Privacy Policy
Last updated: August 22, 2026
Introduction
Operum ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our desktop application and website (collectively, the "Service").
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Password (encrypted)
Usage Data
We automatically collect certain information when you use the Service:
- Device information (operating system, device type, and a normalized device identifier derived from your computer's hostname — for macOS, Linux, or Windows systems we store a platform-specific label like "macOS laptop" rather than the raw hostname)
- IP address (recorded server-side when your device connects to our authentication and database services)
- Local IP address (recorded by the desktop application for device session management)
- Application version and user agent string
- Feature usage statistics
- Error logs and crash reports
Session records — device identifier, operating system, application version, local IP address, and user agent — accumulate for as long as your account exists. Sessions you sign out of are marked inactive rather than deleted.
Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number. We receive only the last four digits of your card, card type, and billing address for record-keeping purposes.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments and questions
- Detect, prevent, and address technical issues
- Comply with legal obligations
Data Storage and Security
Your data is stored securely using industry-standard encryption. We use Supabase for authentication and database services, which employs enterprise-grade security measures.
The desktop application stores authentication tokens and encryption keys securely. Your Anthropic credential is stored in an AES-256-GCM encrypted file on your device, with a master encryption key stored in your operating system's native keychain (macOS Keychain or Windows Credential Manager). On Linux, the encrypted file method is used without keychain storage.
AI Processing and Data Handling
Operum orchestrates AI agents powered by third-party AI models. Here is how your data interacts with AI services:
- Local-first architecture: Your code and project files remain on your device. AI API calls are made directly from your machine to the AI provider (Anthropic) — your data does not pass through our servers.
- Your Anthropic credential: You authorise Operum with a token you generate yourself by running Anthropic's own
claude setup-tokencommand, then paste into the app. It is stored on your device in an encrypted file and passed only to the agent processes running on your machine — it is never sent to our servers. We never see your Anthropic password and never sign in on your behalf. Note: Trial, Standard, and Premium tier users may use Operum-provided Anthropic access instead of their own credential during their subscription period. - AI-generated outputs: Code, text, and other outputs generated by AI agents are created locally on your device. We do not collect, store, or have access to AI-generated content.
- Agent activity logs: The desktop application stores agent activity logs locally on your device. These logs are never transmitted to our servers.
- Agent instruction files: If you customize your agent instruction files (system prompts), those customizations are uploaded to our servers to enable team collaboration features. These files may contain your custom workflows and preferences.
- No training on your data: We do not use your code, prompts, or AI outputs to train any models. Refer to Anthropic's data usage policy for how the AI provider handles API requests.
Third-Party Services
We use the following third-party services:
- Supabase - Authentication and database
- Stripe - Payment processing
- Anthropic - AI model provider (API calls made directly from your device)
- GitHub - Code repository integration (with your explicit authorization)
- Sentry - Error and crash reporting. Reports are keyed to an opaque account identifier and do not include your email address.
- PostHog - Product analytics. Usage events are keyed to an opaque account identifier, not to your name or email address. Note: PostHog may capture IP addresses and geolocation data as part of standard analytics processing.
- Google Analytics (GA4) - Website analytics on our landing pages
- Vercel - Website hosting and analytics
- Resend - Transactional email delivery
Each third-party service has its own privacy policy. We encourage you to review them. We share only the minimum data necessary with each service to provide the functionality described above.
Analytics Consent: When you visit our website, you can choose whether to allow non-essential analytics cookies. Currently, this consent mechanism controls PostHog analytics only. Google Analytics (GA4) and Vercel Analytics operate independently of this consent mechanism. We are working to bring all analytics under unified consent control.
Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data
- Opt out of marketing communications
To exercise these rights, contact us at privacy@operum.ai.
Data Retention and Deletion
User-Requested Account Deletion
You may permanently delete your account at any time — from Settings → Danger Zone in the desktop app, or from your account page on the web. Two paths are available on both surfaces:
- Delete with a recovery window: starts a 7 calendar-day recovery window during which you can sign back in and choose Cancel deletion to revert. At the end of the 7-day period, your account and all associated data are permanently deleted.
- Delete immediately: permanently destroys your account and all associated data right away with no recovery window.
Either path permanently deletes all data associated with your account, except where we are required to retain specific records for legal purposes. This includes your profile, teams, projects, agent configurations, chat history, and schedules.
Important note about Operum-provisioned (Quick Start) repositories: If you use Quick Start and Operum provisions a GitHub repository for your team, that repository is created in Operum's GitHub organization and you do not have direct GitHub access to it by design. When you delete your account, your Operum project data is removed, but the provisioned repository itself is not automatically deleted from GitHub. If you wish to preserve your repository contents, you must export or transfer the repository before deleting your account — see how to export your Quick Start repository. If you connect your own GitHub repository instead of using Quick Start, that repository remains in your GitHub account and Operum cannot and does not delete it.
Exporting or transferring any data you wish to keep before deletion is your responsibility. Only you, signed in to your own account, can export or transfer your data; no other Operum user can read, export, or transfer it. Operum is not liable for data — including provisioned repositories — lost as a result of your own decision to delete your account. Once deletion completes, the data cannot be recovered.
User-Initiated Team Deletion
You can delete a team at any time from Settings → Danger Zone ("Move Team to Trash"). The team then moves to Trash, where it is hidden from your normal team list but its data is preserved for 7 calendar days so you can change your mind.
Within the 7-day Trash window you can:
- Restore the team — it becomes fully accessible again, exactly as it was before deletion.
- Delete Permanently — the team is removed from your account immediately with no further recovery period.
On day 7, any team still in Trash is removed automatically.
Subscription Status and Data Access
Operum does not automatically delete your data based on subscription status. If your subscription enters a past-due state or you cancel your subscription, your data is preserved. Here is what happens:
- Payment failure (past_due): Your account may be suspended for writes — you can still log in and export your data, but cannot run agents or make changes. Your data remains intact. Restoring your subscription at any time fully unlocks your account.
- Voluntary cancellation: You retain full access until the end of your current paid period, then your account continues with reduced features on the Free tier. Your data remains intact.
- Downgrades: Moving to a lower-tier plan has no effect on your existing data. Teams and projects are not archived or deleted due to tier limits.
Only you can delete your data, through the account deletion or team deletion mechanisms described above.
Account Suspension for Security or Policy Violations
If we identify a security concern or policy violation, we may suspend your account. Account suspension restricts access to your account but does not delete your data. Suspended accounts retain their data so that legitimate issues can be resolved and access restored. If you believe your account was suspended in error, contact us at support@operum.ai.
Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, or want to make a data access or deletion request, use the form below.
Prefer email? You can also reach us directly at privacy@operum.ai.