Skip to content
OpenProse

Legal

Privacy Policy

OpenProse, Inc. · Last updated

This policy explains what OpenProse, Inc. ("we," "us") collects when you use our websites and the hosted OpenProse runner (the "Service"), currently served from prose.md and openprose.ai and their subdomains, including run.prose.md, what we do with it, who else sees it, and how to ask us about it. If something is unclear, email support@openprose.ai.

The short version

What we collect

Account information. When you sign in with GitHub we receive your GitHub username, numeric ID, and the email address on your GitHub account (we ask GitHub for it if your profile email is private). We create an API key for your account. We also store the tokens GitHub issues so the Service can act on your GitHub account as you authorized, for example to read a repository you select.

Your content. Programs you write or save, files you upload, contents of repositories you connect, and everything the Service produces for you: run transcripts, generated files, patches, and logs of the tools the agent used. When you select a repository, we keep a snapshot of it so runs can read it. We try to strip things that look like API keys from run transcripts, but do not paste secrets into the Service.

Wallet and payments. Your credit balance, holds, charges, refunds, and top-up history. Card details go directly to Stripe; we never see your full card number.

Usage analytics. Which features you use, which models you pick, run counts and timings, and errors, tied to your account ID. Analytics events are designed not to contain program text, outputs, emails, or credentials.

Logs. Our hosting provider records request logs (timestamps, routes, status codes, IP addresses) for operations and security.

On our website. If you subscribe to Field Notes we store your email address and the IP address it was sent from, and send the newsletter through Loops; every issue has an unsubscribe link. We also collect page analytics (pages visited, referrer, browser and campaign details) under an anonymous visitor id.

We do not knowingly collect data from children. The Service is for people 18 and over. If you believe a child has provided us data, email support@openprose.ai.

How we use it

To run the Service for you: executing programs, storing your work, charging your wallet, and showing you history. To keep the Service working and safe: debugging, preventing abuse and fraud, investigating suspected violations of our Terms, and enforcing credit limits. To improve the Service: understanding which features are used and where they fail, using de-identified and aggregated data. To communicate with you about your account, billing, and material changes.

We do not use your content to train AI models today. Our Terms allow us to use de-identified data to improve the Service. If that changes, we will update this policy with notice.

Who else sees it

We use these providers to deliver the Service. Their handling of data is governed by our agreements with them and by their own policies, linked here.

ProviderRoleWhat it receivesTheir policy
CloudflareHosting, storage, and request logs for the hosted runnerAll Service data at rest and in transit; request logs including IP addressesCloudflare privacy
Fly.ioHosting for our website and APIRequest logs including IP addresses; website analytics and newsletter signupsFly.io privacy
LoopsNewsletter delivery for Field NotesEmail addressLoops privacy
OpenAILanguage models that execute your programsProgram text, uploaded and repository content the program reads, tool results, and generated outputsOpenAI API data usage
StripePaymentsEmail address, GitHub ID reference, payment details you enter on Stripe's pagesStripe privacy
GitHubSign-in, repository access, publishing results to your repositoriesSign-in; read access to a repository you select; if you publish, commits pushed to a branch in that repositoryGitHub privacy
PostHog (US)Product analyticsAccount ID, GitHub username, feature and model usage, error events, IP address and approximate locationPostHog privacy
ExaWeb search when a program uses the search toolSearch queries generated during the run, which may include parts of your contentExa privacy
FirecrawlBrowser automation when a program uses the browser toolTarget URLs, instructions for the browser, and page content retrievedFirecrawl privacy

We will update this table if we change providers.

We do not sell your personal information and we do not share it with advertisers. We may disclose data if required by law, to protect the Service or others from harm, or as part of a merger or acquisition, in which case this policy would continue to apply until changed with notice.

Public sharing

Programs and results are private by default. If you publish a program or result, or share a run link, that content becomes visible to anyone with the link. Published programs and results are attributed to your account. Shared run links expire after a short period. Published programs and results stay public until you unpublish them from the Service. Copies others made while content was public may persist.

How long we keep it

We keep your account data, content, and run history while your account is active. We do not currently delete run data automatically. When you ask us to delete your account, we delete the account data we hold, except records we must keep by law (such as payment and tax records) and de-identified analytics that no longer identify you.

Our providers keep data under their own retention rules; see the links in the table above.

Your choices and requests

Email support@openprose.ai from the email address on your GitHub account to:

We acknowledge requests within 10 business days and complete deletion within 60 days. We verify that requests come from the account holder before acting on them.

You can revoke the Service's access to your GitHub account or repositories at any time from GitHub's settings.

Cookies

Our analytics provider sets a first-party cookie on our domains to remember your anonymous visitor id across our sites, and may derive an approximate location from your IP address. The web app uses local storage to keep your API key and sign-in details so you stay signed in, plus a short-lived cookie during GitHub sign-in to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies, so there is no cookie banner.

If you are outside the United States

The Service is offered to users in the United States and our providers are US companies, which may process your data in the United States or wherever they operate. If you use the Service from elsewhere, you can still make any of the requests above by email.

Security

Data is encrypted in transit and encrypted at rest by our hosting provider. Provider credentials are held by us, not by you. Access to production data is limited to team members who need it. No system is perfectly secure; if we learn of a breach affecting your data we will tell you as required by law.

Changes

We may update this policy. If a change materially reduces your rights, we will give at least 30 days' notice in the Service or by email before it takes effect.

Contact

OpenProse, Inc. 56 Broad St STE 27926, Boston, MA 02109, United States support@openprose.ai


Structure adapted from the 37signals open-source policies, CC BY 4.0.