Margay Privacy Policy

1. Introduction

Welcome to use Margay (hereinafter referred to as "Margay", "this product" or "this service").

Margay is a new generation AI Agent collaboration platform for individual and enterprise users. It provides digital avatars, multi-agent collaboration, knowledge management, workflow orchestration, tool invocation, document generation, automated task execution, local intelligent assistants and other capabilities to help users complete knowledge management, content creation, software development, office collaboration and business automation more efficiently.

We are well aware of the importance of personal information and corporate data to users, and always regard data security and privacy protection as important principles in product design and operation. We will strictly abide by applicable laws and regulations such as the "Personal Information Protection Law of the People's Republic of China", "Cybersecurity Law of the People's Republic of China", "Data Security Law of the People's Republic of China" and other applicable laws and regulations, and take reasonable and necessary technical and management measures to protect the security of your personal information and business data.

This "Margay Privacy Protection Guidelines" (hereinafter referred to as "these Guidelines") aims to explain to you:

Please read carefully and fully understand the entire contents of these Guidelines before registering, logging in or using Margay, especially those involving the processing of your personal information, third-party services, data sharing, user rights and disclaimers.

When you register, log in or continue to use Margay, it means that you have read, understood and agreed to the contents of these guidelines. If you do not agree with these guidelines, please stop using Margay and related services.

For some special functions, we may further explain the relevant data processing rules to you through product pages, function descriptions, authorization pop-ups or separate agreements. Such explanations form an integral part of these Guidelines and have the same legal effect as these Guidelines.

2. Definition

Unless otherwise agreed in these guidelines, the following terms have the following meanings:

2.1 Margay

refers to the artificial intelligence Agent collaboration platform provided and operated by Margay, including website, desktop client, mobile client and related services.

2.2 Users

refers to the natural person, legal person, unincorporated organization or other legally established entity who registers, logs in or uses Margay.

can be divided into:

2.3 Enterprise Administrator

refers to the person authorized by the enterprise user to manage the enterprise workspace, members, model configuration, Agent, workflow, knowledge base, permissions and security policies.

Enterprise administrators can configure enterprise resources and manage enterprise members according to the scope of enterprise authorization.

2.4 Corporate members

refers to those who join the enterprise workspace and use Margay services within the scope of enterprise authorization, including but not limited to employees, partners, outsourcers and other authorized members.

2.5 Enterprise Data

refers to data uploaded, created, generated, processed or managed by enterprise users or enterprise members in the enterprise workspace, including but not limited to:

The purpose of processing and management rights of enterprise data are determined by enterprise users in accordance with the law.

2.6 AI model

refers to the large language model or other artificial intelligence model that provides Margay with natural language understanding, reasoning, generation, planning and other capabilities.

AI models include but are not limited to:

2.7 Third-party model

refers to large language model services provided by third-party service providers and authorized by users, including but not limited to OpenAI, Anthropic, Google, DeepSeek, Zhipu AI, Alibaba Cloud Tongyi Qianwen, Tencent Hunyuan, etc. The data processing rules of

third-party models are subject to the privacy policy and service agreement of the corresponding service provider.

2.8 Agent

refers to an intelligent agent that can independently perform task planning, tool invocation, knowledge retrieval, perform operations and generate results based on user goals.

Agent can be created, configured, shared by users or managed uniformly by the enterprise.

2.9 Digital clone

refers to the long-term intelligent assistant provided by Margay to users, which can combine long-term memory, historical conversations, knowledge base and user configuration to provide users with continuous and personalized intelligent collaboration capabilities.

2.10 Long-term memory

refers to user preferences, background information and other sustainable use information saved by Margay to enhance the continuous collaboration experience with user authorization or user active settings.

2.11 Workflow

refers to a multi-step task execution process configured by the user or automatically generated by the Agent, which can include execution logic such as multiple Agents, tool calls, model calls, and conditional judgments.

2.12 Tools

refers to various external capabilities called by Margay, including but not limited to:

3. Scope of application

3.1

These guidelines apply to all products and services officially provided by Margay, including but not limited to:

3.2

This guideline applies to personal information and related data processing activities generated by users when using Margay, including registration, login, AI dialogue, knowledge base management, Agent execution, workflow running, tool invocation and other functions.

3.3

For third-party services that users access or configure themselves, including but not limited to third-party AI models, MCP services, CLI tools, databases, browser plug-ins, internal corporate systems, open APIs, etc., the data processing behavior is the responsibility of the corresponding third party, and this guideline does not apply. Users should read and abide by the service agreement and privacy policy of the corresponding third party.

3.4

When users access third-party services through Margay, we only transmit data within the scope necessary to fulfill the user's request and will not process relevant information beyond the scope of user authorization.

