Legal

Privacy policy

Last updated 26 July 2026

Murable gives you cloud Linux desktops that an AI agent can operate, and lets you connect your own accounts — Gmail, Google Calendar, Google Drive and others — so the agent can act in them on your behalf. This policy sets out what we store, how long we keep it, and what protects it. The service is operated by Rawira LTD.

Rawira LTD is the data controller for the account data described here. Where you connect a third-party account, we act on your instructions when your agent uses it.

What we collect

Account information

Sign-up and sign-in run through Logto, an identity service we host ourselves rather than delegating to a third-party login provider. We store your email address, your display name, and the authentication records Logto needs to recognise you on your next visit. We never receive or store the password you use with your identity provider.

Connected accounts

When you connect a third-party account, that provider returns an access token to us — a credential that lets your agent act in the account within the permissions you approved on the consent screen. We store the token, its refresh token where the provider issues one, and its expiry. We do not receive your password for that account, and we do not copy your mailbox, calendar or files into our own storage.

Service and metering records

We record when a machine starts, stops or wakes, how long it runs, and its resource size, so that we can operate the service and calculate charges once billing begins. We do not sell this data and we do not use it for advertising.

Audit log

Security-relevant events are written to an audit log: sign-ins, machine lifecycle events, gateway key changes, and every occasion on which a connected credential is released to your agent. Each release is recorded with the account, the tool that requested it and the outcome — including refusals. The log records that access happened; it does not record the content your agent read or wrote.

What lives inside your machines

Files, browser sessions and anything your agent creates stay on the disk attached to your machine. We do not index that disk, scan its contents, or use it to train any model. When you delete a machine and its disk, that content is destroyed with it.

How we protect your data

Credentials for connected accounts are the most sensitive data we hold, so they are handled under specific technical controls rather than general assurances.

Encryption

Every third-party credential is encrypted before it reaches the database, using authenticated symmetric encryption (Fernet: AES-128-CBC with an HMAC-SHA256 authentication tag). No table stores a token in plaintext. The encryption key lives in the environment of the panel service, never in the database or in our source repository, so a database copy on its own reveals no usable credential. If the key is absent the service refuses to write a credential at all rather than falling back to plaintext. Traffic between you and Murable is carried over TLS with HSTS enabled.

Privilege separation

The component that executes your agent's requests to third-party services runs as a separate low-privilege service. It holds no database access, no encryption key and no access to the container runtime. To act on your behalf it must ask the panel to release one credential for one specific tool call. The panel re-derives who is asking from the request token rather than trusting the caller's claim, verifies that the connection belongs to that account, that it is still enabled, and that the requested tool is one the connector actually declares — then releases that single credential and nothing else. Refresh tokens are withheld from that component entirely.

Data minimisation and redaction

Responses returned from third-party services to your agent pass through a filtering step that finds and removes credential values in their literal and URL-encoded forms, so a provider that echoes an authorisation header back in an error message does not expose your token. The filter covers the encodings we know of and we extend it as we find more; it is a layer of defence rather than an absolute guarantee. Requests to release a credential are rate-limited per account and per connection, so abnormal volume is throttled and visible in the audit log.

Access control and isolation

Every machine runs in its own network, isolated from other customers' machines and from our database. Machines are not published to the public internet by default. Reading or regenerating a machine's gateway key requires an owner or administrator role, because that key grants control of the machine. Session cookies are HttpOnly, Secure and SameSite-scoped. Application services run as unprivileged users, and the request-executing component additionally runs with a read-only filesystem and all Linux capabilities dropped.

Revocation

You can disconnect a connected account at any time from the panel. Disconnecting stops any further release of that credential immediately. You can also revoke Murable's access from your provider's own security settings — for Google accounts, at myaccount.google.com/permissions.

Google user data

Where you connect a Google account, the following applies in addition to the sections above.

We request only the permissions the features you enable actually use. Each connector maps to a defined set of operations:

ConnectorWhat the agent can do
GmailSearch and read messages, send messages and replies, add or remove labels (including marking read and archiving), rename labels, and restore messages or threads from the trash.
Google CalendarList calendars, read events, and create, update or delete events on your instruction.
Google DriveFind files, read their contents, create new files and delete files you name.
Google SheetsRead cell ranges, write values and append rows.
Google DocsRead a document, create one, and apply edits.
Google SlidesRead a presentation, create one, and apply edits.
YouTubeRead your channel details and list videos. Read-only.
Google AnalyticsRun reports on your properties. Read-only.
Search ConsoleList your verified sites and query search performance. Read-only.

A connector you have not connected requests nothing. Disconnecting one ends its access.

Limited Use commitment

Murable's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data. We do not use it for advertising, and we do not serve advertisements against it. We do not use it to train, fine-tune or evaluate any machine-learning model, whether ours or a third party's. No human at Rawira LTD reads your Google data, except where you explicitly ask us to in a support request, where it is necessary to investigate a security incident, or where the law requires it. We transfer it only to carry out the operation your agent requested on your instruction.

Where your agent's model provider fits in

Your agent runs inside your machine and uses the model provider you configure with your own API key. When you instruct it to work with your Google data, the content it reads is processed by that provider under their terms, not ours. Choosing the provider and its data-retention settings is yours; we neither route this traffic through Murable nor retain a copy of it.

How we use what we collect

We do not sell personal data, we do not share it with data brokers, and we do not use it for advertising or model training.

Who processes data for us

We keep the list short and name what each one does.

Providers you connect yourself — Google among them — receive requests from Murable because you asked for them. Your relationship with those providers is governed by their own terms and privacy policies.

How long we keep it

DataRetention
Account informationFor as long as your account exists; deleted or anonymised when you close it.
Connected-account tokensUntil you disconnect the account or close your Murable account, at which point the stored token is deleted.
Machine disksUntil you delete the machine and its disk. Deletion destroys the contents.
Metering recordsKept while your account is active and for as long as tax and accounting law requires after billing.
Audit logRetained for security and operational purposes for up to 12 months.

Where the law obliges us to keep a record longer than the period above, we keep that record and nothing more.

Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to the address below. We answer within 30 days. If you are in the UK or the EEA and are not satisfied with our answer, you may complain to your national data protection authority.

To delete everything at once: disconnect your connected accounts, delete your machines together with their disks, then ask us to close your account.

International transfers

Our servers are in the European Union. Where a provider you connect processes data outside the EEA, that transfer takes place under their own safeguards and terms.

Children

Murable is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

Changes to this policy

If we make a material change, we will tell account holders by email and update the date at the top of this page before the change takes effect.

Contact

Questions about this policy, or a request about your data, go to privacy@murable.ai.

Rawira LTD, operator of Murable.