Privacy Policy
Last updated: September 30, 2026
1. Who is responsible for your data
Agon is developed by Edoardo Casciotta, who is the data controller for the personal data described in this policy (except where Sections 5 and 7 say he acts as a processor on a studio's behalf):
Edoardo Casciotta
Carrer d'Aragó 526, 08013 Barcelona, Spain
support@agon-studio.dev
2. Data minimalism, by design
Agon is self-hosted software: it runs on your studio's own computer, and your studio's operational data — client records, bookings, memberships, attendance, and payment history for your studio's customers — is stored in a local database on that machine. Agon's developer (“we”, “us”) does not store that data, does not copy it to our own servers, and has no access to it.
Downloading and using Agon does not involve any payment, any payment processor, any activation or license server, or any account with us. This policy describes the few, limited cases in which we do process personal data.
3. What we do not collect
We do not collect, store, or have access to your studio's client data, booking data, class schedules, attendance records, or any other data about your studio's own customers. That data is created, stored, and managed entirely within the Software on your own computer, under your control. Your studio is the data controller for it under applicable data protection law (such as the GDPR). We also collect no payment details and no account credentials, because there is no payment and no account.
4. Support and feedback
Support and feedback are handled by email. If you write to us (at support@agon-studio.dev), we receive your email address, the content of your message, and anything you choose to attach. We use it only to answer you and to improve Agon.
5. Error diagnostics (off unless you opt in)
Error reporting is off by default. Only if your studio explicitly opts in, in the Software under Settings → Privacy, technical error reports are sent to Sentry (Functional Software, Inc.), our error-monitoring provider, and stored in its EU data region (Frankfurt, Germany). The same choice covers the studio's own installation and its clients' mobile app and booking widget.
A report contains technical data such as the error type and message, the stack trace, and operating-system details, and is tagged with the studio's id and the app version. Before a report leaves the device, email addresses and phone numbers are redacted, and request contents and authentication headers are removed. Despite this scrubbing, an error message may occasionally still contain an identifier. A reduced mode, available on request, limits each report to the error type and the stack trace.
For these reports we act as a data processor on the studio's behalf, under the Data Processing Agreement in Section 6 of our Terms & Conditions, and we use them only to diagnose and fix errors. Error reports are retained for up to 30 days and then deleted automatically. Your studio can turn error reporting off again at any time.
6. The AI Assistant
The AI Assistant works only with an AI provider key that your studio supplies itself (for example Google Gemini or Groq), or with a model running locally. Prompts go directly from your studio's computer to the provider your studio chose; they do not pass through, and are never received by, Agon's developer. That provider processes them under its own terms and privacy policy, in a relationship between your studio and that provider. Without a key, the in-app help is a search of the documentation that runs locally on your computer.
7. Remote connectivity for the mobile app and booking widget
So that your studio's clients can use the Agon mobile app and the booking widget from outside your local network, the Software can connect your studio's computer through a Cloudflare Tunnel, reachable at a studio-specific hostname under agon-studio.dev that is operated by Agon's developer on his own Cloudflare account. Traffic between your clients' devices and your studio's computer is encrypted in transit and is relayed by Cloudflare's network, where the encryption is terminated and re-established on its way to your studio's computer. We do not store the relayed traffic; the data itself stays in your studio's local database.
To route requests to the right studio, a directory service stores the mapping between your studio's id and its public URL. It stores no client, booking, or other studio data. When your studio's computer is offline, the directory service can also hold booking requests in an offline mailbox: they are sealed on the client's device with a key that only your studio's installation can open, so neither we nor Cloudflare can read them.
For this connectivity service, Agon's developer acts as a data processor on behalf of your studio, which remains the data controller, under the Data Processing Agreement in Section 6 of our Terms & Conditions. We process the relayed data only to provide the connection. Cloudflare, Inc. acts as our sub-processor under Cloudflare's Data Processing Addendum. Cloudflare operates a global network, so data may be processed outside the EU/EEA; such transfers rely on the EU-US Data Privacy Framework and on the Standard Contractual Clauses.
8. Connecting a Google or Microsoft account (Email OAuth)
From within the Software, a studio manager may optionally connect a Google (Gmail) or Microsoft (Outlook/365) account so the Software can send booking, membership, and marketing emails to that studio's own clients as the studio manager themselves, instead of from a generic address. This is entirely optional; studios can also configure their own SMTP server instead.
This connection uses OAuth and requests only a send-only permission, plus the minimal identity scope needed to show the studio manager which account is connected — Gmail's gmail.send and userinfo.email scopes, or Microsoft Graph's Mail.Send and User.Read permissions. The identity scope only exposes the connected account's own email address; the Software never requests, and cannot use this connection to read, search, or otherwise access the contents of that mailbox or any other Google or Microsoft data.
Consistent with Section 2, the resulting access credentials are encrypted and stored locally within the Software's own database, on the studio's own computer. Agon's developer never receives, transmits to its own servers, or has any access to these credentials, or to the content of any email sent through them. A studio manager can disconnect a connected account at any time from within the Software, which revokes the Software's access to send further emails.
Agon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. This website
When you visit agon-studio.dev, our website hosting provider processes standard technical data (such as your IP address and request logs) as needed to deliver the site and keep it secure. This website does not require an account and does not process payments.
10. Processors and international transfers
We use a small number of service providers, each under its own data processing agreement: Cloudflare (remote connectivity and the directory service, global network), Sentry (error diagnostics, EU data region in Germany, only if your studio opts in), our email provider (for support correspondence), and our website hosting provider. Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards such as the EU-US Data Privacy Framework or the Standard Contractual Clauses. We do not sell personal data and do not use it for advertising.
11. Data retention
We keep support emails for as long as needed to handle your request and any follow-up. Error reports are retained for up to 30 days and then deleted automatically. A studio's directory entry is kept while the studio uses remote connectivity and is deleted when the studio resets or stops using it, or asks us to delete it. Offline mailbox items are deleted as soon as the studio's installation collects them, and in any case after 7 days if they are never collected. Because your studio's operational data never reaches us, its retention and deletion are entirely up to you within the Software.
12. Your rights
If you are located in the EU/EEA or another jurisdiction with similar data protection law, you have the right to access, correct, delete, or port the personal data we hold about you, and to object to or restrict certain processing. You also have the right to lodge a complaint with the competent supervisory authority, the Agencia Española de Protección de Datos (AEPD), www.aepd.es, or with the supervisory authority of the EU/EEA country where you live or work. To exercise these rights regarding the data described in this policy, contact us at support@agon-studio.dev. Requests relating to a studio's client data should be directed to that studio, as the data controller.
13. Security
We apply reasonable technical and organizational measures to protect the limited data we process, including encryption in transit for remote connectivity and multi-factor authentication on our administrative accounts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Securing the computer on which your studio runs Agon, and backing up its data, is your studio's responsibility.
14. Changes to this policy
We may update this Privacy Policy from time to time, for example when Agon's features or services change. Material changes will be reflected by an updated “Last updated” date on this page and, where required by law, communicated directly.
15. Contact
Questions about this Privacy Policy, or requests regarding your personal data, can be sent to support@agon-studio.dev.