New release v2026.626.0: Hermes agents built in, task watchdogs, and ask work mode.
See what's newEffective Date: July 23, 2026 · Last updated: July 23, 2026
This Privacy Policy describes how Paperclip Labs, Inc. (“Paperclip Labs, Inc.,” “we,” “us,” or “our”) collects, uses, protects, and shares data in connection with Paperclip and the services we operate (the “Services”). It should be read together with our Terms of Service. Paperclip is an AI agent workspace: it lets you run teams of AI agents that plan and carry out work, including — when you choose to connect them — acting in third-party systems on your behalf.
This Privacy Policy applies to all personal data and usage data collected by Paperclip Labs, Inc. through the Services, including data we access from third-party accounts you connect to Paperclip. Where you self-host the open-source Paperclip software, your own deployment processes your data on your infrastructure; this policy governs the hosted and operated Services provided by Paperclip Labs, Inc.
Paperclip Labs, Inc. uses collected data for the following purposes:
Important limitation for connected-account data. Data we access from your connected third-party accounts (Section 4) is used only to provide and improve the user-facing features you have enabled, and is not used for advertising, sold or transferred for advertising purposes, or used to train generalized or non-personalized artificial-intelligence or machine-learning models. Any use of aggregated or anonymized data for analytics, research, or model training applies only to data that is not connected-account data and that can no longer be used to identify you.
Paperclip lets you connect accounts from third-party providers — for example Google, Slack, GitHub, Vercel, and Linear — so that your agents can read and act on information in those systems on your behalf. Connections are established through the provider’s standard OAuth authorization flow, brokered by our connector service at connect.paperclip.ing. We request only the minimum scopes needed for the features you enable, and you see and approve the requested permissions before a connection is created.
How we handle connected-account data:
When you connect a Google account, Paperclip accesses Google user data only within the OAuth scopes you grant (for example, read or send access to Gmail, Google Calendar, or Google Drive) and only to provide the features you have enabled. Paperclip’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data obtained through the Services is:
When you connect a Slack workspace, Paperclip accesses Slack data only within the scopes you grant (for example, reading channels you designate or posting messages as the Paperclip app) and only to provide the features you have enabled. Slack data is stored and processed under the same protections described above: it is not sold, not used for advertising, and not used to train generalized AI/ML models. You control which workspaces and channels Paperclip may access, and you can revoke Paperclip’s access at any time from Slack’s app-management settings or from within Paperclip. Your use of Slack remains subject to Slack’s own terms and policies.
Paperclip Labs, Inc. does not sell your personal data. We may share data in the following circumstances:
Connected-account data, including Google user data, is shared only as permitted by Section 4 and the Limited Use commitments above.
Paperclip Labs, Inc. retains data for as long as reasonably necessary to fulfill the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Connected-account data and OAuth tokens are retained only while the connection is active and are deleted or invalidated after you disconnect the account, subject to short operational backup windows and any legal retention requirements. Anonymized and aggregated data, which cannot be used to identify individual users, may be retained for research, analytics, and product improvement purposes.
We implement commercially reasonable technical, administrative, and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction, including encryption of OAuth credentials at rest and in transit. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for any actions taken through your account.
Depending on your jurisdiction, you may have certain rights with respect to your personal data, including:
To exercise any of these rights, please contact us at the address below. We will respond in accordance with applicable law. Certain rights may be limited where we have a legitimate basis to continue processing your data (for example, legal compliance or the exercise of legal claims).
Your data may be transferred to and processed in countries other than your country of residence, including the United States. By using the Services, you consent to the transfer of your data to jurisdictions that may have different data protection laws than your home jurisdiction.
The Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. Changes will be posted to this page with a revised effective date. We encourage you to review this policy periodically. Your continued use of the Services after changes are posted constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, please contact us:
Paperclip Labs, Inc.
Email: privacy@paperclip.ing (or legal@paperclip.ing)
GitHub: github.com/paperclipai/paperclip