Skip to content

Legal

Privacy Policy

Effective
September 4, 2026
On this page
  1. 1. Introduction
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. AI Processing
  5. 5. Computer Realms and Shared Workspaces
  6. 6. Connected Services and Google User Data
  7. 7. How We Disclose Information
  8. 8. Legal Bases for Processing
  9. 9. Data Storage, Security, and International Processing
  10. 10. Data Retention and Deletion
  11. 11. Your Rights and Choices
  12. 12. Cookies
  13. 13. Children
  14. 14. Changes to This Policy
  15. 15. Contact Us

1. Introduction

Makina ("Makina," "we," "us," or "our") operates the makina.so website, applications, AI agent platform, and related services (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use and disclose it, how we protect it, and the choices available to you.

If you use Makina through an employer or another organization, that organization may control your account and its workspace data. Its own privacy notices and policies may also apply. When we process workspace content solely on an organization's instructions, the organization is responsible for those instructions and Makina acts as its service provider or processor.

2. Information We Collect

The information we collect depends on how you use the Service and which features and external services you choose to connect.

Account information

We collect information used to create and manage your account, such as your name, email address, profile details, authentication identifiers, account preferences, subscription status, and information showing that you meet our age requirements. Our authentication provider may process passwords, passkeys, or other login credentials directly.

Payment information

If you purchase a paid plan, our payment provider processes your payment details. We receive limited billing and transaction information, such as your billing name and address, plan, payment status, invoice details, and the last four digits and type of your payment method. We do not receive or store full payment card numbers unless we expressly tell you otherwise.

Content and agent activity

We process the information you provide to or create with the Service, including:

  • prompts, conversations, messages, files, images, audio, and other content;
  • agent profiles, instructions, skills, memories, preferences, and configurations;
  • tasks, routines, schedules, approvals, browser or computer actions, and task history;
  • webpages and page content, browser or computer state, screenshots or screen frames, and authorized terminal or tool activity;
  • outputs, artifacts, citations, evidence, and action receipts; and
  • feedback and corrections you provide.

This content may include personal information about you or other people. Please provide only information you are authorized to use and that is reasonably needed for your task.

If you choose to enable an optional screen-recording feature, we also process the resulting recordings. Screen recording is off by default, and Makina provides a notice and visible recording indicator when it is active.

Connected-service information

If you connect an external service, such as an email, calendar, messaging, file, or productivity account, Makina may access information from that service within the permissions you approve. Depending on the connection, this may include messages, attachments, events, contacts, files, account identifiers, workspace information, change notifications, and information about actions taken through the connection.

We also process connection status, authorized permission scopes, token references, and related technical information needed to maintain the connection.

Credentials and browser session data

OAuth tokens, API credentials, and similar connector secrets are stored in an encrypted token broker or secret store and are not intentionally included in AI prompts, ordinary logs, or agent histories. Browser cookies and login state may be stored in the protected browser profile for your computer realm so an authorized task can continue an authenticated session. Information retrieved through a connector or authenticated browser session may be sent to an AI model when needed to perform your instruction.

Usage, device, and security information

We automatically collect information needed to operate and protect the Service, such as IP address, approximate location derived from IP address, device and browser type, operating system, application version, pages and features used, task and tool status, timestamps, resource consumption, crash information, security events, and diagnostic data. We design routine telemetry to use identifiers and redacted metadata rather than the full contents of your tasks.

Communications

We collect information you provide when you contact support, report a problem, respond to a survey, submit feedback, or otherwise communicate with us.

3. How We Use Information

We use information to:

  • provide, operate, maintain, and secure the Service;
  • authenticate users and administer accounts, subscriptions, and workspaces;
  • understand your instructions and allow agents to complete authorized tasks;
  • maintain agent memory, preferences, schedules, and task continuity;
  • connect to external services and carry out actions you request;
  • send operational notices, security alerts, and service communications;
  • process payments and provide customer support;
  • detect, prevent, and investigate fraud, abuse, security incidents, and policy violations;
  • troubleshoot, measure performance, and improve reliability and user-facing features; and
  • comply with law, enforce our agreements, and protect the rights and safety of Makina, our users, and others.

We may create aggregated or de-identified information for analytics, capacity planning, security, research, and product improvement. We do not attempt to re-identify information that we maintain as de-identified, except to test whether our de-identification measures work or as permitted by law.

4. AI Processing

Makina uses AI model providers to understand instructions, generate responses, and select or support actions. To complete a task, we send the provider the context reasonably needed for that task, which may include prompts, relevant conversation history, selected files, information returned by connected services, webpage content, and tool results. Model providers process this information for us under their applicable agreements and data-handling terms.

Makina does not use your content to train generalized AI models unless you separately and affirmatively choose to participate in a feature or program that clearly permits that use. We do not allow our AI model providers to train their generalized models on your content when they process it on our behalf, except if you have separately directed or agreed to that use.

AI outputs can be incomplete or inaccurate. Makina's agents are designed to act within the permissions and approval rules configured for the workspace, but you remain responsible for reviewing important outputs and actions. Makina is not designed to make solely automated decisions about individuals that produce legal or similarly significant effects.

5. Computer Realms and Shared Workspaces

Makina provides a hosted computer realm that is logically isolated from other customer realms. A realm may contain agents, files, browser sessions, installed tools, memories, connections, and task history.