3.5

When enterprise users manage enterprise members, knowledge bases, workflows and other enterprise resources through Margay, they should fulfill the relevant obligations of personal information processors in accordance with the law, ensure that authorization from enterprise members has been obtained in accordance with the law, and establish corresponding data management systems. Margay processes corporate data based on the authorization and instructions of corporate users and takes reasonable measures to ensure data security.

4. Information we collect

In order to provide you with stable, secure, and continuous AI services, we may collect, generate or process necessary information based on the specific functions you use. We always follow the principles of legality, legitimacy, necessity, and good faith, and only process your information within the scope necessary to realize product functions and fulfill legal obligations.

The type of information involved in different functions may be different. When a certain function requires obtaining specific information or device permissions, we will explain it to you in the appropriate scenario and obtain your authorization or consent if required by laws and regulations.

4.1 Account information

When you register, log in or use Margay, we may collect the following information:

(1) Registration information

includes but is not limited to:

The above information is mainly used for:

If you refuse to provide the above necessary information, you may not be able to complete account registration or login, but this will not affect browsing public pages or using functions that do not require login (if applicable).

(2) Enterprise account information

When you join an enterprise workspace or an account is created by an enterprise administrator, we may process:

The above information is used for:

The enterprise administrator is responsible for configuring the above information and shall perform relevant personal information protection obligations in accordance with the law.

4.2 Device information

In order to ensure the safe and stable operation of the product, we may automatically collect necessary equipment information, including but not limited to:

The above information is mainly used for:

Unless otherwise provided by laws and regulations, we will not use device information to identify your true identity.

4.3 Usage log

In order to continuously improve product stability and service quality, we may record the operation logs generated during your use of Margay, including:

The above logs are mainly used for:

We will not conduct personal portraits unrelated to the service based on the above logs.

4.4 AI dialogue data

When you use AI dialogue, digital avatar or Agent services, the information you actively submit may include:

-Prompt;

At the same time, during the AI reasoning process:

The above data is mainly used for:

Unless otherwise provided by laws and regulations or with your authorization, we will not publicly display your conversation content, nor will we use the conversation content in the enterprise workspace for purposes unrelated to the enterprise.

4.5 Upload files

When you actively upload files, we may process:

files may include but are not limited to:

The above information is only used to complete the analysis, summary, retrieval, question and answer, translation, generation, editing and other tasks initiated by you.

4.6 Knowledge Base Data

When you create a knowledge base, upload materials, or connect to external data sources, we may process:

The above information is mainly used for:

Knowledge base content is only visible in your or authorized member's workspace by default and will not be open to other users.

4.7 Long-term memory

In order to improve the long-term collaboration capabilities of digital clones and Agents, Margay provides long-term memory function.

After you turn on this function or actively ask the system to remember relevant information, we may save information including but not limited to:

long-term memory is mainly used for:

You can:

After turning off the long-term memory function, we will stop generating new long-term memories; the saved historical memories will not be automatically deleted, and you can delete them yourself as needed.

4.8 Workflow data

When you create, edit or run a workflow, we may log:

The above information is used for:

4.9 Agent execution record

When you create or run an Agent, we may record information related to task execution, including:

The above information is used for:

Except for enterprise administrators who can legally view enterprise operating data within the scope of enterprise management authority, the above execution records are only visible to the creator and its authorized users by default.

5. Data processing of AI model

Margay supports the use of built-in artificial intelligence models and third-party artificial intelligence models that users can access by themselves, providing users with services such as intelligent dialogue, knowledge Q&A, content generation, task planning, code generation, workflow execution, and agent reasoning.

There are differences in the data processing methods of different models. Please read this chapter carefully before using related functions.

5.1 Built-in model

When you use the artificial intelligence model provided by Margay by default, in order to complete your request, we may process the following information:

includes but is not limited to:

The above information is only used for:

Unless otherwise provided by laws and regulations or with your explicit authorization, we will not publicly display your corporate data, knowledge base content or conversation content to other users.

5.2 Third-party model

Margay supports users to call third-party artificial intelligence models, including but not limited to:

-MiniMax

When you actively choose to use a third-party model, in order to complete your request, your input content and necessary context may be sent to the corresponding model service provider for inference, and the model will return the output results. The collection, storage and use of relevant data by

third-party models are independently handled by the corresponding service providers in accordance with their privacy policies and service agreements.

Margay cannot control the data processing behavior of third-party models. It is recommended that you carefully read the relevant agreements of the corresponding service providers before use.

5.3 Custom model

Margay supports users to configure third-party model services, including but not limited to:

-Endpoint;

Model service configured by users. Users decide the model provider, data processing method and access permissions by themselves.

For the above configuration:

Users should keep the relevant keys properly and bear the risks caused by key leaks, configuration errors or third-party model services.

