Privacy and Cookie Notice
Effective date: August 13, 2026
This Notice explains how Valkyr Labs Inc. ("Valkyr," "we") collects, uses, discloses, and retains Personal Data when we act as a controller, such as for our websites, accounts, billing, marketing, support, security, and business operations. When a business customer submits data to Valkyr Services and Valkyr acts as its processor or service provider, that customer's agreement and the DPA govern; individuals should direct requests about that data to the customer.
1. Personal Data we collect
Depending on how you interact with us, we may collect:
- Identifiers and contact data: name, username, email, telephone number, postal address, organization, role, and account identifiers.
- Commercial and transaction data: products considered or purchased, subscription, invoices, payment status, credits, tax and billing information. Payment-card details may be collected directly by our payment processor rather than Valkyr.
- Account and authentication data: credentials or credential hashes, multifactor settings, OAuth grants, authorization choices, PKCE parameters, access and refresh tokens, tenant, role, permission, and scope claims.
- Device, internet, and activity data: IP address, browser, device, operating system, cookie or similar identifiers, pages and features used, timestamps, referring URLs, diagnostics, logs, and approximate location inferred from IP.
- Communications: support requests, survey responses, call or meeting content where disclosed, and other messages.
- AI, workflow, and development data: prompts, outputs, code, schemas, files, agent instructions, integration events, workflow records, and related metadata when you submit them to a Valkyr-controlled account.
- GrayMatter memory and context: memory text and metadata, searches, context-compilation and procedure queries, ContextPage records, retrieval receipts, and authorized object references.
- Professional and applicant data: business contact, employment, education, resume, portfolio, interview, and reference information.
- Inferences: preferences, likely interests, and account or fraud risk derived from the information above.
We do not intend to collect protected health information, full payment-card data, government identifiers, biometric templates, precise geolocation, children's data, or other highly sensitive data through ordinary website and self-service fields. Do not submit those categories unless a signed agreement and configured product expressly authorize them.
2. Sources
We collect Personal Data from you; your organization or account administrator; your device and use of the Services; integrations and Model Providers you enable; payment, identity, hosting, analytics, communications, security, and support providers; public sources; event and marketing partners; and business counterparties. A customer may submit information about other people to its workspace.
3. Purposes and legal bases
We use Personal Data to:
- provide, personalize, maintain, and support products and accounts;
- authenticate users; enforce tenant, role, scope, and object permissions; issue and revoke grants; and protect security;
- process purchases, subscriptions, credits, invoices, taxes, and fraud checks;
- operate AI inference, agents, integrations, generated deliverables, memory, context, and retrieval receipts at your direction;
- communicate service notices and respond to requests;
- analyze performance, troubleshoot, develop features, and create deidentified Usage Data;
- market Valkyr products, measure campaigns, and manage cookie choices where permitted;
- recruit personnel and manage business relationships; and
- comply with law, enforce agreements, establish or defend claims, and protect people and systems.
Where GDPR or similar law applies, our legal bases are performance of a contract, legitimate interests in operating and securing our business and Services, compliance with legal obligations, and consent where required. You may withdraw consent without affecting prior lawful processing. We do not use customer workspace content to train generalized models or improve services for other customers by default; that requires a separate opt-in under the Optional Content Sharing Agreement.
4. How we disclose Personal Data
We may disclose Personal Data to:
- hosting, infrastructure, security, identity, support, communications, analytics, payment, tax, and professional-service providers;
- Model Providers, integrations, MCP servers, and marketplace publishers you or your organization choose to enable;
- your organization, administrators, and Authorized Users according to account permissions;
- authorities or other parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or handle claims; and
- an acquirer, investor, lender, adviser, or successor in a merger, financing, reorganization, bankruptcy, or sale, subject to appropriate confidentiality.
We do not sell Personal Data for money. Some advertising or analytics cookies may constitute "sharing," "sale," or targeted advertising under certain U.S. state laws even without money changing hands. Where applicable, you may opt out through our cookie controls, a recognized universal opt-out signal such as Global Privacy Control, or by contacting us. We do not knowingly sell or share Personal Data of people under 16.
5. Cookies and similar technologies
We use:
- strictly necessary technologies for sign-in, security, network management, purchases, and requested features;
- preference technologies to remember settings;
- analytics technologies to understand use and performance; and
- advertising technologies, if enabled, to measure campaigns or personalize marketing.
Where required, nonessential technologies are disabled until consent. You can use the site's cookie controls and browser settings. We honor legally required universal opt-out signals for the browser or device from which they are sent. Disabling a necessary technology may prevent a requested feature from working.
6. AI, agents, GrayMatter, and provider choices
AI output can include Personal Data from prompts, connected sources, or model behavior. Review outputs before sharing or acting on them. Agents operate using credentials, scopes, policies, and approvals configured by you or your organization; their actions may be logged for security, audit, and support.
GrayMatter memory may persist until an authorized user forgets it, a configured retention rule applies, or the workspace ends. Revoking an OAuth grant prevents future token use but does not by itself delete memory already stored. Hosted GrayMatter derives identity, tenant, roles, permissions, and scopes from validated authorization and uses tenant and object controls to restrict access.
If you use your own Model Provider or integration account, that provider may independently process data under its terms. If Valkyr selects a provider to process customer data, it is handled as a Subprocessor under an applicable DPA.
7. Retention
We retain Personal Data only as long as reasonably necessary for the stated purpose, including the account or contract term, configured workspace retention, legal limitation periods, tax and accounting duties, security, dispute, and abuse-prevention needs. Retention varies by category rather than using a universal period.
Account and workspace data is deleted according to the governing agreement, generally after an export period and then from active systems within 30 days and backups within 90 additional days. OAuth grants and tokens remain until expiration, revocation, or account deletion. Security and transaction records may be retained longer where reasonably necessary or legally required. We delete or deidentify data when the applicable period ends.
8. Security and international transfers
We use reasonable administrative, technical, and physical safeguards appropriate to risk, but no system is absolutely secure. Data may be processed in the United States and other countries. Where required, we use adequacy decisions, contractual clauses, or another valid transfer mechanism. Business customers should review the DPA for transfer terms.
9. Your choices and rights
Depending on your location and subject to exceptions, you may request access, correction, deletion, portability, restriction, or objection; opt out of sale, sharing, targeted advertising, or certain profiling; limit use or disclosure of sensitive Personal Data; withdraw consent; or appeal our denial of a request. You may opt out of marketing email through the message link but will still receive transactional notices.
Submit requests to legal@valkyrlabs.com. We will verify your request proportionately and respond within the legally required period. An authorized agent may submit a request where law permits, subject to proof of authority and identity verification. You will not be discriminated against for exercising privacy rights. If we deny an appeal, you may contact your state attorney general or applicable regulator.
EEA, UK, and Swiss residents may complain to their local supervisory authority. See our GDPR Notice. California residents may also request the categories and specific pieces of Personal Data collected, sources, purposes, and categories of recipients for the period required by law.
10. Children
The Services are not directed to children under 16, and self-service accounts require users to be at least 18. We do not knowingly collect Personal Data from children through self-service Services. Contact us if you believe a child submitted data without appropriate authorization.
11. Changes
We may update this Notice as products or law change. We will post the new effective date and provide additional notice for a material change where required. A material new use requiring consent will not apply without that consent.
12. Contact
Valkyr Labs Inc.
195 Tamal Vista Blvd #201, Corte Madera, CA 94925
legal@valkyrlabs.com