iOS · iPadOS · macOS · Android

Privacy Policy

Version of 29 September 2026

1. Controller

This policy applies to the Agency Companion app on iOS, iPadOS, macOS and Android, on Android both to the version from Google Play and to the direct download from agencyg.de, and to the servers the app works with. Our websites have their own privacy policy.

The controller responsible for processing your data is:
Agency Scripts, owner: Leon Rudolf
Die Halde 2, 64853 Otzberg, Germany
E-mail: [email protected]
Full details in the legal notice.

The competent supervisory authority is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information), Postfach 3163, 65021 Wiesbaden · datenschutz.hessen.de. You can lodge a complaint with this authority or with any other data protection supervisory authority.

2. Key points in brief

  • To use the app, you sign in with Discord, Google or Apple.
  • We show no advertising, do not analyze your behavior with analytics or advertising services and do not sell data.
  • The app creates a pseudonymous device ID. It is not an advertising ID.
  • The camera is used only to scan QR codes, and the microphone only for dictation and voice conversations with AgencyAI. The app does not use either of them until you start the feature.
  • Purchases go through Google Play, Apple or our web shop. We never receive card or bank account details.
  • You can delete your account in the app and export your data.

3. Account and sign-in

The app requires you to sign in. You sign in with Discord, Google or Apple; which of these options are offered is determined by our sign-in service. Signing in takes place in your device's browser through our service help.agencyg.de. The app then receives a session, which it stores in encrypted form in the operating system's secure storage.

From Discord we receive your user ID, your name, your profile picture, your e-mail address if it is verified, and information on whether you are a member of our Discord server. From Google and Apple we receive an identifier, your e-mail address if you share it and, where the provider passes them on, your name and profile picture.

You can link a Google or Apple account to your Discord account. We then merge the accounts, Discord becomes the main identity, and your previous tickets are transferred to it. The app displays the name and profile picture from your account; on Android it loads this information from our server when needed and does not store it permanently.

The legal basis is the performance of our usage contract with you (Art. 6(1)(b) GDPR).

4. Device ID

The app creates a pseudonymous device ID. On Android, this is a hash (SHA-256) formed from the identifier that Android assigns to the app on your device and a fixed salt. The identifier itself does not leave the device. The ID stays the same after a reinstallation and changes if the device is reset.

The device ID is not an advertising ID. It is not used for tracking, not combined with data from other providers and not sold. We use it to sign requests from the app to our servers, to bind licenses and purchases to your device, to count the AgencyAI quota and to protect the referral program from abuse. For a purchase through Google Play, the app passes it to Google as an obfuscated account identifier so that we can match the purchase to your device.

We keep the counters for the AgencyAI quota for 30 days. The legal basis is our legitimate interest in a secure service that is protected against abuse (Art. 6(1)(f) GDPR) and, for purchases, the performance of the contract (Art. 6(1)(b) GDPR).

5. Connection data

Every connection to our servers technically involves transmitting your IP address. We process it to answer the request and to limit the number of requests per address. All connections made by the app are encrypted (HTTPS). The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

6. Connection to FiveM servers

The app connects to FiveM roleplay servers on which our scripts run. You pair them by scanning a QR code or entering a code that a script shows in the game. For each pairing, the app stores a random device token in the operating system's secure storage. It contains no real name and no e-mail address.

The connection runs through our relay at api.agencyg.de. It forwards requests between the app and the game server and does not store your in-game content permanently. When you pair, the game server receives your device name (manufacturer and model) and, if you are signed in, your account ID, so that it can report your in-game rank to the friends feature.

When you open a feature, the app fetches the related data from your game server, such as messages, contacts, account balance, reports or admin data in the game. This is roleplay data of your character. Actions such as transfers in the game are carried out by the game server. Photos that you upload to the in-game gallery go through the relay to the game server.

The game server operator is a separate controller, not us. We cannot influence what the operator does with this data, how long it is kept or to whom it is passed on. To request access to or deletion of this data, contact the operator directly. You can unpair at any time in the app.

7. Camera

The app uses the camera only to scan the QR code for pairing. The images are analyzed on your device, and only the code that was read is used. The app does not store or transmit any camera images.

