DigitalOcean Managed Agent Runtime Services: Harness Runtime & Action Gateway (Insights Enabled): Data Privacypublic

Last verified 22 Sep 2026

Action Gateway gives applications and AI agents governed access to tens of thousands of tools through a managed MCP endpoint or SDK. See What You Can Build for example use cases of Action Gateway with Harness Runtime.

Key definitions

  1. Connected-Account Credentials: OAuth tokens, API keys, and similar credentials you authorize us to use to connect to a Third-Party Service.
  2. Catalog Tool: a connector or tool DigitalOcean makes available in its catalog, which may authenticate using a DigitalOcean-registered OAuth application.
  3. Customer-Provided Tool: a connector, tool, or MCP server you bring and connect using your own OAuth application, API client, API key, or endpoint (aka “bring your own key” or BYOK).
  4. Third-Party Service: defined in Section 7 of the Terms of Service Agreement and includes any model provider, tool, connector, or MCP server that processes data on your instruction through the Services.
  5. Insights: the DigitalOcean Insights observability feature described in Addendum A of the Public Preview Terms, enabled by default during the Public Preview.
  6. Search Signals: operational signals (identifiers and status flags only) reflecting which candidate tools were offered by tool search and whether an invocation succeeded. See Section 5.11 of the Public Preview Terms.

Data we process

DigitalOcean Harness Runtime (agent runtime): To run your agents, DigitalOcean Harness Runtime processes Services Content including source code and repository contents, prompts, agent configurations and environment bindings, workspace files and uploads, and session and event history, together with Usage Data.

Insights (observability): Where Insights is enabled (see Section 14), we process telemetry you generate through the Services, including metrics and logs, which may contain personal data that you submit or that your resources emit.

Action Gateway (tool execution): To execute tool calls on your instruction, Action Gateway processes the tool inputs your agent supplies, the results returned by the tool or Third-Party Service, Connected-Account Credentials you authorize, and Usage Data.

Note about personal data: Services Content may contain personal data that you choose to include. You determine what data you submit. You must not submit highly sensitive data through the Services, including Protected Health Information (PHI) under HIPAA or financial data subject to PCI-DSS, as further described in Section 4.1 (Prohibited Data) of the Public Preview Terms. See Sections 6 and 13 regarding restrictions and your responsibilities.

How we use data

We use Services Content only to provide and support the Services to you - for example, to run your agent sessions, execute the tool calls you direct, return results and records to you, and enable features you configure. We use Usage Data to operate, secure, meter and bill, troubleshoot, and improve the reliability of the Services.

We may also use automated and manual processes to monitor Gateway traffic and metadata to detect, prevent, or investigate violations of law or the applicable terms and to maintain the security and safety of the Services, as described in Section 5.4 of the Public Preview Terms.

Tool-search improvement (Search Signals). To improve the Gateway’s tool-search capability, we collect Search Signals, which are operational identifiers and status flags reflecting which candidate tools were offered and whether an invocation succeeded. Search Signals do not include your prompts, conversation text, tool arguments, or tool results. Per-tenant search improvement is enabled by default and can be disabled by you, and we may use privacy-gated, aggregated Search Signals to improve tool search generally, subject to your ability to opt out. Our use of Search Signals is separate from Section 5 and does not involve training, fine-tuning, or improving any generalized AI/ML model. See Section 5.11 of the Public Preview Terms. We do not use Services Content for advertising, and we do not sell Services Content.

We do not use your content to train AI models

DigitalOcean does not use your Services Content, tool inputs, tool results, or agent outputs to train, fine-tune, or improve any generalized artificial-intelligence or machine-learning model. We process such data only to provide the Services to you or as required by law. This commitment extends to data obtained through a Third-Party Service: we do not use data obtained through a Third-Party Service, including data obtained via the Slack APIs (if and where available), to train, fine-tune, or improve any large language model or other generalized AI/ML model.

