# Privacy Policy

**Last updated:** August 4, 2026

This Privacy Policy explains how Sharkly Teams Inc. ("Sharkly," "we," "us," or "our") handles personal information when people use Sharkly websites, applications, command-line tools, APIs, hosted services, and related support services (collectively, the "Services").

## 1. Scope

This Privacy Policy applies to personal information that Sharkly handles in connection with the Services. It does not govern a third-party service's independent practices, even when that service is connected to Sharkly. For example, Jira, Slack, GitHub, Google, a model provider, a code host, or a customer-selected infrastructure provider may process information under its own terms and privacy policy.

For a self-hosted deployment, the organization or person operating that deployment controls the server, database, storage, analytics settings, infrastructure logs, and many other processing decisions. That operator is responsible for providing any privacy notices, obtaining any required permissions, configuring retention and security, responding to rights requests, and complying with laws that apply to its deployment. This Privacy Policy describes Sharkly's practices and product design, but it does not replace the self-hosted operator's own privacy obligations.

## 2. Sharkly's Role and the Customer's Role

Sharkly handles different categories of information in different roles:

- **Account and service data.** Sharkly generally acts as a controller or business for information needed to create and secure accounts, administer the Services, communicate with users, provide support, and understand service operations.
- **Customer Content.** When an Organization uses the hosted Services to submit, store, synchronize, or process Customer Content, Sharkly generally processes that content on the Organization's instructions. Depending on the applicable agreement and law, Sharkly may act as a processor or service provider for that content, while the Organization acts as the controller or business.
- **Self-hosted data.** The self-hosted operator controls the deployment and is responsible for the personal information processed by that deployment. Sharkly may receive limited information if the operator separately contacts Sharkly for support, downloads software from Sharkly-operated systems, or connects the deployment to a Sharkly-operated service.

"Customer Content" means information submitted to or generated through the Services on behalf of an Organization, including Task content, comments, attachments, prompts, repository content made available to an Agent, and Agent outputs. Account and service data is not Customer Content merely because it relates to a user of an Organization.

If you use Sharkly through an employer, customer, school, or other Organization, that Organization may administer your account and control Customer Content. Please direct questions about the Organization's privacy practices or instructions to that Organization.

## 3. Information We Handle

### Account, profile, and Organization information

We may handle information that you or an Organization provides when creating or administering an account, including:

- name, email address, avatar, profile information, and language or application preferences;
- authentication information, login events, verification-code records, session information, and token metadata;
- Organization, Space, role, permission, membership, invitation, and People directory information;
- support requests, feedback, and communications with Sharkly; and
- administrative settings and records showing who created, changed, archived, or deleted an item.

Sharkly is currently free. We do not describe payment-card or billing-data practices in this Policy because the current Services do not require paid subscription billing.

### Tasks, comments, attachments, and collaboration content

Organizations and users may provide or create Customer Content such as:

- Task titles, descriptions, status, priority, type, workflow, labels, custom fields, due dates, projects, assignees, subscribers, and related Task relationships;
- comments, replies, mentions, reactions, progress updates, activity records, review feedback, and other collaboration history;
- files, screenshots, documents, logs, and other attachments; and
- standalone Agent or Crew conversation content where that feature is used.

Tasks and comments may contain personal information or confidential material selected by the user or Organization. Users should not place passwords, API keys, access tokens, or other secrets in Tasks, comments, prompts, or attachments.

### Agent, Crew, and Skill configuration

The Services may handle configuration used to create and operate AI-assisted workflows, including:

- Agent names, descriptions, instructions, visibility, selected provider or model, reasoning settings, tool permissions, Runtime selection, arguments, environment references, and task-run settings;
- Crew names, descriptions, instructions, leader and member assignments, visibility, and collaboration settings;
- Skill names, descriptions, reusable instructions, uploaded Skill files, supporting text files, source URLs, version information, and Agent assignments; and
- references to environment variables, secrets, credentials, repositories, and execution directories configured for an Agent or Runtime.

A Skill or Agent instruction may become part of the context provided during an Agent run. Do not include secrets in Agent instructions, Crew instructions, or Skills.

