Privacy Policy
Last updated: August 13, 2026
1. Information we collect
OpenBot collects the following information when you use our platform:
- Account information: Name, email address, and profile picture supplied by Google or, when enabled, GitHub during sign-in.
- Usage metadata: Console actions, API request metadata, metered events, and related service records.
- Submitted data: Content you explicitly send through an available platform API or support channel. The local openbot-data toolkit does not require an account or upload your dataset.
- Technical data: IP address, browser type, device information, and log data for security and debugging purposes.
2. How we use your information
We use your information to:
- Provide, maintain, and improve the OpenBot platform.
- Process API requests and support requests you explicitly make.
- Communicate with you about service updates, security alerts, and support matters.
- Analyze usage patterns to improve our services.
- Comply with legal obligations and protect against fraud.
3. Data storage and security
Managed-service data is stored on service infrastructure and protected with access controls and encrypted transport. Access is limited to operating, securing, and supporting the requested service.
OpenBot does not require dataset upload for local inspection. The openbot-data toolkit runs on your machine under its repository license.
4. Data sharing
We do not sell your data. We may share your information only in the following circumstances:
- Service providers: With infrastructure providers necessary to operate the platform.
- Legal requirements: When required by law, court order, or government authority.
- Business transfers: In connection with a merger, acquisition, or sale of assets.
5. Cookies and tracking
OpenBot uses essential storage for authentication, session management, theme preferences, security, and your analytics choice. Essential storage is not optional because the relevant features cannot operate safely without it.
On public pages, OpenBot uses Cloudflare's request-region signal to decide whether analytics requires prior opt-in. Visitors in the EEA, United Kingdom, and Switzerland are asked before Google Tag Manager loads. If the region is unknown, OpenBot also asks first. In other regions, public-page analytics may be enabled by default where regional rules permit. A Global Privacy Control signal keeps analytics disabled.
Google Tag Manager may process public page and CTA event data under Google's service terms. OpenBot does not intentionally send email addresses, private dataset paths, signed URLs, API payloads, or customer content in these events. Choosing Essential onlykeeps the third-party analytics script unloaded. An active choice overrides the regional default. You can change that choice at any time.
6. Data retention
Account and service records are retained while needed to operate the account, meet security or legal obligations, and resolve requests. You may request deletion of your account and associated data through the contact form. Residual copies may remain for a limited period in backups, security logs, or records we are legally required to retain.
Contact-form submissions carry a two-year retention deadline unless a shorter deletion request or a legal obligation applies. Newsletter addresses are retained while subscribed; after unsubscribe through a signed, expiring link they receive a 30-day deletion deadline. The link carries only a hashed subscriber identity, not the email address. Cleanup is processed in bounded batches, so final removal may not be instantaneous.
During the one-time move from historical cache storage, OpenBot keeps a minimal deletion marker so an older cache object cannot recreate a deleted contact or an unsubscribed address. Newsletter markers contain a hash rather than the address. Source objects are eligible for exact-key deletion only after historical writers are frozen, two consecutive complete inventories agree, and a minimum 30-day hold has elapsed. Version, ETag, and size are checked again before deletion; a change stops cleanup and requires a new review. After that source is deleted and permanently retired, its deletion markers are kept for one additional 30-day safety window and then removed in bounded batches.
7. Your rights
You have the right to:
- Access your personal data.
- Correct inaccurate data.
- Request deletion of your data.
- Opt out of non-essential communications.
- Export your data.
To exercise these rights, use the contact form.
8. Children's privacy
OpenBot is not intended for users under 16 years of age. We do not knowingly collect information from children. If we become aware of such collection, we will delete it promptly.
9. International data transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this policy and applicable law.
10. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes by email or prominent notice on our platform. Your continued use after changes constitutes acceptance.
11. Contact
For questions about this privacy policy or our data practices, contact:
