Margay Privacy Policy
1. Introduction
Welcome to use Margay (hereinafter referred to as "Margay", "this product" or "this service").
Margay is a new generation AI Agent collaboration platform for individual and enterprise users. It provides digital avatars, multi-agent collaboration, knowledge management, workflow orchestration, tool invocation, document generation, automated task execution, local intelligent assistants and other capabilities to help users complete knowledge management, content creation, software development, office collaboration and business automation more efficiently.
We are well aware of the importance of personal information and corporate data to users, and always regard data security and privacy protection as important principles in product design and operation. We will strictly abide by applicable laws and regulations such as the "Personal Information Protection Law of the People's Republic of China", "Cybersecurity Law of the People's Republic of China", "Data Security Law of the People's Republic of China" and other applicable laws and regulations, and take reasonable and necessary technical and management measures to protect the security of your personal information and business data.
This "Margay Privacy Protection Guidelines" (hereinafter referred to as "these Guidelines") aims to explain to you:
-
What information we collect;
-
How we use, store and protect this information;
-
Under what circumstances will we share or process your information;
-
Your legal rights related to personal information;
-
How you can contact us to exercise relevant rights or make comments.
Please read carefully and fully understand the entire contents of these Guidelines before registering, logging in or using Margay, especially those involving the processing of your personal information, third-party services, data sharing, user rights and disclaimers.
When you register, log in or continue to use Margay, it means that you have read, understood and agreed to the contents of these guidelines. If you do not agree with these guidelines, please stop using Margay and related services.
For some special functions, we may further explain the relevant data processing rules to you through product pages, function descriptions, authorization pop-ups or separate agreements. Such explanations form an integral part of these Guidelines and have the same legal effect as these Guidelines.
2. Definition
Unless otherwise agreed in these guidelines, the following terms have the following meanings:
2.1 Margay
refers to the artificial intelligence Agent collaboration platform provided and operated by Margay, including website, desktop client, mobile client and related services.
2.2 Users
refers to the natural person, legal person, unincorporated organization or other legally established entity who registers, logs in or uses Margay.
can be divided into:
-
Individual User
-
Enterprise users
-
Enterprise Administrator
-
Corporate Member
2.3 Enterprise Administrator
refers to the person authorized by the enterprise user to manage the enterprise workspace, members, model configuration, Agent, workflow, knowledge base, permissions and security policies.
Enterprise administrators can configure enterprise resources and manage enterprise members according to the scope of enterprise authorization.
2.4 Corporate members
refers to those who join the enterprise workspace and use Margay services within the scope of enterprise authorization, including but not limited to employees, partners, outsourcers and other authorized members.
2.5 Enterprise Data
refers to data uploaded, created, generated, processed or managed by enterprise users or enterprise members in the enterprise workspace, including but not limited to:
-
Enterprise organization information;
-
member information;
-
knowledge base content;
-
Documentation;
-
Conversation record;
-
Agent configuration;
-
Workflow configuration;
-
execution log;
-
business data;
-
Other data managed by the enterprise.
The purpose of processing and management rights of enterprise data are determined by enterprise users in accordance with the law.
2.6 AI model
refers to the large language model or other artificial intelligence model that provides Margay with natural language understanding, reasoning, generation, planning and other capabilities.
AI models include but are not limited to:
-
Margay built-in model;
-
third-party model;
-
model that users can access by themselves.
2.7 Third-party model
refers to large language model services provided by third-party service providers and authorized by users, including but not limited to OpenAI, Anthropic, Google, DeepSeek, Zhipu AI, Alibaba Cloud Tongyi Qianwen, Tencent Hunyuan, etc. The data processing rules of
third-party models are subject to the privacy policy and service agreement of the corresponding service provider.
2.8 Agent
refers to an intelligent agent that can independently perform task planning, tool invocation, knowledge retrieval, perform operations and generate results based on user goals.
Agent can be created, configured, shared by users or managed uniformly by the enterprise.
2.9 Digital clone
refers to the long-term intelligent assistant provided by Margay to users, which can combine long-term memory, historical conversations, knowledge base and user configuration to provide users with continuous and personalized intelligent collaboration capabilities.
2.10 Long-term memory
refers to user preferences, background information and other sustainable use information saved by Margay to enhance the continuous collaboration experience with user authorization or user active settings.
2.11 Workflow
refers to a multi-step task execution process configured by the user or automatically generated by the Agent, which can include execution logic such as multiple Agents, tool calls, model calls, and conditional judgments.
2.12 Tools
refers to various external capabilities called by Margay, including but not limited to:
-
MCP service;
-
CLI tool;
-
browser automation;
-
local program;
-
API service;
-
database;
-
office software;
-
file system;
-
Third-party services accessed by other users.
3. Scope of application
3.1
These guidelines apply to all products and services officially provided by Margay, including but not limited to:
-
Web client;
-
Windows client;
-
macOS client;
-
mobile application;
-
Enterprise management backend;
-
Open platform and related supporting services.
3.2
This guideline applies to personal information and related data processing activities generated by users when using Margay, including registration, login, AI dialogue, knowledge base management, Agent execution, workflow running, tool invocation and other functions.
3.3
For third-party services that users access or configure themselves, including but not limited to third-party AI models, MCP services, CLI tools, databases, browser plug-ins, internal corporate systems, open APIs, etc., the data processing behavior is the responsibility of the corresponding third party, and this guideline does not apply. Users should read and abide by the service agreement and privacy policy of the corresponding third party.
3.4
When users access third-party services through Margay, we only transmit data within the scope necessary to fulfill the user's request and will not process relevant information beyond the scope of user authorization.
3.5
When enterprise users manage enterprise members, knowledge bases, workflows and other enterprise resources through Margay, they should fulfill the relevant obligations of personal information processors in accordance with the law, ensure that authorization from enterprise members has been obtained in accordance with the law, and establish corresponding data management systems. Margay processes corporate data based on the authorization and instructions of corporate users and takes reasonable measures to ensure data security.
4. Information we collect
In order to provide you with stable, secure, and continuous AI services, we may collect, generate or process necessary information based on the specific functions you use. We always follow the principles of legality, legitimacy, necessity, and good faith, and only process your information within the scope necessary to realize product functions and fulfill legal obligations.
The type of information involved in different functions may be different. When a certain function requires obtaining specific information or device permissions, we will explain it to you in the appropriate scenario and obtain your authorization or consent if required by laws and regulations.
4.1 Account information
When you register, log in or use Margay, we may collect the following information:
(1) Registration information
includes but is not limited to:
-
mobile number
-
Email address
-
User nickname
-
User avatar
-
Login password (encrypted storage)
-
Third-party login ID (if applicable)
The above information is mainly used for:
-
Create user account;
-
Identity authentication;
-
Login verification;
-
Retrieve account;
-
Account security protection;
-
Customer Service Support.
If you refuse to provide the above necessary information, you may not be able to complete account registration or login, but this will not affect browsing public pages or using functions that do not require login (if applicable).
(2) Enterprise account information
When you join an enterprise workspace or an account is created by an enterprise administrator, we may process:
-
Company name
-
Unique enterprise identification
-
Department information
-
Job Information
-
Job number
-
Business Email
-
Corporate Membership
-
Permission role
The above information is used for:
-
Enterprise member management;
-
permission control;
-
Enterprise resource access;
-
Enterprise workspace collaboration.