On Android, the app reads the code with Google ML Kit. This library is included in the app and works on the device. According to Google's own statements, ML Kit sends technical diagnostic and usage data to Google, such as device and app information, identifiers, performance metrics and error codes.

8. Microphone and speech

The app uses the microphone only in AgencyAI: for dictation, when you tap the microphone in the chat, and for the voice conversation with AgencyAI (Agency Max). The app asks for the permission only when you use one of these features for the first time.

Your speech is converted into text by the speech recognition of your operating system. The app itself does not record any audio and forwards only the recognized text, like a typed message. Whether the speech recognition sends audio to its provider for this (such as Google or Apple) depends on your device and its settings. On Android, the app requests on-device recognition where the system offers it.

In a voice conversation, AgencyAI reads the answers aloud. For this, the answer text goes to our server together with the language and the selected voice, and our server converts it into audio through a text-to-speech service. The app plays the audio without storing it. If this does not work, the text-to-speech of your device reads the answers aloud.

9. Notifications

Notifications are optional. You only receive them if you turn them on in the app and your device allows them. The app then shows alerts about your paired server (messages, calls, transfers, mails, dispatches), about replies in support and about friends and direct messages.

For push notifications, the app registers with the operating system's push service: on Apple devices with the Apple Push Notification Service (APNs), on Android with Google's Firebase Cloud Messaging (FCM). The app sends the resulting push token to our relay, together with the paired server, the name of the server and of your character, your language, your notification sound and the types of notifications that you have turned off. If you are signed in, the push token also goes to help.agencyg.de, for notifications about your account. The game server does not receive the push token.

Push notifications are delivered through the servers of Apple or Google, respectively. A notification can contain excerpts from the text, such as the beginning of a message. On Android, the app also asks the relay itself for new alerts while it is open, and in the background about every 15 minutes. The app stores the alerts it receives on the device. You can turn off notifications at any time in the app or in your device settings; if you turn them off in the app, the app unregisters the push token.

Occasionally we send product messages about new scripts and updates. You can turn them off at any time, free of charge and permanently, in the notification settings of the app, regardless of whether you have Pro or Max. The legal basis for notifications is the performance of our usage contract (Art. 6(1)(b) GDPR), and for product messages our legitimate interest in informing you about our scripts (Art. 6(1)(f) GDPR).

10. AgencyAI

AgencyAI is the AI assistant in the app. When you write to it, the app sends the following to our server companion.agencyg.de: the most recent messages of the conversation (at most twelve, text only), your language, the selected AI tier and, if you have one, your proof of purchase for Pro or Max, so that the right quota applies. If you have created your own AgencyAI, its name, its tone and your instructions are sent along. The request is signed with your device ID; your sign-in is not sent along.

With Agency Max, you can additionally give AgencyAI data from your active game server: the server name, the name of your character, whether you are in the game, your account balance and cash in the game, and the status of an ongoing ride. This is switched off until you switch it on, and you choose each group individually. Also with Max, AgencyAI can trigger a web search for questions that need current information. In that case, your question or a search query derived from it is sent to a search service.

Our server forwards the request to an AI provider, which processes it on our behalf as a processor (Art. 28 GDPR): OpenAI and, depending on the model tier, Groq. We have agreed with them that your inputs are not used to train their models.

The chat history is stored only on your device; on Android, the app keeps it only for Max users (at most 30 conversations). You can delete it in the app, either individually or entirely. Please do not enter sensitive data, such as passwords, payment data or health data. AI answers can be wrong; please check important information. The legal basis is the performance of our usage contract (Art. 6(1)(b) GDPR).

11. Help and support

You can reach support in the app and at help.agencyg.de; both are the same ticket system. For a ticket we store the subject, category, your messages, status and language, an e-mail address for notifications if you provide one (required for Google and Apple accounts), and a Tebex transaction number if you provide one; we verify it with Tebex.

We store attachments (images and other files up to 10 MB) on our support server. On Android, the app re-encodes images before uploading them (at most 2560 pixels per side); this drops capture data such as the time or the device model. Other files are uploaded unchanged and may contain such information.

