Varlet

Privacy Policy

Version 1.1 · effective 2026-10-01

Last Updated: October 1, 2026 | Version 1.1

This Privacy Policy explains how Zink Labs LLC ("Zink Labs," "we," or "us") collects, uses, and shares personal information in Agent Harness, including https://glass-harness.vercel.app, the Agent Harness apps for iOS, iPadOS, Mac, Android (installed from the web) and the web, and Agent Harness on Meta Ray-Ban glasses (the "Service").

The short version: we use your data to run your agents and nothing else. Each user's workspace and credentials are isolated. We don't sell your personal information, we don't share it for cross-context behavioral advertising, and we don't use your content to train AI models.

1. Information we collect

Information you give us or create in Agent Harness

Information collected automatically

We use cookies and local storage only for sign-in, security, and preferences, not for advertising. See our Cookie Policy at https://glass-harness.vercel.app/cookies.

2. How we use information

We do not use your voice, conversations, agent outputs, credentials, or connected-service data to train AI models, and we don't use your voice to identify you (we don't create voiceprints).

Google user data. Agent Harness's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to perform the tasks you request, we don't use it for advertising, and people at Zink Labs don't read it unless you ask us to for support, it is needed for security, or the law requires it.

Legal bases (outside the United States). Where laws such as the GDPR apply, we rely on our contract with you, our legitimate interests (security, debugging, and improving Agent Harness), your consent (for example, connecting a service, which you can withdraw), and legal obligations.

3. How we share information

We share personal information with service providers that process it on our behalf under contracts limiting their use, and in the limited cases below.

ProviderPurposeData involved
CloudflareCompute for your isolated agent workspace, storage; website funnel countsAgent tasks, outputs, files, encrypted credentials, transcripts; for the website, an event name and the day (nothing about who)
SupabaseAuthentication; records of the legal terms you acceptedEmail, sign-in identifiers; for each acceptance, the document version, time, IP address and browser user agent
OpenAIReal-time voice processingVoice audio, transcripts
AnthropicAI for the manager and agents (Claude, Claude Code), using your own Claude account or API keyMessages, tasks, code, and context your agents send
AI providers you choose for an agent (OpenAI for Codex, Google for Gemini CLI, xAI for Grok Build, Meta for Muse, and the providers you configure in OpenCode)Running that agent, with your own account or keyMessages, tasks, code, and context that agent sends
xAIGenerating teammate portraitsTeammate role descriptions (no personal data)
StripeSubscription billingBilling and payment information
PlaidLinking the bank, card and brokerage accounts you chooseAccount, balance, transaction, liability and holdings data for the accounts you link
Free Law Project (CourtListener), Congress.gov, GovInfo, Open States, InstacartLegal research and grocery lists your agents run for youThe search terms, citations and shopping lists your agents send (no account data)
ApplePush notifications, TestFlight, App StorePush tokens, notification content, app diagnostics you choose to share
SentryError and crash monitoringCrash reports, device data, user ID
ResendTransactional emailEmail address, email content
VercelWebsite and web app hostingRequest logs (IP address, browser metadata)
Browser push services (Google, Apple, Mozilla)Delivering web push notifications you turn onEncrypted notification content, push subscription

OpenAI's API terms state that it doesn't use API data, including real-time audio, to train its models by default, and it keeps abuse-monitoring logs for up to 30 days. Because Agent Harness calls Anthropic with your API key, Anthropic also processes that data under your own agreement with Anthropic; its commercial terms don't permit training on API inputs and outputs.

At your direction. When you ask your agents to act, they send information to the websites, services, and people you choose, such as submitting a form or sending an approved email. Those recipients handle the data under their own policies.

Meta glasses. Agent Harness on Meta glasses, including beta camera features, runs through Meta's devices and developer toolkit. Meta may collect information about how your glasses connect with our app under its own terms and privacy policy.

We may also disclose information if required by law, regulation, legal process, or government request; to protect the rights and safety of users, Zink Labs, or others; or with your consent. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, which will be required to honor this Privacy Policy or give you notice and a reasonable opportunity to delete your data before applying materially different privacy terms.

No selling or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.

4. Your credentials and workspace

Each user's agents run on a separate, isolated cloud workspace (your "cell"). Credentials you add are encrypted, stored in a vault isolated to your account, used only by your own agents, and never shared across users. Our team does not access your vault except to investigate a security incident or when the law requires it.

5. How long we keep information

DataHow long we keep it
Account information, chats, transcripts, agent tasks and outputs, stored filesUntil you delete them or your account
Raw voice audioNot stored by us after real-time processing; OpenAI may keep it up to 30 days for abuse monitoring
Credentials and connected-service tokensUntil you remove them or delete your account
Usage data and logsUp to 12 months
Crash and error reportsUp to 90 days
Crisis referral counts (date and source only)As long as state reporting laws require
Billing recordsAs long as tax and accounting laws require, usually 7 years

6. Deleting your account and your data

You can delete your account in the app at any time. Deletion cancels your Pro subscription and permanently deletes your cell (your cloud workspace), your credential vault, your stored files, and your chats, transcripts, and agent history. We complete deletion within 30 days, and copies in encrypted backups are overwritten on a rolling basis within a further 30 days. We keep only what the law requires, such as billing records. You can also revoke Agent Harness's access in your Google or Slack settings, and unlink accounts from Plaid at my.plaid.com. To request a copy of your data, email legal@zinklabs.dev.