The enterprise administrator is responsible for configuring the above information and shall perform relevant personal information protection obligations in accordance with the law.
4.2 Device information
In order to ensure the safe and stable operation of the product, we may automatically collect necessary equipment information, including but not limited to:
-
operating system type and version;
-
Browser type and version;
-
device model;
-
unique identifier of the device (such as device ID, Machine ID, etc.);
-
network type;
-
IP address;
-
client version;
-
time zone and language settings;
-
crash log;
-
Performance statistics.
The above information is mainly used for:
-
Identity verification;
-
Security risk control;
-
Troubleshooting;
-
Product compatibility optimization;
-
Service quality analysis.
Unless otherwise provided by laws and regulations, we will not use device information to identify your true identity.
4.3 Usage log
In order to continuously improve product stability and service quality, we may record the operation logs generated during your use of Margay, including:
-
Login time;
-
login location (inferred based on IP);
-
Login device;
-
Login status;
-
function access record;
-
Page browsing history;
-
Agent creates and edits records;
-
Workflow running record;
-
Tool call record;
-
API call record;
-
error log;
-
System exception information.
The above logs are mainly used for:
-
Service operation and maintenance;
-
product optimization;
-
Security audit;
-
Exception troubleshooting;
-
Protect against abuse and aggressive behavior.
We will not conduct personal portraits unrelated to the service based on the above logs.
4.4 AI dialogue data
When you use AI dialogue, digital avatar or Agent services, the information you actively submit may include:
-
text content;
-
Picture;
-
Documentation;
-
audio (if supported);
-
video (if supported);
-Prompt;
-
command;
-
contextual content;
-
historical content actively cited by users;
-
Feedback on AI output results.
At the same time, during the AI reasoning process:
-
AI reply content;
-
inference context;
-
conversation title;
-
Conversation time;
-
Token usage statistics;
-
Session state.
The above data is mainly used for:
-
Complete current AI reasoning;
-
Maintain continuity of conversations across multiple rounds;
-
supports automatic execution of Agent;
-
Improve user experience;
-
Helps users manage historical conversations.
Unless otherwise provided by laws and regulations or with your authorization, we will not publicly display your conversation content, nor will we use the conversation content in the enterprise workspace for purposes unrelated to the enterprise.
4.5 Upload files
When you actively upload files, we may process:
-
document content;
-
file name;
-
file type;
-
file size;
-
creation time;
-
modification time;
-
file metadata;
-
OCR recognition result (if applicable);
-
Document parsing results.
files may include but are not limited to:
-
PDF;
-
Word;
-
Excel;
-
PowerPoint;
-
Markdown;
-
Picture;
-
code file;
-
compressed file;
-
Other supported file formats.
The above information is only used to complete the analysis, summary, retrieval, question and answer, translation, generation, editing and other tasks initiated by you.
4.6 Knowledge Base Data
When you create a knowledge base, upload materials, or connect to external data sources, we may process:
-
knowledge base name;
-
document content;
-
document slicing;
-
vector index;
-
Embedding data;
-
label;
-
Retrieve records;
-
reference relationship;
-
update time;
-
Data source information.
The above information is mainly used for:
-
Build knowledge index;
-
Provides search enhanced generation (RAG) capabilities;
-
Improve answer accuracy;
-
Support Agent calling knowledge.
Knowledge base content is only visible in your or authorized member's workspace by default and will not be open to other users.
4.7 Long-term memory
In order to improve the long-term collaboration capabilities of digital clones and Agents, Margay provides long-term memory function.
After you turn on this function or actively ask the system to remember relevant information, we may save information including but not limited to:
-
User identity information;
-
Work background;
-
industry;
-
current project;
-
Commonly used languages;
-
commonly used model;
-
Preferences;
-
Common tools;
-
work habits;
-
Information that the user actively requests the system to remember.
long-term memory is mainly used for:
-
Improve context understanding;
-
Provide more personalized answers;
-
Reduce repeated input;
-
Improve the efficiency of long-term task collaboration;
-
Supports continuous learning of digital avatars.
You can:
-
View long-term memory;
-
Edit long-term memory;
-
Delete the specified memory;
-
Clear all memories;
-
Turn off long-term memory function.
After turning off the long-term memory function, we will stop generating new long-term memories; the saved historical memories will not be automatically deleted, and you can delete them yourself as needed.
4.8 Workflow data
When you create, edit or run a workflow, we may log:
-
Workflow name;
-
Workflow configuration;
-
node configuration;
-
input parameters;
-
output results;
-
execution sequence;
-
conditional judgment;
-
execution time;
-
execution status;
-
exception information;
-
Debug log.
The above information is used for:
-
Workflow execution;
-
task recovery;
-
debugging and optimization;
-
historical version management;
-
Running statistics.
4.9 Agent execution record
When you create or run an Agent, we may record information related to task execution, including:
-
Agent name;
-
Agent configuration;
-
Agent Prompt;
-
model configuration;
-
Tool configuration;
-
execution plan;
-
inference step;
-
Tool calling process;
-
execution result;
-
execution status;
-
Token consumption;
-
error log;
-
Run time.
The above information is used for:
-
Complete user tasks;
-
supports task retry;
-
Improve Agent execution stability;
-
Provides task history query;
-
Optimize product performance.
Except for enterprise administrators who can legally view enterprise operating data within the scope of enterprise management authority, the above execution records are only visible to the creator and its authorized users by default.
5. Data processing of AI model
Margay supports the use of built-in artificial intelligence models and third-party artificial intelligence models that users can access by themselves, providing users with services such as intelligent dialogue, knowledge Q&A, content generation, task planning, code generation, workflow execution, and agent reasoning.
There are differences in the data processing methods of different models. Please read this chapter carefully before using related functions.
5.1 Built-in model
When you use the artificial intelligence model provided by Margay by default, in order to complete your request, we may process the following information:
includes but is not limited to:
-
user input content;
-
current session context;
-
files uploaded by users actively;
-
Knowledge base search results;
-
Intermediate information required for Agent reasoning;
-
Necessary context generated during workflow running.
The above information is only used for:
-
Understand user needs;
-
Complete model inference;
-
Generate reply content;
-
Perform tasks authorized by the user;
-
Maintain continuity of conversations across multiple rounds;
-
Provides digital clone and Agent services.
Unless otherwise provided by laws and regulations or with your explicit authorization, we will not publicly display your corporate data, knowledge base content or conversation content to other users.
5.2 Third-party model
Margay supports users to call third-party artificial intelligence models, including but not limited to:
-
OpenAI
-
Anthropic Claude
-
Google Gemini
-
DeepSeek
-
Alibaba Cloud Tongyi Qianwen
-
Tencent Hunyuan
-
Zhipu AI
-MiniMax
-
Moonshot AI (Kimi)
-
Baichuan Intelligence
-
and other model services compatible with OpenAI API or related open protocols.
