LI

lindy-data-handling

Guidelines for handling PII and sensitive data securely within Lindy AI workflows, including storage and compliance best practices.

Install

mkdir -p .claude/skills/lindy-data-handling && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/6284" && unzip -o skill.zip -d .claude/skills/lindy-data-handling && rm skill.zip

Installs to .claude/skills/lindy-data-handling

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Data handling best practices for Lindy AI agents.
49 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Classify data processed by Lindy agents into categories like Public, Internal, Confidential, and Restricted.
  • Add data handling instructions directly to agent prompts for PII control.
  • Manage data safety for knowledge base files by controlling uploads.
  • Secure agent memory usage by preventing storage of PII or credentials.
  • Isolate Computer Use data by enabling Incognito mode for sensitive sessions.

How it works

The skill outlines steps to classify data, embed data handling rules in agent prompts, and manage data in knowledge bases, memory, and integrations to ensure compliance and security.

Inputs & outputs

You give it
Agent workflows, data types, and regulatory requirements.
You get back
Lindy agents configured with data classification, PII controls, and secure data handling practices.

When to use lindy-data-handling

  • Classify PII data in workflows
  • Audit data retention policies
  • Implement privacy controls for agent memory
  • Ensure compliance with data regulations

About this skill

Lindy Data Handling

Overview

Lindy agents process data through triggers, LLM calls, actions, knowledge bases, and memory. Data flows through Lindy's managed infrastructure with AES-256 encryption at rest and in transit. This skill covers data classification, PII handling, prompt-level data controls, and regulatory compliance.

Prerequisites

  • Understanding of data types processed by your agents
  • Knowledge of applicable regulations (GDPR, CCPA, HIPAA)
  • For HIPAA: Business Associate Agreement (BAA) with Lindy (Enterprise plan)

Lindy Data Architecture

ComponentData StorageRetention
TasksTask inputs, outputs, step dataVisible in dashboard
MemoryPersistent snippets across tasksUntil manually deleted
ContextPer-task accumulated contextTask lifetime only
Knowledge BaseUploaded files, crawled sitesUntil manually removed
IntegrationsOAuth tokens, connection dataUntil disconnected
Computer UseBrowser session, screenshots30 days after last use

Instructions

Step 1: Classify Data in Agent Workflows

Map what data each agent processes:

Data CategoryExamplesHandling
PublicProduct info, FAQs, pricingNo restrictions
InternalSales reports, meeting notesLimit to authorized agents
ConfidentialCustomer emails, CRM dataAccess controls + audit
RestrictedPII, PHI, payment dataMinimize exposure + compliance

Step 2: PII Controls in Agent Prompts

Add data handling instructions directly to agent prompts:

## Data Handling Rules
- Never include full email addresses in summaries — use "[name]@[domain]"
- Redact phone numbers in logs — show only last 4 digits
- Do not forward customer personal information to Slack channels
- When storing to spreadsheet, omit columns: email, phone, address
- If asked to share customer data externally, decline and escalate

Step 3: Knowledge Base Data Safety

Knowledge base files are searchable by the agent. Control what goes in:

DO upload:

  • Product documentation
  • FAQ articles
  • Policy documents
  • Public knowledge articles

DO NOT upload:

  • Customer databases with PII
  • Credentials or API keys
  • Internal HR documents (unless agent specifically needs them)
  • Financial records with account numbers

Resync considerations: KB auto-refreshes every 24 hours. If you upload sensitive content by mistake, remove it AND trigger a manual Resync.

Step 4: Secure Memory Usage

Agent memories persist across all future tasks. Be deliberate:

Safe memory: "Customer prefers email communication over phone"
Safe memory: "Billing questions should escalate to [email protected]"

Risky memory: "John Smith's SSN is 123-45-6789"  ← NEVER store PII in memory
Risky memory: "API key for Stripe: sk_live_xxxx"  ← NEVER store secrets

Add to agent prompt:

## Memory Rules
- Never store personally identifiable information (PII) in memory
- Never store credentials, API keys, or passwords in memory
- Memories should contain preferences, patterns, and procedures only

Step 5: Computer Use Data Isolation

If using Computer Use (browser automation):

  • Sessions persist for 30 days with saved credentials
  • Enable Incognito mode for sessions handling sensitive data
  • Use dedicated (not shared) computer assignments for sensitive agents
  • Review screenshots captured during execution for data exposure

Step 6: Integration Account Isolation

  • Authorize dedicated service accounts per agent (not personal accounts)
  • Use Gmail with a team alias, not an individual inbox
  • Create read-only database credentials where possible
  • Revoke access immediately when an agent is decommissioned

Step 7: Regulatory Compliance

GDPR (EU Data Protection):

  • Document what personal data each agent processes
  • Ensure agents only process data with valid legal basis
  • Implement data subject access/deletion capabilities
  • Agent prompt includes "do not retain personal data beyond task completion"
  • Review Lindy's data processing agreement

CCPA (California Consumer Privacy):

  • Identify agents processing California resident data
  • Ensure opt-out mechanisms exist for data processing
  • Agent prompt prevents selling/sharing personal information

HIPAA (Healthcare):

  • Enterprise plan with BAA in place
  • Agents only access minimum necessary PHI
  • No PHI in agent memory or knowledge base
  • Audit trail enabled for all PHI access
  • Agent prompt includes PHI handling restrictions

Step 8: Data Retention Management

Agent Prompt Addition:
## Data Retention
- Do not reference data from tasks older than 30 days
- Clear task context after each run (do not accumulate indefinitely)
- When updating memory, remove outdated entries
- Summarize customer interactions, do not store verbatim transcripts

Data Handling Checklist

  • Each agent's data classification documented
  • PII handling rules in every agent prompt
  • Knowledge base audited for sensitive content
  • Memory creation restricted (no PII, no secrets)
  • Integration accounts isolated per agent
  • Computer Use sessions set to dedicated + incognito where needed
  • Regulatory compliance requirements mapped
  • BAA in place if handling healthcare data
  • Data retention policy defined and enforced in prompts

Error Handling

IssueCauseSolution
PII in Slack channelAgent forwarded customer emailAdd "never forward PII to Slack" to prompt
Sensitive file in KBUploaded by mistakeRemove file + trigger KB resync immediately
Memory contains PIIAgent auto-created memoryDelete memory + add "never store PII" to prompt
Audit findingAgent accessing unnecessary dataRemove unused integrations from agent

Resources

Next Steps

Proceed to lindy-enterprise-rbac for access control.

When not to use it

  • When managing data for non-Lindy AI agents.
  • When data handling does not involve PII or sensitive information.

Prerequisites

Understanding of data types processed by your agentsKnowledge of applicable regulations (GDPR, CCPA, HIPAA)For HIPAA: Business Associate Agreement (BAA) with Lindy (Enterprise plan)

Limitations

  • Knowledge base auto-refreshes every 24 hours, requiring manual resync for immediate removal of sensitive content.
  • Computer Use sessions persist for 30 days with saved credentials.
  • Agent memory persists across all future tasks, requiring deliberate management.

How it compares

This skill provides specific architectural guidance for data handling within Lindy AI, offering a structured approach to compliance and security that goes beyond general data management.

Compared to similar skills

lindy-data-handling side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
lindy-data-handling (this skill)127dNo flagsIntermediate
reverse-engineering-tools734moNo flagsAdvanced
game-hacking-techniques422moNo flagsAdvanced
solidity-security152moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

Search skills

Search the agent skills registry