Minions by Engagent LLCBack to home

Engagent LLC legal

Privacy Policy

Effective August 10, 2026

Overview

Engagent LLC is a limited liability company in the United States. Engagent LLC operates Minions, an Amazon seller analytics and AI operations service, including the Minions Operational Alerts SMS program. In this policy, “we” and “us” mean Engagent LLC, and “you” means the customer or authorized account owner who uses Minions.

This policy explains what information we collect, how we use it, where it is stored, how it is protected, who it is shared with, how long we keep it, and how it is deleted. It covers information obtained from the Amazon Selling Partner API, Amazon Brand Analytics reports, and the Amazon Advertising API when a seller authorizes us to read their account.

Information we collect

Account information. Your name, business name, email address, and the sign-in identifier from the provider you use to authenticate. We use this to create and secure your account.

Amazon seller information. When you connect your Amazon account, we receive an authorization from Amazon and read the data described in the next section. We never ask for, receive, or store your Amazon username or password.

Other connected services. If you connect additional tools, we receive the authorization for those tools and the data you ask Minions to read from them.

SMS information. Mobile phone number, enrollment and consent records, delivery status, and limited operational event details needed to send and support operational alerts.

Service information. Application logs, integration audit records, and basic website analytics used to operate, secure, and troubleshoot the service.

Amazon Selling Partner and Brand Analytics data

With your authorization, we read information from your own Amazon seller account. Depending on the roles you approve, this includes seller and marketplace details, catalog and listing data, pricing, FBA inventory, inbound shipments, orders and fulfillment status, financial events, advertising performance, and Brand Analytics reports such as Search Query Performance, Search Catalog Performance, Market Basket Analysis, Amazon Search Terms, and Repeat Purchase behavior.

Access is read-only. Minions does not create, change, or delete listings, prices, inventory, shipments, orders, refunds, or advertising campaigns.

We do not seek Amazon buyer personally identifiable information. Where an authorized Amazon response contains buyer names, shipping addresses, contact details, or tax identifiers, those fields are removed before the data is stored, logged, or passed to any AI model.

What Amazon information never reaches an AI model

Buyer names, shipping and billing addresses, buyer contact details, tax identifiers, Amazon credentials, refresh and access tokens, and authorization headers are stripped before any data is used to generate an answer, and are not written to application logs.

How we use information

We use the information above to provide the service you asked for: to produce the analytics, reports, and answers you request; to run the automations you configure; to deliver operational alerts you have opted into; to authenticate you and secure your account; to diagnose and fix problems; to respond to support requests; and to meet legal and recordkeeping obligations.

We do not sell your information. We do not use your Amazon data to build, train, or improve any general model, and we do not pool, benchmark, or resell one seller's data to another seller or to any third party.

Seller authorization and disconnection

Access to your Amazon account begins only when you authorize it on Amazon's own consent screen in Seller Central. Amazon shows you the data roles being requested before you approve them.

You can end that access at any time by revoking the authorization in Seller Central under Apps and Services, or by disconnecting the integration inside Minions. Either action stops all further access. When an integration is disconnected, the stored authorization credential for it is deleted.

Storage and security

The service runs on cloud infrastructure in the United States. Application data is held in a managed Postgres database, and the website and application are served over HTTPS. Data is encrypted in transit.

Integration credentials, including Amazon authorization tokens, are encrypted at rest with AES-256-GCM before they are stored, and are decrypted only on the server at the moment a request you asked for is made. Credentials and tokens are never sent to the browser, written to logs, or included in AI model context.

Access to connected data is scoped to the account that authorized it; another customer's connection is not visible to you and yours is not visible to them. Amazon operations are limited to a server-side list of named read-only calls, so a request outside that list is refused before any call to Amazon is made. Integration activity is recorded as an audit entry containing the operation name and status, without response bodies, credentials, or buyer data.

Administrative access to production systems is limited to Engagent LLC personnel who need it to operate the service. We hold no third-party security certification and do not claim one. No system can guarantee absolute security.

Service providers and subprocessors

We use a small number of service providers to run Minions. They process information only to provide their service to us: Vercel for application hosting; Supabase for authentication and the managed Postgres database; Fly.io for background data-collection services; Resend for transactional email; Composio for connectivity to certain third-party tools you choose to connect; and OpenAI and Cerebras as AI model providers that generate answers from the sanitized data described above. Operational SMS alerts are delivered through a licensed messaging provider and the mobile carriers.

We do not authorize these providers to sell your information or to use it for their own marketing.

Sharing

We do not sell or rent your information, and we do not share it for advertising. We share information only with the service providers listed above, with people you explicitly ask us to share it with, and where we are legally required to do so, such as in response to valid legal process or to protect the rights and safety of Engagent LLC, our customers, or the public. If Engagent LLC is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, and this policy continues to apply until it is replaced by a policy you are notified of.

Retention

Account information is kept while your account is active. Amazon report data and other connected-service data are kept while the connection is active and while the reporting history remains useful to you. Integration audit entries and application logs are kept for a limited operational period and then removed. Encrypted integration credentials are deleted when the integration is disconnected. SMS consent and delivery records are kept as long as reasonably necessary to operate the program and to demonstrate consent.

Deletion and your rights

You can ask us to delete your account, your Amazon and other connected-service data, or both, by emailing mark@engagent.dev. We act on deletion requests within 30 days and confirm when the deletion is complete. You may also ask what information we hold about you and ask us to correct it.

Deletion removes the stored data from our systems. Copies may persist briefly in routine encrypted backups and are removed as those backups age out.

Mobile information and SMS consent

Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. SMS opt-in data and consent will not be shared with third parties.

Message frequency varies, up to 20 messages per month. Message and data rates may apply. Reply STOP to opt out and HELP for help.

How SMS data is treated

Phone numbers and consent records are used only to operate requested alerts. Alert messages contain a short thread identifier and never include prompt text, question text, file paths, URLs, or transcript content.

Changes to this policy

If we make a material change to this policy, we will update the effective date above and, where the change affects how your connected-account data is handled, notify account owners by email.

Privacy contact

Engagent LLC is the controller of the information described here. For privacy questions, access requests, or deletion requests, email mark@engagent.dev.