When you actively choose to use a third-party model, in order to complete your request, your input content and necessary context may be sent to the corresponding model service provider for inference, and the model will return the output results. The collection, storage and use of relevant data by
third-party models are independently handled by the corresponding service providers in accordance with their privacy policies and service agreements.
Margay cannot control the data processing behavior of third-party models. It is recommended that you carefully read the relevant agreements of the corresponding service providers before use.
5.3 Custom model
Margay supports users to configure third-party model services, including but not limited to:
-
API Key;
-
Base URL;
-Endpoint;
-
model name;
-
Access Token;
-
Enterprise private model;
-
self-deployment model;
-
local model.
Model service configured by users. Users decide the model provider, data processing method and access permissions by themselves.
For the above configuration:
-
API Key will be stored in an encrypted manner;
-
Margay will not disclose your key information to other users;
-
We will not actively read your model configuration content unless necessary to complete the user request.
Users should keep the relevant keys properly and bear the risks caused by key leaks, configuration errors or third-party model services.
5.4 Local model
Margay supports connecting to users’ locally deployed large language models or inference services.
When the user uses a local model, the model inference process is completed by the user's local environment.
Except for completing request transmission, status synchronization and necessary system logs, Margay will not actively upload model input content or output content to the platform server.
Since the running environment of the local model is maintained by the user, the user should ensure its network environment, model security and system stability.
5.5 Model input and output
Inputs submitted by users to the model may include:
-
text;
-
Picture;
-
Documentation;
-
table;
-
code;
-
command;
-Prompt;
-
Workflow context;
-
Agent reasoning context;
-
Knowledge base search results;
-
historical content actively cited by users. Output generated by the
model may include:
-
text reply;
-
picture description;
-
document content;
-
code;
-
Workflow configuration;
-
Agent execution plan;
-
Automated operation suggestions;
-
Other artificial intelligence generated content.
AI output content is automatically generated by the model and may be incorrect, incomplete, outdated, or inconsistent with the actual needs of users.
Users should make judgments based on the actual situation and consult professionals with corresponding qualifications for important decisions in medical, legal, financial, production safety and other professional fields.
5.6 Model training and optimization
Margay will not use enterprise workspace data, knowledge base content or user uploaded files for public model training without user authorization.
In order to continue to improve product stability, model capabilities and user experience, we may analyze some service operation data after completing anonymization, de-identification or statistical processing for:
-
product optimization;
-
Model effect evaluation;
-
Function improvements;
-
performance analysis;
-
Trouble diagnosis;
-
Service quality improvement.
related processing will not be for the purpose of identifying specific individuals.
If the product provides an experience optimization plan or similar functions, users can choose whether to participate according to the product settings.
5.7 Model call log
In order to ensure the stable operation of the service, we may record logs related to model calls, including:
-
calling time;
-
call model;
-
request status;
-
Token consumption;
-
response time;
-
error message;
-
interface status;
-
Request identifier.
The above logs are mainly used for:
-
Service monitoring;
-
resource statistics;
-
Troubleshooting;
-
performance optimization;
-
Security audit.
The content of the log will not exceed the scope necessary to achieve the above purposes.
5.8 User Control
For model-related data processing, users can manage it independently according to the functions provided by the product, including but not limited to:
-
select different models;
-
Configure or delete API Key;
-
Switch model service provider;
-
Delete historical conversations;
-
clear context;
-
Managing long-term memory;
-
Delete knowledge base;
-
Turn off long-term memory function;
-
Revoke model authorization (if supported).
After the user stops using the relevant model or deletes the corresponding data, we will stop processing the relevant data to the extent permitted by laws and regulations and necessary to achieve the purpose of the service, and process it in accordance with the provisions of this Guideline on data storage and deletion.
6. Tool calling and automation capabilities
Margay supports calling local or third-party tools through Agent, workflow and user active operations to complete complex tasks, automated processes and cross-system collaboration. We will only perform relevant operations when the user actively initiates, explicitly authorizes, or in accordance with the user's pre-configured workflow. We will not actively call any tools or access user resources without authorization.
Depending on the type and function of different tools, the data processing methods involved may be different.
6.1 Tool calling principles
Margay follows the following principles during the tool calling process:
(1) User authorization principles
Tool invocation should be based on a request initiated by the user, or automatically executed by an Agent or workflow created and authorized by the user.
(2) Minimum necessary principle
only obtains the data necessary to complete the current task and does not access user data or system resources beyond the scope of the task.
(3) Principle of transparency and traceability
For important operations generated by tool calls, Margay will retain necessary execution records to facilitate users to view task status, troubleshoot exceptions, and conduct security audits.
(4) User controllable principle
Users can independently enable, disable, configure or delete related tools, Agents, workflows and authorization information based on the capabilities provided by the product.
6.2 MCP Service
Margay supports connecting to services that comply with the MCP (Model Context Protocol) protocol.
Users can access local or third-party MCP Server according to their own needs, providing Agent with capabilities such as knowledge retrieval, database access, file management, and business system calls.
During the process of calling the MCP service, we may process:
-
MCP service address;
-
service name;
-
tool name;
-
tool parameters;
-
request content;
-
return result;
-
calling time;
-
calling status;
-
Error log.
The above information is only used to complete the user's current request, maintain service operation and record necessary execution logs.
For MCP services that users access by themselves, the data processing behavior is the responsibility of the corresponding service provider. Margay is not responsible for the data processing methods of third-party services.
6.3 CLI tool
Margay supports calling the command line tool (CLI) installed or configured locally by the user to assist in completing development, operation and maintenance, testing, office and automation tasks.
Depending on the user authorization, the CLI tool may execute including but not limited to:
-
project build;
-
Environmental check;
-
file processing;
-
Git operation;
-
Container management;
-
script execution;
-
third-party application call;
-
automated testing;
-
System administration tasks.
During execution, we may record:
-
tool name;
-
execute command;
-
input parameters;
-
execution status;
-
return result;
-
error message;
-
Execution time. The actual execution permission of
CLI tool depends on the user's local operating system and operating environment. Margay will not perform any operations beyond operating system permission restrictions.
6.4 Browser Automation
Margay supports calling browser automation capabilities according to user instructions to realize web access, information query, page operations and business process automation.
Within the scope of the user's authorization, browser automation may perform:
-
Open a web page;
-
page search;
-
form filling;
-
information reading;
-
click operation;
-
File upload;
-
file download;
-
page screenshot;
-
automatic test;
-
Web page data collection (within the scope permitted by laws and regulations). During
browser access, the website operator may collect user-related information in accordance with its own rules, and the relevant data processing behavior shall be governed by the privacy policy of the corresponding website.
6.5 File operations
According to user instructions, Margay can call the local file system to complete related tasks. Operations involved in
include but are not limited to:
-
read file;
-
Create file;
-
edit file;
-
save file;
-
Rename file;
-
copy file;
-
Move files;
-
Delete file;
-
Batch processing of files.
Margay will only process files that are actively selected, explicitly specified by the user, or required during workflow execution, and will not actively scan or access irrelevant directories and files.
For unrecoverable operations involving deletion, overwriting, etc., the product may provide confirmation prompts based on specific scenarios to reduce the risk of misoperations.
6.6 Local program call
Margay supports calling software or applications installed in the user's device to assist in completing related tasks.
