Account and service data. Sharkly generally acts as a controller or business for information needed to create and secure accounts, administer the Services, communicate with users, provide support, and understand service operations.
Customer Content. When an Organization uses the hosted Services to submit, store, synchronize, or process Customer Content, Sharkly generally processes that content on the Organization's instructions. Depending on the applicable agreement and law, Sharkly may act as a processor or service provider for that content, while the Organization acts as the controller or business.
Self-hosted data. The self-hosted operator controls the deployment and is responsible for the personal information processed by that deployment. Sharkly may receive limited information if the operator separately contacts Sharkly for support, downloads software from Sharkly-operated systems, or connects the deployment to a Sharkly-operated service.
name, email address, avatar, profile information, and language or application preferences;
authentication information, login events, verification-code records, session information, and token metadata;
Organization, Space, role, permission, membership, invitation, and People directory information;
support requests, feedback, and communications with Sharkly; and
administrative settings and records showing who created, changed, archived, or deleted an item.
Task titles, descriptions, status, priority, type, workflow, labels, custom fields, due dates, projects, assignees, subscribers, and related Task relationships;
comments, replies, mentions, reactions, progress updates, activity records, review feedback, and other collaboration history;
files, screenshots, documents, logs, and other attachments; and
standalone Agent or Crew conversation content where that feature is used.
Agent names, descriptions, instructions, visibility, selected provider or model, reasoning settings, tool permissions, Runtime selection, arguments, environment references, and task-run settings;
Crew names, descriptions, instructions, leader and member assignments, visibility, and collaboration settings;
Skill names, descriptions, reusable instructions, uploaded Skill files, supporting text files, source URLs, version information, and Agent assignments; and
references to environment variables, secrets, credentials, repositories, and execution directories configured for an Agent or Runtime.
repository URLs, code-host type, repository description, branch or commit references, and the Space or Agent associated with the repository;
code-host credential metadata and encrypted credentials where the Organization chooses to store them in Sharkly;
source code and files read or changed during execution;
patches, diffs, generated files, test results, build results, and summaries of code changes; and
local directory references and working-directory metadata used to route an Agent run.
the Task, comment, prompt, Agent, Crew, Skill, repository, and configuration context supplied to the run;
run identifiers, queue and status records, start and end times, duration, retry and cancellation information, and failure categories;
execution traces, model requests and responses made through configured tools or providers, tool calls, tool inputs and results, command metadata, logs, and error information;
text, files, code changes, comments, progress updates, and other Agent outputs; and
human approvals, denials, review actions, and follow-up instructions.
Computer identifiers, display name, visibility, operating system or platform, status, timezone, and heartbeat or last-seen information;
Runtime identifiers, Runtime type, detected AI command-line tools, tool versions, supported capabilities, model or provider configuration, and availability;
daemon and local-service version, process status, uptime, capacity, task concurrency, and coarse diagnostic information;
network endpoints and Organization routing information needed to connect the Runtime to the Services; and
local execution metadata such as working-directory mode, run directory references, repository cache state, and task dispatch status.
Jira. This may include the Jira hostname, account identifier or email, encrypted API token or personal access token, project metadata, webhook configuration, mappings, and imported or synchronized issues, epics, titles, descriptions, statuses, priorities, assignees, labels, estimates, comments, attachments, links, sprints, and user references.
Slack. This may include Slack team and app information, encrypted app configuration, OAuth, bot, signing, and client credentials, message and thread identifiers, user and channel identifiers, mentions, messages sent to an Agent, Agent replies, event metadata, and installation status.
GitHub and other code hosts. This may include connected account and organization identifiers, repository URLs and metadata, OAuth or installation identifiers, credential metadata and encrypted credentials, webhook request metadata, and events involving pull requests, pushes, issues, issue comments, and sub-issues. Depending on enabled features, Sharkly may process titles, descriptions, branch and commit references, actors, comments, attachments, and relationship data to link pull requests or commits to Tasks, create or update Tasks from issues, synchronize comments or attachments, and update Task state when linked issues change.
Google and other OAuth providers. This may include OAuth identifiers, authorization responses, account identity information returned by the provider, and tokens or token metadata needed to complete or maintain the connection.
Model and Agent-tool providers. Depending on the Agent, Runtime, and customer configuration, prompts, instructions, selected repository context, tool results, attachments, and other run content may be sent to a customer-selected model provider or Agent command-line tool so it can produce an output.
IP address, request time, browser or application type, operating system, device and session identifiers, language, and referring or requested page information;
authentication, security, API, WebSocket, and audit events;
feature interactions, route or screen usage, coarse configuration values, counts, durations, status values, and error categories;
hosted server and application logs and diagnostics;
connected Computer and Runtime telemetry such as versions, status, heartbeats, execution state, and failure categories; and
cookies, local storage, and similar technologies used for authentication, security, preferences, session continuity, and service operation.
Agent tools may run on a local or remote Computer selected by the Organization.
A Runtime may clone repositories, read or modify files, run commands, and communicate with model or tool providers from that Computer.
A self-hosted operator controls its Sharkly application server, PostgreSQL database, object storage, email provider, OAuth configuration, analytics destination, infrastructure access, backups, and logs.
Private attachments can be stored in operator-configured S3-compatible storage using authorized access methods. Public avatars may use a separately configured public storage location.
Optional analytics is off unless the operator configures it.
provide, operate, maintain, and improve the Services;
create and secure accounts, authenticate users, manage sessions, and administer Organizations, Spaces, permissions, and People;
create, store, organize, search, display, synchronize, and deliver Tasks, comments, attachments, projects, and other Customer Content;
configure and run Agents, Crews, Skills, Computers, and Runtimes;
dispatch work, provide context to an Agent, invoke configured tools or model providers, and return execution traces and Agent outputs;
connect and synchronize customer-selected integrations;
provide support, troubleshoot failures, prevent abuse, protect the Services, and enforce applicable agreements;
send service, security, support, and administrative communications;
monitor availability, reliability, capacity, and performance; and
comply with law and protect the rights, safety, and integrity of Sharkly, users, Organizations, and others.
