Privacy Policy
Fullmakt · Last updated 15 September 2026
Fullmakt ("Fullmakt", "we") is a credential broker for AI agents. It issues scoped, short-lived credentials to your agents, verifies their access, and records a tamper-proof audit of every call. This policy explains what data the hosted service handles and where it goes.
Summary: We store the data needed to run your account and broker credentials on your behalf — your account details, the upstream secrets you ask us to broker (encrypted), and audit records of agent activity. We do not run analytics, telemetry, or tracking, and we never sell, rent, or share your data for advertising.
Data we handle
- Account details. When you sign up we store your email address and a hashed password to create and secure your account. Team and workspace membership is stored so collaborators can share configuration.
- Brokered credentials & configuration. The upstream API keys, OAuth/OIDC client secrets, and connection details you ask Fullmakt to broker are stored encrypted so we can mint scoped, short-lived credentials for your agents. These secrets are never exposed to the AI model — agents receive only the short-lived credential.
- Audit & activity records. Each credential issuance, agent call, and revocation is recorded in a cryptographically chained audit log so you can answer which agent did what, when, and on whose behalf. This is core to the product and cannot be disabled.
- Contact enquiries. If you use the contact form, the email address and message you submit are emailed to our team so we can reply. They are not used for any other purpose.
- Sandbox sessions. The no-signup sandbox creates a temporary, anonymous account seeded with demo data. Sandbox accounts and their data are automatically expired and deleted; if you claim the account, it converts to a normal account and this policy applies to it.
Connectors for Claude, ChatGPT and Claude Code
You can add Fullmakt to an AI assistant as a connector (an MCP server at
https://fullmakt.ai/mcp). Here is exactly what crosses that boundary:
- What the assistant sends us. Only the arguments of the tools it calls — workspace, collection, request and environment identifiers, variable values you ask it to set, and the URL and headers of a request you ask it to run. We never receive your conversation, the assistant's memory, or files you shared with the assistant.
- What we send back. The metadata of your workspaces, collections and requests, the results of requests the assistant runs on your behalf, and your request history. Stored secrets are never returned: credentials are injected server-side when a request executes and appear as references, never as values.
- Sign-in and tokens. Connecting uses OAuth 2.1: you sign in on a Fullmakt page and consent once. The assistant provider (Anthropic or OpenAI) then holds a short-lived access token and a refresh token for your account. Those tokens can only call the connector endpoint — not the rest of the Fullmakt API and not your vault. You can end the connection at any time by removing the connector in the assistant; refresh tokens are rotated on every use and expire after 30 days of inactivity.
- What we record. Requests the assistant runs are written to the same workspace history and audit log as requests you run yourself, so you can see what it did. We keep the connector's client registration for 30 days after its last use, then delete it.
- Credentials are never collected in chat. The connector has no tool that accepts an API key or secret. Upstream credentials are entered by a human in the Fullmakt console, and only there.
What we do NOT do
- No analytics, telemetry, or usage tracking.
- No third-party trackers or advertising.
- No selling, renting, or sharing of your data.
- We never expose your stored secrets to the AI model or to other tenants.
Subprocessors
We use a small number of third parties strictly to operate the service:
- Polar — payment processing for paid plans. Card details are entered with Polar and handled by them; we do not store your full card number.
- Email delivery — our email provider transmits contact-form enquiries and transactional account email.
Data retention
Account data and brokered configuration persist for as long as your account is active. When you delete your account we remove your account data and stored secrets; audit records may be retained as long as needed to meet security and legal obligations. Sandbox data is purged automatically when the session expires.
Your rights
You can access, correct, export, or delete your account data. To make a request, or for any question about this policy, contact us below.
Contact
Questions about this policy: privacy@fullmakt.ai