5.4 Local model

Margay supports connecting to users’ locally deployed large language models or inference services.

When the user uses a local model, the model inference process is completed by the user's local environment.

Except for completing request transmission, status synchronization and necessary system logs, Margay will not actively upload model input content or output content to the platform server.

Since the running environment of the local model is maintained by the user, the user should ensure its network environment, model security and system stability.

5.5 Model input and output

Inputs submitted by users to the model may include:

-Prompt;

model may include:

AI output content is automatically generated by the model and may be incorrect, incomplete, outdated, or inconsistent with the actual needs of users.

Users should make judgments based on the actual situation and consult professionals with corresponding qualifications for important decisions in medical, legal, financial, production safety and other professional fields.

5.6 Model training and optimization

Margay will not use enterprise workspace data, knowledge base content or user uploaded files for public model training without user authorization.

In order to continue to improve product stability, model capabilities and user experience, we may analyze some service operation data after completing anonymization, de-identification or statistical processing for:

related processing will not be for the purpose of identifying specific individuals.

If the product provides an experience optimization plan or similar functions, users can choose whether to participate according to the product settings.

5.7 Model call log

In order to ensure the stable operation of the service, we may record logs related to model calls, including:

The above logs are mainly used for:

The content of the log will not exceed the scope necessary to achieve the above purposes.

5.8 User Control

For model-related data processing, users can manage it independently according to the functions provided by the product, including but not limited to:

After the user stops using the relevant model or deletes the corresponding data, we will stop processing the relevant data to the extent permitted by laws and regulations and necessary to achieve the purpose of the service, and process it in accordance with the provisions of this Guideline on data storage and deletion.

6. Tool calling and automation capabilities

Margay supports calling local or third-party tools through Agent, workflow and user active operations to complete complex tasks, automated processes and cross-system collaboration. We will only perform relevant operations when the user actively initiates, explicitly authorizes, or in accordance with the user's pre-configured workflow. We will not actively call any tools or access user resources without authorization.

Depending on the type and function of different tools, the data processing methods involved may be different.

6.1 Tool calling principles

Margay follows the following principles during the tool calling process:

(1) User authorization principles

Tool invocation should be based on a request initiated by the user, or automatically executed by an Agent or workflow created and authorized by the user.

(2) Minimum necessary principle

only obtains the data necessary to complete the current task and does not access user data or system resources beyond the scope of the task.

(3) Principle of transparency and traceability

For important operations generated by tool calls, Margay will retain necessary execution records to facilitate users to view task status, troubleshoot exceptions, and conduct security audits.

(4) User controllable principle

Users can independently enable, disable, configure or delete related tools, Agents, workflows and authorization information based on the capabilities provided by the product.

6.2 MCP Service

Margay supports connecting to services that comply with the MCP (Model Context Protocol) protocol.

Users can access local or third-party MCP Server according to their own needs, providing Agent with capabilities such as knowledge retrieval, database access, file management, and business system calls.

During the process of calling the MCP service, we may process:

The above information is only used to complete the user's current request, maintain service operation and record necessary execution logs.

For MCP services that users access by themselves, the data processing behavior is the responsibility of the corresponding service provider. Margay is not responsible for the data processing methods of third-party services.

6.3 CLI tool

Margay supports calling the command line tool (CLI) installed or configured locally by the user to assist in completing development, operation and maintenance, testing, office and automation tasks.

Depending on the user authorization, the CLI tool may execute including but not limited to:

During execution, we may record:

CLI tool depends on the user's local operating system and operating environment. Margay will not perform any operations beyond operating system permission restrictions.

6.4 Browser Automation

Margay supports calling browser automation capabilities according to user instructions to realize web access, information query, page operations and business process automation.

Within the scope of the user's authorization, browser automation may perform:

browser access, the website operator may collect user-related information in accordance with its own rules, and the relevant data processing behavior shall be governed by the privacy policy of the corresponding website.

6.5 File operations

According to user instructions, Margay can call the local file system to complete related tasks. Operations involved in

include but are not limited to:

Margay will only process files that are actively selected, explicitly specified by the user, or required during workflow execution, and will not actively scan or access irrelevant directories and files.

For unrecoverable operations involving deletion, overwriting, etc., the product may provide confirmation prompts based on specific scenarios to reduce the risk of misoperations.

6.6 Local program call

Margay supports calling software or applications installed in the user's device to assist in completing related tasks.

For example:

-IDE;

call, only the information necessary to complete the current task is passed.

The corresponding software is responsible for the data processing behavior generated by the program itself.

6.7 API call

Margay supports calling HTTP API, Webhook, open platform interface and other network services provided by user configuration or platform.

Depending on specific business needs, it may handle:

Users should ensure that the API services they configure are legal and valid, and have corresponding data processing permissions.

