Version 1.0 · Last updated 2026-09-21

Privacy Policy

What OpenProse, Inc. collects when you use our websites and the hosted OpenProse runner, what we do with it, who else sees it, and how to ask us about it.

This policy explains what OpenProse, Inc. ("we," "us") collects when you use our websites and the hosted OpenProse runner (the "Service"), currently served from prose.md and openprose.ai and their subdomains, including run.prose.md, what we do with it, who else sees it, and how to ask us about it. It is written to be read. If something is unclear, email support@openprose.ai.

The short version

What we collect

Account information. When you sign in with GitHub we receive your GitHub username, numeric ID, and the email address on your GitHub account (we ask GitHub for it if your profile email is private). We create an API key for your account. When you sign in with GitHub, we store the tokens GitHub issues so the Service can act on your GitHub account as you authorized, for example to read a repository you select. You can revoke this at any time from your GitHub settings.

Your content. Programs you write or save, files you upload, contents of repositories you connect, and everything the Service produces for you: run transcripts, generated files, patches, and logs of the tools the agent used. When you select a repository, we keep a snapshot of it on our side so runs can read it; that snapshot stays until you ask us to delete it. Run transcripts are sanitized to strip credentials that look like API keys, but you should not paste secrets into the Service.

Wallet and payments. Your credit balance, holds, charges, refunds, and top-up history. Card details go directly to Stripe; we never see your full card number. Stripe receives your email and a reference to your GitHub ID.

Usage analytics. Which features you use, which models you pick, run counts and timings, and errors, tied to your account ID. Analytics events are designed not to contain program text, outputs, emails, or credentials.

Logs. Our hosting provider records request logs (timestamps, routes, status codes, IP addresses) for operations and security.

Browser storage. The web app keeps your API key and sign-in details in your browser's local storage so you stay signed in. We do not use advertising cookies. See "Cookies" below.

On our website. If you subscribe to Field Notes we store your email address and the IP address it was sent from, and send the newsletter through Loops; every issue has an unsubscribe link. We also collect page analytics (pages visited, referrer, browser and campaign details) under an anonymous visitor id.

We do not collect data from children. The Service is for people 18 and over.

How we use it

To run the Service for you: executing programs, storing your work, charging your wallet, and showing you history. To keep the Service working and safe: debugging, preventing abuse and fraud, investigating suspected violations of our Terms, and enforcing credit limits. To improve the Service: understanding which features are used and where they fail, using de-identified and aggregated data. To communicate with you about your account, billing, and material changes.

We do not use your content to train AI models today. Our Terms of Service, which incorporate the Common Paper Standard Terms, allow us to use de-identified data to improve the Service. If that changes in a way that affects you, we will update this policy and the Terms with notice.

Who else sees it

We use these providers to deliver the Service. Each one receives only what it needs for its role. Their handling of data is governed by our agreements with them and by their own policies, linked here.

Provider Role What it receives Their policy
Cloudflare Hosting, storage, execution sandboxes, request logs for the hosted runner All Service data at rest and in transit; request logs including IP addresses Cloudflare privacy
Fly.io Hosting for our website and API Request logs including IP addresses; website analytics and newsletter signups Fly.io privacy
Loops Newsletter delivery for Field Notes Email address Loops privacy
OpenAI Language models that execute your programs Program text, uploaded and repository content the program reads, tool results, and generated outputs OpenAI API data usage
Stripe Payments Email address, GitHub ID reference, payment details you enter on Stripe's pages Stripe privacy
GitHub Sign-in, repository access, publishing results to your repositories Sign-in and the permissions shown on the GitHub authorization screen; read access to a repository you select; if you publish, commits pushed by the OpenProse GitHub App to a branch it creates in that repository GitHub privacy
PostHog (US) Product analytics Account ID, GitHub username, feature and model usage, error events PostHog privacy
Exa Web search when a program uses the search tool Search queries generated during the run, which may include parts of your content Exa privacy
Firecrawl Browser automation when a program uses the browser tool Target URLs, instructions for the browser, and page content retrieved Firecrawl privacy

We may change providers. We will update this table when we do.

We do not sell your personal information and we do not share it with advertisers. We may disclose data if required by law, to protect the Service or others from harm, or as part of a merger or acquisition, in which case this policy would continue to apply until changed with notice.

Public sharing

Programs and results are private by default. If you publish a program or result, or share a run link, that content becomes visible to anyone with the link or URL. Published programs and results are attributed to your account. Shared run links expire after 24 hours. Published programs and results stay public until you unpublish them from the Service. Copies others made while content was public may persist.

How long we keep it

We keep your account data, content, and run history while your account is active. We do not currently delete run data automatically. When you ask us to delete your account we delete the data listed under "What we collect," except payment and tax records we are required to keep, and de-identified analytics that no longer identify you.

Our providers keep data under their own retention rules; see the links in the table above.

Your choices and requests

Email support@openprose.ai from the email address on your GitHub account to:

We acknowledge requests within 10 business days and complete deletion within 60 days. We verify that requests come from the account holder before acting on them. We will not discriminate against you for making a request.

You can revoke the Service's access to your GitHub account or repositories at any time from GitHub's settings. You can unpublish programs and results from the Service. You can stop using the Service at any time; see the Terms of Service for how credits are handled.

Cookies

Our analytics provider sets a first-party cookie on our domains to remember your anonymous visitor id across our sites, and may derive an approximate location from your IP address. The web app uses local storage to keep you signed in, plus a short-lived cookie during GitHub sign-in to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies, so there is no cookie banner.

If you are outside the United States

The Service is offered to users in the United States, is priced in US dollars, and is provided in English. We do not direct the Service at users in the European Union, the United Kingdom, or other regions. Our providers are US companies. If you use the Service from elsewhere, your data will be transferred to and processed in the United States. You can make any of the requests above by emailing support@openprose.ai.

Security

Data is encrypted in transit and encrypted at rest by our hosting provider. Model, search, and browser provider credentials are held by us, never by you, and are isolated from the parts of the Service that store your content. Access to production data is limited to the OpenProse team members who operate the Service. No system is perfectly secure; if we learn of a breach affecting your data we will tell you as required by law.

Changes

We may update this policy. Material changes will be announced in the Service or by email at least 30 days before they take effect.

Contact

OpenProse, Inc. 56 Broad St STE 27926, Boston, MA 02109, United States support@openprose.ai


Structure adapted from the 37signals open-source policies, CC BY 4.0.