### Repository and source-code information

When an Organization connects a repository or configures a local working directory, the Services may handle:

- repository URLs, code-host type, repository description, branch or commit references, and the Space or Agent associated with the repository;
- code-host credential metadata and encrypted credentials where the Organization chooses to store them in Sharkly;
- source code and files read or changed during execution;
- patches, diffs, generated files, test results, build results, and summaries of code changes; and
- local directory references and working-directory metadata used to route an Agent run.

Depending on the configuration, repository access and code processing may occur on a customer-controlled Computer through a local Runtime, on a customer-managed remote Computer, or in another configured execution environment. Deleting a repository reference from Sharkly does not delete the underlying repository from the code host or a local Computer.

### Agent execution data

When an Agent or Crew performs work, Sharkly may handle operational records needed to dispatch, display, troubleshoot, and audit the run, including:

- the Task, comment, prompt, Agent, Crew, Skill, repository, and configuration context supplied to the run;
- run identifiers, queue and status records, start and end times, duration, retry and cancellation information, and failure categories;
- execution traces, model requests and responses made through configured tools or providers, tool calls, tool inputs and results, command metadata, logs, and error information;
- text, files, code changes, comments, progress updates, and other Agent outputs; and
- human approvals, denials, review actions, and follow-up instructions.

Execution traces may expose sensitive content from tools, repositories, commands, or connected services. Sharkly uses redaction measures for recognized secret patterns in certain Agent output paths, but automated redaction cannot identify every secret or sensitive value. Organizations should use least-privilege credentials, review Agent permissions, and avoid placing secrets in prompts or content.

### Computer, Runtime, and local-service information

To connect a Computer and run Agent work, Sharkly may handle:

- Computer identifiers, display name, visibility, operating system or platform, status, timezone, and heartbeat or last-seen information;
- Runtime identifiers, Runtime type, detected AI command-line tools, tool versions, supported capabilities, model or provider configuration, and availability;
- daemon and local-service version, process status, uptime, capacity, task concurrency, and coarse diagnostic information;
- network endpoints and Organization routing information needed to connect the Runtime to the Services; and
- local execution metadata such as working-directory mode, run directory references, repository cache state, and task dispatch status.

Local or self-hosted execution does not mean that all related data stays only on the Computer. The Runtime receives the context needed to perform the work and sends run status, execution records, logs, and results back to the configured Sharkly server. The operator controls where that server and its storage are hosted.

### Integration data

If an Organization connects a third-party service, Sharkly may handle information needed to authorize, configure, and operate that connection.

- **Jira.** This may include the Jira hostname, account identifier or email, encrypted API token or personal access token, project metadata, webhook configuration, mappings, and imported or synchronized issues, epics, titles, descriptions, statuses, priorities, assignees, labels, estimates, comments, attachments, links, sprints, and user references.
- **Slack.** This may include Slack team and app information, encrypted app configuration, OAuth, bot, signing, and client credentials, message and thread identifiers, user and channel identifiers, mentions, messages sent to an Agent, Agent replies, event metadata, and installation status.
- **GitHub and other code hosts.** This may include connected account and organization identifiers, repository URLs and metadata, OAuth or installation identifiers, credential metadata and encrypted credentials, webhook request metadata, and events involving pull requests, pushes, issues, issue comments, and sub-issues. Depending on enabled features, Sharkly may process titles, descriptions, branch and commit references, actors, comments, attachments, and relationship data to link pull requests or commits to Tasks, create or update Tasks from issues, synchronize comments or attachments, and update Task state when linked issues change.
- **Google and other OAuth providers.** This may include OAuth identifiers, authorization responses, account identity information returned by the provider, and tokens or token metadata needed to complete or maintain the connection.
- **Model and Agent-tool providers.** Depending on the Agent, Runtime, and customer configuration, prompts, instructions, selected repository context, tool results, attachments, and other run content may be sent to a customer-selected model provider or Agent command-line tool so it can produce an output.

The Organization decides which integrations to enable and is responsible for ensuring that it has authority to disclose information to and receive information from those services. Disconnecting an integration stops future activity through that connection but may not delete information already stored in Sharkly or the third-party service.