Margay does not guarantee the authenticity, accuracy, completeness or continued availability of data returned by third-party APIs.

6.8 Database connection

Margay supports connecting to user-authorized databases or data services. Databases that

may support include but are not limited to:

Based on user authorization, Agent can perform query, analysis, statistics and other operations explicitly allowed by the user.

Margay will not modify database contents or perform destructive database operations unless actively authorized by the user.

6.9 Tool execution log

In order to ensure the stable operation of the system, support task tracking and troubleshooting, we may record necessary logs generated during the tool calling process, including:

The above logs are only used for service operation and maintenance, security audit and product optimization, and will not be used for purposes unrelated to the current service.

6.10 Third-party tools

Margay supports users to connect to various third-party applications and services, including but not limited to:

The data processing rules of third-party tools are the responsibility of the corresponding service provider.

When a user actively authorizes Margay to call third-party tools, we will only process relevant data within the scope necessary to complete the user's request, and will not access or use information in third-party services beyond the scope of authorization.

6.11 User authorization and revocation

Users can follow the management functions provided by the product at any time:

When the user revokes authorization or deletes related tools, Margay will stop subsequent calls; the execution records that have been generated will be processed in accordance with the data storage and deletion rules of this guideline.

7. Agent permissions description

In order to help users complete complex tasks, realize automated processes and intelligent collaboration, Margay supports Agent to call local resources, third-party tools and system capabilities within the scope of user authorization. The permission scope of different Agents is configured by the user or enterprise administrator, and the Agent will not obtain access permissions beyond the authorized scope by default.

Users can turn on, turn off or adjust Agent permissions according to actual needs.

7.1 Rights Management Principles

Margay implements unified management of Agent permissions and follows the following principles:

(1) Principle of least privilege

Agent only obtains the permissions necessary to complete the current task and will not actively apply for or use permissions unrelated to the task.

(2) User authorization principles

In addition to the basic permissions necessary for product operation, when access to local resources, system capabilities, third-party services or enterprise resources is involved, execution must be explicitly authorized by the user or enterprise administrator.

(3) Principle of use on demand

Authorization does not mean that the Agent will continue to access relevant resources. It only invokes necessary permissions during the execution of the current task and stops using it after the task is completed.

(4) Principle of manageability

Users can view, modify, limit or revoke the permissions that Agent has obtained at any time, and enterprise administrators can uniformly configure the permission scope according to enterprise management policies.

7.2 File system permissions

When the Agent needs to process local files, it may apply for the following permissions:

Click on the image to view the complete spreadsheet

Agent will not actively scan all files in the user's computer, nor will it access directories that the user has not authorized.

When unrecoverable operations such as deletion and overwriting are involved, the product can require the user to confirm again according to specific scenarios.

7.3 Browser permissions

In order to complete web page access and automation tasks, Agent can call browser capabilities after user authorization, including but not limited to:

browser access, the data processing behavior of the relevant website shall be governed by the website's own privacy policy.

7.4 System command execution permissions

For development, operation and maintenance, and automation scenarios, Agent can execute local commands or scripts based on user authorization.

may involve:

-Terminal;

-CMD;

All commands are executed according to user instructions or workflow configuration.

Margay will not bypass operating system permission restrictions to execute any commands, nor will it actively escalate system permissions.

7.5 Local program calling permission

According to user task requirements, Agent can call locally installed software to complete related work, such as:

Agent will not install, uninstall or modify local software configuration unless the user explicitly issues relevant instructions.

7.6 Clipboard permissions

When the user actively performs operations such as copying and pasting, the Agent can read the clipboard content currently pasted by the user to Margay and use it to complete the current task.

Margay will not continuously monitor, record or upload the system clipboard content, and will only read the corresponding data when the user actively pastes or authorizes use.

7.7 Network access rights

Agent can access the Internet or corporate internal network resources according to user needs, such as:

Network access is limited to what is needed to complete user tasks, and will not actively access websites or network resources that are not related to the current task.

7.8 Third-party service access rights

When a user connects to a third-party service, the Agent can access relevant resources within the authorized scope, such as:

Agent is only used to complete the user's current request and will not be accessed, modified or shared beyond the scope of authorization.

7.9 Enterprise resource access rights

Enterprise administrators can configure the Agent's permissions to access enterprise resources according to enterprise security policies.

Enterprise resources may include:

Agent's access to enterprise resources is controlled by the enterprise permission system, and the range of resources that different members can access may vary.

7.10 Permission change and revocation

Users or enterprise administrators can use the rights management functions provided by the product to:

After the permission is revoked, the Agent will stop accessing the corresponding resources. We will save the execution records that have been generated to the extent permitted by laws and regulations and necessary to achieve the purpose of the service, and process them in accordance with the provisions of this guideline on data storage and deletion.

