Nightjar / Privacy notice
Privacy notice
Nightjar is a private beta for running connected background agents. This notice describes the information held by this deployment and how it is used.
Who operates the service
Your workspace operator manages access to this Nightjar deployment. Contact your workspace owner or use the Nightjar support page for privacy questions, access changes, or deletion requests.
Information the service holds
Nightjar stores account details such as your name, email, profile image when supplied, sign-in records, and workspace memberships. It also stores agent settings, prompts, run outputs, progress events, schedules, connection settings, and webhook delivery records. Password sign-in uses a password hash, rather than storing the password itself.
Connected tools and execution environments may require credentials. These credentials are held by the server; saved connector and runner secrets are encrypted with the deployment's master key. Native model sign-in credentials are stored on the selected execution environment. Workspace administrators and the deployment operator have privileged access needed to operate and support the service.
Where run information goes
A run sends its instructions and relevant connected-tool content to its selected execution environment and model provider. Tool requests go to the services you connect, such as GitHub, PostHog, Linear, Notion, Google Calendar, Google Drive, Gmail, Slack, Expo, Supabase, Vercel, or Railway. Enabled webhooks send run information, including results, to the destinations configured for the workspace. Those providers and destinations have their own privacy practices.
Only connect accounts you are authorized to use, and choose tool permissions appropriate to the work. Avoid putting credentials or unnecessary personal information into prompts and outputs, which can remain in run history.
Cookies and records
Nightjar uses cookies for sign-in and account enrollment. Operational records support execution, troubleshooting, access control, and delivery retries. This deployment does not include advertising trackers.
Retention and deletion
Account and run records remain in the deployment until removed by its operator; this beta does not yet provide an automatic retention schedule. Disconnecting a tool prevents future use of that saved connection, but does not erase information already included in past runs or sent to third parties. Ask the workspace operator to remove records or credentials you no longer want held. Backup copies and third-party records may require separate handling.
Changes
This notice may change as the beta develops. The date below identifies the current version.
Updated September 20, 2026 · Private beta
This policy also covers the Nightjar MCP
connector. A connected assistant can access workspace runs within the permissions you grant.
Its provider’s own privacy policy applies to information it receives.