### Information collected automatically

When a person or system uses the Services, we may automatically receive:

- IP address, request time, browser or application type, operating system, device and session identifiers, language, and referring or requested page information;
- authentication, security, API, WebSocket, and audit events;
- feature interactions, route or screen usage, coarse configuration values, counts, durations, status values, and error categories;
- hosted server and application logs and diagnostics;
- connected Computer and Runtime telemetry such as versions, status, heartbeats, execution state, and failure categories; and
- cookies, local storage, and similar technologies used for authentication, security, preferences, session continuity, and service operation.

Ordinary CLI and local-service log files remain on the Computer unless a user chooses to provide them to Sharkly, such as in a support request.

## 4. Local Processing and Self-Hosting

Sharkly supports customer-controlled execution and self-hosting:

- Agent tools may run on a local or remote Computer selected by the Organization.
- A Runtime may clone repositories, read or modify files, run commands, and communicate with model or tool providers from that Computer.
- A self-hosted operator controls its Sharkly application server, PostgreSQL database, object storage, email provider, OAuth configuration, analytics destination, infrastructure access, backups, and logs.
- Private attachments can be stored in operator-configured S3-compatible storage using authorized access methods. Public avatars may use a separately configured public storage location.
- Optional analytics is off unless the operator configures it.

A self-hosted operator is responsible for securing the deployment, configuring transport and storage protections, selecting third parties, limiting access, managing backups, setting retention, responding to incidents and rights requests, and informing its users about the operator's practices.

## 5. How We Use Information

We may use personal information and Customer Content to:

- provide, operate, maintain, and improve the Services;
- create and secure accounts, authenticate users, manage sessions, and administer Organizations, Spaces, permissions, and People;
- create, store, organize, search, display, synchronize, and deliver Tasks, comments, attachments, projects, and other Customer Content;
- configure and run Agents, Crews, Skills, Computers, and Runtimes;
- dispatch work, provide context to an Agent, invoke configured tools or model providers, and return execution traces and Agent outputs;
- connect and synchronize customer-selected integrations;
- provide support, troubleshoot failures, prevent abuse, protect the Services, and enforce applicable agreements;
- send service, security, support, and administrative communications;
- monitor availability, reliability, capacity, and performance; and
- comply with law and protect the rights, safety, and integrity of Sharkly, users, Organizations, and others.

## 6. No Model Training on Customer Content

**Sharkly does not use Customer Content, source code, prompts, or Agent outputs to train Sharkly models or third-party foundation models.**

For model-provider accounts and contractual paths controlled by Sharkly, Sharkly does not authorize providers to use that content to train generalized foundation models. Relevant content may still be sent to those providers to perform the requested inference or tool operation.

If a user or Organization connects or operates a provider account under its own agreement, that provider’s terms, account tier, retention settings, and data controls govern its processing. Sharkly does not authorize model training on the customer’s behalf, but the Organization is responsible for selecting and configuring a provider arrangement that prohibits training where required.

## 7. How We Disclose Information

We may disclose information in the following circumstances:

- **At the direction of an Organization or user.** We disclose content to People, Agents, Crews, Computers, Runtimes, repositories, integrations, model providers, and other recipients selected through the Services.
- **Service providers.** We may use providers that support hosting, databases, storage, content delivery, email, authentication, customer support, security, monitoring, and other service operations. 
- **Connected third parties.** We disclose information to Jira, Slack, GitHub, Google, code hosts, model providers, and other services when a user or Organization enables or uses the connection.
- **Organization administrators and authorized users.** Administrators and other authorized People may access account data, Customer Content, settings, audit information, and execution records according to their permissions.
- **Legal and safety reasons.** We may disclose information when we believe disclosure is required by law or reasonably necessary to protect rights, safety, security, property, users, Organizations, the public, or the Services.
- **Business transactions.** Information may be disclosed as part of a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate safeguards and applicable law.
- **With consent.** We may disclose information for another purpose with the relevant person's or Organization's direction or consent.

## 8. Cookies and Optional Analytics

Sharkly may use cookies, local storage, and similar technologies that are necessary for authentication, security, preferences, session continuity, and operation of the Services.

Sharkly-hosted applications may use PostHog when a product build is configured with a PostHog project key. The current client integration can collect page views, automatic interaction events, session recordings, and an anonymous session identifier that may later be associated with a signed-in user.

Session recordings can capture rendered interface content unless appropriate masking, blocking, or exclusion controls are configured. The event-property rules described below do not, by themselves, limit what a session recording may capture.

