Data practices

Privacy Policy

Last updated July 20, 2026

Information in your environment

Agent prompts, credentials, and task results should remain within the runtime and services you configure. Review the privacy terms and logging behavior of every connected provider before supplying data.

Credentials

Use runtime-managed secrets and narrowly scoped keys. Never place API keys in prompts, source control, exported lists, screenshots, or support messages.

Prospecting data

You are responsible for determining the lawful basis, permitted purpose, retention period, and response process for business contact data used in your workflows. Regional requirements may differ.

Operational records

Technical logs may be necessary to diagnose installation and execution. Minimize personal data in logs, restrict access, and retain records only as long as needed for a defined purpose.

Purpose and minimization

Configure a workflow for a defined business purpose and avoid collecting fields unrelated to that purpose. A broad source does not make every available field necessary. Use exclusions and result limits during testing, then document why a field enters a downstream system.

Retention and deletion

Set retention periods according to operational need, contractual obligations, and applicable law. Remove test exports after validation, delete stale records where required, and ensure copies in connected systems follow the same policy. Uninstalling the skill does not erase provider-held data.

International processing

An agent runtime, enrichment provider, or destination may process information in another jurisdiction. Evaluate transfer mechanisms, provider terms, and regional requirements before connecting services. References to GDPR or CCPA/CPRA describe evaluation considerations and do not represent certification.

Security response

If you suspect exposed credentials or unintended access, revoke affected keys, disable connected tools, preserve relevant technical records, and follow your organization's incident process. Rotating a key without reviewing logs may leave the cause unresolved.

Your choices

You can stop using the skill, revoke connected credentials, remove configured integrations, and follow your runtime's uninstall procedure. Provider-held data remains subject to each provider's controls.