Where your agent uses a third-party model (see Section 7), that provider’s own data-use and training practices apply to data you route to it; those practices are governed by your relationship with, and the terms of, that provider and not by DigitalOcean.

For clarity, our collection and use of Search Signals to improve tool search (described in Section 4) is limited to operational identifiers and status flags, does not use your Services Content, tool inputs, tool results, or agent outputs, and is not model training.

Your content, your control

As between you and DigitalOcean, you retain all rights in your Services Content. DigitalOcean retains rights in the Services and underlying technology, but not in your Services Content. You control which Catalog and Customer-Provided Tools you enable, which credentials you provide and their scope, and, where offered, the region in which your sessions run. You can delete configurations, revoke connected accounts, and remove workspace data through the Services’ controls; you can also disable Insights by contacting DigitalOcean Customer Support (see Section 14); see Section 11 on retention and deletion.

Third-Party AI Model providers and Tools

  1. The Services let your agents use Third-Party AI Models (for example, hosted coding agents) and third-party tools (including Catalog Tools and Customer-Provided Tools). Data flows to these Third-Party Services only when you or your agent directs it.
  2. Bring-your-own-key (BYOK) / Customer-Provided Tools: When you connect a Third-Party Service using your own credentials, you are the party in privity with that provider; your use is subject to that provider’s terms, data-use policies, and any charges the provider imposes. DigitalOcean acts at your direction in dispatching calls.
  3. Catalog Tools. Where a Catalog Tool authenticates through a DigitalOcean-registered application, we facilitate the connection; your use of the underlying service remains subject to that provider’s terms and data-use policies.
  4. No control over third-party processing: DigitalOcean does not control, and is not responsible for, how a Third-Party Service processes, retains, or uses data you send to it. Review each provider’s privacy terms before connecting it.
  5. Third-party model retention and data-use details: For models made available through DigitalOcean’s inference infrastructure, provider-specific data-use and retention details (including any zero-data-retention (ZDR) arrangements or mandatory retention periods) are described in the DigitalOcean Inference data privacy documentation at https://docs.digitalocean.com/products/inference/details/data-privacy/.
  6. Inclusion is not endorsement: A provider’s presence in our catalog is for convenience and is not an endorsement, certification, or warranty of that provider.

Credentials and scope of access

Connected-Account Credentials you authorize are brokered to your session using scoped, short-lived capability tokens. Credentials are used only to execute the connections and tool calls you direct, and to comply with law.

You control the scope of access you grant and can revoke credentials. Because an agent that can use a credential can also read it within its execution environment, you are responsible for the scope you grant and for rotating or revoking credentials as appropriate (see Section 13).

Isolation and multi-tenancy

Harness Runtime. runs each agent session in its own hardware-isolated microVM (Firecracker), and Action Gateway scopes credentials, policies, and records to your tenant. This architecture is designed to keep each customer’s workloads and data separated from other customers’. Data obtained through a Third-Party Service for one organization is not used to benefit any other organization or third party.

Data residency and regions

Services Content is processed in the United States region(s) in which the Services operate. For data obtained through a Third-Party Service, including data obtained via the Slack APIs (if applicable), we comply with applicable requirements for any international transfer of personal data.

Insights telemetry (including metrics and logs) is processed and stored in a DigitalOcean United States data center region. Insights does not offer regional data storage or data localization at this time (see Addendum A of the Public Preview Terms).

Data retention and deletion

We retain Services Content for as long as needed to provide the Services and then in accordance with our retention schedule. For data obtained through a Third-Party Service, we limit our use, processing, and retention to the minimum necessary to operate and support the connection and the tool calls you direct. We may, however, preserve specific data where required by law or legal process.

Search Signals are stored on a per-tenant basis, retained for the period stated in the Documentation, and deleted on tenant offboarding. Insights telemetry is retained in accordance with Addendum A of the Public Preview Terms and the applicable documentation. Because the Services are offered as a Public Preview, data, records, and execution states may be lost, or (upon termination or deletion of a preview instance) permanently and irreversibly destroyed, as described in Sections 2.4 and 7.2 of the Public Preview Terms; you are responsible for maintaining your own backups.