Agents and authorized people within the same realm may share and use the realm's files, browser login state, installed tools, connections, and other workspace resources. An individual agent, screen, browser tab, or folder is not a separate security boundary. We disclose this sharing when a realm is created or shared, and you should place people and agents in the same realm only when that sharing is appropriate.

If an organization manages your realm, its authorized administrators may manage membership, permissions, connections, retention settings, exports, and access to organization-controlled content.

Tasks and routines may continue running after you close the application. Makina retains the state needed to continue, verify, and recover those tasks.

6. Connected Services and Google User Data

Makina accesses a connected service only after an authorized user approves the requested permissions. We use information from that service to provide the features and actions the user requests, maintain the connection, protect the Service, and comply with law. We request permissions in context and aim to limit them to what the selected features require.

You can disconnect a service through the available connection settings. When you disconnect it, we stop new access, revoke or delete the connection credentials under our control, and retain previously imported content only as described in Section 10.

If you connect a Google service, Makina's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve the user-facing features you request, for security, or as required by law. We do not use Google Workspace data for advertising.

External services are governed by their own terms and privacy policies. Makina is not responsible for an external service's independent privacy practices.

7. How We Disclose Information

We may disclose information to:

  • service providers that support hosting, storage, authentication, payment processing, AI processing, security, analytics, communications, and customer support;
  • connected services and action recipients when you ask Makina to retrieve, send, post, upload, purchase, schedule, or otherwise act;
  • realm members and organizations according to the workspace, membership, sharing, and administrator settings you or your organization configure;
  • professional advisers and authorities when reasonably necessary to comply with law, respond to lawful requests, enforce our agreements, investigate abuse, or protect rights, safety, and security;
  • transaction participants in connection with a proposed or completed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice requirements; and
  • other parties at your direction or with your consent.

Our service providers may use personal information only to perform services for us and subject to contractual restrictions appropriate to their role. We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use your content to serve third-party advertisements.

Makina personnel may access content only when you authorize access to specific content for support, when necessary to investigate security or abuse, when required by law, or after the information has been aggregated or de-identified for internal operations. We use role-based access, confidentiality obligations, and logging or other controls appropriate to the access.

Where law requires us to identify a legal basis, we process personal information as needed to perform our contract with you, operate and secure the Service, and provide features you request. We also process information for legitimate interests such as preventing abuse, improving reliability, communicating with users, and protecting our legal rights, where those interests are not overridden by your rights. We rely on consent where required, and you may withdraw that consent at any time. We also process information when necessary to comply with a legal obligation.

9. Data Storage, Security, and International Processing

We use technical and organizational safeguards designed to protect information, including encryption in transit, encryption for protected credentials and stored data where appropriate, isolated computer realms, access controls, secret-management systems, audit records, redaction, monitoring, and incident response procedures. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

Makina and its service providers may process information in countries other than the country where you live. Where required, we use recognized safeguards for international transfers, such as adequacy decisions or contractual protections.

10. Data Retention and Deletion

We retain account information and workspace data while your account is active and for as long as reasonably necessary to provide the Service, maintain security and auditability, resolve disputes, enforce our agreements, and comply with law. Retention may also depend on the type of information, workspace settings, and an organization's instructions.

When you delete your account or an authorized administrator deletes a realm, we revoke active sessions and connections, stop ongoing tasks, and place the associated data in our deletion process. Deletion may occur asynchronously. Limited copies may remain temporarily in encrypted backups, security records, fraud-prevention systems, or records we must retain for legal, tax, accounting, or dispute purposes. We isolate retained data from ordinary use and delete or de-identify it when the applicable reason for retention ends.

Deleting an individual agent does not automatically delete files, connections, or other information shared within its realm. Disconnecting a service stops new collection but does not automatically remove content already copied into tasks, messages, artifacts, or audit records. You can separately delete that content or the realm, subject to the limitations above.

11. Your Rights and Choices

Depending on where you live, you may have the right to:

  • access and receive a copy of your personal information;
  • correct inaccurate personal information;
  • delete personal information;
  • export information in a portable format;
  • object to or restrict certain processing;
  • withdraw consent without affecting earlier lawful processing;
  • appeal our response to a privacy request; and
  • complain to your local privacy or data-protection authority.

You can manage many choices through your account, realm, memory, connection, and communication settings. You may also submit a request through the support channel available in the Service or by emailing contact@makina.so. We may need to verify your identity and authority before acting on a request. An authorized agent may submit a request where local law permits. We will not discriminate against you for exercising a privacy right.

If your account is managed by an organization, please direct requests concerning organization-controlled workspace content to that organization. We will assist it as required by law and our agreement with it.

12. Cookies

We use cookies and similar local-storage technologies that are necessary to keep you signed in, protect sessions, remember preferences, and operate the Service. We may also use limited first-party analytics to understand whether the Service is working as intended. We do not use third-party advertising cookies or cross-site tracking cookies. Browser settings can block or delete cookies, but some features may then stop working.

13. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information to Makina, email contact@makina.so so we can investigate and delete it as appropriate.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service, our practices, or applicable law. We will post the updated policy and change the effective date above. The current version will be available at makina.so/privacy. If a change materially affects how we use personal information, we will provide additional notice before the change takes effect and obtain consent where required by law.

15. Contact Us

If you have a question, concern, or privacy request, contact us at:

Email: contact@makina.so
Website: makina.so

We will route privacy requests to the person responsible for privacy matters and respond as required by applicable law.