Cyborg Systems, Corp.

Privacy Policy

What we collect, where it lives, who we share it with, and the control you have over it.

Last updated October 2, 2026

1. Who we are and what this covers

Cyborg Systems, Corp., a Delaware corporation (“Cyborg”, “we”, “us”), provides Cyborg, a workspace where humans and AI agents work together. This policy covers our website at cyborg7.com, the web app at app.cyborg7.com, our desktop, command-line and mobile applications, and the Cyborg software that runs on your computers (together, the “Service”).

Two roles. For your account details, billing records, usage and diagnostic data, and website data, Cyborg is the controller, and this policy applies. For the content of a workspace, such as its messages, files, tasks and agent transcripts (“Workspace Content”), we act as a processor (a “service provider” under U.S. state privacy laws) on behalf of the organization that controls the workspace. That organization’s own privacy notice and our agreement with it govern Workspace Content. If you have a question about Workspace Content, start with your workspace admin; we will help them respond.

2. Where your data lives

Where data lives depends on how you set Cyborg up. Typically:

Your machines

Laptops, workspace machines or cloud servers you connect

  • Agents, terminals and sessions
  • AI API keys and logins you add, encrypted
  • Your files and repositories
  • Full agent history and logs

Your AI provider

Your subscription or API key with Anthropic, OpenAI and others

  • Prompts and responses for your agents
  • Governed by your agreement with that provider

Cyborg cloud

Amazon Web Services, United States

  • Account and workspace membership
  • Messages, tasks, pages and files
  • Recent agent history and session titles
  • Machine names and status

Terminal output passes through Cyborg cloud in real time and is not stored.

3. Information we collect

You give us

  • Account information: your name, email address and password (stored only as a salted hash). If you use passkeys, we store the passkey’s public key. If you sign in with Google or GitHub, we receive your account identifier, verified email address and name. We do not store their access tokens.
  • Workspace Content: messages, files, reactions, tasks, pages, agent instructions, memories and skills that you and your teammates create, and data synced from tools you connect.
  • Communications: what you send us when you request early access, contact support or answer a survey. Our early-access form asks for your email address, your team size, which AI agents you use and what is hardest about using them.
  • Billing: your billing email address and subscription details. Payment card details go directly to Stripe. We never see or store full card numbers.

Collected automatically

  • Machine information: for each connected computer, its name, operating system, processor and memory, app and software versions, install location, update status, the AI tools installed on it and the number of agents running.
  • Agent activity: the recent history of each agent (we keep up to the last 2,000 entries per agent in our cloud; the full history stays on your machine), plus session titles, summaries and working directories.
  • Sign-in and security events: sign-ins, account changes and administrative actions, with the IP address and browser or device information used.
  • Diagnostics: error messages, stack traces, app version, platform and the page where an error occurred.
  • Product usage: which features are used, and for agent runs the model name, token counts and cost. These events never include the content of messages, prompts or responses. They are linked to pseudonymous identifiers.
  • Notifications: device push tokens and device names, used to deliver notifications to you.
  • Website analytics: pages visited, referrer, browser and device information, collected with PostHog when you visit cyborg7.com.

From connected services

When you or your admin connect Slack, Microsoft Teams, GitHub, Jira, Linear, ClickUp or another app, we receive the data that integration is designed to sync, such as channel messages, issues or user directory information, and the access tokens needed to keep it connected. We encrypt those tokens. Connections made through Composio are held in Composio’s vault, and we keep only a reference to them.

4. How we use information

PurposeExamplesLegal basis (EEA/UK)
Provide the ServiceCreate your account, sync your workspace, deliver messages and notifications, run integrationsPerformance of a contract
Secure the ServiceVerify sign-ins, detect abuse and fraud, investigate incidents, enforce our termsLegitimate interests; legal obligation
Support and improveFix bugs, understand which features are used, plan capacityLegitimate interests
BillingCharge for subscriptions, send receipts, keep financial recordsPerformance of a contract; legal obligation
CommunicateSend service and security notices; send product news if you opt in or are an existing customerPerformance of a contract; legitimate interests; consent
Comply with lawRespond to lawful requests, meet tax and accounting rulesLegal obligation

We do not use your information for targeted advertising, and we do not make automated decisions about you that have legal or similarly significant effects.

5. AI and your data

  • No training. We do not use Workspace Content to train or fine-tune AI models, and our subprocessors may not either.
  • Your provider, your terms. Agents use AI models through your own subscription or API key, whether they run on a laptop, a workspace machine or a cloud server. What a provider does with prompts and responses is governed by your agreement with that provider. Check its settings for retention and training.
  • Your keys. API keys you add are stored encrypted on the machine where your agents run.
  • Voice. Speech features run on your device by default. If you choose OpenAI for speech, audio is sent to OpenAI using your own key.
  • Secrets. When a message or an agent transcript contains something that looks like a credential, we detect it and encrypt it with a key specific to your workspace.

6. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share it only:

  • With subprocessors that help us run the Service, such as Amazon Web Services, Stripe, Resend, Google Firebase Cloud Messaging and PostHog, under contracts that limit their use of it to providing services to us. The full list, and what each receives, is at /subprocessors.
  • With the services you connect, as directed by you or your admin.
  • Within your workspace, where members and admins can see content according to their roles. Push notifications include a short preview of the message, which passes through Apple, Google or your browser’s push service to reach your device.
  • For legal reasons, when we believe in good faith that disclosure is required by law or legal process, or necessary to protect the rights, property or safety of our users, the public or Cyborg. Where lawful, we will notify the affected customer first.
  • In a business transfer, such as a merger or acquisition, subject to this policy.
  • With your consent.

7. How long we keep it

  • Account data is kept while your account exists.
  • When you delete your account, we permanently delete your user record, sign-in methods, sessions, workspace memberships and the machines you own. Workspaces where you were the only member are deleted with all their content. Workspaces with other members are transferred to another member. Messages you posted in those workspaces remain with that workspace, because they are its records. Your agent sessions there are kept without their titles, summaries or working directories.
  • Workspace Content is kept until it is deleted by the workspace or the workspace is deleted. When a workspace is deleted, its messages, tasks, pages, agent history and connections are deleted with it.
  • Backups of our database are encrypted and expire on a rolling 14-day schedule.
  • Security and audit records, such as sign-in events, billing and administrative actions, are kept as long as needed for security, fraud prevention, dispute resolution and legal compliance. Routine operational events are deleted after 30 days.
  • Billing records are kept as long as tax and accounting law requires.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. You can:

  • update your profile and delete your account in the app’s settings;
  • unsubscribe from marketing email using the link in any message; and
  • email s@cyborg7.com for any other request, including an export of your data.

We will verify your identity before acting on a request, and respond within the time the law requires, usually 30 days. You may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our decision. If you are in the EEA, the UK or Switzerland, you may also complain to your local data protection authority.

For Workspace Content, we act on the instructions of the organization that controls the workspace, so we will refer your request to it and support it in responding.

9. Cookies and local storage

The Cyborg app keeps you signed in using your browser’s local storage, not cookies. It sets one short-lived, strictly necessary cookie while you connect Slack, to protect that sign-in flow. Our website uses PostHog analytics, which stores first-party cookies and local storage to recognize returning visitors and measure how the site is used. We do not use advertising cookies or third-party ad trackers. You can block or delete cookies in your browser settings. Because we do not sell or share personal information, we do not respond to Do Not Track signals, for which there is no common standard.

10. International transfers

We are based in the United States, and our cloud is hosted by Amazon Web Services in the United States. If you use the Service from elsewhere, your information is transferred to and processed in the United States. Where the law requires, we protect those transfers with the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are built into our Data Processing Addendum.

11. Security

We use encryption in transit and at rest, application-level encryption for integration credentials and detected secrets, and access controls on our systems and in the product. API keys you add are stored encrypted on the machine where your agents run. No system is perfectly secure. If a breach affects your personal information, we will notify you and the authorities as the law requires. Details are on our Security page.

12. Children

The Service is for professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email s@cyborg7.com and we will delete it.

13. Google user data

When you sign in with Google, we receive only your Google account identifier, email address and name, and we use them only to sign you in. Cyborg’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve ads or to train general-purpose AI or machine learning models, we do not transfer it to data brokers, and we do not allow humans to read it except with your consent, for security purposes, or as required by law.

14. Notice for California and other U.S. states

In the last 12 months we have collected the following categories of personal information, from the sources and for the purposes described above. We disclose each category for business purposes only to the subprocessors listed at /subprocessors and to services you connect.

CategoryExamples
IdentifiersName, email address, account identifiers, IP address, device identifiers
Customer recordsBilling email and subscription details
Commercial informationPlans purchased and billing history
Internet activityProduct usage events, diagnostics, website analytics
Professional informationTeam size and tools used, from our early-access form
Sensitive personal informationAccount sign-in credentials, used only to authenticate you

We do not sell or share personal information, and we have not done so in the last 12 months. We do not knowingly sell or share the personal information of anyone under 16. We use sensitive personal information only for purposes permitted by law. Retention periods are described in Section 7.

15. Changes to this policy

We will update this policy as the Service changes. If a change is material, we will notify you by email or in the app before it takes effect. The date at the top shows when it was last updated.

16. Contact

Cyborg Systems, Corp., a Delaware corporation.
Email s@cyborg7.com with any question about this policy or your personal information.