Who this covers#
This policy explains how Operon (“Operon”, “we”, “us”) handles personal information when you visit our website or use the hosted Operon service (the “Service”).
When you use the Service to process information about other people, for example contacts in a CRM, you decide what data the agent works with. In that case you are the controller of that data and we process it on your behalf, only to run your workflows.
The open-source core can be self-hosted. A self-hosted deployment does not send us any data, and this policy does not apply to it.
What we collect#
Information you give us
- Account details: your email address, display name and sign-in method. If you sign in with a third-party provider, we receive your basic profile from them.
- Workflows and goals: the outcomes you describe, the plans Operon produces and any settings you choose.
- App credentials: OAuth tokens and API keys you authorise so that runs can act in your connected apps.
- Support messages: anything you send us when you ask for help.
Information created when you use the Service
- Run history: each step's inputs, tool calls, a reasoning summary, outputs and timing. This is your audit trail.
- Usage counters: how many runs you start per day and how many model tokens they use, so we can apply plan limits.
- Technical logs: our hosting providers record IP addresses, browser type and request times to keep the Service secure and working.
Billing is handled by our payment processor. We do not see or store your full card number.
How we use it#
We use personal information only to:
- provide the Service, including planning and executing your workflows;
- keep accounts and runs secure, and detect abuse and rate-limit violations;
- apply plan limits, process payments and send receipts;
- send service messages such as security alerts, billing notices and changes to these terms;
- respond to support requests;
- meet our legal obligations.
Where privacy law requires a legal basis, we rely on performing our contract with you, our legitimate interest in running a secure service, and, where needed, your consent.
AI processing#
Agent steps are processed by a large language model provided by a third party (currently Google's Gemini API). For each step we send only the content that step needs, such as your goal, the plan, and relevant outputs from earlier steps.
- Credentials are never sent to the model. When a step calls one of your apps, the run engine adds the credential to the outgoing request itself. The model only sees the result.
- Secrets are redacted from logs. Run events are scanned for tokens and keys before they are stored.
- No training on your data. We do not use your workflows, run history or credentials to train or fine-tune any model.
- Approval gates. Actions you mark as sensitive, such as sending email, making payments or deleting records, wait for a person to approve them before they run.
How we protect it#
- Account isolation: every table that holds your data uses Postgres row-level security, so a query can only return rows owned by the signed-in account.
- Encrypted vault: credentials are stored in Supabase Vault, encrypted at rest, and decrypted only on the server while a step executes.
- Encryption in transit: all traffic to and from the Service uses TLS.
- Outbound request protection: outgoing HTTP calls are checked so they cannot reach private or internal network addresses.
- Limits: per-account daily quotas and per-workflow rate limits stop runaway runs.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any relevant authority as the law requires. To report a vulnerability, email support@operon.app. You can read more on our security overview.
How long we keep it#
We keep your information for as long as your account is open. Deletion is built into the database itself:
- Deleting a workflow deletes all of its runs and run events.
- Disconnecting a credential deletes the encrypted secret from the vault.
- Deleting your account deletes your profile, workflows, runs, events, credentials and usage records.
Encrypted backups held by our database provider are overwritten on their regular schedule, after which deleted data cannot be recovered. We may keep billing records for as long as tax law requires.
Your controls and rights#
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Many of these you can do yourself in the app. For anything else, email support@operon.app.
We will reply within 30 days and may need to confirm your identity first. We will not treat you differently for exercising your rights. If you are unhappy with our reply, you can complain to your local data protection authority.
International transfers#
Our service providers may process information in countries other than yours. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses to protect information transferred internationally.
Children#
The Service is not directed at children, and you must be at least 18 to create an account. If you believe a child has given us personal information, contact us and we will delete it.
Changes and contact#
We will update the version and effective date at the top of this page whenever we change it. If a change is material, we will email account holders at least 14 days before it takes effect. All changes are also recorded in our changelog.
Questions, requests or complaints: support@operon.app.