An AI assistant reads the ticket, prepares it and suggests replies. On request, it also revises your draft before you send it. For this, the content is sent to our AI providers (section 17). Our team sees the tickets and can take over at any time. With Agency Max, you can pass a ticket directly to the team without AI.

We notify you of replies by Discord direct message or e-mail (sent through Brevo), depending on what you choose. If you share a ticket, anyone who opens the link and signs in can read the ticket and reply to it. The legal basis is the performance of our contract and our legitimate interest in well-functioning customer support (Art. 6(1)(b) and (f) GDPR).

12. Friends and direct messages

In the app, you can find friends through their handle, a friend code or an invite link, send and accept requests, write direct messages, and block and report users. This runs through our service help.agencyg.de.

Other users see your profile: display name, handle, profile picture and your plan (Pro or Max). The app also shows your online status, when you were last active, and your ranks on game servers (job and rank, reported by the game server), to the extent that our server releases them for the respective user. The server derives the online status from your use of the app. The app does not collect your location.

Our server stores direct messages so that they reach you and the other person on all devices. If you report a user or a message, our team sees the report with the reason and the reported message. So that your plan can be displayed, the app sends your proof of purchase for Pro or Max along at startup for verification. The legal basis is the performance of our usage contract (Art. 6(1)(b) GDPR) and, for reports, our legitimate interest in safe interaction between users (Art. 6(1)(f) GDPR).

13. AgencyMod

AgencyMod is our Discord bot. If you are signed in with Discord or have linked Discord to your account, the app asks at startup which Discord servers you manage with AgencyMod and connects them to the app. In doing so, the identifiers of these servers, your device name and your language are sent to our server. Settings and images that you set in the app for AgencyMod go to the AgencyMod service at bot.agencyscripts.dev.

14. Purchases

The app offers Agency Companion Pro (one-time purchase) and Agency Max (subscription). Payment is made through Google Play, Apple or our web shop, depending on the version. We never receive your payment data such as card or account numbers and passwords; Google, Apple, Tebex or PayPal process them under their own privacy policies.

Google Play (Android, Google Play version)

You buy in the Google Play dialog. The app passes your device ID to Google as an obfuscated account identifier. It then sends the purchase to our server for verification: the purchase token from Google, the product ID, the order number, the purchase time and your language, plus your device ID and, if you are signed in, your session. Our server asks Google whether the purchase is valid, for a subscription also about its term and renewal, and then activates it.

For this we store a hash of the purchase token (not the token itself), the order number from Google, the device IDs on which the purchase is activated (at most two), the ID of your account if you were signed in, the license code issued, the status of the purchase, the start and expiry of a subscription and whether it was a test purchase. To detect refunds, we check the purchase with Google again when the app presents it again, and we query Google for the list of refunded purchases.

Apple (iOS, iPadOS, macOS)

Apple handles purchases through the App Store. For verification, the app sends us the transaction confirmation signed by Apple. Apple also notifies us of events relating to purchases and subscriptions, such as renewal, cancellation or refund. We store the numbers of the transactions that we have already processed.

Web shop (Android, direct download)

In the agencyg.de version, you buy Pro, Max and scripts in the browser through our web shop. Payment is made with Tebex (with sign-in through Cfx.re) or with PayPal. We receive the order and payment numbers, the status, the product purchased and, where the payment provider passes it on, your e-mail address. You receive Pro as a license code, which we link to at most two device IDs; we link a Max subscription to your device ID and, if you are signed in, to your account.

If you are signed in with the same Discord account as in the web shop, the app also shows your points balance, your purchased scripts, your order history and your shopping cart from your shop account. Our server retrieves this from the shop.

Proof of purchase and internal reporting

After the purchase, the app receives a proof of purchase signed by us and bound to your device. The app re-checks license codes about every 14 days. We report purchases made through Apple and the web shop internally in a channel of our team on Discord, with the product, amount, platform, purchase or transaction number and, for web shop purchases, where applicable your account name. The legal basis is the performance of the purchase contract (Art. 6(1)(b) GDPR), our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR) and, for accounting records, our legal obligation to retain them (Art. 6(1)(c) GDPR).