7.11 Permission anomalies and security assurance

In order to ensure the security of user data, Margay will continue to monitor the use of Agent permissions and take necessary security measures, including but not limited to:

If we discover abnormal access, unauthorized calls, or behavior that may affect user data security, we have the right to suspend relevant tasks, limit Agent permissions, or take other necessary measures to protect the legitimate rights and interests of users and the platform.

8. Enterprise Edition Data

Margay Enterprise Edition aims to provide enterprises with a unified, secure, and controllable AI Agent collaboration platform. Enterprise users can uniformly manage resources such as members, agents, knowledge bases, workflows, models, and tools through the enterprise workspace.

When you use Margay as an enterprise user, in addition to the provisions in other chapters of these guidelines, this section applies to the processing rules of enterprise data.

8.1 Enterprise workspace

Enterprise workspace is an organizational unit for enterprises to uniformly manage members, data and AI capabilities.

Enterprise administrators can create multiple workspaces according to enterprise management needs and configure:

enterprise workspace is only accessible to members with corresponding permissions.

8.2 Enterprise data scope

Enterprise data includes but is not limited to data created, uploaded, generated or managed by enterprise users during the use of Margay, such as:

The ownership and management rights of enterprise data belong to enterprise users or entities that enjoy rights according to law.

8.3 Enterprise Administrator Permissions

Enterprise administrators can conduct unified management of enterprise workspaces based on enterprise authorization, including but not limited to:

Enterprise administrators should configure permissions appropriately to avoid processing personal information of enterprise members beyond the needs of enterprise management.

8.4 Enterprise member data

Data generated by enterprise members in the enterprise workspace may include:

Corporate members should use Margay reasonably in accordance with the company's internal policies and shall not use the platform to process data that is illegal, illegal or infringes upon the legitimate rights and interests of others.

8.5 Enterprise resource access control

Margay adopts an access control mechanism based on identity and permissions to implement unified management of enterprise resources.

Enterprise administrators can configure different resource access rights for different members based on job responsibilities, organizational structure or business needs, including but not limited to:

Unauthorized members cannot access the corresponding enterprise resources.

8.6 Enterprise Audit Log

In order to help enterprises carry out security management and risk control, Margay Enterprise Edition may record necessary audit information, including but not limited to:

audit log is mainly used for:

Enterprise administrators should use relevant logs in a legal and reasonable manner and shall not process enterprise member information beyond legitimate management purposes.

8.7 Enterprise model and tool management

Enterprise administrators can uniformly configure AI models and tools that can be used by the enterprise, including:

-MCP Server;

Enterprise administrators can restrict model types, tool scope, and resource access permissions based on enterprise security policies.

8.8 Enterprise data security

Margay takes reasonable technical and management measures to protect corporate data security, including but not limited to:

Corporate users should also establish an internal security management system, reasonably configure member permissions, properly keep account numbers and access credentials, and jointly maintain corporate data security.

8.9 Enterprise data export and migration

Within the scope of product support, enterprise administrators can export, back up or migrate enterprise data according to enterprise business needs.

Data export and migration should comply with relevant laws, regulations and internal corporate management requirements, and must not infringe on the legitimate rights and interests of other users or third parties.

Enterprise users shall bear the corresponding responsibilities for risks arising from enterprises exporting, backing up, migrating or sharing data on their own.

8.10 Corporate Data Processing Responsibility

As managers of corporate data, corporate users should ensure that their processing of corporate members' personal information and business data complies with applicable laws and regulations, and perform corresponding information protection obligations in accordance with the law.

Margay provides technical services based on the authorization and instructions of enterprise users, processes enterprise data within the scope of laws and regulations and the scope agreed by both parties, and takes reasonable measures to ensure the security, integrity and availability of enterprise data.

The responsibilities of enterprise users and Margay for enterprise data shall be subject to the service agreement, data processing agreement or other written agreement signed by both parties.

9. How we use information

We will only process your personal information and related data within the scope of achieving the purposes stated in these Guidelines and permitted by laws and regulations, and follow the principles of legality, legitimacy, necessity, and good faith, and will not process your information beyond the scope necessary to achieve the purpose of the service.

The use of information involved in different functions may be different. We mainly use relevant information for the following purposes.

9.1 Providing products and services

In order to provide you with various functions of Margay, we may use relevant information to implement the following services, including but not limited to:

If a function requires the processing of specific information, we will process it to the extent necessary to achieve that function.

9.2 Provides a continuous intelligent collaboration experience

In order to improve Margay's intelligent collaboration capabilities, we may combine user authorized information to provide you with a more continuous and consistent experience, including:

For long-term memory related information, you can independently view, edit, delete or close it according to the functions provided by the product.