For example:
- Office software;
-IDE;
-
PDF reader;
-
image processing tool;
-
data analysis tool;
-
Enterprise office software;
-
User-configurable local program. During the
call, only the information necessary to complete the current task is passed.
The corresponding software is responsible for the data processing behavior generated by the program itself.
6.7 API call
Margay supports calling HTTP API, Webhook, open platform interface and other network services provided by user configuration or platform.
Depending on specific business needs, it may handle:
-
API address;
-
request method;
-
request parameters;
-
request header information;
-
Identity authentication information;
-
return result;
-
status code;
-
Call log.
Users should ensure that the API services they configure are legal and valid, and have corresponding data processing permissions.
Margay does not guarantee the authenticity, accuracy, completeness or continued availability of data returned by third-party APIs.
6.8 Database connection
Margay supports connecting to user-authorized databases or data services. Databases that
may support include but are not limited to:
-
MySQL;
-
PostgreSQL;
-
SQL Server;
-
SQLite;
-
Redis;
-
MongoDB;
-
Elasticsearch;
-
Enterprise self-built database.
Based on user authorization, Agent can perform query, analysis, statistics and other operations explicitly allowed by the user.
Margay will not modify database contents or perform destructive database operations unless actively authorized by the user.
6.9 Tool execution log
In order to ensure the stable operation of the system, support task tracking and troubleshooting, we may record necessary logs generated during the tool calling process, including:
-
tool name;
-
calling time;
-
call source;
-
execution status;
-
time-consuming information;
-
error log;
-
Resource consumption.
The above logs are only used for service operation and maintenance, security audit and product optimization, and will not be used for purposes unrelated to the current service.
6.10 Third-party tools
Margay supports users to connect to various third-party applications and services, including but not limited to:
-
Office collaboration platform;
-
project management platform;
-
code hosting platform;
-
Cloud storage service;
-
Enterprise business system;
-
open platform interface;
-
User developed tool.
The data processing rules of third-party tools are the responsibility of the corresponding service provider.
When a user actively authorizes Margay to call third-party tools, we will only process relevant data within the scope necessary to complete the user's request, and will not access or use information in third-party services beyond the scope of authorization.
6.11 User authorization and revocation
Users can follow the management functions provided by the product at any time:
-
New tool;
-
Modify tool configuration;
-
Delete tool;
-
Update access credentials;
-
Revoke tool authorization;
-
Stop workflow execution;
-
Disables the Agent's ability to call tools.
When the user revokes authorization or deletes related tools, Margay will stop subsequent calls; the execution records that have been generated will be processed in accordance with the data storage and deletion rules of this guideline.
7. Agent permissions description
In order to help users complete complex tasks, realize automated processes and intelligent collaboration, Margay supports Agent to call local resources, third-party tools and system capabilities within the scope of user authorization. The permission scope of different Agents is configured by the user or enterprise administrator, and the Agent will not obtain access permissions beyond the authorized scope by default.
Users can turn on, turn off or adjust Agent permissions according to actual needs.
7.1 Rights Management Principles
Margay implements unified management of Agent permissions and follows the following principles:
(1) Principle of least privilege
Agent only obtains the permissions necessary to complete the current task and will not actively apply for or use permissions unrelated to the task.
(2) User authorization principles
In addition to the basic permissions necessary for product operation, when access to local resources, system capabilities, third-party services or enterprise resources is involved, execution must be explicitly authorized by the user or enterprise administrator.
(3) Principle of use on demand
Authorization does not mean that the Agent will continue to access relevant resources. It only invokes necessary permissions during the execution of the current task and stops using it after the task is completed.
(4) Principle of manageability
Users can view, modify, limit or revoke the permissions that Agent has obtained at any time, and enterprise administrators can uniformly configure the permission scope according to enterprise management policies.
7.2 File system permissions
When the Agent needs to process local files, it may apply for the following permissions:
Click on the image to view the complete spreadsheet
Agent will not actively scan all files in the user's computer, nor will it access directories that the user has not authorized.
When unrecoverable operations such as deletion and overwriting are involved, the product can require the user to confirm again according to specific scenarios.
7.3 Browser permissions
In order to complete web page access and automation tasks, Agent can call browser capabilities after user authorization, including but not limited to:
-
Open a web page;
-
Search information;
-
browse page;
-
click on page element;
-
input text;
-
Upload files;
-
Download file;
-
page screenshot;
-
automated testing;
-
Web page process execution. During
browser access, the data processing behavior of the relevant website shall be governed by the website's own privacy policy.
7.4 System command execution permissions
For development, operation and maintenance, and automation scenarios, Agent can execute local commands or scripts based on user authorization.
may involve:
-
Shell command;
-
PowerShell;
-Terminal;
- Bash;
-CMD;
-
Python script;
-
Node.js script;
-
Git command;
-
Docker command;
-
User-configurable CLI tool.
All commands are executed according to user instructions or workflow configuration.
Margay will not bypass operating system permission restrictions to execute any commands, nor will it actively escalate system permissions.
7.5 Local program calling permission
According to user task requirements, Agent can call locally installed software to complete related work, such as:
-
Document editing;
-
form processing;
-
presentation generation;
-
image processing;
-
video processing;
-
IDE development tool;
-
PDF reading tool;
-
User-installed software.
Agent will not install, uninstall or modify local software configuration unless the user explicitly issues relevant instructions.
7.6 Clipboard permissions
When the user actively performs operations such as copying and pasting, the Agent can read the clipboard content currently pasted by the user to Margay and use it to complete the current task.
Margay will not continuously monitor, record or upload the system clipboard content, and will only read the corresponding data when the user actively pastes or authorizes use.
7.7 Network access rights
Agent can access the Internet or corporate internal network resources according to user needs, such as:
-
Query public information;
-
Call the open interface;
-
Download user-specified resources;
-
Call third-party AI service;
-
Call MCP Server;
-
Call the enterprise business system.
Network access is limited to what is needed to complete user tasks, and will not actively access websites or network resources that are not related to the current task.
7.8 Third-party service access rights
When a user connects to a third-party service, the Agent can access relevant resources within the authorized scope, such as:
-
Knowledge Base;
-
cloud disk;
-
project management tool;
-
Enterprise office system;
-
development platform;
-
Data analysis platform;
-
User-built service. The data obtained by
Agent is only used to complete the user's current request and will not be accessed, modified or shared beyond the scope of authorization.
7.9 Enterprise resource access rights
Enterprise administrators can configure the Agent's permissions to access enterprise resources according to enterprise security policies.
Enterprise resources may include:
-
Enterprise knowledge base;
-
Enterprise workflow;
-
Enterprise Agent;
-
Enterprise model;
-
Corporate documents;
-
Enterprise organizational structure;
-
Enterprise business system;
-
Enterprise API;
-
Enterprise MCP Service.
Agent's access to enterprise resources is controlled by the enterprise permission system, and the range of resources that different members can access may vary.
7.10 Permission change and revocation
Users or enterprise administrators can use the rights management functions provided by the product to:
-
View the permissions the Agent has obtained;
-
Adjust permission scope;
-
disable a certain permission;
-
Delete Agent;
-
Revoke Agent authorization;
-
Reset Agent configuration.