For self-hosted deployments, analytics is disabled unless the operator supplies a PostHog project key, and the operator can force analytics off. A self-hosted deployment is not configured to send analytics to a Sharkly-operated destination by default.

For structured analytics events, Sharkly's documented analytics rules prohibit prompts, instructions, chat or comment text, Task titles or descriptions, generated output, full repository URLs, file paths, diffs, logs, command output, tokens, authorization data, environment variables, full email addresses, and raw provider or shell errors without a separate privacy review.

## 9. International Data Transfers

Sharkly, an Organization, a self-hosted operator, or a connected service may process information in a country other than the country where the user is located. The locations involved depend on the hosted deployment, operator infrastructure, connected integrations, model providers, and other services selected by the Organization.

For Sharkly-hosted Services, Sharkly is based in the United States and may use service providers located in the United States and other countries. Where personal information is transferred from the European Economic Area, Switzerland, or the United Kingdom to a country that has not been recognized as providing an adequate level of protection, Sharkly uses appropriate safeguards where required, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another valid UK transfer mechanism, and contractual commitments with service providers. Customer-selected integrations, model providers, code hosts, and self-hosted infrastructure may use their own transfer mechanisms and locations.

## 10. Retention and Deletion

We retain information for as long as reasonably necessary to provide and secure the Services, maintain legitimate business records, comply with law, resolve disputes, and enforce agreements. The appropriate period depends on the type of information, the Organization's settings and instructions, whether an account or integration remains active, security needs, and legal requirements.

The following criteria generally apply to Sharkly-hosted Services:

- **Account, profile, Organization, membership, and authentication records** are retained while the account or Organization remains active and for a reasonable period afterward for security, audit, dispute-resolution, and legal-compliance purposes.
- **Customer Content, including Tasks, comments, attachments, repository references, prompts, Agent inputs, and Agent outputs** is retained according to the Organization's settings, user actions, and service controls, unless a longer period is required for security, legal, backup, or dispute-resolution purposes.
- **Execution traces, logs, command metadata, run status, and diagnostic records** are retained for the period reasonably needed to operate, secure, troubleshoot, audit, and improve the Services.
- **Integration credentials, access tokens, OAuth records, webhook settings, and related configuration** are retained while the integration or account remains connected and for a reasonable period afterward as needed for security, audit, and legal-compliance purposes.
- **Support communications and feedback** are retained as needed to provide support, maintain business records, improve the Services, and resolve disputes.
- **Security logs, audit records, abuse-prevention records, and legal records** may be retained for longer periods where needed to protect the Services, investigate incidents, comply with law, or establish, exercise, or defend legal claims.
- **Backups** may retain deleted or changed information for a limited period until overwritten or deleted through the ordinary backup lifecycle. Information in backups is generally not restored except for disaster recovery, security, legal, or business-continuity purposes.

Users and authorized administrators may be able to edit, archive, disconnect, or delete profile information, Personal Access Tokens, Organizations, Computers, Agents, Crews, Skills, Tasks, comments, attachments, repositories, integrations, and other records where the Services provide the relevant control. Some actions stop future processing without deleting historical records. For example:

- disconnecting Jira or Slack does not automatically delete information already synchronized into Sharkly or retained by that provider;
- deleting a repository reference does not delete the underlying repository or local files;
- removing a local Runtime does not necessarily delete records already sent to the configured Sharkly server; and
- archived items and execution history may remain available according to Organization settings and applicable requirements.

Self-hosted operators control database records, object storage, logs, backups, and deletion for their deployment.

## 11. Security

Sharkly uses administrative, technical, and organizational measures designed to protect information. Product and deployment measures described in current documentation include:

- Organization-scoped server access and membership checks;
- permission and visibility controls for Organizations, Spaces, People, Agents, Crews, Computers, and other resources;
- signed authentication tokens, expiring or revocable access mechanisms, and one-time display of certain personal access tokens;
- encryption of supported stored integration credentials and secrets;
- signature verification for supported webhook integrations;
- private attachment storage and authorized access options when correctly configured;
- secret-pattern and local-path redaction in certain Agent output and diagnostic paths;
- isolated temporary work directories or worktrees for configured Agent runs; and
- logging rules intended to exclude raw prompts, model output, credentials, full environment dumps, and other sensitive values from specified diagnostic events.