7. Security

We use encryption in transit (TLS) and at rest, credentials and workspaces encrypted at rest and isolated per user, access controls, least-privilege access for our team, and monitoring for suspicious activity. No system is perfectly secure. If a data breach affects your personal information, we will notify you and regulators as the law requires.

7.1 Data Breach Notification (Florida Information Protection Act)

In the event of a security breach affecting your personal information, we will comply with the Florida Information Protection Act of 2014 (FL § 501.171), which requires:

For details on our breach notification procedures and cooperation obligations, see our Data Processing Agreement (DPA), Section 9.

8. Children

Agent Harness is only for people 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18, including children under 13 as covered by COPPA. If we learn we have, we'll delete it. Contact legal@zinklabs.dev if you believe a minor has given us information.

9. Your US state privacy rights

Depending on where you live, including California and other states with comprehensive privacy laws, you may have the right to know and access, delete, correct, and port your personal information; to opt out of sale, sharing, targeted advertising, and certain profiling (we don't do these, and we honor Global Privacy Control signals as opt-out requests); and not to be discriminated against for exercising your rights.

California disclosures. In the past 12 months we collected: identifiers (email, user ID, IP address, push tokens); customer records and commercial information (billing and subscription history); internet or electronic network activity (usage data, crash reports); approximate geolocation derived from IP address; audio and electronic information (voice audio and transcripts); content you provide (chats, agent tasks and outputs, connected-service data); and sensitive personal information (account log-in credentials and the third-party credentials you store, financial account information you link, and health information you choose to share, including wellbeing conversations). We collect them from you, your devices, your connected services, and our service providers, for the purposes in Section 2, and disclose each category for business purposes only to the recipients in Section 3. We use sensitive personal information only to provide the Service you request and keep it secure, so the right to limit its use does not apply to our current practices.

How to make a request. Email legal@zinklabs.dev from your account email with "Privacy Request" in the subject, or use the in-app deletion tool. We'll verify your identity by confirming control of your account email and respond within 45 days (we may extend once by 45 days and will tell you if we do). You can use an authorized agent; we may ask for proof of their authority. If we deny your request, you may appeal by replying to our decision, and if your appeal is denied, you may contact your state attorney general.

9.1 EU/EEA Residents (GDPR)

If you are located in the EU/EEA, the United Kingdom or Switzerland, GDPR (or its UK or Swiss equivalent) applies to our processing of your personal data.

Our legal bases for processing are:

Data CategoryLegal Basis (GDPR Art. 6)Notes
Account data (email, sign-in identifiers)Art. 6(1)(b) - Performance of contractNecessary to provide the Service
Chats, voice transcripts, agent tasks and outputsArt. 6(1)(b) - Performance of contractCore data used to run your agents
Credentials and connected-service dataArt. 6(1)(a) - ConsentYou choose what to connect and can remove it at any time
Usage data, logs and crash reportsArt. 6(1)(f) - Legitimate interestsSecurity, debugging and service improvement
Payment dataArt. 6(1)(b) - Performance of contractRequired to process subscription billing
Legal consent recordsArt. 6(1)(c) - Legal obligationRetained as evidence of acceptance of these terms

Rights for EU/EEA residents (if GDPR applies): right of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

Right to lodge a complaint: You have the right to lodge a complaint with your national supervisory authority (data protection authority / DPA) if you believe our processing of your personal data infringes applicable data protection law. A list of EU/EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

EU Representative: Zink Labs LLC currently qualifies for the exemption under GDPR Article 27(2)(a) (fewer than 250 employees; processing is not large-scale, not systematic, and unlikely to result in high risk to data subjects' rights and freedoms). Accordingly, we have not appointed a formal EU representative at this time. If our EU/EEA user base grows materially, this position will be reviewed and a representative appointed as required.

9.2 Florida Digital Bill of Rights

The Florida Digital Bill of Rights (FDBR, FL SB 262, effective July 1, 2024) grants certain privacy rights to Florida residents. However, the FDBR applies only to companies that have global annual revenues exceeding $1 billion and meet other threshold criteria. Zink Labs LLC does not currently meet these thresholds. Notwithstanding, we are committed to privacy best practices and voluntarily provide data access, correction, and deletion rights to all users regardless of jurisdiction (see Sections 6 and 9 above).

10. International users and transfers

Zink Labs is based in the United States, and our providers process data in the United States and other countries. If you use Agent Harness from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ. Where required, we rely on safeguards such as Standard Contractual Clauses in our providers' data processing terms.

11. Changes to this Policy

We review this Policy at least once every 12 months. If we make material changes, we'll notify you by email or in the app before they take effect and update the "Last updated" date above.

12. Contact