After the permission is revoked, the Agent will stop accessing the corresponding resources. We will save the execution records that have been generated to the extent permitted by laws and regulations and necessary to achieve the purpose of the service, and process them in accordance with the provisions of this guideline on data storage and deletion.
7.11 Permission anomalies and security assurance
In order to ensure the security of user data, Margay will continue to monitor the use of Agent permissions and take necessary security measures, including but not limited to:
-
permission verification;
-
Identity authentication;
-
Operation log record;
-
abnormal behavior detection;
-
risk control;
-
permission isolation;
-
Audit of sensitive operations.
If we discover abnormal access, unauthorized calls, or behavior that may affect user data security, we have the right to suspend relevant tasks, limit Agent permissions, or take other necessary measures to protect the legitimate rights and interests of users and the platform.
8. Enterprise Edition Data
Margay Enterprise Edition aims to provide enterprises with a unified, secure, and controllable AI Agent collaboration platform. Enterprise users can uniformly manage resources such as members, agents, knowledge bases, workflows, models, and tools through the enterprise workspace.
When you use Margay as an enterprise user, in addition to the provisions in other chapters of these guidelines, this section applies to the processing rules of enterprise data.
8.1 Enterprise workspace
Enterprise workspace is an organizational unit for enterprises to uniformly manage members, data and AI capabilities.
Enterprise administrators can create multiple workspaces according to enterprise management needs and configure:
-
Corporate member;
-
user role;
-
Agent;
-
Workflow;
-
Knowledge Base;
-
model configuration;
-
Tool configuration;
-
MCP service;
-
third-party applications;
-
Permission policy. In principle, the data in
enterprise workspace is only accessible to members with corresponding permissions.
8.2 Enterprise data scope
Enterprise data includes but is not limited to data created, uploaded, generated or managed by enterprise users during the use of Margay, such as:
-
basic company information;
-
Enterprise member information;
-
Enterprise knowledge base;
-
Corporate documents;
-
AI conversation record;
-
Agent configuration;
-
Workflow configuration;
-
Prompt template;
-
model configuration;
-
Tool configuration;
-
MCP service configuration;
-
Enterprise API configuration;
-
Enterprise business data;
-
execution log;
-
audit log;
-
Token usage statistics;
-
Other enterprise resources.
The ownership and management rights of enterprise data belong to enterprise users or entities that enjoy rights according to law.
8.3 Enterprise Administrator Permissions
Enterprise administrators can conduct unified management of enterprise workspaces based on enterprise authorization, including but not limited to:
-
Create, modify or delete a workspace;
-
Invite and remove corporate members;
-
Assign member roles and permissions;
-
Create or manage Agent;
-
Create or manage workflows;
-
Create or manage a knowledge base;
-
configure enterprise model;
-
Configure enterprise tools and MCP services;
-
configure security policy;
-
View enterprise resource usage;
-
Management Enterprise API;
-
View enterprise operation statistics.
Enterprise administrators should configure permissions appropriately to avoid processing personal information of enterprise members beyond the needs of enterprise management.
8.4 Enterprise member data
Data generated by enterprise members in the enterprise workspace may include:
-
User information;
-
AI dialogue;
-
Workflow running record;
-
Agent creates record;
-
knowledge base content;
-
file;
-
Tool call record;
-
model call record;
-
Token usage;
-
Task execution record.
Corporate members should use Margay reasonably in accordance with the company's internal policies and shall not use the platform to process data that is illegal, illegal or infringes upon the legitimate rights and interests of others.
8.5 Enterprise resource access control
Margay adopts an access control mechanism based on identity and permissions to implement unified management of enterprise resources.
Enterprise administrators can configure different resource access rights for different members based on job responsibilities, organizational structure or business needs, including but not limited to:
-
workspace permissions;
-
knowledge base permissions;
-
Agent usage rights;
-
Workflow permissions;
-
model permissions;
-
Tool permissions;
-
MCP service permission;
-
API call permission;
-
File access permissions.
Unauthorized members cannot access the corresponding enterprise resources.
8.6 Enterprise Audit Log
In order to help enterprises carry out security management and risk control, Margay Enterprise Edition may record necessary audit information, including but not limited to:
-
Login record;
-
Member operation record;
-
Agent execution record;
-
Workflow running record;
-
Tool call record;
-
permission change record;
-
model call record;
-
Enterprise configuration change record;
-
Security event record.
audit log is mainly used for:
-
Security audit;
-
Troubleshooting;
-
risk analysis;
-
Compliance Management;
-
Business operations analysis.
Enterprise administrators should use relevant logs in a legal and reasonable manner and shall not process enterprise member information beyond legitimate management purposes.
8.7 Enterprise model and tool management
Enterprise administrators can uniformly configure AI models and tools that can be used by the enterprise, including:
-
built-in model;
-
Enterprise self-deployment model;
-
third-party model;
-MCP Server;
-
CLI tool;
-
API service;
-
Browser automation tool;
-
Enterprise internal system;
-
Other services authorized by the enterprise to access.
Enterprise administrators can restrict model types, tool scope, and resource access permissions based on enterprise security policies.
8.8 Enterprise data security
Margay takes reasonable technical and management measures to protect corporate data security, including but not limited to:
-
Identity authentication;
-
permission control;
-
data isolation;
-
encrypted transmission;
-
encrypted storage (in applicable scenarios);
-
Operational audit;
-
risk monitoring;
-
Security Alert.
Corporate users should also establish an internal security management system, reasonably configure member permissions, properly keep account numbers and access credentials, and jointly maintain corporate data security.
8.9 Enterprise data export and migration
Within the scope of product support, enterprise administrators can export, back up or migrate enterprise data according to enterprise business needs.
Data export and migration should comply with relevant laws, regulations and internal corporate management requirements, and must not infringe on the legitimate rights and interests of other users or third parties.
Enterprise users shall bear the corresponding responsibilities for risks arising from enterprises exporting, backing up, migrating or sharing data on their own.
8.10 Corporate Data Processing Responsibility
As managers of corporate data, corporate users should ensure that their processing of corporate members' personal information and business data complies with applicable laws and regulations, and perform corresponding information protection obligations in accordance with the law.
Margay provides technical services based on the authorization and instructions of enterprise users, processes enterprise data within the scope of laws and regulations and the scope agreed by both parties, and takes reasonable measures to ensure the security, integrity and availability of enterprise data.
The responsibilities of enterprise users and Margay for enterprise data shall be subject to the service agreement, data processing agreement or other written agreement signed by both parties.
9. How we use information
We will only process your personal information and related data within the scope of achieving the purposes stated in these Guidelines and permitted by laws and regulations, and follow the principles of legality, legitimacy, necessity, and good faith, and will not process your information beyond the scope necessary to achieve the purpose of the service.
The use of information involved in different functions may be different. We mainly use relevant information for the following purposes.
9.1 Providing products and services
In order to provide you with various functions of Margay, we may use relevant information to implement the following services, including but not limited to:
-
User registration, login and identity authentication;
-
AI dialogue;
-
digital clone;
-
Agent creation and execution;
-
Workflow run;
-
Document generation and processing;
-
Knowledge base search;
-
multiple model calls;
-
tool call;
-
Enterprise collaboration;
-
API service;
-
Other product features that you actively use.
