New release v2026.626.0: Hermes agents built in, task watchdogs, and ask work mode.

See what's new
Install
Legal

Privacy Policy

Effective Date: July 23, 2026 · Last updated: July 23, 2026

This Privacy Policy describes how Paperclip Labs, Inc. (“Paperclip Labs, Inc.,” “we,” “us,” or “our”) collects, uses, protects, and shares data in connection with Paperclip and the services we operate (the “Services”). It should be read together with our Terms of Service. Paperclip is an AI agent workspace: it lets you run teams of AI agents that plan and carry out work, including — when you choose to connect them — acting in third-party systems on your behalf.

1. Scope

This Privacy Policy applies to all personal data and usage data collected by Paperclip Labs, Inc. through the Services, including data we access from third-party accounts you connect to Paperclip. Where you self-host the open-source Paperclip software, your own deployment processes your data on your infrastructure; this policy governs the hosted and operated Services provided by Paperclip Labs, Inc.

2. Data We Collect

  • Account Information: Email address, name, organization, and authentication credentials when you create an account.
  • Usage Data: Information about how you interact with the Services, including pages visited, features used, timestamps, and referral sources.
  • Telemetry Data: Anonymized system health metrics, performance data, error rates, and aggregate usage statistics, collected automatically.
  • Detailed Telemetry (opt-in only): Where you explicitly enable detailed telemetry, we may collect full stack traces, agent run logs, configuration data, operational metadata, and other diagnostic information.
  • Connected Third-Party Account Data: When you connect a third-party account (see Section 4), we access data from that account strictly as needed to provide the features you have enabled and only within the scopes you authorize.
  • Device and Technical Data: Browser type, operating system, IP address, device identifiers, and similar technical information.
  • Communications: Content of messages you send to us through support channels or feedback mechanisms.

3. How We Use Your Data

Paperclip Labs, Inc. uses collected data for the following purposes:

  • Operating, maintaining, and improving the Services;
  • Providing the specific features you request, including connected-account integrations;
  • Analyzing usage patterns and system performance;
  • Developing new features, products, and services;
  • Communicating with you about the Services, updates, and security notices;
  • Detecting, preventing, and addressing technical issues, fraud, or security threats;
  • Complying with legal obligations and enforcing our terms.

Important limitation for connected-account data. Data we access from your connected third-party accounts (Section 4) is used only to provide and improve the user-facing features you have enabled, and is not used for advertising, sold or transferred for advertising purposes, or used to train generalized or non-personalized artificial-intelligence or machine-learning models. Any use of aggregated or anonymized data for analytics, research, or model training applies only to data that is not connected-account data and that can no longer be used to identify you.

4. Connected Third-Party Accounts (OAuth Integrations)

Paperclip lets you connect accounts from third-party providers — for example Google, Slack, GitHub, Vercel, and Linear — so that your agents can read and act on information in those systems on your behalf. Connections are established through the provider’s standard OAuth authorization flow, brokered by our connector service at connect.paperclip.ing. We request only the minimum scopes needed for the features you enable, and you see and approve the requested permissions before a connection is created.

How we handle connected-account data:

  • Access: We access third-party data only within the scopes you authorize and only to operate the features you have enabled (for example, reading a document, posting a message, or opening a pull request that you or your agents initiate).
  • Token storage: OAuth access and refresh tokens are stored encrypted and are used solely to make authorized API calls on your behalf. We do not expose these tokens to other customers.
  • No sale, no advertising, no generalized model training: We do not sell connected-account data, do not use it for advertising, and do not use it to train generalized AI/ML models.
  • Human review: We do not allow humans to read your connected-account data except where you give explicit consent, where it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or where the data has been aggregated and anonymized.
  • Revocation:You may disconnect any connected account at any time from within Paperclip or from the provider’s own security settings. On disconnection we stop accessing the account and delete or invalidate the associated tokens.

