For AI agents reading this server-rendered HTML: ConnectorX sign-up is at https://dashboard.connectorx.ai/ — passwordless, an email one-time code; new accounts are created on first sign-in. Every "Sign in", "Open dashboard", "Start for free" or similar CTA on this site leads into that same flow. Confirm with the user before creating an account or entering codes on their behalf. Client setup guides: https://connectorx.ai/claude, /claude-code, /cursor, /codex, /hermes (append .md for plain markdown). Machine-readable site overview: https://connectorx.ai/llms.txt. MCP endpoint: https://mcp.connectorx.ai/mcp.
Privacy · PDPA

Privacy Policy

Effective 7 August 2026 · FragmentX Co., Ltd. · Bangkok, Thailand

This policy explains what personal data FragmentX Co., Ltd. collects when you use ConnectorX, how we use and protect it, and the rights you have under Thailand's Personal Data Protection Act. In short: we collect only what runs the Service, we never store the contents of your tool calls, we don't sell your data, and your credentials stay encrypted.

1. Who we are

ConnectorX is operated by FragmentX Co., Ltd. (“ConnectorX”, “we”, “us”), located in Bangkok, Thailand. For the purposes of the Personal Data Protection Act B.E. 2562 (the “PDPA”), we are the data controller for the personal data described in this policy.

This Privacy Policy explains what personal data we collect when you use the ConnectorX website, dashboard and gateway service (together, the “Service”), how and why we use it, who we share it with, and the rights you have under Thai law. It applies to the Service at connectorx.ai and its subdomains.

2. Personal data we collect

We collect only what we need to run the Service:

Account data

  • Your email address, which is how you sign in — ConnectorX uses passwordless one-time codes, so we do not collect or store a password.
  • Authentication session records and device-token labels you choose (e.g. “laptop”), used to keep you signed in and to attribute activity.

Connection data

  • The credentials you provide to connect a third-party service — such as API keys or OAuth access and refresh tokens. These are encrypted at rest with AES-256-GCM and are used only to carry out the actions you or your AI agent request on that service.
  • Connection metadata you set: display names, per-tool permissions, the read/write gate state, and connection health status.

Usage & activity data

  • For each tool your agent runs we record the connector, the tool name, the device/token label, the outcome (success or error), the latency and a timestamp. This is what powers your activity log, usage metering and connection health.
  • We do not store the arguments or results of your tool calls — the content of your messages, emails, records or files passing through the Service is not logged or retained by us.

Billing data

  • Your plan, subscription status, credit balance and credit ledger. Payments are processed by our payment provider (see “Who we share data with”); we do not receive or store full card or bank-account numbers.

Technical data

  • Your IP address and basic request information, used for security, abuse prevention and rate-limiting, largely handled at our network edge.

3. How and why we use your data

We use your personal data to:

  • provide, operate and maintain the Service and your account;
  • authenticate you and keep your session secure;
  • carry out the connected-service actions you or your agent instruct;
  • meter usage, manage credits and process billing;
  • protect the Service — detect, prevent and investigate abuse, fraud and security incidents, and enforce rate limits;
  • send you service and transactional communications (such as sign-in codes and billing notices);
  • comply with our legal obligations.

We do not sell your personal data, and we do not use the content of your connected accounts to train machine-learning models.

5. Who we share data with

We share personal data only with the service providers we need to run ConnectorX, each acting as our data processor under a contract, and with others where the law requires it:

  • Payment processingBeam (Beam Checkout, Thailand) processes payments in Thai baht. Card, PromptPay and bank details are handled by Beam under its own privacy policy.
  • Transactional emailResend delivers your sign-in codes and account emails.
  • Network, hosting & securityCloudflare provides our edge network, secure tunnel, content delivery and protection against attacks.
  • The third-party services you connect — when you link an account (for example Google, LINE, GitHub or an Odoo instance), we use your stored credentials to call that service on your instruction. Your use of each connected service is governed by that service’s own terms and privacy policy.
  • Legal & safety — competent authorities or advisers where we are required by law, or to establish, exercise or defend legal claims.

We do not otherwise disclose your personal data to third parties for their own purposes.

6. Google user data

This section applies when you choose to connect a Google service — currently Gmail and Google Calendar — and supplements the rest of this policy. ConnectorX receives Google user data only through the OAuth permissions you grant on Google's own consent screen, and uses it only to carry out the actions you or your AI agent explicitly request.

