Skip to main content
Open for Agents
WordPressShopifyCheck a siteConnectAssistantWhy agent-readyDemoDocsStoriesInstall plugin
WordPressShopifyCheck a siteConnectAssistantWhy agent-readyDemoDocsStoriesInstall plugin

Legal

Privacy Policy

Last updated: August 26, 2026. This policy applies to the Open for Agents website, public tools and demos operated by Enoki Limited.

Who We Are

Open for Agents is operated by Enoki Limited (New Zealand). If you have privacy questions, email hello@openforagents.com.

Information You Give Us

When you ask to receive product updates, we collect:

  • Email address
  • Role/persona selection (optional)
  • The page or form that sent the request
  • Basic request information used to prevent abuse

When directory submissions are available, we collect:

  • Site name and primary URL
  • Operator email address
  • Selected categories and declared capabilities
  • Optional readiness report URL
  • Optional notes you provide
  • Results from checking the public URLs you submitted
  • Basic request information used to prevent abuse

If you email us, we receive your email address and the information you include in the message.

Agent Readiness Assessment Requests

When you request an Agent Readiness Assessment, we collect:

  • Your name and work email address
  • The public WordPress site address
  • Your authority confirmation and consent to read-only public checks
  • Basic request information used to prevent abuse

If the site is a fit and you continue with the assessment, we also handle the agreed scope, authority and client permission record, invoice reference, intended public state, the privacy-minimized evidence file you choose to export from WordPress, public observations, report records, correction and follow-up correspondence, and a closeout or deletion record. We do not ask for a WordPress username or password.

An uploaded evidence file is validated against the named site and reduced to the approved fields needed for the report. The raw upload is then deleted. Normalized evidence and report records are kept for the period confirmed with you before report release, subject to legal, tax, dispute and security obligations. Inquiry records expire from the website request queue after 90 days. Related correspondence or business records may be kept longer where reasonably needed to answer the inquiry, prevent abuse or meet legal and tax obligations.

Website Hosting and Security

Our hosting and security providers process ordinary request information needed to deliver and protect the website. This can include IP address, requested URL, date and time, browser or device information, and security events. Cloudflare Turnstile is used on selected public tools to distinguish people from automated abuse.

Website Analytics

The website uses Vercel Analytics, Plausible Analytics, and Google Analytics 4 to understand page views, navigation, referrals, and general site performance. Depending on the service, this may include the page URL, referrer, browser and device information, approximate location, and network identifiers. The Plausible tracker is served through stats.enoki.nz.

We use analytics reports to understand aggregate website usage and improve the product and documentation. We do not use this analytics data to make automated decisions about visitors or sell it to third parties.

When you arrive from a supported MCP or AI app directory, the site keeps that directory name in the current browser tab so related actions can be counted with the same source. It does not include your email, report content, or the website you checked, and it is discarded when that browser session ends.

Updates and Contact Requests

Signup data is processed by our website and stored in Kit (ConvertKit), our email service provider. We keep subscriber data until you unsubscribe or request deletion.

Website Visibility Checks

When you use the Website Visibility Check, the website address you enter and a Turnstile verification result are sent to the checking service. The service requests selected public pages and files from that website and returns the findings to your browser. It does not log in to the website, bypass access controls, or save copies of the pages as part of the report. Normal security and service logs may record request metadata.

You can also connect a compatible AI app to the hosted Website Visibility Check. For that connection, Supabase processes your email sign-in, account identifier, requesting client and approval. Open for Agents stores the connected client identifier, website origin, report, report digest and check time so a later result can be compared with a recent one. It does not store page bodies, access tokens, client secrets or website credentials in report history.

Connected-account history is limited to 100 recent checks per account and each check expires no later than 90 days after it is saved. The browser version remains available without an account and keeps its comparison history in that browser. To request deletion of connected account history, email hello@openforagents.com.

Directory Submissions

Directory submission data is stored by the website for review and directory operation. We keep queued, rejected, removed, and published submission records only as long as needed to operate the directory, prevent duplicate or abusive submissions, and handle correction or removal requests.

A submitted listing is not published automatically. If a listing is approved, the public directory may show the site name, primary URL, categories, declared capabilities, readiness or validation URLs, and the date of the public check, and the result of each public check. Operator email addresses, private notes, reviewer information, and request metadata are not included in the public listing.

To correct a listing, remove a listing, or ask what directory data we hold for your site, email hello@openforagents.com. We may ask you to verify that you operate the site before changing or removing a listing.

Assistant and Any-Web Conversations

When you use Open for Agents Assistant or the Any-Web controlled preview, your prompt, relevant recent conversation, the reviewed tools or public sources available to that experience, and the resulting tool or source information are processed by the hosted service and its configured model provider. Any-Web is read-only and answers from selected public Open for Agents material.

These conversation features are optional. They do not make a model request until you open the interface and submit a prompt. Short-lived session and execution identifiers, IP-derived abuse controls, token usage, timing, and tool-call counts are processed to operate and protect the service. New Chat clears the active conversation in the interface. Do not submit passwords, payment details, health information, government identifiers, or other sensitive information in a prompt.

In the WordPress Assistant demo, supported cart or form changes require approval for the exact proposed values. The service temporarily holds the encrypted approval review and removes it after approval, cancellation, or expiry. Checkout, payment, order placement, authentication, and account changes remain outside the demo Assistant.

Plugin Data Handling

The Open for Agents plugin is designed to run locally on your WordPress site. Scan and validation History is stored as private WordPress database records and is available only to authorized administrators. It is not published in the public agent catalog or public discovery surfaces. New History records do not depend on public files or web-server configuration for confidentiality. Scan results and generated action maps remain on your site unless you explicitly export or share them.

Shopify App Data

Open for Agents for Shopify reads the supported catalogue evidence needed to compare how products are represented and to record comparison history. It does not request protected customer, order, payment, or account data. Shopify may make store-owner information available to installed apps through its standard platform access; Open for Agents does not use or store that information for catalogue assurance. Removing the app ends its access to the store.

Service Providers and International Processing

We use providers where needed to host and secure the website, send requested updates, measure website use, operate visitor verification, store assessment requests and report records, process an agreed payment, and provide optional model-backed conversations. These providers can include Vercel, Kit, Plausible Analytics, Google Analytics, Cloudflare, our database and payment providers, and the configured model provider. They can include Supabase for connected-account authentication and consent. They may process information in countries outside New Zealand under their own privacy and security terms. We do not sell personal information.

Your Rights

You can request access, correction, or deletion of your personal data by emailing hello@openforagents.com. You may also unsubscribe from product email using the link in each message. We process privacy requests in line with applicable law, including the New Zealand Privacy Act 2020 and the GDPR where it applies.

Updates

We may update this policy as the product evolves. Material updates will be reflected by the date at the top of this page.

See also: Terms of Service

Open for Agents

Choose what AI agents can discover and do on your website, check how public pages respond, and keep visitors in control of any changes.

Products

OverviewWordPress pluginShopifyAssistantAny-Web preview

Resources

How it worksWhy agent-readyCheck a siteConnect an AI appMCP connection guideLive demosDocumentationIntegrationsReferences

Company

AboutDirectoryStoriesX (@openforagents)

Support

PrivacyTermsTrademarkshello@openforagents.com

Built by Enoki Limited in New Zealand. Copyright 2026 Enoki Limited.