Pinksheep Privacy Policy
Last Updated: May 2026 | Effective Date: March 2026
1. Introduction
This Privacy Policy explains how Pinksheep, Inc., operating as “Pinksheep” (“Pinksheep”, “we”, “us”, or “our”), collects, uses, discloses, and safeguards your personal information.
This policy applies to all visitors of our website, users of our web application, and individuals who interact with our AI agent builder platform and related application programming interfaces (collectively, the “Services”).
We are committed to protecting your privacy and strive to comply with applicable data protection laws, including the Australian Privacy Act 1988 (Cth), the EU General Data Protection Regulation (GDPR), the UK GDPR, and relevant US state privacy laws such as the California Consumer Privacy Act (CCPA), to the extent they apply to our operations.
By accessing or using our Services, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy.
2. Data Controller and Processor Roles
Pinksheep plays different roles depending on the type of data involved:
- Controller: For account registration, billing, website analytics, support communications, and security logging, Pinksheep acts as the data controller and determines the purposes and means of processing.
- Processor: For Customer Data processed within a workspace (including prompts, assistant responses, tool arguments and results, artifacts, memories, and preferences), Pinksheep acts as a data processor on behalf of the customer organization that manages the workspace. The customer organization is typically the data controller for this content.
If you use the Services through a workspace managed by your employer or organization, that organization controls how your workspace data is used. Please refer to their privacy policies for information about their practices. Business customers may formalize this arrangement through a Data Processing Addendum.
3. Information We Collect
We collect information that identifies, relates to, describes, or could reasonably be linked to you (“Personal Information”). We collect this information directly from you, automatically through your use of the Services, and from third-party integrations you authorize.
3.1. Information You Provide Directly
- Account Information: When you register, we collect your first name, last name, email address, and password.
- Payment Information: If you purchase a subscription or Credits, our third-party payment processors collect your billing address and payment details. We do not store raw credit card numbers on our servers.
- Agent Configuration and Chat Inputs: We collect the text prompts, chat messages, and configurations you input when building or communicating with an Agent.
- Support and Inquiries: If you contact us for customer support or sales inquiries, we collect the contents of your messages.
3.2. Information from Connected Accounts
A core feature of Pinksheep is the ability to connect third-party applications (your “Connected Accounts”, such as CRMs, messaging platforms, or productivity suites).
- Authentication Data: When you authorize a connection, we receive and securely store authentication tokens (such as OAuth tokens) brokered by our integration gateways.
- Operational Data: To execute the Agents you configure, our systems access, retrieve, and process data from your Connected Accounts. We only access the specific data required to execute the workflow steps defined in your Agent’s blueprint.
3.3. Information Collected Automatically
- System and Device Data: We automatically collect your IP address, browser type, operating system, and device identifiers when you visit our website or use our app.
- Usage and Telemetry Data: We track how you interact with the Services, including pages visited, features used, clicks, and navigation paths.
- Audit and Execution Logs: We generate and store step-by-step execution logs of your Agents’ activities. This includes records of API requests sent to and responses received from your Connected Accounts, timestamps, and error codes. These logs are necessary for debugging, cost accounting, and providing transparency into autonomous actions.
3.4. Public and Shared Artifacts
If you choose to publish, share, or make available content, Agents, templates, workflows, outputs, or other materials through the Services (“Shared Artifacts”), we will collect and display the information you provide as part of that Shared Artifact, along with related metadata (for example, your display name and basic engagement metrics). Depending on how you share, Shared Artifacts may be visible to other users or the public. Please do not include sensitive information or personal information you are not authorized to share in Shared Artifacts.
4. How We Use Your Information
We use the information we collect for the following purposes:
- To Provide the Services: To create and manage your account, authenticate your logins, and securely connect to your authorized third-party applications.
- To Execute Agents: To process your prompts and pass necessary context to AI models, allowing your Agents to perform their configured tasks.
- To Process Payments: To manage your Credit balance, process subscriptions, and prevent fraudulent transactions.
- To Communicate With You: To send administrative notifications, such as Agent failure alerts, approval requests, billing updates, and security notices.
