Effective date: 2026-06-23
London System Agent (the “Service”) values your privacy and complies with applicable data protection laws. This policy explains what personal data we collect, why, and how we protect it. The Service is currently operated by an individual and is in a beta stage, prior to incorporation or business registration.
1. Information We Collect
Account authentication (Google OAuth): your name, email address, and profile image.
BYOK API keys: LLM provider keys (Vertex AI, OpenAI, Anthropic) you register yourself. They are stored encrypted on the server and shown only in masked form (••••xxxx).
Payment information: handled by our payment processor (Stripe) when you top up credits. The Service does not store full card numbers or other sensitive payment instrument details.
Usage records: compile/run requests, generated agent graphs (IR), credit usage history, and access logs (timestamps, error records, etc.).
2. How We Use Information
To identify and authenticate you and to provide personalized features such as the library and settings.
To provide core features: compiling, running, simulating, and deploying agents.
To process payments and reconcile paid usage, including credit top-ups and deductions.
To operate and improve the Service, analyze errors, and prevent abuse.
3. Retention
We delete personal data without undue delay once the purpose of collection is fulfilled or upon account closure.
Where law requires retention (e.g., payment and contract records), we keep the relevant data for the mandated period.
4. Sharing and Processors
We do not share personal data with third parties except where required by law or where you consent.
We rely on the following processors to operate the Service: payments (Stripe), authentication (Google), and the LLM providers you call with your BYOK keys in Real mode (Vertex AI, OpenAI, Anthropic). Each processor’s own policy also applies to its handling of your data.
Cross-border transfer: when you call an LLM with your own BYOK keys in Real mode, the prompts and execution data you input may be transmitted to and processed by that provider, whose servers may be located outside Korea (e.g., the United States). These calls are made with keys you registered yourself, and the provider’s own data policy also applies. No external LLM calls occur in Stub mode.
5. Your Rights
You may request access, correction, deletion, or restriction of processing of your personal data at any time.
You can delete BYOK keys and review account details in Settings; other requests can be made via the contact below.
6. Security
Sensitive data such as BYOK keys is stored encrypted and displayed only in masked form.
We apply reasonable technical and organizational safeguards, including encryption in transit (HTTPS) and access controls.
7. Cookies
We use cookies to maintain your login session and to store your language preference (NEXT_LOCALE).
You may refuse cookies in your browser settings, but some features such as sign-in may then be unavailable.
8. Operator and Privacy Contact
The Service is currently operated by an individual and is in a beta stage, prior to incorporation or business registration. Responsibility for personal data protection rests with the Service operator.
For privacy inquiries or requests to access, correct, or delete your data, contact: totaro@totaro.co.kr
After incorporation or business registration, business identity details (legal name, representative, address) will be added to this policy.
9. Changes to This Policy
If we add, remove, or modify this policy, we will announce the change within the Service before it takes effect.