← Back to home

Privacy Policy

Last updated: June 25, 2026

Cicada ("Cicada", "we", "us") operates the platform at cicadalabs.io that lets you create and run autonomous AI agents which connect to your tools and act on your behalf. This policy explains what we collect, how we use it, and the choices you have. Questions: support@cicadalabs.io.

What we collect

Account data: your email address and basic profile when you sign up.
Connection credentials: when you connect an app (for example Slack, Gmail, Notion, HubSpot), we store the OAuth tokens / credentials needed to act on your behalf. These are stored server-side only and are never exposed to your browser.
Workspace data you direct an agent to access: to carry out the tasks you configure, your agent reads and writes data in the apps you connect — for Slack, that means the messages, channels, and profile data permitted by the scopes you grant. We process this data only to perform the actions you ask the agent to take.
Agent configuration and run logs: the agents you create, their instructions and files, and a record of each run (what was checked, what actions were taken) so you can review and audit your agents.

How we use it

We use your data solely to operate the service: to run the agents you create, perform the actions you configure, show you the results, secure the platform, and provide support. We do not sell your data, and we do not use your workspace content to train foundation models.

Slack data

When you connect Slack, Cicada accesses your workspace only within the scopes you approve, and only to do what you've asked your agent to do (such as reading channel history for context, replying to a message, posting an update, or creating a channel). Messages the agent sends are posted on your behalf. You can disconnect Slack at any time from the Apps tab, which revokes and deletes the stored connection.

Subprocessors

We rely on a small set of infrastructure providers to deliver the service — including an AI model provider, a managed database and authentication provider, and cloud hosting. Each processes data only to provide its part of the service. A current list of subprocessors is available on request at support@cicadalabs.io.

Storage, security, and retention

Data is stored in a managed PostgreSQL database with row-level security; connection tokens are restricted to server-side service roles. Data is encrypted in transit (TLS). We retain your data while your account is active. Disconnecting an app deletes its stored credentials; deleting an agent or your account removes the associated data. You can also email us to request deletion.

Your rights

You can access, correct, export, or delete your data. To exercise any of these, or to ask a question about this policy, contact support@cicadalabs.io.

Changes

We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date.