If a function requires the processing of specific information, we will process it to the extent necessary to achieve that function.
9.2 Provides a continuous intelligent collaboration experience
In order to improve Margay's intelligent collaboration capabilities, we may combine user authorized information to provide you with a more continuous and consistent experience, including:
-
Maintain conversation context across multiple rounds;
-
Manage historical sessions;
-
Supports continuous collaboration with digital avatars;
-
supports long-term task execution;
-
supports continuous running of workflow;
-
Provide personalized configuration;
-
Reduce repeated input;
-
Improve task execution efficiency.
For long-term memory related information, you can independently view, edit, delete or close it according to the functions provided by the product.
9.3 Perform tasks authorized by the user
When you create an Agent, workflow or call a tool, we may process information necessary to complete the task, including:
-
mission goal;
-
execution parameters;
-
context information;
-
tool call result;
-
file content;
-
knowledge base data;
-
model output;
-
Execution log.
The above information is only used to complete the tasks initiated or authorized by you.
Margay will not actively perform relevant operations without your authorization.
9.4 Provide customer service and technical support
When you contact us for assistance, we may process:
-
Contact information;
-
Problem description;
-
System log;
-
error message;
-
screenshot;
-
product version;
-
Operation record;
-
Other information related to problem handling.
The above information is only used for:
-
Problem location;
-
Troubleshooting;
-
technical support;
-
Service improvements;
-
User feedback processing.
9.5 Ensure product operation and safety
In order to ensure the stable operation and information security of Margay, we may use relevant information:
-
Identity verification;
-
Login protection;
-
permission control;
-
Risk identification;
-
Anomaly detection;
-
Security audit;
-
Network attack protection;
-
Prevent fraud and abuse;
-
System maintenance;
-
Fault recovery.
We have the right to take necessary measures in accordance with laws, regulations and relevant agreements for behavior suspected of violating laws, regulations, service agreements or endangering platform security.
9.6 Product optimization and function improvement
In order to continue to improve Margay's product capabilities and user experience, we may carry out: based on statistical analysis, anonymized or de-identified information:
-
Function optimization;
-
Product design improvements;
-
Model effect evaluation;
-
Service quality analysis;
-
performance optimization;
-
stability improvement;
-
User experience improvements.
related analysis will not be aimed at identifying specific individuals.
9.7 Enterprise Operation and Management
For enterprise version services, we may process relevant information based on the configuration of the enterprise administrator and enterprise authorization for:
-
Enterprise member management;
-
Permission management;
-
Enterprise Resource Management;
-
Agent management;
-
Workflow management;
-
Audit management;
-
Token quota management;
-
Enterprise usage statistics;
-
Enterprise security management;
-
Enterprise operations support.
Enterprise administrators should use relevant management functions in a reasonable and legal manner and shall not process members' personal information beyond the needs of enterprise management.
9.8 Legal and regulatory requirements
When permitted or required by laws and regulations, we may process your relevant information for:
-
Fulfill legal obligations;
-
Cooperate with judicial agencies, administrative agencies or other competent agencies to conduct investigations in accordance with the law;
-
Handling complaints, disputes and disputes;
-
Protect the legitimate rights and interests of users, third parties and Margay;
-
Fulfill other obligations stipulated in laws and regulations.
9.9 Other uses with your separate consent
If we intend to use your personal information for other purposes not specified in these guidelines, or use your information beyond the original processing purpose, processing method and processing scope, we will separately notify you in accordance with the requirements of laws and regulations, and obtain your authorization or consent in accordance with the law before processing. We will not use your personal information for purposes unrelated to the purposes stated in these Guidelines without your explicit authorization.
10. Information Sharing
We fully respect and protect the security of your personal information and data. Except as expressly stated in these Guidelines or as otherwise provided by laws and regulations, we will not sell your personal information to any third party, nor will we provide your personal information to third parties without your authorization.
Under the following circumstances, we may share, entrust processing or disclose relevant information in accordance with the law.
10.1 Sharing actively authorized by users
When you actively choose to use third-party services, connect third-party applications, call third-party models or configure third-party tools, in order to complete your request, we may transmit necessary information to the relevant service provider in accordance with your authorization.
For example:
-
Call third-party AI model;
-
Call MCP service;
-
Call open API;
-
Call CLI tool;
-
Call browser automation service;
-
Connect to enterprise internal systems;
-
Call a third-party application configured by the user.
We only transfer the information necessary to complete the current task and will not share relevant data beyond the scope of user authorization.
10.2 Third Party Service Provider
In order to provide you with complete product capabilities, Margay may access third-party services, including but not limited to:
-
AI model service;
-
Object storage service;
-
Message notification service;
-
Identity authentication service;
-
File parsing service;
-
map and network services (if applicable);
-
Log analysis service;
-
Security protection service;
-
Other third-party services authorized by the user.
For the above third-party services, we will make reasonable efforts to select partners with corresponding data protection capabilities, and require them to process relevant data in accordance with applicable laws and regulations through agreements and other means.
Third-party service providers are responsible for the data they collect, store and process.
10.3 Enterprise Administrator
For enterprise version services, within the scope of enterprise authorization, enterprise administrators may view or manage some information in the enterprise workspace according to enterprise management needs, including but not limited to:
-
Enterprise member account information;
-
Enterprise resource configuration;
-
Agent configuration;
-
Workflow configuration;
-
Knowledge Base;
-
Enterprise log;
-
Token usage;
-
Enterprise statistics;
-
Audit log.
Enterprise administrators shall fulfill their personal information protection obligations in accordance with the law and shall not process the personal information of enterprise members beyond the purpose of enterprise management.
10.4 Delegate processing
In order to achieve the purposes stated in this Guideline, we may entrust a third party to process some information on our behalf, such as:
-
Cloud computing service;
-
data storage;
-
technical support;
-
Network security services;
-
system operation and maintenance;
-
message notification;
-
Customer Service.
For the entrusted processing parties, we will clarify their processing purposes, processing methods, security obligations and confidentiality responsibilities through contracts, agreements or other legal documents, and supervise their processing of relevant information in accordance with the law.
Without our authorization, the entrusted processor shall not use relevant information for other purposes.
10.5 Merger, Acquisition or Asset Transfer
In the event of a corporate merger, division, reorganization, acquisition, asset transfer or similar transaction involving the transfer of personal information, we will require the recipient to continue to perform its obligations under these Guidelines in accordance with the law.
If the recipient intends to change the original purpose or method of processing, we will re-fulfill our notification obligations in accordance with the law and obtain your authorization or consent if required by laws and regulations.
10.6 Legal and regulatory requirements
Under the following circumstances, we may share, disclose or provide relevant information in accordance with the law without obtaining your authorization:
(1) To fulfill obligations stipulated in laws and regulations;
(2) To implement court judgments, rulings or other legal documents;
(3) According to the requirements made by administrative agencies, judicial agencies or other competent agencies in accordance with the law;
(4) To safeguard national security, public safety, public health and major public interests;
(5) Necessary to protect the life, property and other legitimate rights and interests of users, third parties or Margay;
(6) Other situations stipulated by laws and regulations.
