Agent Workbench · Product privacy
Your work.
Your information.
Copilot handles the conversation. When you use hosted Workbench features, Celest processes package files, configuration checks, and saved evaluation results. This notice explains that data flow and your choices.
Scope
Celest AI, Inc. operates Agent Workbench. This notice applies to hosted package processing, Model Context Protocol (MCP) configuration checks, saved evaluations, companion accounts, Marketplace fulfillment where available, and product support. The Celest website notice covers this marketing website.
Microsoft 365 Copilot performs conversational inference for the Microsoft 365 experience. Celest’s Azure Function receives and processes the files and requests needed for hosted Workbench features. Celest does not operate a separate inference service on this path.
Your original Copilot conversations and Microsoft 365 content remain governed by your Microsoft agreements. Answers copied into a Workbench evaluation become part of the work Celest stores. Deleting that work does not delete the original Microsoft conversation.
What we collect
- Package work: packages you submit, manifests, instructions, referenced files, working revisions, check results, reports, and exports.
- Evaluations: test inputs, returned agent answers, comparisons, conversation identifiers, your evaluation preferences, and error details recorded when you run or save an evaluation.
- MCP configuration: endpoints you select, tool names and schemas, protocol metadata, and diagnostic results. When a provider requires authorization, Celest may store OAuth access and refresh tokens, authorization-state records, and callback information used for the connection check.
- Identity and account details: Microsoft account and tenant identifiers, names and email addresses when supplied, your confirmed contact details, and optional organization name.
- Companion and Marketplace records: setup progress, session records, accepted terms and timestamps, and offer, subscription, purchaser, activation, and entitlement records where applicable.
- Operations and support: request identifiers, status and timing, errors, service versions, security records, and messages or attachments you send us.
The companion uses basic Microsoft sign-in to manage your account. Hosted features can separately request Microsoft permissions or provider authorization for the operation you choose. Review the permission screen before granting access. Do not put passwords, access tokens, private keys, or unrelated customer information into account fields or support messages.
How we use it
We use this information to perform the package operations and evaluations you request, check MCP configuration, return and preserve your work, authenticate you, manage your account and entitlements, respond to support requests, and operate and protect the service. We also keep records needed to meet legal and Marketplace obligations.
An MCP configuration check contacts the endpoint you select to inspect its connection and advertised tools. The check does not itself run those tools or authorize Copilot to use them later.
Where data protection law requires a legal basis, we process information as needed to provide the service under an agreement, meet legal obligations, or pursue legitimate interests in operating, supporting, and securing the service. Where processing relies on consent, you can withdraw that consent. When Celest processes package content on behalf of your organization, your organization determines the purpose of that work.
Retention and cookies
Hosted workspace content becomes unavailable after seven days without meaningful user activity. Importing, editing, checking, reconciling, starting a preflight, advancing an evaluation, and requesting an export count as activity; background polling, status reads, automatic retries, and fetching a download link do not. Existing preview work receives a seven-day grace period when the retention policy first applies. An hourly cleanup works through eligible stored copies in batches and retries incomplete cleanup. Removal can finish after the access cutoff.
Deleting a workspace removes Celest-held originals, revisions, reports, exports, copied evaluation inputs and answers, and related investigation records for that workspace. “Delete my Workbench account and data” covers all workspaces owned by your verified Microsoft identity, then closes the companion account and its sessions. We retain minimal deletion and lifecycle records, such as an owner or account reference, status, and timestamps, to enforce the deletion, retry failures, and prevent late work from restoring content.
Deletion can remain pending while cleanup retries. If it does not complete, contact support with the signed-in account and workspace details; do not send credentials or package content. Workbench deletion does not delete your Microsoft account or conversations, uninstall an agent, revoke a provider-side grant, cancel a Marketplace subscription, or promise immediate erasure from provider backups and recovery copies.
