company, and not to us. We receive nothing from it. GitHub receives what any website receives from a request, which is your network address and which file was asked for. It carries no identity, no account, no key and none of the counts described in section 5.1, and it is not joined to anything else in this policy.
Section 4 governs this section too. Nothing about your files, your code, your prompts, your keys or your paths is sent in order to ask whether there is a new version.
A copy of Agentbox run from its source code asks a different question in the same way. Every half hour it asks the GitHub repository it was copied from whether newer code has been published there, using the ordinary git fetch that copying it used. If there is newer code it says so and waits for you to restart, and restarting is a button you press. A copy whose folder holds changes of your own, or that follows no repository, does not offer to update at all. GitHub receives the same things as above and nothing more, and section 4 governs this question as it governs the other.
We use what is described in section 5 to see whether Agentbox is used and which parts of it are used, to find and fix faults, to decide what to build next, and to count installations. We use it for nothing else.
We do not use it to build a profile of you, to target advertising, to score you, or to make any decision about you by automated means. We do not attempt to identify you from it and we hold nothing that would let us.
Where data protection law requires us to name a basis, we rely on our legitimate interest in understanding, maintaining and improving software we make. We consider that interest balanced against your privacy by the limit in section 4, which keeps everything of consequence off our systems entirely, and by the control in section 10.
You may object to this use at any time, and section 10 is how you do it without writing to anyone.
One outside service stores the counts and the crash reports for us and processes them only on our instructions and for no purpose of its own. That service is PostHog. No other company receives any of it.
A feedback message takes a different path and passes through two other companies, which receive only what is in the feedback box and nothing else in this policy. Supabase hosts the small program the application sends it to, and Resend delivers it to us as an email. Both act only on our instructions, neither keeps it for any purpose of its own, and neither receives the counts or the crash reports.
The one thing that goes anywhere else is the question in section 5.5, which asks GitHub whether a newer version of Agentbox has been released. GitHub is not storing anything for us and receives none of the counts, none of the crash reports and nothing from the feedback box.
We may disclose what we hold if the law requires it of us, such as under a valid legal demand, or where it is necessary to establish or defend a legal claim or to protect the safety of a person. If we are ever asked for information in a way we are permitted to tell you about, we will.
If Astral AI Inc. is sold, merged or reorganised, what we hold may pass to the buyer. The buyer would be bound by this policy until it gives notice of a different one.
The counts and the crash reports described in sections 5.1 to 5.3 are stored by the service named first in section 8, in the United States. If you use Agentbox from another country, using it sends that information there.
A feedback message is not stored by that service at all. It passes through the two companies named after it in section 8 and arrives with us as an email, which we hold in our own mailbox.
One setting in Agentbox controls all of it. It is on when you install Agentbox. Turning it off stops the counts and stops the crash reports, and nothing else about the application changes. There is no reduced or partial mode and no second setting to find.
The check for a newer version in section 5.5 is not part of that setting and keeps running, because it is how Agentbox repairs itself and how a fault you reported reaches you fixed. It sends us nothing either way.
Turning it off stops sending from that moment. It does not by itself delete what was sent before, which section 12 covers.
We keep what arrives only for as long as it is useful for building, fixing and understanding the use of Agentbox, and we delete it when it is not. We have not yet fixed a period, and when we do it will be stated in this section rather than left to practice.
Depending on where you live you may have the right to ask what we hold about you, to receive a copy of it, to have it corrected, to have it deleted, to object to or restrict how we use it, and to complain to your data protection authority. We will not treat you differently for exercising any of them, and there is nothing to treat differently, because Agentbox has no account and no paid tier that could be withdrawn.
Because Agentbox holds no account, what we receive from the counts and the crash reports is tied to the installation identifier in section 5.2 and to nothing else. To act on a request we need that identifier, since without it we cannot find your records among anyone else's, and we will not ask you for identity documents or any other personal information in order to answer. Requests are made in the way section 17 states.
Agentbox is a developer tool for adults. It is not directed at children under 13, we do not knowingly collect information from them, and if we learn that we have, we delete it.
What we receive is held on systems reachable only by the people who need them, and by the service in section 8 under its own security terms. No method of transmission or storage is completely secure and we do not claim otherwise.
The strongest protection in this policy is not a security measure. It is section 4, which means that the material that would actually matter if it were exposed is never on our systems in the first place.
We do not sell personal information and we do not share it for cross context behavioural advertising, as those terms are used in California law. We have never done either. We run no advertising in Agentbox, we place no advertising trackers in it, and we hand nothing to a data broker or to any third party for that party's own purposes.
Agentbox sets no cookies and there is no browser signal for us to honour, but if we ever add anything a Global Privacy Control signal would apply to, we will honour it.
The page you are reading loads no fonts, no scripts and no trackers from any other company, and sets no cookies. The company that hosts it keeps ordinary records of the requests it serves, including the network address a request came from, in the way every web host does. We do not use those records to identify anyone.
Agentbox changes quickly and this policy changes with it. Whenever we change what the application collects, sends or stores, this page is changed in the same release, not afterwards. The date at the top says when it last changed. Where a change materially reduces the protection this policy gives you, we will say so in the application rather than quietly editing this page.
A request under section 12, or a question that this policy is required to give you an address for, is sent in writing to [contact email to be added before launch].