10.7 Situations that do not belong to the sharing of personal information
The following processing actions are generally not considered sharing your personal information with third parties:
-
Users choose to connect to third-party models and send requests;
-
Users call third-party tools or MCP services themselves;
-
User calls the enterprise's internal system through workflow;
-
Users actively share content with other users;
-
Information published publicly by users;
-
Statistical analysis data formed after anonymizing information.
We have the right to use anonymized data for product analysis, statistical research and service optimization in accordance with the law, provided that the specific individual cannot be identified and cannot be restored.
10.8 Information Sharing Principles
We always adhere to the following principles for information sharing:
-
Legal compliance principles: Strictly comply with applicable laws and regulations.
-
Minimum necessary principle: only share information necessary to complete the business.
-
User authorization principle: Fully respect the user's independent choice when it comes to authorization matters.
-
Security Guarantee Principle: Take reasonable measures to protect data security during the sharing process.
-
Principle of clear responsibilities: Clarify the data protection responsibilities of each party through agreements and other means.
Except as described in this section, we will not sell your personal information to any third party, nor will we use your personal information for commercial purposes without your authorization.
11. Data storage
We attach great importance to the security management of user data and take reasonable technical and management measures to store, manage and protect user data.
Unless otherwise stipulated by laws and regulations or otherwise agreed by both parties, we will save relevant data for the period necessary to achieve the processing purposes described in these guidelines, and delete or anonymize it in accordance with the law after the retention period expires.
11.1 Data storage location
In principle, we will store user data in servers and infrastructure that comply with applicable laws and regulations.
Depending on the service type, user location or product deployment method, data may be stored in:
-
Cloud service environment provided by Margay;
-
Enterprise private cloud environment;
-
Enterprise local deployment environment;
-
User's local device (applicable to local model, local knowledge base, local Agent and other functions);
-
Other data storage environments permitted by laws and regulations.
For the enterprise privatized deployment version, the storage location and management method of enterprise data are decided by the enterprise users themselves.
11.2 Data storage period
We only save relevant data for the period necessary to achieve the purpose of the service.
Different types of data may have different retention periods, for example:
Click on the image to view the complete spreadsheet
If laws and regulations provide otherwise, relevant regulations should be followed.
11.3 Data actively deleted by users
When the user actively deletes the following data:
-
AI dialogue;
-
Long-term memory;
-
Knowledge Base;
-
Upload files;
-
Agent;
-
Workflow;
-
API configuration;
-
Tool configuration;
-
Enterprise resources (with permissions);
We will complete the deletion within a reasonable period or process it in accordance with product function requirements.
Due to system caching, data synchronization, backup and recovery, etc., some data may not be completely deleted from all storage media immediately. We will complete the processing as soon as technical conditions permit.
11.4 Data backup
In order to ensure the stable operation of the system and prevent accidental loss of data, we may back up some data.
backup data is mainly used for:
-
Disaster recovery;
-
System recovery;
-
Data integrity guarantee;
-
Security;
-
Service Continuity.
Backup data can only be accessed by authorized personnel when necessary and will not be used for purposes unrelated to the backup purpose.
11.5 Enterprise Data Storage
Enterprise version user data is logically isolated according to the enterprise workspace.
Enterprise administrators can perform the following operations on enterprise data based on product functions and deployment methods:
-
export;
-
Backup;
-
restore (if supported);
-
Delete;
-
migration;
-
Permission management.
In an enterprise privatized deployment environment, enterprise data is managed by the enterprise itself, and Margay will not actively access the enterprise's internal data, unless otherwise agreed by both parties.
11.6 Cross-border data
In principle, we will store user data in a region that complies with applicable laws and regulations.
If users actively use overseas models, overseas cloud services or other cross-border services, resulting in the need to transfer relevant data overseas, we will perform corresponding obligations within the scope of laws and regulations and remind users to pay attention to the data processing rules of relevant third-party services.
11.7 Data retention under special circumstances
Even if the user deletes the relevant data or cancels the account, we may still continue to save some information in accordance with the law under the following circumstances:
(1) Fulfill obligations stipulated in laws and regulations;
(2) Comply with court judgments, rulings or other legal procedures;
(3) Cooperate with administrative agencies, judicial agencies or other competent agencies to conduct investigations in accordance with the law;
(4) Handling complaints, disputes or litigation;
(5) Protect the legitimate rights and interests of users, third parties or Margay;
(6) Ensure network security, information security and stable system operation;
(7) Other situations stipulated by laws and regulations.
After the above situation disappears, we will delete or anonymize the relevant information in accordance with the law.
12. Data Security
We attach great importance to the security of users' personal information and corporate data, and continue to take technical and management measures in line with industry practices to prevent data from unauthorized access, leakage, tampering, damage, loss or other security risks.
However, please understand that the Internet environment is not absolutely safe, and no technical measures can guarantee 100% security of information. Therefore, we recommend that you properly keep sensitive information such as your account number, password, access credentials, and API Key to jointly maintain data security.
12.1 Safety technical measures
In order to ensure data security, we may take measures including but not limited to the following:
-
Data transmission encryption;
-
Data storage encryption (in applicable scenarios);
-
Identity authentication;
-
multi-factor authentication (if supported);
-
permission control;
-
data isolation;
-
Network access control;
-
Security log;
-
Operational audit;
-
risk monitoring;
-
abnormal behavior detection;
-
bug fix;
-
security update;
-
Data backup and recovery.
We will continue to optimize security protection measures based on business development and technical capabilities.
12.2 Access Control
We have established a corresponding data access control mechanism to only authorize authorized personnel required for work to access relevant data.
For access to users' personal information and corporate data, we will take necessary identity verification, authority verification and audit measures, and require relevant personnel to fulfill confidentiality obligations.
12.3 Enterprise Security Management
For enterprise version products, we support enterprises to configure security policies according to their own management needs, including but not limited to:
-
Member rights management;
-
Agent permission management;
-
Workflow permission management;
-
Model permission management;
-
Tool permission management;
-
audit log;
-
Enterprise resource isolation;
-
Enterprise identity authentication (if supported);
-
Enterprise security policy configuration.
Enterprise users should reasonably configure permissions according to their own business needs and strengthen internal security management.
12.4 User Security Responsibility
In order to protect the security of your account and data, we recommend that you:
-
Keep your account number and password properly;
-
Do not disclose verification codes or access credentials to others;
-
Properly manage sensitive information such as API Keys and Access Tokens;
-
Authorize third-party models, tools and MCP services with caution;
-
Regularly check account security settings;
-
Log in to Margay using a trusted device;
-
Update the client version in a timely manner.
For information leakage, account theft or other security incidents caused by the user himself, the user shall bear corresponding responsibilities in accordance with the law; unless otherwise provided by laws and regulations or due to Margay reasons.
12.5 Security incident handling
If an incident occurs that may affect the security of users' personal information or corporate data, we will take timely measures based on the nature of the incident, including but not limited to:
-
Start security emergency plan;
-
Control risk expansion;
-
Troubleshoot the cause of the event;
-
fix security vulnerability;
-
restore system operation;
-
Fulfill reporting and notification obligations in accordance with legal and regulatory requirements.
