Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
Autonomous agenthostedProprietary

Genspark

MainFunc Inc. (Genspark) · genspark.ai

Genspark's Super Agent runs entirely on Genspark's cloud (hosted on Microsoft Azure) with a proprietary multi-model orchestration layer, and it documents no agent export, audit log or verifiable runtime. Owners do get some controls: custom MCP servers, saved skills and custom agents, disconnectable integrations, an explicit confirmation before AI phone calls, and self-serve deletion with a 30-day window. Overall the agent is rented, not owned.

Strengths
  • Custom MCP servers can be added from the Tools menu
  • Reusable skills and custom Super Agents
  • Explicit 'Place Call' confirmation for Call For Me
  • Self-serve deletion; account data removed within 30 days
  • Policy states no sale of data or targeted advertising
Gaps
  • No documented bulk or agent export; portable copy only on request
  • Closed, cloud-only runtime and model routing
  • System instructions not disclosed; no complete action record
  • No local or open-weight model option for the Super Agent
  • Prompts and outputs used to improve services, with no documented opt-in
Evidence

All 34 findings

Genspark AI Workspace 6.0 (Super Agent, SecondBrain, AI Drive, Call For Me) as documented in September 2026 under the privacy policy of July 24, 2026. Free and paid individual plans.

Portable · Can you leave, and take the whole agent with you?

0%

Transparent · Can you see everything the agent is, with ordinary tools?

8%
  • T1
    Open storage format

    Agent state is stored on Genspark's Azure-hosted servers in an undocumented format, and no open-format export of that state is documented.

    Fail
  • T2
    No hidden instructions

    Genspark does not disclose the system instructions and orchestration prompts its Mixture-of-Agents layer places in model context.

    Fail
  • T3
    No shadow memory

    The privacy policy says Genspark automatically collects prompts and outputs and uses information for data analysis and service improvement, and it shares usage data with analytics vendors such as Google Analytics.

    Fail
  • T4
    Complete action history

    Conversation and task history and Call For Me transcripts are visible in the product, but no complete record of tool calls is documented as available to the owner or exportable.

    Partial
  • T5
    Readable logic

    The orchestration logic is proprietary, and the storage format of saved skills and custom agents is not documented as readable source.

    Fail
  • T6
    No third-party influence channel

    The policy states that Genspark does not sell personal data or use it for targeted advertising. It does not say whether partners or merchants can influence agent context or rankings.

    Unverified

Auditable · Can you reconstruct exactly what the agent did?

0%

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The Super Agent runtime is proprietary. Genspark's open-source GenOffice project (Apache-2.0) is a separate office suite, not the agent runtime.

    Fail
  • V2
    Active config is inspectable config

    Model routing and agent configuration are chosen automatically server-side and are not visible to the owner.

    Fail
  • V3
    Attributable messages

    Outbound actions (email, calls, integrations) go through Genspark-held accounts and tokens; recipients have no way to verify they came from this agent under the owner's authority.

    Fail
  • V4
    Independently checkable record

    No action record with checkable integrity exists, so nothing can be verified with open tools.

    Fail
  • V5
    Comparable state

    State is held server-side and not exposed, so the owner cannot verify whether it changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

33%

Controllable · Is your word final?

25%
  • C1
    Communication boundaries

    Integrations require explicit authorization and can be disconnected, but owners have no documented way to decide which recipients or channels the agent may use, enforced outside the model.

    Unverified
  • C2
    Approval gates

    Call For Me requires the owner to press 'Place Call', and scheduled calls can be cancelled. Owner-configurable approval gates for other Super Agent actions are not documented.

    Partial
  • C3
    Immediate halt

    Scheduled calls can be cancelled beforehand. The desk review found no documentation of an immediate halt for running Super Agent tasks.

    Unverified
  • C4
    Data sovereignty

    Prompts and outputs are collected automatically and used to evaluate and improve the service, and usage data goes to analytics vendors. The policy documents no opt-in for use in model improvement, though it excludes Google Workspace data from model training.

    Fail
  • C5
    Credential custody

    Integrations need explicit OAuth authorization and can be disconnected at any time. Tokens are held by Genspark and cannot be inspected or exported by the owner.

    Partial
  • C6
    Full deletion

    Self-serve 'Delete User' permanently removes history, content, settings and files, and the policy commits to deleting account data within 30 days. Other personal data may be kept for undefined 'legitimate business purposes'.

    Partial
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding