Operon
policy://privacy In effect

Privacy Policy

Operon runs work inside your apps, so it touches data you care about. This page says exactly what we keep, why, and how to make us delete it. Every section has a plain-English note next to it.
Version
1.0
Effective
4 Oct 2026
Reading time
≈ 8 min
Data sold
Never
Ask a question

The short version

Everything we store, on one screen.

Generated from our actual database schema, not written from memory. If it isn't listed here, we don't keep it.

data-manifest.json
  • Account

    Email, display name, sign-in method

    WhyTo sign you in and send service notices
    WhereSupabase Auth
    AccessYou. Our team only when you ask for support
    Kept untilYou delete your account
  • Workflows and goals

    What you asked for, the plan, step settings

    WhyTo run the work you describe
    WherePostgres, isolated per account by row-level security
    AccessOnly your account
    Kept untilYou delete the workflow
  • Run history

    Step inputs, tool calls, outputs, timings

    WhyYour audit trail, so you can trace every result
    WherePostgres, isolated per account
    AccessOnly your account
    Kept untilIts workflow is deleted
  • App credentialsencrypted

    OAuth tokens, API keys

    WhyTo act in your apps when a run needs to
    WhereSupabase Vault, encrypted at rest
    AccessThe run engine, only while a step executes. Never the model, never logs
    Kept untilYou disconnect the app
  • Usage counters

    Runs per day, model tokens used

    WhyPlan limits, rate limits and billing
    WherePostgres
    AccessYou, and us for billing
    Kept untilYou delete your account
  • Step content for the model

    Only the text that one step needs

    WhySo the agent can plan and reason
    WhereSent over TLS to our model provider for that request
    AccessModel provider, to produce a response
    Kept untilNot kept by us outside your run history
We never: Sell your data Run ads or ad trackers Use third-party analytics Train models on your data Show credentials to the model
§01

Who this covers#

This policy explains how Operon (“Operon”, “we”, “us”) handles personal information when you visit our website or use the hosted Operon service (the “Service”).

When you use the Service to process information about other people, for example contacts in a CRM, you decide what data the agent works with. In that case you are the controller of that data and we process it on your behalf, only to run your workflows.

The open-source core can be self-hosted. A self-hosted deployment does not send us any data, and this policy does not apply to it.

§02

What we collect#

Information you give us

  • Account details: your email address, display name and sign-in method. If you sign in with a third-party provider, we receive your basic profile from them.
  • Workflows and goals: the outcomes you describe, the plans Operon produces and any settings you choose.
  • App credentials: OAuth tokens and API keys you authorise so that runs can act in your connected apps.
  • Support messages: anything you send us when you ask for help.

Information created when you use the Service

  • Run history: each step's inputs, tool calls, a reasoning summary, outputs and timing. This is your audit trail.
  • Usage counters: how many runs you start per day and how many model tokens they use, so we can apply plan limits.
  • Technical logs: our hosting providers record IP addresses, browser type and request times to keep the Service secure and working.

Billing is handled by our payment processor. We do not see or store your full card number.

§03

How we use it#

We use personal information only to:

  • provide the Service, including planning and executing your workflows;
  • keep accounts and runs secure, and detect abuse and rate-limit violations;
  • apply plan limits, process payments and send receipts;
  • send service messages such as security alerts, billing notices and changes to these terms;
  • respond to support requests;
  • meet our legal obligations.

Where privacy law requires a legal basis, we rely on performing our contract with you, our legitimate interest in running a secure service, and, where needed, your consent.

§04

AI processing#

Agent steps are processed by a large language model provided by a third party (currently Google's Gemini API). For each step we send only the content that step needs, such as your goal, the plan, and relevant outputs from earlier steps.

  • Credentials are never sent to the model. When a step calls one of your apps, the run engine adds the credential to the outgoing request itself. The model only sees the result.
  • Secrets are redacted from logs. Run events are scanned for tokens and keys before they are stored.
  • No training on your data. We do not use your workflows, run history or credentials to train or fine-tune any model.
  • Approval gates. Actions you mark as sensitive, such as sending email, making payments or deleting records, wait for a person to approve them before they run.
§05

Who we share it with#

We do not sell or rent personal information, and we do not share it for advertising. We share it only with the service providers below, who process it on our instructions:

ProviderWhat they do for us
SupabaseDatabase, authentication, encrypted credential vault, run engine and live updatesAll Service data listed in the manifest
VercelHosting and delivery of the website and appTechnical request logs
Google (Gemini API)AI model that plans and reasons for agent stepsContent of individual agent steps

When a run acts in an app you connected, such as Slack or Gmail, it sends that app the data the step requires. That app's own privacy policy applies to the data once it arrives there.

We may also disclose information if the law requires it, to protect people's safety, or as part of a merger or acquisition. If a transfer of ownership happens, we will tell you in advance.

§06

How we protect it#

  • Account isolation: every table that holds your data uses Postgres row-level security, so a query can only return rows owned by the signed-in account.
  • Encrypted vault: credentials are stored in Supabase Vault, encrypted at rest, and decrypted only on the server while a step executes.
  • Encryption in transit: all traffic to and from the Service uses TLS.
  • Outbound request protection: outgoing HTTP calls are checked so they cannot reach private or internal network addresses.
  • Limits: per-account daily quotas and per-workflow rate limits stop runaway runs.

No system is perfectly secure. If a breach affects your personal information, we will notify you and any relevant authority as the law requires. To report a vulnerability, email support@operon.app. You can read more on our security overview.

§07

How long we keep it#

We keep your information for as long as your account is open. Deletion is built into the database itself:

  • Deleting a workflow deletes all of its runs and run events.
  • Disconnecting a credential deletes the encrypted secret from the vault.
  • Deleting your account deletes your profile, workflows, runs, events, credentials and usage records.

Encrypted backups held by our database provider are overwritten on their regular schedule, after which deleted data cannot be recovered. We may keep billing records for as long as tax law requires.

§08

Your controls and rights#

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Many of these you can do yourself in the app. For anything else, email support@operon.app.

We will reply within 30 days and may need to confirm your identity first. We will not treat you differently for exercising your rights. If you are unhappy with our reply, you can complain to your local data protection authority.

§09

Cookies and local storage#

We use only strictly necessary storage:

  • Session cookies that keep you signed in.
  • Local storage for interface preferences such as your colour theme.
  • Session storage to remember a goal you typed on the homepage while you create an account.

We do not use advertising, cross-site tracking or third-party analytics cookies.

§10

International transfers#

Our service providers may process information in countries other than yours. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses to protect information transferred internationally.

§11

Children#

The Service is not directed at children, and you must be at least 18 to create an account. If you believe a child has given us personal information, contact us and we will delete it.

§12

Changes and contact#

We will update the version and effective date at the top of this page whenever we change it. If a change is material, we will email account holders at least 14 days before it takes effect. All changes are also recorded in our changelog.

Questions, requests or complaints: support@operon.app.