If required by laws and regulations, we will inform affected users through on-site notifications, emails, text messages or other reasonable means of the basic situation of the incident, possible impacts, measures taken or planned, and risk prevention suggestions that users can take.
12.6 Continuous improvement of security
We will continue to improve the information security management system in accordance with laws, regulations, industry standards and technological development, continue to improve data security protection capabilities, and provide users with more secure, stable and reliable AI services.
13. User Rights
We attach great importance to your legal rights to personal information and provide corresponding management methods to help you manage personal information and related data.
Unless otherwise provided by laws and regulations, you can exercise relevant rights based on product functions or through the contact information published in these guidelines.
13.1 Check personal information
You have the right to review the personal information we hold about you.
Within the scope of product support, you can check including but not limited to:
-
basic account information;
-
corporate identity information;
-
AI conversation record;
-
Long-term memory;
-
Knowledge Base;
-
Agent;
-
Workflow;
-
model configuration;
-
Tool configuration;
-
API configuration;
-
Login record;
-
Token usage;
-
Enterprise resources (with appropriate permissions).
For information that is currently not supported for online viewing, you can apply to us through the contact information published in these guidelines.
13.2 Correct or update personal information
If you find that the personal information we process is incorrect, incomplete or has changed, you have the right to modify it yourself or ask us to correct it.
For example:
-
Modify nickname;
-
Modify avatar;
-
Modify contact information;
-
Update personal information;
-
Update company information;
-
Modify long-term memory;
-
Update model configuration;
-
Update tool configuration.
In order to ensure the security of your account, we may require you to complete necessary identity verification.
13.3 Delete personal information
You have the right to request the deletion of your personal information in compliance with laws and regulations.
includes but is not limited to:
-
Delete AI dialogue;
-
Delete long-term memory;
-
Delete knowledge base;
-
Delete uploaded files;
-
Delete Agent;
-
Delete workflow;
-
Delete API Key;
-
Delete tool configuration;
-
Delete enterprise resources (with appropriate permissions).
You also have the right to request deletion of relevant personal information when one of the following circumstances occurs:
(1) Our processing of personal information violates laws and regulations;
(2) We have not obtained your consent in accordance with the law;
(3) We process personal information in violation of the agreement with you;
(4) You no longer use related products or services;
(5) Other situations stipulated by laws and regulations.
Unless otherwise provided by laws and regulations or deletion will seriously affect the public interest, judicial procedures or the performance of other legal obligations.
13.4 Export personal data
For the data types supported by the product, you can export relevant data based on product functions, including but not limited to:
-
AI dialogue;
-
Knowledge Base;
-
Workflow;
-
Agent configuration;
-
Documentation;
-
Other supported exported data. The specific data range and export format supported by
are subject to the actual functions provided by the product.
13.5 Withdraw authorization
For the permissions you have authorized Margay to use, you can withdraw or adjust the authorization at any time according to the product functions, such as:
-
file access permissions;
-
Browser permissions;
-
Tool calling permission;
-
model calling permission;
-
MCP service authorization;
-
API authorization;
-
long-term memory function;
-
Third-party application authorization.
After withdrawing the authorization, we will stop processing the corresponding information, but the withdrawal of the authorization will not affect the data processing activities that have been carried out based on your authorization before the withdrawal.
13.6 Cancel account
You have the right to apply to cancel your Margay account at any time. After canceling your
account, we will cancel your account after completing the identity verification and confirming that there are no circumstances that require continued retention of information as required by laws and regulations or agreed by both parties. After
account cancellation is completed:
-
You will no longer be able to log in to your account;
-
The products and services associated with the account will cease to be provided;
-
Personal resources such as personal Agents, workflows, and long-term memories you created may be deleted;
-
Deleted data cannot be recovered.
If you are a member of an enterprise workspace, canceling your personal account may not affect the enterprise's business data saved by the enterprise in accordance with the law.
13.7 Managing long-term memory
Margay provides long-term memory management capabilities, you can according to product functions:
-
View long-term memory;
-
Edit long-term memory;
-
Delete the specified memory;
-
Clear all long-term memory;
-
Turn off the long-term memory function.
After turning off the long-term memory function, Margay will stop generating new long-term memories; the saved historical memories can still be deleted by you.
13.8 Manage AI conversations and history
You can manage historical conversations according to the functions provided by the product, including:
-
Delete a single conversation;
-
Delete all historical conversations;
-
Create a new session;
-
Export conversation (if supported);
-
Manage conversation categories;
-
Manage collection content.
The deleted data will be processed in accordance with the relevant provisions of these Guidelines to the extent permitted by laws, regulations and technically feasible.
13.9 Respond to your request
We will handle your relevant requests in accordance with laws and regulations in a timely manner after verifying your identity.
Under normal circumstances, we will respond within fifteen (15) working days after receiving the application.
If the request cannot be completed within the above period due to complex content, large amounts of data or other reasonable reasons, we will explain the reasons to you to the extent permitted by laws and regulations and complete the processing within a reasonable period.
We have the right to refuse in accordance with the law and explain the reasons to you for requests that are obviously repetitive, exceed reasonable scope, are malicious, or may damage the legitimate rights and interests of others.
14. Protection of minors
Margay mainly provides products and services for adults.
We attach great importance to the protection of minors' personal information and will take corresponding protective measures in accordance with the "Personal Information Protection Law of the People's Republic of China", the "Minor Protection Law of the People's Republic of China" and other relevant laws and regulations.
14.1 Use by minors
Minors under the age of 18 should use Margay under the guidance, supervision and consent of their guardians.
Guardians should help minors correctly understand these guidelines and guide them to use artificial intelligence products and related services reasonably and safely.
14.2 Minors under the age of fourteen
If you are a minor under the age of fourteen, please use Margay after your guardian has fully read and agreed to these guidelines.
If required by laws and regulations, we may take appropriate measures to verify the guardian's consent.
14.3 Guardian Responsibilities
Guardians should pay attention to minors’ use of Margay and reasonably guide them:
-
Properly protect personal information;
-
Do not upload illegal content;
-
Do not disclose account password;
-
Fair use of AI services;
-
Avoid being addicted to the Internet.
14.4 Processing of minors’ information
If we find that the personal information of minors has been collected without the consent of the guardian, or that the relevant information processing violates legal and regulatory requirements, we will take deletion, stop processing or other necessary measures in accordance with the law.
If guardians have questions about the processing of minors’ personal information, they can contact us through the contact information published in this guideline.
15. Contact us
If you have any questions, comments, suggestions or complaints about these Guidelines, personal information protection, data security or related products and services, you can contact us in the following ways:
official website: https://margay-ai.com/
We will process your application as soon as possible after receiving it and respond within the time limit specified by laws and regulations.
Updates to the guidelines
With the development of product functions, changes in laws and regulations, or business adjustments, we may revise this "Margay Privacy Protection Guidelines" from time to time.
For important changes that involve your major rights and interests, we will remind you through product announcements, site notifications, emails or other reasonable methods. The updated guidance will be effective on the date of publication.
If you continue to use Margay after this guide is updated, it means that you have read and understood the updated content; if you do not agree with the updated content, please stop using related products or services.