- To Improve the Platform: To analyze usage trends, monitor platform health, troubleshoot bugs, and develop new features.
- To Enforce Legal Obligations: To investigate and prevent abusive or fraudulent activity, and to comply with legal and regulatory requirements.
4.1 Legal bases (EEA/UK)
If you are located in the EEA or the United Kingdom, we process Personal Information under one or more of the following legal bases:
- Contract: To provide the Services you request, including operating your account and executing Agents you configure.
- Legitimate interests: To secure and improve the Services, prevent fraud and abuse, and maintain platform performance and reliability.
- Consent: Where required by law, for certain cookies and similar tracking technologies (you can manage cookie preferences through your browser settings and any consent tools we provide).
- Legal obligation: To comply with applicable laws, lawful requests, and regulatory requirements.
5. How We Share Your Information
We do not sell your Personal Information. We share your information only in the following circumstances:
- Third-Party AI Model Providers: To generate outputs and determine Agent actions, we securely transmit your prompts and the necessary contextual data retrieved from your Connected Accounts to third-party AI model APIs.
- Integration and Authentication Gateways: We use secure infrastructure partners to broker OAuth connections and API requests to your Connected Accounts.
- Cloud Infrastructure Providers: Our database, application hosting, and MCP API endpoints are hosted on secure cloud infrastructure providers located in Australia and globally.
- Analytics Partners: We share usage and telemetry data with analytics providers to help us understand web traffic and UI interactions.
- Payment Processors: We share billing information with secure payment gateways to process your purchases.
- Other Users and the Public (When You Choose to Share): If you publish or share Shared Artifacts, we will disclose that content and related metadata to the audience you select (for example, other users or the public).
- Legal Compliance and Safety: We may disclose your information if required to do so by law, court order, or government request, or to protect the rights, property, or safety of Pinksheep, our users, or the public.
6. AI Processing, Routing, and Model Providers
The Services use multiple layers of processing to generate responses and execute actions:
- Local routing and classification: A lightweight classifier running on Pinksheep-managed infrastructure analyzes each message to determine intent and select a response strategy. This layer processes a summary or embedding of your message, not the full conversation. It does not generate the final response.
- Third-party model providers: Responses are generated by hosted AI models from providers such as Anthropic (Claude) and OpenAI (GPT). Your prompts and relevant context are transmitted to the selected provider. The specific provider depends on your workspace configuration and model selection.
- Connected tool providers: When an Agent uses a connected app, relevant data is sent to that third-party service (currently brokered via Pipedream or direct API connections) to complete the requested action.
We maintain API-level agreements with our model providers designed to limit their use of submitted content for training their publicly available models. A current list of subprocessors, including model providers and infrastructure partners, is available on request and is provided as part of any Data Processing Addendum.
7. Our Stance on AI Training
We understand that your business data is sensitive.
We explicitly do not use your Account Information, Customer Data, chat inputs, or any data retrieved from your Connected Accounts to train our own proprietary foundational AI models.
We also take steps designed to prevent our third-party AI model providers from using the content we submit via their APIs to train their publicly available models. Depending on the provider and configuration, those providers may retain submitted content for a limited period to provide the service, maintain safety, prevent abuse, or comply with legal obligations.
8. Conversation Storage, Memory, and Logs
The Services handle different categories of workspace data separately:
- Conversation history: Your chat messages (prompts and assistant responses) are stored as part of your workspace to provide continuity and transparency. Conversations remain until you delete them or your configured retention period removes them.
- Memory and preferences: When memory is enabled, the Assistant may extract preferences or facts from conversations to personalize future responses. Disabling memory stops new preference and memory extraction but does not delete existing conversation messages.
- Artifacts: Documents, spreadsheets, emails, and other structured outputs created during conversations are stored as artifacts within your workspace.
- Action audit records: When your Assistant executes a tool or connected-app action, a record of the action (including the tool name, app, risk classification, and a summary of the result) is retained for audit and transparency.
- Operational logs and traces: Service-level logs containing metadata (model identifiers, routing decisions, timestamps, error codes, and execution summaries) are retained for debugging, security, and cost accounting. These logs are subject to a shorter retention schedule and do not contain full message text.
