Legal
Privacy Policy
This policy explains what Magnifio collects, why we collect it, and the controls you have over your account and connected sources.
Effective and last updated: July 29, 2026
Scope
This Privacy Policy applies to the Magnifio website, applications, APIs and related services (the “Service”). Magnifio is a multi-tenant knowledge and coding-agent platform that lets users connect sources they choose, search and ask questions across those sources, and request workspace tasks.
An organization may provide your access to a Magnifio workspace. In that case, the organization controls the workspace and may manage membership, shared connections and content according to its own policies.
Information we collect
We collect information in the following categories:
- Account and identity information. Your name, email address, authentication identifiers, session information, workspace memberships and role.
- Content you provide. Questions, instructions, conversations, feedback and workspace-task inputs, along with generated answers, citations, plans, patches and task status.
- Connected-source information. Data from a source you intentionally connect, as described in the next section.
- Service and security information. Bounded identifiers, request timestamps, counts, states, error codes, device or browser information and network information needed to operate, protect and troubleshoot the Service.
Magnifio does not use advertising trackers and does not sell personal information.
Google account and Workspace data
Google sign-in and Google source connections are separate. Google sign-in requests only basic identity information: your name, email address and profile. Signing in does not give Magnifio access to your Gmail, Drive or Calendar.
If you separately choose to connect a source, Magnifio requests only the permission needed for that feature:
- Gmail: read-only access to messages, threads, message metadata, settings needed for synchronization, and supported attachments.
- Google Calendar: read-only access to events on calendars you can access, plus basic account identity needed to identify the connected account.
- Google Drive: read-only access to all files and file metadata available to the connected account, plus basic account identity needed to identify that account. Magnifio currently indexes only supported files modified within the configured ingestion window.
Each source is authorized independently. You can decline to connect a source or disconnect it without disconnecting the others.
How we use connected data
Magnifio uses connected-source data only to provide and secure the user-facing features you request. Depending on the feature, this includes synchronizing authorized content; extracting supported text; creating searchable chunks, embeddings and a derived knowledge graph; retrieving relevant evidence; producing answers and citations; detecting conflicting information; and completing a requested workspace task.
Relevant prompts and excerpts may be processed by the model and embedding providers enabled for your workspace to deliver the requested feature. Magnifio does not use Google Workspace data to create, train or improve a generalized machine-learning or artificial intelligence model, and does not use it for advertising, creditworthiness or surveillance.
Magnifio’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Other connected services
If enabled for your workspace, Magnifio may process approved GitHub repository content and metadata, pull-request and check status, or bounded identifiers and diagnostics from a connected Google Cloud project. Magnifio uses this information only to provide the integration, search, incident and workspace-task features selected by authorized workspace members.
Production coding tasks run in isolated, temporary workspaces. The agent cannot merge or deploy changes and receives no GitHub or cloud credentials. A trusted service validates the exact patch before creating or updating a draft pull request.
Storage and security
Magnifio stores canonical source data, searchable chunks, embeddings, connection records, conversations and task records in workspace-scoped systems. Data is encrypted in transit and protected at rest. Google refresh tokens and other provider credentials are envelope-encrypted using a cloud key-management service and are never returned to browser code or workspace agents.
Access controls derive a user’s permitted workspace and connections from authenticated server-owned records. Magnifio limits logs to bounded identifiers, counts, states and sanitized error codes; logs are not intended to contain source bodies, prompts, tokens, attachments, embeddings or provider payloads.
No system is perfectly secure. Please contact us promptly if you believe your account or data has been compromised.
When we disclose information
Magnifio may disclose information only as follows:
- At your direction. To workspace members, connected services or other recipients you authorize, subject to the Service’s permission checks.
- Service providers. To providers that support authentication, cloud hosting, databases, model inference, security and source integrations, including Supabase, Google Cloud, MongoDB, GitHub and a model provider enabled for your workspace. They receive only the information needed to provide their service.
- Safety and law. When reasonably necessary to protect users or the Service, investigate abuse, or comply with applicable law or valid legal process.
- Business transactions. In connection with a merger, financing, acquisition or sale of assets, subject to applicable law. Google Workspace data will be transferred in such a transaction only with any explicit prior consent required by Google’s Limited Use requirements.
Magnifio personnel do not read Google Workspace content unless you give documented consent for specific support, it is necessary for security, or it is required by law.
Retention and deletion
We retain account and workspace records while needed to provide the Service, meet legal obligations, resolve disputes and secure the platform. Conversations remain available until you delete an individual conversation or clear your history.
When an authorized user disconnects Gmail, Calendar, Drive or another source, Magnifio immediately removes that connection’s content from active search visibility, attempts to revoke the provider grant and queues deletion. Active canonical records, vectors, graph data and stored source objects have a 24-hour deletion target. Encrypted backups and noncurrent encrypted object versions expire within 30 days.
Temporary workspace-task records generally expire after seven days, although a bounded outcome saved in a conversation may remain until that conversation is deleted. Security, incident or action-audit records may be retained longer where necessary for platform security or legal compliance.
Your choices and rights
You can choose whether to connect each source, revoke a connection from Magnifio or the provider, delete chat history, and sign out. You may also request access, correction, export or deletion of your personal information, subject to applicable law and the rights of other workspace members.
If an organization manages your workspace, it may be the appropriate contact for a request concerning organization-controlled data. We may need to verify your identity before completing a request.
Cookies and local storage
Magnifio and its authentication provider use cookies or browser storage that are necessary to maintain sessions, remember security state and preserve interface preferences. Magnifio does not use this storage to build advertising profiles.
International processing and children
Magnifio and its service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws from your location.
The Service is intended for business and professional use and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Changes and contact
We may update this policy as the Service or legal requirements change. We will update the date above and provide additional notice when required by law.
Questions, privacy requests and security concerns can be sent to privacy@magnifio.io.