Privacy Policy
Effective Date: May 25, 2026
This Privacy Policy describes how AI OS Orchestration Lab ("we", "us", "our") collects, uses, and protects your information when you use the AI OS platform ("Service"). We are committed to protecting your privacy and being transparent about our data practices.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address — used for account identification, login, and essential communications.
- Payment information — processed and stored exclusively by Stripe. We receive only a customer ID, subscription status, and plan type. We never see or store your credit card number.
1.2 Usage Data
We automatically collect:
- Server access logs — IP address, request timestamp, URL path, HTTP method, response status, and user agent, kept for security and debugging purposes. On self-hosted instances these logs live on your own server and their retention is under your control; on the Managed Service the operator manages retention.
- Feature usage — which agents you run, skill executions, and general usage patterns. This is used to improve the Service and is not shared with third parties.
1.3 Information We Do NOT Collect (Self-Hosted Deployments)
The following statements apply to self-hosted deployments only. They do not apply to the Managed Website Service, where the operator necessarily stores and processes hosted client data — see Section 11.
- For self-hosted deployments, we do not read, store, or log the content of your API calls to third-party providers (Anthropic, OpenAI, Google, DeepSeek, xAI, Perplexity, etc.).
- We do not access the contents of your knowledge vault, agent outputs, or generated artifacts on your self-hosted instance.
- We do not store your third-party API keys. They are held in your server's environment variables and are never transmitted to us.
- We do not use cookies for advertising or cross-site ad targeting. (Our public marketing website uses Google Analytics for aggregate usage measurement — see the Cookies section below.)
2. How We Use Your Information
- Account management — authenticating your login, managing your subscription, processing payments through Stripe.
- Service delivery — routing requests, maintaining session state, providing dashboard access.
- Security — detecting unauthorized access, rate limiting, abuse prevention.
- Communication — subscription confirmations, billing receipts, service announcements, and security alerts. We do not send marketing emails without your explicit opt-in consent.
- Service improvement — understanding aggregate usage patterns to prioritize features and fix issues.
3. Cookies
The dashboard application uses a single essential cookie:
- ai-os-session — An HTTP-only session cookie that authenticates your login. It contains a random token (not your email or personal data), expires after 30 days, and is required for dashboard access.
Our public marketing website (the pages outside the dashboard) additionally uses Google Analytics, which sets analytics cookies to measure aggregate, anonymized site usage. This is the only third-party cookie we use, and it does not run inside the dashboard application. (Draft note: a cookie-consent mechanism for the analytics cookie is pending counsel review.)
4. Data Sharing
We do not sell, rent, or trade your personal information. We share data only in these limited circumstances:
- Stripe — Your email and payment details are shared with Stripe to process subscriptions. Stripe's privacy policy governs their handling of this data.
- Legal requirements — We may disclose information if required by law, court order, or governmental regulation.
- Business transfer — In the event of a merger, acquisition, or sale of assets, your information may be transferred. You will be notified via email before your data is subject to a different privacy policy.
- Managed Website Service sub-processors — If you are a Managed Service client, we additionally rely on the VPS host and the AI providers as sub-processors. See Section 11.
5. Data Storage & Security
- For self-hosted deployments, your data lives on your own server instance, not ours. We hold only the minimal account records needed to manage licenses and billing (such as your email and subscription status), plus — for Managed Service clients — the hosted site and its data on the operator VPS.
- At rest: the application does not encrypt stored data. Protecting data at rest (full-disk/volume encryption and filesystem permissions) is the responsibility of the server operator — you, when self-hosting; us, for the Managed Service.
- In transit: all connections use TLS (HTTPS) encryption.
- API endpoints are protected by authentication, rate limiting, and input validation. Session tokens are cryptographically random and stored server-side.
- Application activity logs are stored on the server instance and their retention is managed by the server operator; the application does not run an automatic purge job.
While we implement industry-standard security measures, no method of electronic storage is 100% secure. We cannot guarantee absolute security.
