TRUST / PRIVACY

Your credentials are not model context.

Understand the Working Machines data path, credential boundary, execution records, analytics, and user responsibilities.

Data path

Working Machines receives the action inputs needed to call a connected provider and returns the provider result to the calling agent or application. Tool inputs and results are not automatically anonymized. If an action returns personal or sensitive information, that information can enter the calling model's context.

Choose actions, provider accounts, model vendors, prompts, and retention settings appropriate for the data involved. Avoid requesting more data than the task requires.

Credentials

Provider OAuth tokens, refresh tokens, API keys, and passwords remain inside the Working Machines credential boundary. Discovery responses expose connection identities and available capabilities, not raw provider credentials.

An agent's ability to call an action is not the same as possession of the underlying credential. Access remains attached to the selected connection, provider scopes, workspace policy, and runtime authorization.

Execution records

The runtime can keep redacted execution records needed for reliability, auditability, metering, and support. Records may include the action identity, connection identity, status, timing, policy decisions, and a redacted view of inputs or results. Retention depends on the selected plan and deployment configuration.

Website analytics

The public website uses privacy-conscious deployment analytics and Google Analytics when the configured measurement ID is present. These tools can record page visits, device and browser information, referral information, and aggregate interaction events. They are separate from provider action execution.

User control

Users choose which applications to connect and authorize provider-native permissions during connection. Connections can be removed from the workspace. Agent clients should ask for confirmation before destructive, financial, externally visible, or difficult-to-reverse work.

  • Connect the least-privileged provider account
  • Limit actions to the workflow being automated
  • Review model-provider data controls
  • Remove connections that are no longer needed

Updates

This public privacy explanation was last updated on September 1, 2026. Product behavior is also documented in the security model and developer documentation. Where a commercial agreement applies, its terms control for that customer.