Privacy Policy
Version 1.1 · effective 2026-10-01
Last Updated: October 1, 2026 | Version 1.1
This Privacy Policy explains how Zink Labs LLC ("Zink Labs," "we," or "us") collects, uses, and shares personal information in Agent Harness, including https://glass-harness.vercel.app, the Agent Harness apps for iOS, iPadOS, Mac, Android (installed from the web) and the web, and Agent Harness on Meta Ray-Ban glasses (the "Service").
The short version: we use your data to run your agents and nothing else. Each user's workspace and credentials are isolated. We don't sell your personal information, we don't share it for cross-context behavioral advertising, and we don't use your content to train AI models.
1. Information we collect
Information you give us or create in Agent Harness
- Account information: your email address and sign-in identifiers.
- Voice audio and transcripts: when you talk to Agent Harness, your voice audio is streamed for real-time processing, and we keep text transcripts of your conversations.
- Chats and messages: what you type to Agent Harness and what the manager and agents reply.
- Agent tasks and outputs: the tasks you give your agents, the steps they take (including their terminal sessions), the plans, code, pull requests, files, screenshots, and results they produce in your workspace, and the repositories you connect.
- Credentials you add: passwords, API keys (including your Claude account token or Anthropic API key, and any other AI provider keys you add for an agent), and similar secrets you store for your agents.
- Connected services data: if you connect Google or Slack, the account details and content your agents access to do the tasks you ask for, such as emails, calendar events, files, or messages.
- Financial account data: if you link bank, card or brokerage accounts through Plaid, or connect Robinhood, the balances, transactions, recurring charges, loans and holdings your Finance teammate reads to answer you. We never receive your bank login.
- Health and wellbeing information: if you use the Health Coach or the Wellbeing Coach, the health data you choose to sync (such as sleep, heart rate and steps from Apple Health), lab results you send, and what you share in conversations with the Wellbeing Coach.
- Support messages: anything you send us.
Information collected automatically
- Device information: device type, operating system, app version, and push notification tokens (Apple push tokens, and web push subscriptions if you turn on notifications in a browser).
- Usage data: features used, voice minutes, agent run times, timestamps, IP address, and approximate location derived from IP address.
- Billing data: subscription plan, status, and payment history from Stripe. Stripe handles your full card details; we never see or store them.
- Crash and error reports: technical details about errors and the actions leading up to them.
We use cookies and local storage only for sign-in, security, and preferences, not for advertising. See our Cookie Policy at https://glass-harness.vercel.app/cookies.
2. How we use information
- Run the Service: understand your voice and text requests, dispatch your agents, let them use your credentials and connected services on your behalf, deliver results, and notify you, including when an action needs your approval.
- Billing and limits: manage your Pro subscription and track voice minutes against your monthly cap.
- Maintain and secure Agent Harness: debug problems, monitor performance, keep users isolated from each other, and prevent fraud and abuse.
- Communicate with you: sign-in links, receipts, renewal reminders, service and security notices, and support replies.
- Safety: when a message signals a crisis, show crisis resources such as the 988 Suicide and Crisis Lifeline right away (see our crisis protocol at https://glass-harness.vercel.app/docs/crisis/). We keep only a count of these referrals, with the date and whether your message or the coach's reply triggered it, for state reporting; never the message text.
- Legal: enforce our Terms and comply with law.
We do not use your voice, conversations, agent outputs, credentials, or connected-service data to train AI models, and we don't use your voice to identify you (we don't create voiceprints).
Google user data. Agent Harness's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to perform the tasks you request, we don't use it for advertising, and people at Zink Labs don't read it unless you ask us to for support, it is needed for security, or the law requires it.
Legal bases (outside the United States). Where laws such as the GDPR apply, we rely on our contract with you, our legitimate interests (security, debugging, and improving Agent Harness), your consent (for example, connecting a service, which you can withdraw), and legal obligations.
3. How we share information
We share personal information with service providers that process it on our behalf under contracts limiting their use, and in the limited cases below.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Compute for your isolated agent workspace, storage; website funnel counts | Agent tasks, outputs, files, encrypted credentials, transcripts; for the website, an event name and the day (nothing about who) |
| Supabase | Authentication; records of the legal terms you accepted | Email, sign-in identifiers; for each acceptance, the document version, time, IP address and browser user agent |
| OpenAI | Real-time voice processing | Voice audio, transcripts |
| Anthropic | AI for the manager and agents (Claude, Claude Code), using your own Claude account or API key | Messages, tasks, code, and context your agents send |
| AI providers you choose for an agent (OpenAI for Codex, Google for Gemini CLI, xAI for Grok Build, Meta for Muse, and the providers you configure in OpenCode) | Running that agent, with your own account or key | Messages, tasks, code, and context that agent sends |
| xAI | Generating teammate portraits | Teammate role descriptions (no personal data) |
| Stripe | Subscription billing | Billing and payment information |
| Plaid | Linking the bank, card and brokerage accounts you choose | Account, balance, transaction, liability and holdings data for the accounts you link |
| Free Law Project (CourtListener), Congress.gov, GovInfo, Open States, Instacart | Legal research and grocery lists your agents run for you | The search terms, citations and shopping lists your agents send (no account data) |
| Apple | Push notifications, TestFlight, App Store | Push tokens, notification content, app diagnostics you choose to share |
| Sentry | Error and crash monitoring | Crash reports, device data, user ID |
| Resend | Transactional email | Email address, email content |
| Vercel | Website and web app hosting | Request logs (IP address, browser metadata) |
| Browser push services (Google, Apple, Mozilla) | Delivering web push notifications you turn on | Encrypted notification content, push subscription |
OpenAI's API terms state that it doesn't use API data, including real-time audio, to train its models by default, and it keeps abuse-monitoring logs for up to 30 days. Because Agent Harness calls Anthropic with your API key, Anthropic also processes that data under your own agreement with Anthropic; its commercial terms don't permit training on API inputs and outputs.
At your direction. When you ask your agents to act, they send information to the websites, services, and people you choose, such as submitting a form or sending an approved email. Those recipients handle the data under their own policies.
Meta glasses. Agent Harness on Meta glasses, including beta camera features, runs through Meta's devices and developer toolkit. Meta may collect information about how your glasses connect with our app under its own terms and privacy policy.
We may also disclose information if required by law, regulation, legal process, or government request; to protect the rights and safety of users, Zink Labs, or others; or with your consent. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, which will be required to honor this Privacy Policy or give you notice and a reasonable opportunity to delete your data before applying materially different privacy terms.
No selling or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.
4. Your credentials and workspace
Each user's agents run on a separate, isolated cloud workspace (your "cell"). Credentials you add are encrypted, stored in a vault isolated to your account, used only by your own agents, and never shared across users. Our team does not access your vault except to investigate a security incident or when the law requires it.
5. How long we keep information
| Data | How long we keep it |
|---|---|
| Account information, chats, transcripts, agent tasks and outputs, stored files | Until you delete them or your account |
| Raw voice audio | Not stored by us after real-time processing; OpenAI may keep it up to 30 days for abuse monitoring |
| Credentials and connected-service tokens | Until you remove them or delete your account |
| Usage data and logs | Up to 12 months |
| Crash and error reports | Up to 90 days |
| Crisis referral counts (date and source only) | As long as state reporting laws require |
| Billing records | As long as tax and accounting laws require, usually 7 years |
6. Deleting your account and your data
You can delete your account in the app at any time. Deletion cancels your Pro subscription and permanently deletes your cell (your cloud workspace), your credential vault, your stored files, and your chats, transcripts, and agent history. We complete deletion within 30 days, and copies in encrypted backups are overwritten on a rolling basis within a further 30 days. We keep only what the law requires, such as billing records. You can also revoke Agent Harness's access in your Google or Slack settings, and unlink accounts from Plaid at my.plaid.com. To request a copy of your data, email legal@zinklabs.dev.
7. Security
We use encryption in transit (TLS) and at rest, credentials and workspaces encrypted at rest and isolated per user, access controls, least-privilege access for our team, and monitoring for suspicious activity. No system is perfectly secure. If a data breach affects your personal information, we will notify you and regulators as the law requires.
7.1 Data Breach Notification (Florida Information Protection Act)
In the event of a security breach affecting your personal information, we will comply with the Florida Information Protection Act of 2014 (FL § 501.171), which requires:
- Individual Notification: We will notify affected Florida residents no later than thirty (30) days after determination of the breach or reason to believe a breach occurred.
- Notification Content: The notice will include the date (or estimated date) of the breach, a description of the personal information involved, and contact information for the Company.
- Regulatory Notification: If the breach affects 500 or more individuals, we will notify the Florida Department of Legal Affairs within 30 days of the breach determination.
- Large-Scale Breaches: If the breach affects 1,000 or more individuals, we will also notify all consumer reporting agencies.
- Notification Method: Notification will be provided by email (to your registered account email), by mail, or by substitute notice as permitted under FIPA if direct contact information is unavailable.
For details on our breach notification procedures and cooperation obligations, see our Data Processing Agreement (DPA), Section 9.
8. Children
Agent Harness is only for people 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18, including children under 13 as covered by COPPA. If we learn we have, we'll delete it. Contact legal@zinklabs.dev if you believe a minor has given us information.
9. Your US state privacy rights
Depending on where you live, including California and other states with comprehensive privacy laws, you may have the right to know and access, delete, correct, and port your personal information; to opt out of sale, sharing, targeted advertising, and certain profiling (we don't do these, and we honor Global Privacy Control signals as opt-out requests); and not to be discriminated against for exercising your rights.
California disclosures. In the past 12 months we collected: identifiers (email, user ID, IP address, push tokens); customer records and commercial information (billing and subscription history); internet or electronic network activity (usage data, crash reports); approximate geolocation derived from IP address; audio and electronic information (voice audio and transcripts); content you provide (chats, agent tasks and outputs, connected-service data); and sensitive personal information (account log-in credentials and the third-party credentials you store, financial account information you link, and health information you choose to share, including wellbeing conversations). We collect them from you, your devices, your connected services, and our service providers, for the purposes in Section 2, and disclose each category for business purposes only to the recipients in Section 3. We use sensitive personal information only to provide the Service you request and keep it secure, so the right to limit its use does not apply to our current practices.
How to make a request. Email legal@zinklabs.dev from your account email with "Privacy Request" in the subject, or use the in-app deletion tool. We'll verify your identity by confirming control of your account email and respond within 45 days (we may extend once by 45 days and will tell you if we do). You can use an authorized agent; we may ask for proof of their authority. If we deny your request, you may appeal by replying to our decision, and if your appeal is denied, you may contact your state attorney general.
9.1 EU/EEA Residents (GDPR)
If you are located in the EU/EEA, the United Kingdom or Switzerland, GDPR (or its UK or Swiss equivalent) applies to our processing of your personal data.
Our legal bases for processing are:
| Data Category | Legal Basis (GDPR Art. 6) | Notes |
|---|---|---|
| Account data (email, sign-in identifiers) | Art. 6(1)(b) - Performance of contract | Necessary to provide the Service |
| Chats, voice transcripts, agent tasks and outputs | Art. 6(1)(b) - Performance of contract | Core data used to run your agents |
| Credentials and connected-service data | Art. 6(1)(a) - Consent | You choose what to connect and can remove it at any time |
| Usage data, logs and crash reports | Art. 6(1)(f) - Legitimate interests | Security, debugging and service improvement |
| Payment data | Art. 6(1)(b) - Performance of contract | Required to process subscription billing |
| Legal consent records | Art. 6(1)(c) - Legal obligation | Retained as evidence of acceptance of these terms |
Rights for EU/EEA residents (if GDPR applies): right of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Right to lodge a complaint: You have the right to lodge a complaint with your national supervisory authority (data protection authority / DPA) if you believe our processing of your personal data infringes applicable data protection law. A list of EU/EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
EU Representative: Zink Labs LLC currently qualifies for the exemption under GDPR Article 27(2)(a) (fewer than 250 employees; processing is not large-scale, not systematic, and unlikely to result in high risk to data subjects' rights and freedoms). Accordingly, we have not appointed a formal EU representative at this time. If our EU/EEA user base grows materially, this position will be reviewed and a representative appointed as required.
9.2 Florida Digital Bill of Rights
The Florida Digital Bill of Rights (FDBR, FL SB 262, effective July 1, 2024) grants certain privacy rights to Florida residents. However, the FDBR applies only to companies that have global annual revenues exceeding $1 billion and meet other threshold criteria. Zink Labs LLC does not currently meet these thresholds. Notwithstanding, we are committed to privacy best practices and voluntarily provide data access, correction, and deletion rights to all users regardless of jurisdiction (see Sections 6 and 9 above).
10. International users and transfers
Zink Labs is based in the United States, and our providers process data in the United States and other countries. If you use Agent Harness from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ. Where required, we rely on safeguards such as Standard Contractual Clauses in our providers' data processing terms.
11. Changes to this Policy
We review this Policy at least once every 12 months. If we make material changes, we'll notify you by email or in the app before they take effect and update the "Last updated" date above.
12. Contact
- Company: Zink Labs LLC
- Email: legal@zinklabs.dev
- Website: https://www.zinklabs.dev