6. Your Rights
You have the right to:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate data.
- Deletion — For self-hosted deployments, you control your data directly on your own instance and can delete it at any time. For the account and billing records we hold (such as your email and Stripe billing history), and for Managed Service data on our VPS, you may request deletion and we will act on it within a reasonable period, except where retention is required by law.
- Export — For self-hosted deployments, your data resides on your own server and is directly accessible to you as files; the platform additionally provides website export (ZIP download or GitHub push) via Web Studio. For account records we hold, you may request a copy.
- Objection — Object to processing of your data for specific purposes.
To exercise these rights, contact us at the email address below.
7. Data Retention
- Account data — retained while your account is active and for 30 days after deletion request.
- Application activity logs — stored on the server instance; retention is managed by the server operator (no fixed automatic purge).
- Payment records — retained by Stripe according to their policies and applicable tax/financial regulations.
- Vault and agent data (self-hosted) — stored on your own server instance and controlled entirely by you; it is deleted when you remove it. Because this data lives on your own server, we have no access to it and cannot delete it on your behalf.
- Managed Service hosted site & data — stored on the operator's VPS; retained for a 30-day grace period after cancellation/termination, then may be permanently deleted. See the Terms of Service, Section 15.4.
8. International Users
The Service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
For users in the European Economic Area (EEA) or United Kingdom, we process data under the legal basis of contract performance (providing the Service you subscribed to) and legitimate interests (security, service improvement).
9. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete that information promptly.
10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.
11. Managed Website Service — Data
DRAFT — pending review by legal counsel; not final/binding. A formal Data Processing Agreement / GDPR Art. 28 processor addendum is required to govern this relationship.
This section applies only to clients of the optional Managed Website Service (operator-hosted, done-for-you), described in Section 15 of the Terms of Service. Under this service, we build and host your website on the operator's virtual private server (VPS), so we necessarily store and process more data than for self-hosted deployments.
11.1 Data We Store & Process on the VPS
- Your site content — the pages, media, and configuration of the website we host for you.
- Your end-users' data — any personal data your website collects from your own visitors/customers (e.g., contact form submissions), and any CRM data managed within your workspace.
- Audit data — SEO/AEO audit results and related analysis generated for your site.
11.2 Your Scoped Client Account Data
For your scoped client account on the operator's instance, we store:
- Email address — account identifier and login.
- A single-use setup token — a one-time, time-limited token (expires after 7 days) used only to set your password; it is consumed on use and not retained thereafter.
- Stripe customer ID and subscription ID — to manage your $250/month subscription.
- Managed purchase records (
managedPurchases) — which managed site(s) you have purchased. - Owned sites — the site(s) provisioned to your scoped workspace.
11.3 Controller vs. Processor
For your scoped account data (email, billing identifiers, purchase records), the operator acts as a data controller. For your end-users' / CRM data that we host and process on your behalf, the operator acts as a data processor, and you are the controller. Processing as your processor will be governed by a Data Processing Agreement (pending counsel review).
11.4 Sub-Processors
To deliver the Managed Website Service we rely on the following sub-processors:
- Stripe — payment processing for the subscription.
- The VPS host — the infrastructure provider on which your site and data are hosted.
- The AI providers — Anthropic (Claude), OpenAI (GPT), Google (Gemini), DeepSeek, xAI (Grok), and Perplexity, used to generate and optimize content.
11.5 Retention & Deletion
While your Managed Service subscription is active, we retain your hosted site and associated data to provide the service. Following cancellation or termination for non-payment, the hosted site is taken offline and the site and its data are retained for a 30-day grace period during which you may request an export, after which they may be permanently deleted from the VPS. Billing records held by Stripe are retained per Stripe's policies and applicable financial regulations. (Final retention period requires counsel review.)
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to active subscribers at least 30 days before taking effect. The "Effective Date" at the top of this page indicates when the policy was last revised.
13. Contact
For privacy-related questions, data requests, or concerns, reach us through our contact page. Enterprise license holders may also use their priority support channel.