No method of transmission, storage, or processing is completely secure. Security also depends on customer choices, including Agent permissions, Runtime configuration, integration scopes, model-provider settings, self-hosted infrastructure, credential hygiene, and what users place in Tasks, prompts, comments, attachments, Skills, and source repositories.

## 12. Rights and Choices

Depending on where a person lives and subject to applicable exceptions, the person may have rights to request access, correction, deletion, restriction, portability, or objection, or to withdraw consent where processing is based on consent.

Users can manage some information through account, Profile, Preferences, Organization, integration, and token settings. They can also choose whether to connect optional integrations, which model or Agent tool to configure, which content to submit, and whether to operate a self-hosted deployment.

To make a privacy request concerning account and service data controlled by Sharkly, contact support@sharkly.ai. We may need to verify the requester's identity and authority.

If Sharkly processes Customer Content on behalf of an Organization, the requester should generally contact that Organization first. We will assist the Organization as required by the applicable agreement and law. For a self-hosted deployment, requests should be directed to the self-hosted operator.

## 13. United States State Privacy Disclosures

This section provides additional disclosures for residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Delaware, Oregon, Texas, Virginia, Utah, and other states where similar laws apply. These rights and disclosures apply only when the relevant state law applies to Sharkly and to the person making the request.

Sharkly Teams Inc. is a Delaware corporation. Delaware's Personal Data Privacy Act and other state privacy laws may require disclosures about the categories of personal information we process, the sources of that information, the purposes for processing it, the categories of recipients to whom it is disclosed, and the rights available to residents of those states.

During the period described in this Policy, Sharkly may process the following categories of personal information:

- **Identifiers and account information,** such as name, email address, account identifiers, avatar, authentication records, session information, and token metadata.
- **Organization and collaboration information,** such as Organization, Space, role, membership, invitation, People directory, Task, comment, attachment, project, activity, and review information.
- **Internet, device, and network activity,** such as IP address, browser or application type, operating system, device and session identifiers, routes or screens used, request metadata, cookies, local storage, logs, and diagnostics.
- **Integration and authentication information,** such as OAuth identifiers, webhook metadata, connected account identifiers, authorization responses, credential metadata, encrypted credentials, and information synchronized from customer-enabled integrations.
- **Customer Content,** such as prompts, instructions, comments, files, attachments, repository content made available to an Agent, and Agent inputs and outputs.
- **Repository and source-code information,** such as repository URLs, branch or commit references, source files, patches, diffs, generated files, test results, build results, and code-change summaries.
- **Agent, Crew, Skill, Computer, and Runtime information,** such as configuration, permissions, selected providers or models, execution traces, tool calls, command metadata, run status, logs, Runtime capabilities, Computer status, and heartbeat information.
- **Sensitive information,** only where it is included in account security data, credentials or secrets configured by an Organization, Customer Content selected by a user or Organization, precise categories defined by applicable law, or other information that may be treated as sensitive under state law. Sharkly does not seek to infer sensitive characteristics from Customer Content.

We collect these categories from users, Organizations, administrators, connected Computers and Runtimes, customer-enabled integrations, model and tool providers, code hosts, service providers, and automatically when the Services are used.

We process these categories for the business and operational purposes described in Section 5, including to provide, secure, support, troubleshoot, maintain, and improve the Services; administer accounts and Organizations; run Agents, Crews, Skills, Computers, and Runtimes; synchronize integrations; monitor reliability and performance; prevent abuse and security incidents; comply with law; and enforce agreements.

We may disclose these categories to the recipients described in Section 7, including Organization administrators and authorized users, customer-selected integrations, model and Agent-tool providers, code hosts, Computers and Runtimes selected by the Organization, service providers, professional advisers, authorities where legally required, and parties to a business transaction. We disclose Customer Content at the direction of the relevant Organization or user and as needed to provide and protect the Services.

Sharkly does not sell personal information for money. Based on the current Services described in this Policy, Sharkly does not share personal information for cross-context behavioral advertising, process personal information for targeted advertising, or use personal information for profiling that produces legal or similarly significant effects. If Sharkly changes these practices in a way that requires an opt-out right, we will provide the required notice and opt-out method before or at the time required by law.

