Last updated 6 October 2026

Privacy policy

Who we are

Accred Automation is a service of Accred that lets you describe a job in plain words and have an AI agent run it for you. This policy covers the app at agent.accred.sh. Questions go to contact@accred.sh.

What we store

  • Your Accred API key. It identifies your account and pays for your runs. We store it encrypted, plus a one-way hash used to sign you in and its last four characters so you can recognise it.
  • Your automations. The instruction you wrote, the trigger, the model choice, the credit budgets, and any short notes the agent saved between runs.
  • Your connections. What is needed to act in the apps you link: a Telegram chat ID and, if you use your own bot, its token; a Slack or Discord webhook address; a GitHub token and repository name; an API address and header; for Gmail, your email address and the access grant Google issues. Secrets are stored encrypted and are never shown again.
  • Run history. For each run: the steps the agent took, which model handled each step, the credits charged, the result, and a short excerpt of what each tool returned. Those excerpts can contain content from your connected apps, such as the sender and subject of an email. Payloads sent to a webhook trigger are stored with the run they started.
  • A sign-in cookie. One cookie keeps you signed in. We set no advertising or analytics cookies.

Gmail and other Google data

If you connect Gmail, we ask Google for read-only access to your mail. The app cannot send, delete or change email.

  • We read your mail only while one of your automations runs, and only to carry out the instruction you wrote for it.
  • The emails an automation reads are passed to the AI model that runs the job, through the Accred API, so the model can do what you asked. Short excerpts are saved in that run's history so you can see what the agent did.
  • We do not sell Google data, use it for advertising, or use it to develop or train generalised AI models.
  • Nobody at Accred reads your email, except with your permission to resolve a support request, when needed to investigate abuse or a security problem, or when the law requires it.

Accred Automation's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who receives your data

  • AI model providers, through Accred. The instruction and whatever the agent reads during a run are sent to the model that handles each step.
  • The apps you connect. When your automation sends a message or makes a change, that content goes to the app you chose, such as Telegram or GitHub.
  • Our infrastructure providers. The app and its database run on hosting services that store data on our behalf.

We do not sell your data or share it for advertising.

How long we keep it, and how to delete it

  • Data stays until you remove it. Deleting an automation removes its run history.
  • Removing a connection deletes its stored secret. Removing a Gmail connection also withdraws the access grant at Google. You can withdraw it yourself at any time at myaccount.google.com/permissions.
  • Delete account, under Settings, removes your automations, run history, connections and stored key from this service. Your Accred account and credits are separate and are not affected.

Security

API keys, tokens and other connection secrets are encrypted before they are stored, and the app is served over HTTPS. Requests the agent makes on your behalf cannot reach private network addresses. No system is perfectly secure; if you believe your account has been misused, revoke the key at accred.sh and write to us.

Changes and contact

If this policy changes in a way that affects how your data is used, we will update the date above and say so in the app. Write to contact@accred.sh with any question or request about your data.