Back to home

Effective September 7, 2026

Privacy policy

The short version: your agent is built to work with private information, so we want to be unusually clear about where that information goes and when a human could see it.

1. Who we are

AgentMarkit is an early-stage service operated by Mari Zumbro. In this policy, “AgentMarkit,” “we,” and “us” mean the AgentMarkit service and its operator.

Use the contact form for questions or privacy requests. Please do not send passwords, API keys, or private workspace content.

2. What we collect

Account and setup information

We collect your email address, a service-specific account identifier, the starter and add-ons you choose, your machine name, setup status, and recent setup logs. Magic sign-in links expire after 15 minutes. Email sign-in sessions expire after 30 days, isolated public demo sessions after 24 hours, and private pilot sessions after seven days. The browser keeps its local email or demo session token until you clear site data or the token stops working.

Billing information

Stripe processes checkout. We receive order, subscription, payment-status, and customer identifiers, but not your full card number.

Your agent workspace

Your prompts, outputs, memory, files, installed skills, integration data, and configuration live on the Agent37-hosted machine. When you use AgentMarkit's built-in web chat, the full message and agent reply pass through our Cloudflare Worker on the way to and from that machine. We do not save that full chat content in our customer database. We do save the Agent37 chat-session identifier, message count, last-chat time, and input and output character counts. The model provider you choose receives the prompts and context sent to that model. Its own terms and privacy policy apply.

Credentials

A model API key entered during setup passes through the AgentMarkit service so it can be installed on your machine. AgentMarkit does not save that key in its customer database. The key is stored in the Hermes configuration on your Agent37 machine. Other integrations may store their own tokens on the machine or with the integration provider; we will identify that before you connect one.

Support and contact information

If you use the contact form or ask for help, we collect the topic, reply email, message, your name if you provide it, and any diagnostics or access permission needed to answer you. We also use a short-lived network signal to limit spam. If support requires a human to inspect private workspace material, we ask for separate, specific permission.

Website requests

Cloudflare may process basic network and security information when you visit the site, such as IP address, browser details, requested page, and timing. AgentMarkit does not currently run advertising pixels, session replay, or a separate behavioral analytics product on this site.

3. How we use information

We use information to sign you in, build and operate your machine, install the choices you make, process payment, send service messages, prevent abuse, debug problems, and comply with law. We may use de-identified operational patterns to improve setup reliability, but we do not use private agent content or Google-derived data for general product research or model training.

We do not sell personal information. We do not use it for targeted advertising, credit decisions, or data-broker enrichment.

4. Machine access and support

AgentMarkit and Agent37 maintain privileged technical access needed to provision, update, secure, restart, support, and delete hosted machines. This means the workspace is not end-to-end encrypted from AgentMarkit or Agent37.

That technical capability is not blanket permission for a person to browse your workspace. We do not routinely read prompts, files, memory, or outputs. Before ordinary support work that requires human review, we will tell you the machine, material, purpose, whether we need read-only or change access, and the expected duration. We wait for your written approval. You may withdraw that approval before the work is complete.

We may act without prior approval only when reasonably necessary to stop an active security incident, protect the service or another person, or comply with law. We limit that access to what the situation requires. Work performed through our support process is documented, but direct provider-level access does not yet produce a customer-visible audit log.

5. Gmail metadata

The Gmail connection is still being built and is not available through the public AgentMarkit site. We will not turn it on for customers until the OAuth client, consent flow, token storage, revocation, deletion, and Google verification requirements are confirmed.

The hosted Network Observatory design requests only https://www.googleapis.com/auth/gmail.metadata. Its fixed tools can return From, To, Cc, Bcc, Date, labels, internal date, and stable Gmail message or thread IDs. They strip subject lines, snippets, message bodies, and attachments before returning data to the agent.

If this feature launches, we will show the exact fields, provider path, purpose, storage location, and deletion controls immediately before you connect Google. Google access will be optional and requested only when you choose the Gmail feature.

AgentMarkit's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We will use Google data only to provide the authorized, prominently disclosed feature you ask for or to personalize that feature for you. We will not use it for general product development. We will not sell it, use it for advertising, use it to determine creditworthiness, or use it to train a general-purpose AI model. A person will access Google data only with your specific consent for support, when necessary to investigate abuse or a security incident, or when required by law.

6. Who helps us run the service

CloudflareWebsite delivery, security, serverless code, and account/setup recordsPrivacy
Agent 37 Inc.Cloud machine hosting, provisioning, backups, maintenance, and infrastructure supportPrivacy
StripeCheckout, subscriptions, fraud prevention, and payment recordsPrivacy
ResendMagic sign-in links and service emailPrivacy
Your model providerProcesses the prompts, files, tool results, and outputs sent to the model you selectYou choose

We may add an integration provider only when you choose a feature that needs one. We will identify it before data is sent. Service providers may process information in the United States and other places where they operate.

7. How long we keep information

Your agent files remain on the hosted machine while that machine exists. Agent37 states that after a Cloud API instance is deleted, it keeps an encrypted recovery copy for seven days and then purges it. Contact-form submissions automatically expire after 180 days. We may keep a separate record longer when reasonably needed for security, billing, disputes, or legal obligations. Other AgentMarkit account, setup, acceptance, support, and billing records do not currently have an automatic self-service deletion schedule. We keep them while the service is active and as reasonably needed for support, security, accounting, disputes, and legal obligations.

You can ask us to delete eligible AgentMarkit records. Some payment, fraud, security, or legal records may need to remain longer. Deleting a machine does not automatically cancel a subscription or delete every account record.

8. Your choices

You decide which starter, model, skills, and integrations to use. You can decline an integration, revoke a third-party connection, delete a disposable test machine from the setup page, or ask us to delete a regular hosted machine and eligible AgentMarkit records. See Data controls for the current steps and important limits.

Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to certain processing. Use the contact form to make a request. We may need to verify that the request belongs to you.

9. Security and sensitive information

We use access controls and service-specific identifiers, but no internet service is perfectly secure. Your agent can reach tools and accounts you connect, and model prompts can contain sensitive information. Start with the least access it needs. Do not give it passwords or credentials in chat when an API key or OAuth connection is available.

10. Children

AgentMarkit is not intended for children under 18, and we do not knowingly collect their personal information.

11. Changes to this policy

We may update this policy as the service changes. We will post the new date here. If a change materially affects how we use information already collected, we will give reasonable notice and ask for consent when law or Google policy requires it.

12. Contact

Use the contact form and choose “Privacy or data request.”