9.3 Perform tasks authorized by the user

When you create an Agent, workflow or call a tool, we may process information necessary to complete the task, including:

The above information is only used to complete the tasks initiated or authorized by you.

Margay will not actively perform relevant operations without your authorization.

9.4 Provide customer service and technical support

When you contact us for assistance, we may process:

The above information is only used for:

9.5 Ensure product operation and safety

In order to ensure the stable operation and information security of Margay, we may use relevant information:

We have the right to take necessary measures in accordance with laws, regulations and relevant agreements for behavior suspected of violating laws, regulations, service agreements or endangering platform security.

9.6 Product optimization and function improvement

In order to continue to improve Margay's product capabilities and user experience, we may carry out: based on statistical analysis, anonymized or de-identified information:

related analysis will not be aimed at identifying specific individuals.

9.7 Enterprise Operation and Management

For enterprise version services, we may process relevant information based on the configuration of the enterprise administrator and enterprise authorization for:

Enterprise administrators should use relevant management functions in a reasonable and legal manner and shall not process members' personal information beyond the needs of enterprise management.

9.8 Legal and regulatory requirements

When permitted or required by laws and regulations, we may process your relevant information for:

9.9 Other uses with your separate consent

If we intend to use your personal information for other purposes not specified in these guidelines, or use your information beyond the original processing purpose, processing method and processing scope, we will separately notify you in accordance with the requirements of laws and regulations, and obtain your authorization or consent in accordance with the law before processing. We will not use your personal information for purposes unrelated to the purposes stated in these Guidelines without your explicit authorization.

10. Information Sharing

We fully respect and protect the security of your personal information and data. Except as expressly stated in these Guidelines or as otherwise provided by laws and regulations, we will not sell your personal information to any third party, nor will we provide your personal information to third parties without your authorization.

Under the following circumstances, we may share, entrust processing or disclose relevant information in accordance with the law.

10.1 Sharing actively authorized by users

When you actively choose to use third-party services, connect third-party applications, call third-party models or configure third-party tools, in order to complete your request, we may transmit necessary information to the relevant service provider in accordance with your authorization.

For example:

We only transfer the information necessary to complete the current task and will not share relevant data beyond the scope of user authorization.

10.2 Third Party Service Provider

In order to provide you with complete product capabilities, Margay may access third-party services, including but not limited to:

For the above third-party services, we will make reasonable efforts to select partners with corresponding data protection capabilities, and require them to process relevant data in accordance with applicable laws and regulations through agreements and other means.

Third-party service providers are responsible for the data they collect, store and process.

10.3 Enterprise Administrator

For enterprise version services, within the scope of enterprise authorization, enterprise administrators may view or manage some information in the enterprise workspace according to enterprise management needs, including but not limited to:

Enterprise administrators shall fulfill their personal information protection obligations in accordance with the law and shall not process the personal information of enterprise members beyond the purpose of enterprise management.

10.4 Delegate processing

In order to achieve the purposes stated in this Guideline, we may entrust a third party to process some information on our behalf, such as:

For the entrusted processing parties, we will clarify their processing purposes, processing methods, security obligations and confidentiality responsibilities through contracts, agreements or other legal documents, and supervise their processing of relevant information in accordance with the law.

Without our authorization, the entrusted processor shall not use relevant information for other purposes.

10.5 Merger, Acquisition or Asset Transfer

In the event of a corporate merger, division, reorganization, acquisition, asset transfer or similar transaction involving the transfer of personal information, we will require the recipient to continue to perform its obligations under these Guidelines in accordance with the law.

If the recipient intends to change the original purpose or method of processing, we will re-fulfill our notification obligations in accordance with the law and obtain your authorization or consent if required by laws and regulations.

10.6 Legal and regulatory requirements

Under the following circumstances, we may share, disclose or provide relevant information in accordance with the law without obtaining your authorization:

(1) To fulfill obligations stipulated in laws and regulations;

(2) To implement court judgments, rulings or other legal documents;

(3) According to the requirements made by administrative agencies, judicial agencies or other competent agencies in accordance with the law;

(4) To safeguard national security, public safety, public health and major public interests;

(5) Necessary to protect the life, property and other legitimate rights and interests of users, third parties or Margay;

(6) Other situations stipulated by laws and regulations.

10.7 Situations that do not belong to the sharing of personal information

The following processing actions are generally not considered sharing your personal information with third parties:

We have the right to use anonymized data for product analysis, statistical research and service optimization in accordance with the law, provided that the specific individual cannot be identified and cannot be restored.

10.8 Information Sharing Principles

We always adhere to the following principles for information sharing:

Except as described in this section, we will not sell your personal information to any third party, nor will we use your personal information for commercial purposes without your authorization.