Provider-specific terms - Slack (subject to pending availability)

Where you connect Slack through the Services, the following apply in addition to the general terms above, reflecting Slack’s API Terms of Service:

  • Minimum-necessary handling. We use, process, and retain data obtained from the Slack APIs (including messages, files, and metadata, “Slack API Data”) only as necessary to operate and support the connection and the tool calls you direct.
  • No model training. We do not use Slack API Data to train, fine-tune, or improve any large language model or other AI/ML model.
  • No bulk export. We do not bulk-export Slack message or file data except where expressly permitted by Slack.
  • No cross-organization use. We do not use Slack API Data obtained for one organization to benefit any other organization or third party; Slack API Data is scoped to your tenant.
  • Your authorization. You are responsible for obtaining any authorization required from the Slack workspace or organization whose data is accessed, and for ensuring your use of the Slack Third-Party Service complies with Slack’s applicable terms.
  • Temporary handling for real-time/data-access retrieval. To the extent we retrieve Slack data via Slack’s Data Access API or Real-Time Search API, we do not create persistent copies, archives, or indexes of that data; any handling or caching is temporary, minimized, promptly deleted, and not used to improve our Services, and we do not perform background collection unrelated to your requests.
  • Transparency. This disclosure, together with the Terms and DPA, describes how we collect, use, store, and share data obtained through a Third-Party Service, including Slack API Data.

Shared responsibility

Privacy and security in the Services are a shared responsibility:

DigitalOcean is responsible for operating the Services securely, handling Connected-Account Credentials as described in Section 8, maintaining the isolation architecture in Section 9, and meeting our commitments in this disclosure and the DPA.

You are responsible for the Services Content you submit and the actions your agents take; not submitting prohibited or highly sensitive data (including PHI and PCI-DSS financial data) as described in Section 3 and Section 4.1 of the Public Preview Terms; ensuring you have the rights and authorizations to connect each Third-Party Service and to have DigitalOcean act on your behalf; reviewing your Insights configuration and disabling Insights if you do not wish to use it; complying with each Third-Party Service’s terms, including Slack’s API Terms of Service where you connect Slack; the scope of access you grant and the timely revocation of credentials; and configuring appropriate approvals and human oversight.

DigitalOcean Insights (observability)

During the Public Preview, DigitalOcean has enabled the DigitalOcean Insights feature (“Insights”) for your account by default, subject to Addendum A of the Public Preview Terms. Insights is a separate DigitalOcean Beta and Private Preview observability feature that provides metrics, logs, alerting, and dashboarding across supported resources.

  1. Data processed. Insights ingests telemetry, including metrics and logs, which may contain personal data that you submit or that your resources emit. You must not submit prohibited or highly sensitive data (see Section 3 and Section 4.1 of the Public Preview Terms).

  2. No model training. We do not use Insights telemetry to train, fine-tune, or improve any generalized AI/ML model; we process it only to provide the observability features to you or as required by law.

  3. Data residency. Insights telemetry is processed and stored in a DigitalOcean United States data center region. Insights does not offer regional data storage or data localization at this time.

  4. Subprocessors. DigitalOcean uses Amazon Web Services, Cloudflare, and Traversal (located in the United States) as subprocessors to support Insights. See the DigitalOcean Subprocessor List at https://www.digitalocean.com/trust/subprocessors.

  5. Your control; survival. You can disable Insights at any time by contacting DigitalOcean Customer Support; disabling Insights does not affect your use of the Services. Insights is governed by Addendum A of the Public Preview Terms, which survives the transition of Harness Runtime. and the Action Gateway to General Availability until Insights itself transitions to Public Preview or General Availability or is discontinued.

We can't find any results for your search.

Try using different keywords or simplifying your search terms.