Legal

OpenCloud privacy policy

Effective August 8, 2026

This policy explains how OpenCloud handles personal information for the hosted service at opencloud.ai, its related service domains, and the OpenCloud plugin and connector for ChatGPT, Codex, and Claude. It does not replace the privacy notice of an app built and operated by an OpenCloud customer.

Scope and roles

OpenCloud determines how account, support, security, and platform-operation data are used to provide the hosted service. An app owner determines what their app collects from its users and is responsible for providing any notice, consent, and controls required for that app.

When a user chooses to operate OpenCloud through ChatGPT, Codex, or Claude, the applicable client provider, including OpenAI or Anthropic, also processes the conversation and the tool inputs and outputs under its own terms and privacy policy. OpenCloud receives the MCP tool calls sent to its server; it does not receive the rest of a conversation unless the client or user includes that content in a tool call.

Information OpenCloud handles

OpenCloud may handle:

How OpenCloud uses information

OpenCloud uses information to:

OpenCloud does not sell personal information or use it for cross-context behavioral advertising.

How information is disclosed

OpenCloud may disclose information:

Service providers may process information in countries other than the user's. OpenCloud uses contractual, technical, and organizational safeguards where required for those transfers.

Retention

OpenCloud keeps account and app information while it is needed to provide the service or while the relevant account or app remains active. The retention period also depends on security, backup integrity, dispute resolution, and legal obligations.

One-time access links and provisional onboarding grants expire. Custom metric points are bounded and retained for up to 14 days. Backups, audit evidence, and security records may remain after active data changes until their operational or legal retention period ends. Backup object-lock and versioning can delay final removal from backup media.

Security

OpenCloud uses HTTPS, scoped credentials, private-app admission, per-app data boundaries, row-level security, bounded tool outputs, redaction, and separate secret-entry workflows. No system is completely secure, and OpenCloud cannot guarantee that unauthorized access or loss will never occur.

Choices and rights

Users can update supported profile fields in OpenCloud preferences and can manage app content through authorized OpenCloud interfaces. Depending on their location, users may also have rights to request access, correction, deletion, portability, restriction, or objection, and to appeal or complain to a data protection authority.

Send a request to [email protected] with Privacy request in the subject. OpenCloud may verify account control before responding. Some information may be retained when required for security, fraud prevention, legal compliance, or the rights of others.

Children

The hosted service is not directed to children under 13. Do not create an OpenCloud account for a child or submit a child's personal information unless you have lawful authority and have satisfied any consent requirements. App owners are responsible for deciding whether their own apps are appropriate for children.

Changes

OpenCloud may update this policy as the service changes. The page will show a new effective date, and OpenCloud will provide additional notice when required.

Contact

Questions and privacy requests: [email protected]

Support information: OpenCloud support