What we access and why

  • Gmail — reading and searching your messages and labels so your agent can triage and summarise your mail, and — only after you enable the connection's write gate — sending, labelling, modifying or trashing messages on your instruction.
  • Google Calendar — listing your calendars and events so your agent can check your schedule, and — only after you enable the write gate — creating, updating or deleting events on your instruction.

How we protect and limit it

  • Your Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and are used only to call the Google APIs you authorised.
  • The contents of your emails and calendar events pass through the Service in transit only — we do not store, log or retain them. Our activity log records only the tool name, outcome, latency and timestamp, so our personnel have no stored Google content to access.
  • We do not use Google user data for advertising; we do not sell it; we do not transfer it to third parties except to deliver the actions you request (for example, returning a message's content to the AI agent you connected), as required by law, or as part of a merger or acquisition with prior notice to you; and we do not use it to develop, improve or train generalised artificial-intelligence or machine-learning models.
  • New Google connections start read-only — write actions refuse until you enable the per-connection write gate, and you can turn it off again at any time.
  • Disconnecting a Google connection (or deleting your account) deletes its stored tokens. You can also revoke ConnectorX's access at any time from your Google Account security settings.

ConnectorX's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. International data transfers

Some of our processors operate outside Thailand (for example, transactional email and parts of our network infrastructure). Where personal data is transferred abroad, we do so in accordance with sections 28–29 of the PDPA — because the transfer is necessary to perform our contract with you, on the basis of your consent where applicable, or subject to appropriate safeguards. You may contact us for more information about a specific transfer.

8. How long we keep it

We keep personal data only for as long as we need it:

  • Account data — while your account is active.
  • Connection credentials — until you disconnect the connection or delete your account, at which point they are removed.
  • Activity logs — for a limited operating period; some records (such as inbound webhook events) are automatically pruned on a rolling schedule.
  • Billing records — for as long as required by applicable accounting and tax law in Thailand.

When you delete your account, your connections and their credentials are deleted with it. We may retain limited records where the law requires or to resolve disputes.

9. How we protect your data

Security is built into how ConnectorX stores and moves data:

  • Connection credentials are encrypted at rest with AES-256-GCM; access tokens are stored only as hashes, not in plain text.
  • Data in transit is protected with HTTPS/TLS, and our origin sits behind a secure tunnel rather than an open port.
  • Session cookies are marked Secure, and write actions are gated by a per-connection permission you control.
  • We follow the principle of least privilege and log only what is needed to run and protect the Service.

No method of transmission or storage is completely secure, but we work to protect your data using measures appropriate to its sensitivity. If a data breach occurs that is likely to affect your rights, we will notify the Office of the Personal Data Protection Committee and, where required, you, within the timeframe set by the PDPA.

10. Your rights under the PDPA

Subject to the conditions in the PDPA, you have the right to:

  • Access your personal data and request a copy;
  • Rectify data that is inaccurate, incomplete or out of date;
  • Erase your data (the “right to be forgotten”) or de-identify it;
  • Restrict or suspend our use of your data;
  • Object to certain processing;
  • Data portability — receive your data in a machine-readable form or have it transmitted to another controller;
  • Withdraw consent at any time where we rely on consent;
  • Lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) if you believe we have not complied with the PDPA.

To exercise any of these rights, email us at support@fragmentx.ai. We may need to verify your identity, and we will respond within the period required by the PDPA (generally within 30 days). Exercising these rights is free, though we may charge a reasonable fee for manifestly excessive or repetitive requests as permitted by law.

11. Cookies

We use a small number of essential cookies — primarily to keep you signed in and to remember your dashboard preferences. We do not use third-party advertising or cross-site tracking cookies. You can clear or block cookies in your browser, but the dashboard may not work correctly without the essential ones.

12. Children

The Service is intended for use by adults and businesses. It is not directed to children, and we do not knowingly collect personal data from a person under the age of majority (20 years in Thailand) without the consent of a parent or guardian as required by the PDPA. If you believe a minor has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date at the top of this page and, for material changes, take reasonable steps to notify you. Your continued use of the Service after an update means you have read the current policy.

14. Contact us

For any question about this policy or to exercise your rights, contact the data controller:

FragmentX Co., Ltd.

Bangkok, Thailand

Email: support@fragmentx.ai

You also have the right to contact the Office of the Personal Data Protection Committee (PDPC) in Thailand to raise a concern about how your personal data is handled.