11. Data storage

We attach great importance to the security management of user data and take reasonable technical and management measures to store, manage and protect user data.

Unless otherwise stipulated by laws and regulations or otherwise agreed by both parties, we will save relevant data for the period necessary to achieve the processing purposes described in these guidelines, and delete or anonymize it in accordance with the law after the retention period expires.

11.1 Data storage location

In principle, we will store user data in servers and infrastructure that comply with applicable laws and regulations.

Depending on the service type, user location or product deployment method, data may be stored in:

For the enterprise privatized deployment version, the storage location and management method of enterprise data are decided by the enterprise users themselves.

11.2 Data storage period

We only save relevant data for the period necessary to achieve the purpose of the service.

Different types of data may have different retention periods, for example:

Click on the image to view the complete spreadsheet

If laws and regulations provide otherwise, relevant regulations should be followed.

11.3 Data actively deleted by users

When the user actively deletes the following data:

We will complete the deletion within a reasonable period or process it in accordance with product function requirements.

Due to system caching, data synchronization, backup and recovery, etc., some data may not be completely deleted from all storage media immediately. We will complete the processing as soon as technical conditions permit.

11.4 Data backup

In order to ensure the stable operation of the system and prevent accidental loss of data, we may back up some data.

backup data is mainly used for:

Backup data can only be accessed by authorized personnel when necessary and will not be used for purposes unrelated to the backup purpose.

11.5 Enterprise Data Storage

Enterprise version user data is logically isolated according to the enterprise workspace.

Enterprise administrators can perform the following operations on enterprise data based on product functions and deployment methods:

In an enterprise privatized deployment environment, enterprise data is managed by the enterprise itself, and Margay will not actively access the enterprise's internal data, unless otherwise agreed by both parties.

11.6 Cross-border data

In principle, we will store user data in a region that complies with applicable laws and regulations.

If users actively use overseas models, overseas cloud services or other cross-border services, resulting in the need to transfer relevant data overseas, we will perform corresponding obligations within the scope of laws and regulations and remind users to pay attention to the data processing rules of relevant third-party services.

11.7 Data retention under special circumstances

Even if the user deletes the relevant data or cancels the account, we may still continue to save some information in accordance with the law under the following circumstances:

(1) Fulfill obligations stipulated in laws and regulations;

(2) Comply with court judgments, rulings or other legal procedures;

(3) Cooperate with administrative agencies, judicial agencies or other competent agencies to conduct investigations in accordance with the law;

(4) Handling complaints, disputes or litigation;

(5) Protect the legitimate rights and interests of users, third parties or Margay;

(6) Ensure network security, information security and stable system operation;

(7) Other situations stipulated by laws and regulations.

After the above situation disappears, we will delete or anonymize the relevant information in accordance with the law.

12. Data Security

We attach great importance to the security of users' personal information and corporate data, and continue to take technical and management measures in line with industry practices to prevent data from unauthorized access, leakage, tampering, damage, loss or other security risks.

However, please understand that the Internet environment is not absolutely safe, and no technical measures can guarantee 100% security of information. Therefore, we recommend that you properly keep sensitive information such as your account number, password, access credentials, and API Key to jointly maintain data security.

12.1 Safety technical measures

In order to ensure data security, we may take measures including but not limited to the following:

We will continue to optimize security protection measures based on business development and technical capabilities.

12.2 Access Control

We have established a corresponding data access control mechanism to only authorize authorized personnel required for work to access relevant data.

For access to users' personal information and corporate data, we will take necessary identity verification, authority verification and audit measures, and require relevant personnel to fulfill confidentiality obligations.

12.3 Enterprise Security Management

For enterprise version products, we support enterprises to configure security policies according to their own management needs, including but not limited to:

Enterprise users should reasonably configure permissions according to their own business needs and strengthen internal security management.

12.4 User Security Responsibility

In order to protect the security of your account and data, we recommend that you:

For information leakage, account theft or other security incidents caused by the user himself, the user shall bear corresponding responsibilities in accordance with the law; unless otherwise provided by laws and regulations or due to Margay reasons.

12.5 Security incident handling

If an incident occurs that may affect the security of users' personal information or corporate data, we will take timely measures based on the nature of the incident, including but not limited to:

If required by laws and regulations, we will inform affected users through on-site notifications, emails, text messages or other reasonable means of the basic situation of the incident, possible impacts, measures taken or planned, and risk prevention suggestions that users can take.

12.6 Continuous improvement of security

We will continue to improve the information security management system in accordance with laws, regulations, industry standards and technological development, continue to improve data security protection capabilities, and provide users with more secure, stable and reliable AI services.

13. User Rights

We attach great importance to your legal rights to personal information and provide corresponding management methods to help you manage personal information and related data.

Unless otherwise provided by laws and regulations, you can exercise relevant rights based on product functions or through the contact information published in these guidelines.