At the direction of an Organization or user. We disclose content to People, Agents, Crews, Computers, Runtimes, repositories, integrations, model providers, and other recipients selected through the Services.
Service providers. We may use providers that support hosting, databases, storage, content delivery, email, authentication, customer support, security, monitoring, and other service operations.
Connected third parties. We disclose information to Jira, Slack, GitHub, Google, code hosts, model providers, and other services when a user or Organization enables or uses the connection.
Organization administrators and authorized users. Administrators and other authorized People may access account data, Customer Content, settings, audit information, and execution records according to their permissions.
Legal and safety reasons. We may disclose information when we believe disclosure is required by law or reasonably necessary to protect rights, safety, security, property, users, Organizations, the public, or the Services.
Business transactions. Information may be disclosed as part of a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate safeguards and applicable law.
With consent. We may disclose information for another purpose with the relevant person's or Organization's direction or consent.
Account, profile, Organization, membership, and authentication records are retained while the account or Organization remains active and for a reasonable period afterward for security, audit, dispute-resolution, and legal-compliance purposes.
Customer Content, including Tasks, comments, attachments, repository references, prompts, Agent inputs, and Agent outputs is retained according to the Organization's settings, user actions, and service controls, unless a longer period is required for security, legal, backup, or dispute-resolution purposes.
Execution traces, logs, command metadata, run status, and diagnostic records are retained for the period reasonably needed to operate, secure, troubleshoot, audit, and improve the Services.
Integration credentials, access tokens, OAuth records, webhook settings, and related configuration are retained while the integration or account remains connected and for a reasonable period afterward as needed for security, audit, and legal-compliance purposes.
Support communications and feedback are retained as needed to provide support, maintain business records, improve the Services, and resolve disputes.
Security logs, audit records, abuse-prevention records, and legal records may be retained for longer periods where needed to protect the Services, investigate incidents, comply with law, or establish, exercise, or defend legal claims.
Backups may retain deleted or changed information for a limited period until overwritten or deleted through the ordinary backup lifecycle. Information in backups is generally not restored except for disaster recovery, security, legal, or business-continuity purposes.
Organization-scoped server access and membership checks;
permission and visibility controls for Organizations, Spaces, People, Agents, Crews, Computers, and other resources;
signed authentication tokens, expiring or revocable access mechanisms, and one-time display of certain personal access tokens;
encryption of supported stored integration credentials and secrets;
signature verification for supported webhook integrations;
private attachment storage and authorized access options when correctly configured;
secret-pattern and local-path redaction in certain Agent output and diagnostic paths;
isolated temporary work directories or worktrees for configured Agent runs; and
logging rules intended to exclude raw prompts, model output, credentials, full environment dumps, and other sensitive values from specified diagnostic events.
Identifiers and account information, such as name, email address, account identifiers, avatar, authentication records, session information, and token metadata.
Organization and collaboration information, such as Organization, Space, role, membership, invitation, People directory, Task, comment, attachment, project, activity, and review information.
Internet, device, and network activity, such as IP address, browser or application type, operating system, device and session identifiers, routes or screens used, request metadata, cookies, local storage, logs, and diagnostics.
Integration and authentication information, such as OAuth identifiers, webhook metadata, connected account identifiers, authorization responses, credential metadata, encrypted credentials, and information synchronized from customer-enabled integrations.
Customer Content, such as prompts, instructions, comments, files, attachments, repository content made available to an Agent, and Agent inputs and outputs.
Repository and source-code information, such as repository URLs, branch or commit references, source files, patches, diffs, generated files, test results, build results, and code-change summaries.
Agent, Crew, Skill, Computer, and Runtime information, such as configuration, permissions, selected providers or models, execution traces, tool calls, command metadata, run status, logs, Runtime capabilities, Computer status, and heartbeat information.
Sensitive information, only where it is included in account security data, credentials or secrets configured by an Organization, Customer Content selected by a user or Organization, precise categories defined by applicable law, or other information that may be treated as sensitive under state law. Sharkly does not seek to infer sensitive characteristics from Customer Content.
confirm whether Sharkly processes their personal information;
access, correct, or delete personal information;
receive a portable copy of personal information;
opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling, where those activities occur;
limit or opt out of certain uses or disclosures of sensitive personal information, where applicable;
not be discriminated against for exercising privacy rights; and
appeal a denied privacy request where state law provides an appeal right.
Contract. We process account, service, support, authentication, Organization, and operational information where processing is necessary to provide the requested Services, administer accounts, run configured workflows, provide support, and perform our agreements.
Legitimate interests. We process information where necessary for legitimate interests such as securing the Services, preventing abuse, troubleshooting failures, maintaining reliability, improving product functionality, communicating about service administration, and protecting Sharkly, users, Organizations, and others, balanced against affected rights and expectations.
Legal obligations. We process information where necessary to comply with applicable law, respond to lawful requests, maintain required records, and enforce legal rights.
Consent. We rely on consent where consent is requested and legally required, such as for certain cookies, optional analytics, marketing communications, or processing of sensitive information where consent is the required basis. A person may withdraw consent at any time where processing is based on consent.
request access to their personal information;
request correction of inaccurate or incomplete personal information;
request deletion of personal information;
request restriction of processing;
object to processing based on legitimate interests;
receive a portable copy of personal information they provided;
withdraw consent where processing is based on consent; and
lodge a complaint with a competent data-protection authority.