Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Data handling best practices for Lindy AI agents. Use when managing sensitive data in agent workflows, implementing data privacy controls, or ensuring compliance. Trigger with phrases like "lindy data", "lindy privacy", "lindy PII", "lindy data handling", "lindy GDPR", "lindy HIPAA".
.claude/skills/jeremylongshore-lindy-data-handling/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 6% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 3% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 10% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 32% | 0% |
| case-21 | ✓→✓ | = Same ✓ | 43% | 0% |
Lindy agents process data through triggers, LLM calls, actions, knowledge bases, and memory. Data flows through Lindy's managed infrastructure with AES-256 encryption at rest and in transit. This skill covers data classification, PII handling, prompt-level data controls, and regulatory compliance.
| Component | Data Storage | Retention | |-----------|-------------|-----------| | Tasks | Task inputs, outputs, step data | Visible in dashboard | | Memory | Persistent snippets across tasks | Until manually deleted | | Context | Per-task accumulated context | Task lifetime only | | Knowledge Base | Uploaded files, crawled sites | Until manually removed | | Integrations | OAuth tokens, connection data | Until disconnected | | Computer Use | Browser session, screenshots | 30 days after last use |
Map what data each agent processes:
| Data Category | Examples | Handling | |--------------|---------|----------| | Public | Product info, FAQs, pricing | No restrictions | | Internal | Sales reports, meeting notes | Limit to authorized agents | | Confidential | Customer emails, CRM data | Access controls + audit | | Restricted | PII, PHI, payment data | Minimize exposure + compliance |
Add data handling instructions directly to agent prompts:
## Data Handling Rules
- Never include full email addresses in summaries — use "[name]@[domain]"
- Redact phone numbers in logs — show only last 4 digits
- Do not forward customer personal information to Slack channels
- When storing to spreadsheet, omit columns: email, phone, address
- If asked to share customer data externally, decline and escalateKnowledge base files are searchable by the agent. Control what goes in:
DO upload:
DO NOT upload:
Resync considerations: KB auto-refreshes every 24 hours. If you upload sensitive content by mistake, remove it AND trigger a manual Resync.
Agent memories persist across all future tasks. Be deliberate:
Safe memory: "Customer prefers email communication over phone"
Safe memory: "Billing questions should escalate to finance@company.com"
Risky memory: "John Smith's SSN is 123-45-6789" ← NEVER store PII in memory
Risky memory: "API key for Stripe: sk_live_xxxx" ← NEVER store secretsAdd to agent prompt:
## Memory Rules
- Never store personally identifiable information (PII) in memory
- Never store credentials, API keys, or passwords in memory
- Memories should contain preferences, patterns, and procedures onlyIf using Computer Use (browser automation):
GDPR (EU Data Protection):
CCPA (California Consumer Privacy):
HIPAA (Healthcare):
Agent Prompt Addition:
## Data Retention
- Do not reference data from tasks older than 30 days
- Clear task context after each run (do not accumulate indefinitely)
- When updating memory, remove outdated entries
- Summarize customer interactions, do not store verbatim transcripts| Issue | Cause | Solution | |-------|-------|----------| | PII in Slack channel | Agent forwarded customer email | Add "never forward PII to Slack" to prompt | | Sensitive file in KB | Uploaded by mistake | Remove file + trigger KB resync immediately | | Memory contains PII | Agent auto-created memory | Delete memory + add "never store PII" to prompt | | Audit finding | Agent accessing unnecessary data | Remove unused integrations from agent |
Proceed to lindy-enterprise-rbac for access control.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 21,902 | 14,220 | -35% | 1 | 1 | 0% | 2,753 | 2,929 | +6% | 0 | 0 | — |
case-02 | pass→pass | 18,792 | 15,085 | -20% | 1 | 1 | 0% | 2,383 | 3,154 | +32% | 0 | 0 | — |
case-03 | fail→pass | 38,593 | 29,521 | -24% | 1 | 1 | 0% | 5,322 | 5,499 | +3% | 0 | 0 | — |
case-21 | pass→pass | 12,093 | 14,992 | +24% | 1 | 1 | 0% | 2,219 | 3,173 | +43% | 0 | 0 | — |
case-04 | pass→pass | 15,516 | 9,236 | -40% | 1 | 1 | 0% | 1,641 | 2,185 | +33% | 0 | 0 | — |
case-05 | pass→pass | 12,535 | 7,091 | -43% | 1 | 1 | 0% | 1,196 | 1,727 | +44% | 0 | 0 | — |
case-06 | pass→pass | 14,697 | 11,115 | -24% | 1 | 1 | 0% | 1,613 | 2,463 | +53% | 0 | 0 | — |
case-07 | pass→pass | 18,282 | 12,965 | -29% | 1 | 1 | 0% | 2,038 | 2,690 | +32% | 0 | 0 | — |
case-08 | pass→pass | 15,248 | 7,278 | -52% | 1 | 1 | 0% | 1,588 | 1,817 | +14% | 0 | 0 | — |
case-09 | pass→pass | 16,496 | 11,987 | -27% | 1 | 1 | 0% | 1,894 | 2,422 | +28% | 0 | 0 | — |
case-10 | fail→pass | 14,563 | 8,911 | -39% | 1 | 1 | 0% | 1,888 | 2,084 | +10% | 0 | 0 | — |
case-11 | pass→pass | 12,415 | 8,225 | -34% | 1 | 1 | 0% | 1,317 | 2,001 | +52% | 0 | 0 | — |
case-12 | pass→pass | 18,315 | 7,475 | -59% | 1 | 1 | 0% | 1,712 | 1,768 | +3% | 0 | 0 | — |
case-13 | pass→pass | 13,977 | 9,788 | -30% | 1 | 1 | 0% | 1,576 | 2,160 | +37% | 0 | 0 | — |
case-14 | pass→pass | 19,040 | 12,169 | -36% | 1 | 1 | 0% | 1,847 | 2,338 | +27% | 0 | 0 | — |
case-15 | pass→pass | 5,880 | 7,316 | +24% | 1 | 1 | 0% | 749 | 1,708 | +128% | 0 | 0 | — |
case-16 | pass→pass | 12,357 | 3,316 | -73% | 1 | 1 | 0% | 1,518 | 1,863 | +23% | 0 | 0 | — |
case-17 | pass→pass | 15,875 | 7,259 | -54% | 1 | 1 | 0% | 1,577 | 2,361 | +50% | 0 | 0 | — |
case-18 | pass→pass | 21,175 | 7,911 | -63% | 1 | 1 | 0% | 2,095 | 1,902 | -9% | 0 | 0 | — |
case-19 | pass→pass | 20,056 | 9,984 | -50% | 1 | 1 | 0% | 2,074 | 2,067 | -0% | 0 | 0 | — |
case-20 | pass→pass | 15,180 | 18,269 | +20% | 1 | 1 | 0% | 1,709 | 3,580 | +109% | 0 | 0 | — |
case-22 | pass→pass | 16,726 | 13,921 | -17% | 1 | 1 | 0% | 1,675 | 2,885 | +72% | 0 | 0 | — |
case-23 | pass→pass | 10,739 | 6,572 | -39% | 1 | 1 | 0% | 1,606 | 2,360 | +47% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +13 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.