13.1 Check personal information

You have the right to review the personal information we hold about you.

Within the scope of product support, you can check including but not limited to:

For information that is currently not supported for online viewing, you can apply to us through the contact information published in these guidelines.

13.2 Correct or update personal information

If you find that the personal information we process is incorrect, incomplete or has changed, you have the right to modify it yourself or ask us to correct it.

For example:

In order to ensure the security of your account, we may require you to complete necessary identity verification.

13.3 Delete personal information

You have the right to request the deletion of your personal information in compliance with laws and regulations.

includes but is not limited to:

You also have the right to request deletion of relevant personal information when one of the following circumstances occurs:

(1) Our processing of personal information violates laws and regulations;

(2) We have not obtained your consent in accordance with the law;

(3) We process personal information in violation of the agreement with you;

(4) You no longer use related products or services;

(5) Other situations stipulated by laws and regulations.

Unless otherwise provided by laws and regulations or deletion will seriously affect the public interest, judicial procedures or the performance of other legal obligations.

13.4 Export personal data

For the data types supported by the product, you can export relevant data based on product functions, including but not limited to:

are subject to the actual functions provided by the product.

13.5 Withdraw authorization

For the permissions you have authorized Margay to use, you can withdraw or adjust the authorization at any time according to the product functions, such as:

After withdrawing the authorization, we will stop processing the corresponding information, but the withdrawal of the authorization will not affect the data processing activities that have been carried out based on your authorization before the withdrawal.

13.6 Cancel account

You have the right to apply to cancel your Margay account at any time. After canceling your

account, we will cancel your account after completing the identity verification and confirming that there are no circumstances that require continued retention of information as required by laws and regulations or agreed by both parties. After

account cancellation is completed:

If you are a member of an enterprise workspace, canceling your personal account may not affect the enterprise's business data saved by the enterprise in accordance with the law.

13.7 Managing long-term memory

Margay provides long-term memory management capabilities, you can according to product functions:

After turning off the long-term memory function, Margay will stop generating new long-term memories; the saved historical memories can still be deleted by you.

13.8 Manage AI conversations and history

You can manage historical conversations according to the functions provided by the product, including:

The deleted data will be processed in accordance with the relevant provisions of these Guidelines to the extent permitted by laws, regulations and technically feasible.

13.9 Respond to your request

We will handle your relevant requests in accordance with laws and regulations in a timely manner after verifying your identity.

Under normal circumstances, we will respond within fifteen (15) working days after receiving the application.

If the request cannot be completed within the above period due to complex content, large amounts of data or other reasonable reasons, we will explain the reasons to you to the extent permitted by laws and regulations and complete the processing within a reasonable period.

We have the right to refuse in accordance with the law and explain the reasons to you for requests that are obviously repetitive, exceed reasonable scope, are malicious, or may damage the legitimate rights and interests of others.

14. Protection of minors

Margay mainly provides products and services for adults.

We attach great importance to the protection of minors' personal information and will take corresponding protective measures in accordance with the "Personal Information Protection Law of the People's Republic of China", the "Minor Protection Law of the People's Republic of China" and other relevant laws and regulations.

14.1 Use by minors

Minors under the age of 18 should use Margay under the guidance, supervision and consent of their guardians.

Guardians should help minors correctly understand these guidelines and guide them to use artificial intelligence products and related services reasonably and safely.

14.2 Minors under the age of fourteen

If you are a minor under the age of fourteen, please use Margay after your guardian has fully read and agreed to these guidelines.

If required by laws and regulations, we may take appropriate measures to verify the guardian's consent.

14.3 Guardian Responsibilities

Guardians should pay attention to minors’ use of Margay and reasonably guide them:

14.4 Processing of minors’ information

If we find that the personal information of minors has been collected without the consent of the guardian, or that the relevant information processing violates legal and regulatory requirements, we will take deletion, stop processing or other necessary measures in accordance with the law.

If guardians have questions about the processing of minors’ personal information, they can contact us through the contact information published in this guideline.

15. Contact us

If you have any questions, comments, suggestions or complaints about these Guidelines, personal information protection, data security or related products and services, you can contact us in the following ways:

official website: https://margay-ai.com/

We will process your application as soon as possible after receiving it and respond within the time limit specified by laws and regulations.

Updates to the guidelines

With the development of product functions, changes in laws and regulations, or business adjustments, we may revise this "Margay Privacy Protection Guidelines" from time to time.

For important changes that involve your major rights and interests, we will remind you through product announcements, site notifications, emails or other reasonable methods. The updated guidance will be effective on the date of publication.

If you continue to use Margay after this guide is updated, it means that you have read and understood the updated content; if you do not agree with the updated content, please stop using related products or services.