Last updated August 25, 2026
Current as of August 25, 2026. These pages describe Agentform on tellme.sh as it ships today.
Scope
This addendum applies when an individual account holder uses Agentform on tellme.sh to collect personal data from respondents. It does not create an EU entity, a named data-protection officer, or a Standard Contractual Clauses pack. Those documents are not published here.
Account data about you (your Clerk identity, settings, keys) is described in the Privacy Policy. This page is about respondent data you collect through forms.
Roles
You are the controller of respondent personal data. You decide what fields to ask, who receives a link or embed, and which destinations (webhook URL, MCP client) may receive a copy.
Mosnin Co., operating Agentform, is the processor. We process that data only to store it, show it in your workspace, run the conversation agent you published, deliver configured webhooks, and answer MCP tool calls authenticated with your key.
Instructions
Your instructions are the product configuration: field blocks, flow text, visibility, password, webhook URL, and API keys you create or revoke. We will not use respondent data to train a public model of our own. Model providers process conversation text (and audio, if you enable voice) so the agent can run.
Sub-processors
- Clerk, authentication for account holders.
- Convex, database and realtime application records.
- Wasabi, S3-compatible storage for uploads.
- OpenRouter, model inference for builder and form agents.
- OpenAI, realtime voice when voice mode is used.
- Vercel, application hosting.
We will list material processor changes on this page. If you cannot accept a processor, stop collecting that data or delete the form.
Security
Access to dashboard data requires a Clerk session. Private forms require a password. Uploads use short-lived signed URLs. MCP access uses revocable keys that must be sent as a Bearer token. Webhooks can include a shared secret you set. Free-plan and rate limits reduce abuse. No security control is perfect.
International processing
Mosnin Co. has not established a separate European company on this site. Sub-processors may process data in the United States and other regions. You are responsible for deciding whether that is lawful for the data you collect.
Assistance, incidents, deletion
We will give reasonable help so you can respond to a respondent request, within the product: you can delete an account and its forms from Settings, and you can email mosninco@gmail.com to request deletion of a specific submission.
If we become aware of a breach that affects respondent data we process for you, we will notify the email on the Clerk account when we can do so without undue delay.
When you delete a form or account, we delete associated respondent records we store, subject to short-lived backups and logs needed to operate the service. Data already delivered to your webhook or MCP client is outside our control.
Contact
Privacy and processing questions: mosninco@gmail.com.