Privacy Policy
This policy describes how Matrices (“we”, “us”) collects, uses, and protects information when you use our services, including the Matrices API and the web console at app.matrices.com.
We run agents on your behalf. Doing that responsibly means handling credentials, conversations, and tool outputs with care. The sections below explain what we collect and why.
Information we collect
Account information. When you sign up, we collect your email address and the public key of the passkey you register. We never see or store a password. If you join a workspace, we store your role and membership.
Agent and thread data. To run agents, we store the prompts you send, the messages your agents produce, tool inputs and outputs, memory entries, files your agents read and write, schedules, and sandbox execution history.
Integration credentials.When you connect a third-party service (Google, Slack, GitHub, Linear, Notion, or an MCP server you configure), we store the OAuth tokens required to call that service on your agents’ behalf. Tokens are encrypted at rest and never exposed to the model.
Google user data. If you connect Google services, we may process the Google account information and Google Workspace data you authorize, including profile details, email messages, drafts, labels, attachments, calendar events, and Drive file metadata or content. We access this data only for the tools, agents, and workflows you configure.
Usage and diagnostic data. We collect logs, error reports, and usage metrics (requests, token counts, latency) so we can debug, bill, and improve the service. We also keep an audit log of the actions your agents take.
Cookies. The console uses cookies only to keep you signed in. We do not use advertising or third-party tracking cookies.
How we use your information
We use the information we collect to:
- Provide, maintain, and improve the Matrices services.
- Execute the agents, tool calls, and schedules you configure.
- Verify your identity and enforce access controls.
- Send service communications, billing notices, and security alerts.
- Call Google APIs and other connected services on your behalf when an authorized tool or agent action requires it.
- Detect abuse, prevent fraud, and investigate incidents.
- Comply with legal obligations.
We do not sell your data, and we do not use your prompts, messages, or agent outputs to train models — ours or anyone else’s.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Our use and transfer of information received from any other Google API likewise adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, credit decisions, or resale, and we do not use it to create, train, or improve generalized AI or machine learning models.
Who we share data with
We share data only with the subprocessors we rely on to deliver the service:
- Amazon Web Services — infrastructure. Our databases, object storage, and agent runtime run inside our AWS VPC, and we deliver email through Amazon SES.
- Vercel — hosting for the web console.
- Anthropic, OpenAI, Google, Fireworks, xAI, Amazon Bedrock — model providers. Prompts, context, and tool outputs, including any Google Workspace data an agent reads on your behalf, are forwarded to the provider that serves the model you selected. OpenAI also serves the model that ranks which tools an agent can see for a given task. Every provider processes this data under API terms that prohibit using it to train or improve their models, and none of it is used to train models of our own.
- Stripe — billing and payments.
- Sentry — error monitoring.
We may also disclose information when required by law, to enforce our terms, or to protect the rights and safety of our users.
How we protect your data
Data is encrypted in transit and at rest. Integration credentials are stored encrypted and are decrypted only at the moment of a tool call — the model never receives raw secrets.
Every agent action is checked against your workspace’s permissions before it runs, sensitive tool calls can require human approval, and we keep a full audit trail of tool invocations. Internal service credentials are minted per request and never persisted.
Matrices personnel read Google user data only to operate the service with your permission — for example, when you ask us to look into a specific agent run. Beyond that, we access it only where necessary to investigate a security incident or abuse, or where required by law; internal operations otherwise rely on aggregated, anonymized metrics.
Retention
We retain your data for as long as your account is active and as needed to provide the service. You can delete agents, threads, memory entries, and connections at any time from the console. To close your account, email privacy@matrices.com; we delete your data within 30 days of the request, except where we are required to retain it for legal or compliance reasons.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing.
To exercise any of these rights, email privacy@matrices.com. We will respond within the timeframe required by applicable law.
Children
Matrices is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “last updated” date at the top of this page and, for material changes, notify you through the service or by email.
Contact
Questions about this policy? Email privacy@matrices.com.