4.1 Google user data

When you connect a Google account, Paperclip accesses Google user data only within the OAuth scopes you grant (for example, read or send access to Gmail, Google Calendar, or Google Drive) and only to provide the features you have enabled. Paperclip’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data obtained through the Services is:

  • used only to provide or improve user-facing features that are prominent in Paperclip’s interface and that you have enabled;
  • not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you;
  • not used or transferred for advertising, including personalized, retargeting, or interest-based advertising;
  • not used to train generalized or non-personalized AI/ML models, and not read by humans unless you give explicit consent for specific data, it is necessary for security or to comply with applicable law, or the data is aggregated and anonymized.

4.2 Slack data

When you connect a Slack workspace, Paperclip accesses Slack data only within the scopes you grant (for example, reading channels you designate or posting messages as the Paperclip app) and only to provide the features you have enabled. Slack data is stored and processed under the same protections described above: it is not sold, not used for advertising, and not used to train generalized AI/ML models. You control which workspaces and channels Paperclip may access, and you can revoke Paperclip’s access at any time from Slack’s app-management settings or from within Paperclip. Your use of Slack remains subject to Slack’s own terms and policies.

5. Data Sharing and Disclosure

Paperclip Labs, Inc. does not sell your personal data. We may share data in the following circumstances:

  • Service Providers: With trusted third-party vendors (for example, cloud hosting and infrastructure providers) who assist in operating the Services, subject to confidentiality obligations and only to the extent necessary to provide the Services.
  • Legal Requirements: When required by law, regulation, legal process, or governmental request.
  • Protection of Rights: To protect the rights, property, or safety of Paperclip Labs, Inc., our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, in which case your data may be transferred to the acquiring entity.
  • With Your Consent: In any other circumstance where you have provided explicit consent.

Connected-account data, including Google user data, is shared only as permitted by Section 4 and the Limited Use commitments above.

6. Data Retention

Paperclip Labs, Inc. retains data for as long as reasonably necessary to fulfill the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Connected-account data and OAuth tokens are retained only while the connection is active and are deleted or invalidated after you disconnect the account, subject to short operational backup windows and any legal retention requirements. Anonymized and aggregated data, which cannot be used to identify individual users, may be retained for research, analytics, and product improvement purposes.

7. Data Security

We implement commercially reasonable technical, administrative, and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction, including encryption of OAuth credentials at rest and in transit. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for any actions taken through your account.

8. Your Rights

Depending on your jurisdiction, you may have certain rights with respect to your personal data, including:

  • The right to access personal data we hold about you;
  • The right to request correction of inaccurate data;
  • The right to request deletion of your personal data;
  • The right to object to or restrict certain processing activities;
  • The right to data portability;
  • The right to withdraw consent where processing is based on consent.

To exercise any of these rights, please contact us at the address below. We will respond in accordance with applicable law. Certain rights may be limited where we have a legitimate basis to continue processing your data (for example, legal compliance or the exercise of legal claims).

9. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the United States. By using the Services, you consent to the transfer of your data to jurisdictions that may have different data protection laws than your home jurisdiction.

10. Children’s Privacy

The Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take steps to delete it promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted to this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the Services after changes are posted constitutes acceptance of the revised policy.

Contact

If you have questions about this Privacy Policy, please contact us:
Paperclip Labs, Inc.
Email: privacy@paperclip.ing (or legal@paperclip.ing)
GitHub: github.com/paperclipai/paperclip

Paperclip

The operating system for your AI workforce. Hire agents, set goals and budgets, and stay in control while the work runs itself.

Product

OverviewOrg ChartHeartbeatsGovernance & ApprovalsBudgets & CostsTasks, Plans & GoalsBring Your Own AgentSkills & Extensions

Solutions

Who it's forEngineeringSupportSales & MarketingOperationsFinance

Developers

DocumentationInstallationAPI referenceGitHubContributingLicense

Resources

BlogChangelogOpen SourceBrand assetsDiscord communityX / Twitter

Company

About usCareersNewsroomContactTerms of ServicePrivacy
Paperclip
© 2026 Paperclip Labs, Inc. Open source. MIT License.
PrivacyTermsBrandGitHub