Introduction
Darwin Technologies, Inc. ("Darwin," "we," "us," or "our") provides a platform for finding public AI capabilities and coordinating authorized actions with them. This Privacy Policy explains how we handle information when you use darwin.so, our web application, APIs, SDKs, Model Context Protocol ("MCP") server, Search, Act, developer tools, and related support services (collectively, the "Services").
1. Information We Collect
1.1 Account and Developer Information
We collect information you provide when you create or manage an account, application, or developer integration, such as your name, email address, organization, profile details, authentication identifiers, API-key metadata, application configuration, support messages, and account preferences. We store a one-way representation of API keys rather than the secret key itself.
1.2 Search Information
Search requests may include natural-language queries, filters, selected capability identifiers, and the results returned. Anonymous and app-only searches are not associated with a Darwin account. When a signed-in user chooses to keep search history, we associate that history with the account as described below.
1.3 Action and Conversation Information
When you use Act, we process the information needed to coordinate the selected AI capability. This can include your instructions, messages, attachment metadata, the selected AI and capability revision, Action and interaction identifiers, approvals, status changes, timestamps, outcomes, and content-free receipts. Files are handled through owner-scoped references; binary file bodies and durable raw media URLs are not placed in MCP responses.
1.4 Authentication and Connection Information
If a destination requires authentication, we process the provider, requested scopes, connection status, expiry, and other information needed to complete and maintain that connection. OAuth tokens and explicitly saved secrets are encrypted and access-controlled. External-vault integrations retain an opaque reference instead of importing the underlying secret. We do not put passwords, authorization codes, access tokens, refresh tokens, or vault contents in prompts, Action responses, analytics, or ranking inputs.
1.5 Payment Information
If an Action requires payment, we may process the merchant, amount, currency, payment protocol, payment status, expiry, and a tokenized payment-method reference. Payment processors and financial institutions process the underlying card, bank, wallet, or other payment credentials. Darwin does not store full card or bank-account credentials in prompts or public API responses.
1.6 Device, Usage, and Diagnostic Information
We collect information such as IP address, browser and device type, operating system, pages and features used, request and correlation identifiers, tool name, protocol version, duration, status, security events, and error codes. Our operational telemetry is designed not to include credentials, authorization codes, payment details, message bodies, or arbitrary provider responses.
2. How We Use Information
- Provide, maintain, secure, and troubleshoot the Services.
- Rank and return public AI capabilities in response to Search requests.
- Route and coordinate authorized Actions with the AI and capability you select.
- Complete authentication, approval, and payment steps that you request.
- Prevent fraud, abuse, replay, duplicate charges, and unauthorized access.
- Provide account support and communicate about security, product, billing, and policy updates.
- Comply with law, enforce our agreements, and protect users, Darwin, and third parties.
- Improve reliability and product quality using appropriately limited operational and aggregate data.
3. How We Disclose Information
We may disclose information in these circumstances:
- At your direction. We send the information necessary for an Action to the AI, capability provider, authentication provider, vault, or payment method that you select.
- Service providers. Vendors supporting hosting, storage, authentication, communications, observability, security, payments, and customer support may process information for us under contractual restrictions.
- Legal and safety reasons. We may disclose information when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Services.
- Business transactions. Information may transfer in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law.
- With consent. We may disclose information for another purpose that you authorize.
Darwin does not sell personal information for money or use personal information for cross-context behavioral advertising.
4. AI Services and Third Parties
Search indexes information about public AI capabilities. When you choose a capability, Darwin may transmit your request and the minimum necessary context to that destination. A destination AI or provider may process and retain information under its own terms and privacy policy. Darwin does not control those independent practices. Review the destination's information before starting an Action or authorizing access.
Private message bodies, credentials, payment details, and reviewed sensitive interaction payloads are not used as Search ranking inputs. Public capability metadata and aggregate reliability signals may be used to improve Search and the Services.
5. Retention
- Search history. Search history that a signed-in user chooses to retain is kept for up to 90 days. Anonymous and app-only searches are not associated with a Darwin account.
- Darwin-managed conversations. When selected, encrypted transcript content is retained until the user deletes it or the account is closed, subject to backup and legal-retention limits.
- Remote-only conversations. Message bodies are transient. Darwin retains only minimal, content-free Action receipts needed for lifecycle, security, and accountability.
- Connections and saved methods. Saved connections and tokenized payment-method references are retained until revoked, deleted, expired, or no longer needed to provide the Services.
- Operational and legal records. Account, security, transaction, and audit records are kept only as long as reasonably necessary for the Services, legal obligations, disputes, and fraud prevention.
Deletion from active systems may take a reasonable period, and limited copies may remain in backups until they cycle out. A destination provider may retain information independently under its own policy.
6. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, encryption for stored credentials and secrets, access controls, expiry and replay protections, and logging controls. Sensitive hosted flows bind the signed-in user, Action, interaction, revision, requested scopes, and expiry. No security method is perfect, and we cannot guarantee absolute security.
7. Your Choices and Rights
Depending on your location, you may have the right to:
- Access, correct, export, or delete personal information associated with your account.
- Delete Search or conversation history and choose Darwin-managed or remote-only conversation retention.
- Revoke an AI connection, delete a saved secret, or remove a tokenized payment-method reference.
- Object to or restrict certain processing, or withdraw consent where processing is based on consent.
- Appeal a denied privacy request where applicable.
To exercise a privacy right, email privacy@darwin.so. We may need to verify your identity and authority. You may use an authorized agent where local law permits. We will not discriminate against you for exercising a privacy right.
8. Cookies and Similar Technologies
We use essential cookies and local storage for authentication, security, preferences, and core product functionality. We may use limited analytics technologies to understand performance and feature usage. You can control cookies through your browser, but disabling essential storage may prevent parts of the Services from working.
9. International Transfers
Darwin is based in the United States. Information may be processed in the United States and other countries where we or our service providers operate. Where required, we use legally recognized transfer mechanisms and safeguards.
10. Children
The Services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. Contact us if you believe a child has provided personal information.
11. Changes to This Policy
We may update this Privacy Policy. We will post the updated version and change the date above. If a change materially affects your rights, we will provide additional notice where required by law.
12. Contact Us
For privacy questions or requests, contact Darwin Technologies, Inc. at privacy@darwin.so. For general or legal inquiries, contact legal@darwin.so.