Skip to content
AgentWiki
  • How it works
  • Security
  • Pricing
  • FAQ
  • Docs
Sign in Start free
Menu
  • How it works
  • Security
  • Pricing
  • FAQ
  • Docs
  • Sign in

Privacy policy

Last updated: 2026-10-06

This policy explains what AgentWiki collects when you use this website (vividkit.app) and the web app at app.vividkit.app, how we use it, and the choices you have. Questions go to privacy@vividkit.app.

Data we receive from Google sign-in

When you choose "Sign in with Google", we ask Google only for the openid, email and profile scopes. Google then shares with us:

  • your Google account ID,
  • your email address,
  • your name, and
  • the URL of your profile picture, if you have one.

When Google sign-in creates your AgentWiki account, we store your email address, name, profile picture URL and Google account ID with it. If an account with the same email address already exists (for example one created with GitHub), we sign you in to that account and keep the name and picture from the provider you first signed in with. We use the Google access token once, to read this profile, and do not store it. We never receive your Google password, and we do not request access to Gmail, Google Drive, Contacts, Calendar or any other Google data.

How we use Google user data

  • To create your account and your first workspace, and to sign you in.
  • To show your name and picture to you and to members of workspaces you belong to.
  • To send service email to your address, such as a welcome message and security alerts about your secrets.

We do not sell Google user data, use it for advertising, or use it to train AI models. We share it only with the service providers listed below, as needed to run AgentWiki, or when the law requires it. AgentWiki's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Other data we process

  • Sign-in with GitHub: your GitHub user ID, name, avatar URL and primary email address, used in the same way as the Google data above.
  • Content you add: documents, Sources, wiki pages, files and settings. We process it only to provide the features you use, such as search, summaries, the knowledge graph and context for your agents.
  • Uploaded files are public by default: a file you upload to Storage gets a link that anyone who has it can open without signing in, so files can be embedded and shared. To keep a file private, upload it with agentwiki upload put --private, or make an existing file private with agentwiki upload public <id> --off (API: isPublic=false on upload, or PATCH /api/uploads/<id>/public). Private files need a signed-in member or a download token. Do not upload confidential files without making them private.
  • Secrets: values you store as secrets are encrypted with a key specific to your workspace. Every reveal is recorded in your workspace's audit log.
  • Security and audit logs: sign-ins and sensitive actions are logged with the time, IP address and browser user agent, to protect your account and investigate abuse.
  • Billing: credit balance and purchase history. Card details are handled by our payment provider; we never see or store them.
  • Cookies: the web app sets strictly necessary cookies to keep you signed in and to protect the sign-in flow. We use no advertising or analytics cookies.

This website

vividkit.app is a static site. It sets no cookies, runs no analytics or trackers, and loads no resources from third parties; its fonts are served from the same domain. Our hosting provider may keep standard request logs (such as IP address and time) for security.

Service providers

  • Cloudflare: hosting, database, file storage and AI processing (summaries and search embeddings).
  • Google and GitHub: sign-in, when you choose them.
  • Polar: payment processing for credit purchases.
  • Resend: delivery of service email.
  • Google Gemini: descriptions of uploaded images, when file extraction is enabled.
  • File extraction service: when file extraction is enabled, uploaded PDFs and office files are converted to text by a Docling-based extraction service that we host ourselves on infrastructure we operate. File extraction can be turned off, in which case files are only stored.
  • AI providers you configure: if you add your own AI provider key, the content needed for the feature you use is sent to that provider under its terms.

Retention and deletion

We keep account data while your account is active. In the app you can delete files (removed from storage at once) and documents (hidden and removed from search; the record and its version history are kept until your account is deleted), and destroy secrets (their stored values are erased). Sources cannot be deleted in the app: they are kept as the citation record for wiki pages. To have specific documents or Sources erased, or to delete your account and all data tied to it, email privacy@vividkit.app from the address on the account; we will confirm and complete the deletion within 30 days, except where we must keep records by law. You can also revoke AgentWiki's access at any time from your Google account's security settings.

Security

Traffic is encrypted with TLS, workspaces are isolated from each other, and secrets use envelope encryption with a key per workspace. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.

Children

AgentWiki is not directed at children under 13, and we do not knowingly collect their data.

Changes

If we change this policy, we will update the date above, and for material changes we will notify account holders by email before they take effect.

Contact

Email privacy@vividkit.app for any privacy question or request, including access to, correction of or deletion of your data.

AgentWiki

A cited wiki for coding agents and the people who review them.

Product

  • How it works
  • Pricing
  • Docs
  • Web app

Legal

  • Privacy
  • Terms
  • Contact: privacy@vividkit.app

© 2026 AgentWiki