MCP authorization has a separate short lifecycle. A pending authorization attempt expires 15 minutes after its sign-in link is created. Expired private state is removed when next accessed or by hourly cleanup. When a check ends, its stored credentials and private authorization material are removed. Saved redacted investigation results follow the hosted content lifecycle. These timings do not promise revocation of a grant held by Microsoft or an MCP provider.
When optional ad measurement is available, its preference cookie stores only your allow or decline choice for up to 180 days; see Optional ad measurement below. The companion uses necessary sign-in and session cookies. A sign-in attempt expires after 10 minutes; a companion session expires after 7 days or when you sign out or delete the account. Expired companion sign-in and session records are scheduled for cleanup each hour. The configured cleanup status and failure telemetry is retained for 30 days; other operational records, support correspondence, acceptance and transaction records, security logs, and records subject to legal obligations can have separate retention periods. The 30-day period applies to this cleanup telemetry, not every application or provider log.
Optional ad measurement
Ad measurement is optional. When it is available, Privacy choices lets you allow or decline it for this browser. The link is available from the Agent Workbench website and companion footers. Measurement stays off until you allow it, and declining does not affect your account or product access. We also respect your browser’s Global Privacy Control signal. Accepting the product terms is a separate choice.
When measurement is allowed and a new account finishes activation, Celest sends OpenAI a registration event and time, a one-way event identifier used to prevent duplicates, and the signup page address without its query or fragment. The event includes OpenAI’s ad-click reference when available. To help OpenAI match the registration to an ad, it also includes a one-way SHA-256 hash of your normalized signup email address, your browser’s user-agent string, and your IP address when available from Cloudflare. OpenAI can match the email hash to an email address it already holds; hashing does not make the address anonymous. We do not send your name, Microsoft tenant or account identifiers, Workbench files, or package content. Events are flagged to opt out of future user-level ad personalization.
The celest_ad_measurement preference cookie remembers allow or decline for up to 180 days on celest.dev and workbench.celest.dev. It contains only a preference version and your choice, not an account identifier or ad-click reference. Use Privacy choices to change it; the change applies to future events in this browser and does not erase events already sent. Clearing browser cookies removes the saved choice. Other browsers have their own choices. An allowed choice applies to any new Workbench account created from this browser while it remains on, including a later visit without an ad link. Global Privacy Control overrides a saved allow without deleting it. A new recipient or additional matching fields require a new choice before they can be sent.
With measurement allowed, the website can carry the ad-click reference into the signup link. The existing sign-in return cookie can hold that URL for up to 10 minutes while Microsoft sign-in completes, and is then cleared. This integration adds no browser pixel, persistent ad-reference cookie, or separate conversion-event database. OpenAI processes received events under its advertising data practices; the hosted-workspace deletion and retention periods above do not describe OpenAI’s records. Contact support about a measurement privacy request.
The Workbench landing page also counts clicks on Allow, Don’t allow, and Sign up while the banner is unanswered using Celest’s first-party Cloudflare analytics. These counts use no analytics cookie or persistent visitor identifier, contain no email or ad-click reference, and are not joined to account records or reports sent to OpenAI. They help us understand the banner’s use even when ad measurement is declined or left unanswered. Raw observations are retained for at most three months; see the website analytics notice.
Your choices
You can change optional ad measurement through Privacy choices. You can correct companion account details, sign out, or delete the account in Account settings. “Delete my Workbench account and data” uses your verified Microsoft identity and covers Celest-held Workbench work; deleting one workspace is the smaller action. For access, correction, deletion, portability, an objection to processing, or a request to restrict processing where applicable, contact [email protected]. You may also raise a concern with your data protection authority. Where your organization controls the relevant content, we may direct the request to that organization or work with it to respond.
We may need to verify your identity and the scope of the request. Include enough information to identify the work, without emailing credentials or a full customer package. We may retain information required for legal, security, or transaction obligations and will explain applicable limits.
We publish changes with a new version date. This notice expands the description of hosted Workbench features; it does not authorize a new use of companion account information or replace an accepted agreement. If we materially change how we use account information, we will provide notice through the service or your account contact address.