15. Referral program

Each device receives its own invite code. For this, the app registers your device ID with our referral service at startup and queries your status. When someone redeems a code, the device ID, the paired game server and a proof from the device (a signature from the system's key store) are sent to the service. For this we store the proof from the device; we store device IDs and IP addresses only as salted hashes. We use this data exclusively to credit referrals correctly and to prevent fraud, such as self-referrals, fake devices or automated redemptions. The legal basis is our legitimate interest in a fair program (Art. 6(1)(f) GDPR).

16. Backup, updates and what stays on the device

On Android, the app creates a small backup through Google's Block Store so that you can continue on a new device: your paired servers with their access tokens, the name and number of your character, your Pro license code with its proof of purchase, your accent color, the app lock, your notification settings and details about the trial period and bonus. If backup is turned on in your Google account, Google stores it there. When you move to a new device with Android's transfer feature, further app data may come along; the access tokens of the pairings are excluded from this.

On Apple devices, app settings and pairing data, such as saved servers and display and notification settings, can be synchronized through your Apple account (iCloud). This data is then held by Google or Apple, respectively, under their terms; we have no access to it.

The direct-download version checks agencyg.de for updates and downloads them only from there. The app loads profile pictures and images from the game from the server on which they are hosted, such as Discord, Google or your game server, in part through our relay; the respective server sees your IP address in the process.

The app lock checks your fingerprint or face through the system; we receive none of it. Widgets, shortcuts and your notification history stay on your device.

17. Recipients and third countries

We do not sell data and do not pass it on for advertising. We use the following service providers, each only for the purpose stated:

  • OpenAI, Groq and Anthropic: AgencyAI answers and the AI in support.
  • a text-to-speech service: reading aloud in the voice conversation; a search service: the web search of AgencyAI.
  • Brevo: e-mails about your tickets.
  • Cloudflare: network service for some of our web addresses.
  • Discord: sign-in, notifications about tickets and internal purchase reports to our team.
  • Google: sign-in, Google Play, Firebase Cloud Messaging, Block Store and ML Kit.
  • Apple: sign-in, App Store, push notifications (APNs) and iCloud.
  • Tebex, Cfx.re and PayPal: payment in the web shop.

The game server operators that you pair with are separate controllers (section 6).

Some of these providers are based in the USA or process data there, such as OpenAI, Groq, Anthropic, Google, Apple, Discord and Cloudflare. We base the transfer on an adequacy decision of the European Commission (for the USA, the EU-U.S. Data Privacy Framework, where the provider is certified under it) or on the Standard Contractual Clauses of the European Commission.

18. Retention periods

  • On your device: until you delete the data in the app, sign out, unpair or uninstall the app.
  • Account, friends and direct messages: until you delete your account.
  • Tickets: up to 24 months after closure, earlier on request.
  • AgencyAI quota: 30 days.
  • Push registrations: until you turn off notifications or unpair, or until Apple or Google declares the token invalid.
  • Proofs of purchase: as long as the activation applies, so that your purchase is preserved after a reinstallation or on another device, and afterwards only to the extent that statutory retention obligations exist.
  • Accounting records: ten years under § 147 of the German Fiscal Code (Abgabenordnung); during this time they are blocked for any other use.
  • Referral program: as long as necessary for verification and for the reward to remain valid.

19. Your rights and deleting your account

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing that is based on our legitimate interest (Art. 21). You can also lodge a complaint with a supervisory authority (section 1).

You can exercise two of these directly in the app, via your profile picture on the home screen, under "Your data":

  • Delete account removes your login, the links between your sign-in methods, your support tickets including attachments, your stored e-mail address, your notification registrations and your purchase history from our servers. Records that we are legally required to retain are kept. Deletion is permanent. You remove data on your device by uninstalling the app.
  • Export my data gives you the account data we have stored about you as a machine-readable JSON file.

Proofs of purchase that are bound to your device ID, such as a purchase through Google Play, are kept so that your purchase remains valid. On request, we delete them too; the activation then lapses. For data held by game server operators, contact them. For anything else, write to us at [email protected]. We reply within one month.

20. Children

The app is not aimed at children. It is intended for people who play on FiveM roleplay servers.

21. Changes

If the app changes, we update this policy. The version with the date above applies.