You can configure a message retention period for each Assistant. Messages older than that period are automatically removed. You can also export your Assistant data or delete individual conversations, memory, or the entire Assistant at any time.
9. Cookies and Tracking Technologies
We use cookies, local storage, and similar tracking technologies to ensure the proper functioning of our Services and to analyze user behavior.
- Necessary Cookies: These are required for the platform to function, such as maintaining your logged-in session and securing your account.
- Analytics Cookies: These help us understand how visitors interact with our website by collecting reporting data anonymously.
Where required by law (including in the EEA and the UK), we seek your consent before placing non-essential cookies and similar technologies. You can withdraw consent at any time through any cookie preference tools we make available, or through your browser settings.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept necessary cookies, you may not be able to use the logged-in features of our app.
For more information, please see our Cookie Policy.
10. Data Security and Retention
Security: We implement industry-standard technical and organizational measures to protect your Personal Information from unauthorized access, loss, or alteration. This includes encryption of data in transit and at rest. However, no internet transmission or electronic storage system is 100% secure, and we cannot guarantee absolute security.
Retention: We retain different categories of data for different periods:
- Account information: Retained while your account is active and for a reasonable period after closure for legal and billing purposes.
- Conversation messages: Retained according to your configured retention period, or until you delete them. If no retention period is set, messages persist for the duration of the workspace.
- Memory and preferences: Retained until you delete them or delete the Assistant.
- Artifacts: Retained until you delete them or the conversation retention period removes them.
- Action audit records: Retained for the configured retention period. After expiry, action payloads are redacted while the audit record is preserved.
- Operational logs and traces: Retained for a shorter period (typically 90 days or less) for debugging and security purposes.
- Backups: May persist for a limited period after deletion before being purged from backup systems.
You may delete your Agents or request account deletion at any time, after which we will delete or anonymize your data, except where retention is required for legal, tax, or accounting purposes.
11. Your Privacy Rights
Depending on your location, you may have the following rights regarding your Personal Information:
- Access: The right to request a copy of the personal data we hold about you.
- Correction: The right to request that we correct inaccurate or incomplete data.
- Deletion (Right to be Forgotten): The right to request the deletion of your personal data.
- Objection and Restriction (EEA/UK): Where applicable, the right to object to certain processing or request that we restrict processing.
- Portability (EEA/UK): Where applicable, the right to request a copy of certain personal data in a structured, commonly used, machine-readable format.
- Revocation of Consent: You may revoke Pinksheep’s access to any Connected Account at any time via the Integrations page in your dashboard. This immediately ceases our ability to read or write data to that specific third-party service.
To exercise any of these rights, please contact us at privacy@pinksheep.ai. We will respond to your request in accordance with applicable data protection laws. If you use the Services through a workspace managed by your employer or organization, we may direct your request to that organization while providing them reasonable assistance.
11.1 Data Export
You can export your Assistant data (including conversations, artifacts, memory, preferences, and action audit history) in a structured, machine-readable JSON format through the product interface or by contacting us.
11.2 Complaints
If you have a privacy complaint or concern, please contact us first so we can try to resolve it. If you are not satisfied with our response, you may be able to lodge a complaint with your local regulator. In Australia, this includes the Office of the Australian Information Commissioner (OAIC).
12. International Data Transfers
Pinksheep operates globally. Your Personal Information may be transferred to, processed, and stored in countries outside of your jurisdiction of residence, including Australia and the United States, where our cloud infrastructure and third-party service providers are located. Where required, we use contractual and other safeguards designed to help protect your Personal Information during international transfers (for example, standard contractual clauses or equivalent mechanisms).
13. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Information from children under 18. If we become aware that we have collected Personal Information from a child under 18 without parental consent, we will take steps to remove that information and terminate the associated account.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. We may also notify you via email or through a prominent notice on our platform.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Pinksheep, Inc.
Delaware, USA
Email: privacy@pinksheep.ai
Business customers who require a processor agreement for EU/UK data protection compliance can request our Data Processing Addendum.