Sharkly does not knowingly sell or share personal information of children under 18.

Subject to applicable law and exceptions, residents of some U.S. states may have rights to:

- confirm whether Sharkly processes their personal information;
- access, correct, or delete personal information;
- receive a portable copy of personal information;
- opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling, where those activities occur;
- limit or opt out of certain uses or disclosures of sensitive personal information, where applicable;
- not be discriminated against for exercising privacy rights; and
- appeal a denied privacy request where state law provides an appeal right.

To exercise these rights, contact support@sharkly.ai. We may need to verify your identity and authority before fulfilling a request. If your request concerns Customer Content controlled by an Organization, you should generally contact that Organization first; Sharkly will assist the Organization as required by applicable law and agreement. If we deny a request and applicable state law gives you an appeal right, you may appeal by replying to our denial or contacting support@sharkly.ai with "Privacy Appeal" in the subject line.

## 14. EEA and UK Disclosures

This section provides additional information for people in the European Economic Area, Switzerland, and the United Kingdom where the EU GDPR, UK GDPR, or similar law applies.

For account and service data that Sharkly determines how and why to process, the controller is Sharkly Teams Inc., a Delaware corporation. For Customer Content processed through an Organization's use of the Services, the Organization is generally the controller and Sharkly acts as a processor or service provider acting on the Organization's instructions. For a self-hosted deployment, the self-hosted operator controls the deployment and is generally responsible for the personal information processed by that deployment.

Sharkly's legal bases for processing personal information may include:

- **Contract.** We process account, service, support, authentication, Organization, and operational information where processing is necessary to provide the requested Services, administer accounts, run configured workflows, provide support, and perform our agreements.
- **Legitimate interests.** We process information where necessary for legitimate interests such as securing the Services, preventing abuse, troubleshooting failures, maintaining reliability, improving product functionality, communicating about service administration, and protecting Sharkly, users, Organizations, and others, balanced against affected rights and expectations.
- **Legal obligations.** We process information where necessary to comply with applicable law, respond to lawful requests, maintain required records, and enforce legal rights.
- **Consent.** We rely on consent where consent is requested and legally required, such as for certain cookies, optional analytics, marketing communications, or processing of sensitive information where consent is the required basis. A person may withdraw consent at any time where processing is based on consent.

People in the European Economic Area, Switzerland, or the United Kingdom may have rights, subject to applicable conditions and exceptions, to:

- request access to their personal information;
- request correction of inaccurate or incomplete personal information;
- request deletion of personal information;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive a portable copy of personal information they provided;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data-protection authority.

To exercise these rights for account and service data controlled by Sharkly, contact support@sharkly.ai. We may need to verify your identity and authority. If the request concerns Customer Content controlled by an Organization, you should generally contact that Organization first; Sharkly will assist the Organization as required by applicable law and agreement. Requests concerning a self-hosted deployment should be directed to the self-hosted operator.

Sharkly is based in the United States, and the Services, customer-selected integrations, model providers, support providers, and infrastructure providers may process information outside the European Economic Area, Switzerland, or the United Kingdom. Where required, Sharkly uses appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another valid UK transfer mechanism, and contractual protections with service providers and customer agreements. Additional international-transfer information appears in Section 9.

## 15. Children

The Services are not intended for children under 18. Sharkly does not knowingly permit a child below that age to create an account for the Services.

If you believe a child has provided personal information through the Services in a manner not permitted by law, contact support@sharkly.ai.

## 16. Third-Party Services and Customer-Selected Providers

The Services can interact with third-party services selected by a user, Organization, or self-hosted operator. Those services may include code hosts, Jira, Slack, Google or another OAuth provider, model providers, Agent command-line tools, email providers, storage and content-delivery providers, infrastructure hosts, and optional PostHog analytics.

Sharkly does not control a third party's independent processing. Before enabling a provider, the Organization should review the provider's terms, privacy practices, security, data-use settings, retention options, locations, and access controls. The Organization should also configure the narrowest permissions appropriate for the intended use.

## 17. Changes to This Policy

We may update this Privacy Policy as the Services, our practices, or legal requirements change. We will post the updated Policy and revise the last updated date.

## 18. Contact

Questions, concerns, and privacy requests may be sent to:

Sharkly Teams Inc. 
support@sharkly.ai
