Overview
Product (“Product,” “we,” “us,” or “our”) operates Product Agent, an AI marketing workspace for commerce teams, available at product.ag. This Privacy Policy explains what information we collect when you use the Service, how we use it, and the choices you have.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
Information we collect
Account and profile
- Email address, password (if you sign up with email), and display name.
- Profile details you provide, such as avatar images.
- If you sign in with Google, identity information Google provides through our authentication provider (typically email and profile basics).
- Notification preferences, including whether you opt in to product and marketing emails.
Workspace and product data
- Workspace settings (name, plan, membership roles, security settings such as MFA requirements).
- Product catalog data you create or import (titles, descriptions, prices, images, SKUs, variants, inventory, collections, and related marketing intelligence).
- Campaigns, creatives, goals, insights, jobs, and other content you generate or store in a workspace.
- Workspace invites (invitee email, role, and invite metadata).
Authentication and security
- Session information needed to keep you signed in.
- Optional multi-factor authentication (TOTP) factors you enroll.
- Session audit events such as login and revoke actions, which may include IP address and user agent.
Billing and wallet
- Workspace billing plan and wallet balances.
- Payment and subscription records processed by Stripe (for example customer identifiers, payment method references, and transaction history). We do not store full card numbers on our servers.
Connected services
- OAuth tokens and account identifiers when you connect commerce platforms (such as Shopify, WooCommerce, BigCommerce, Amazon, or Squarespace) or advertising accounts (such as Google Ads), so we can import catalogs and manage connected marketing activity on your behalf.
- Product and account data retrieved from those connections.
AI chat and agent usage
- Messages and product/workspace context you send to the agent are processed by our servers to generate responses and take actions you request.
- Conversation history is stored in your browser (local storage) on your device, not as a durable server-side chat archive. Messages are still transmitted to us (and, when AI is enabled, to model providers) when you send them.
- Model preference and similar UI state may also be stored locally in your browser.
Merchant measurement (Product Plugin)
If you install our optional Product Plugin on a merchant site, the plugin may collect measurement events from that site (for example event type, page URL, referrer, user agent, IP address, session or visitor identifiers, and related event payload data), subject to the tags and consent settings you configure.
Information we do not collect by default
The Product Agent web app does not currently embed third-party product analytics trackers (such as advertising pixels or general website analytics suites) for our own marketing site usage.
How we use information
- Provide, operate, and secure the Service (accounts, workspaces, catalogs, creatives, billing, and support).
- Authenticate users, enforce workspace access controls, and operate optional MFA.
- Process payments, subscriptions, and AI usage metering.
- Send transactional messages (for example authentication emails and workspace invites).
- Send optional product or marketing communications when you have opted in.
- Import and sync catalogs or advertising data from services you connect.
- Generate AI outputs (chat replies, creatives, media, and related job results) from the content and context you provide.
- Improve reliability, prevent abuse, and comply with law.
AI processing
When AI features are enabled, prompts and related content (including chat messages, product details, creative briefs, and similar workspace context) may be sent to our AI gateway and underlying model or media providers to produce responses, images, audio, or video. Usage may be attributed to your workspace for billing.
If AI gateway credentials are not configured in an environment, the Service may fall back to limited offline/deterministic behavior that does not call external models.
Cookies and similar technologies
- Authentication cookies managed by our auth provider to maintain your session.
- An active-workspace cookie so we can remember which workspace you are using.
- Short-lived cookies used during OAuth connection flows (for CSRF/state protection).
- Local storage for agent conversations, UI preferences, and similar client-side state.
These technologies are primarily required for the Service to function. You can clear local storage and cookies in your browser, which may sign you out or remove locally stored chat history.
How we share information
We share information with service providers that help us operate Product Agent, including:
- Supabase — authentication, database, and file storage.
- Stripe — payments, subscriptions, and wallet top-ups.
- Resend — workspace invite emails (when configured).
- Vercel AI Gateway and underlying model providers — AI chat and creative generation.
- Media providers such as ElevenLabs and Higgsfield — text-to-speech and video generation for creatives, when those features are used.
- Background job infrastructure (for example Trigger.dev) — asynchronous campaign, creative, and related jobs.
- Commerce and ads platforms you choose to connect — to import data and perform requested actions.
- Google — if you use Google sign-in or Google Ads connections.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset transfer.
We do not sell your personal information.
Storage and retention
- Account, workspace, product, billing, and connection data are retained while your account or workspace is active and as needed to operate the Service.
- Uploaded assets (product images, avatars, creative media) are stored in our storage provider and may be accessible via public URLs depending on bucket configuration.
- Agent chat history retained in your browser remains until you clear it or clear site data.
- Plugin measurement events, if collected, are retained as needed for the measurement features you enable.
Security
We use industry-standard safeguards appropriate to our Service, including encrypted transport, access controls (including row-level security in our database), and encryption of certain third-party connection secrets at rest. No method of transmission or storage is completely secure.
Your choices
- Update profile, notification, and security settings in the app.
- Disconnect commerce or ads integrations from workspace settings.
- Clear browser local storage to remove locally stored conversations.
- Request account or data deletion by contacting us (see below).
- For Product Plugin installs, configure consent categories and use available opt-out controls on merchant sites.
Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
International users
We may process and store information in the United States and other countries where we or our processors operate. If you access the Service from outside those locations, you understand that information may be transferred to and processed in those countries.
Changes
We may update this Privacy Policy from time to time. We will change the effective date above and, when appropriate, provide additional notice in the Service. Continued use after an update means you accept the revised policy.
Contact
Questions about privacy or this policy: reach us through product.ag.
See also our Terms of Service.