opencompany

Legal

Privacy policy

Last updated September 17, 2026

This policy explains how opencompany collects, uses, shares, retains, and protects personal information when you use our websites, hosted product, and integrations, including our Slack apps. It also explains the choices available to you.

Information we collect

We collect the following categories of information:

  • Account and workspace information: names, email addresses, authentication identifiers, workspace membership, roles, and settings.
  • Content you provide: prompts, conversations, files, code, tasks, workflows, wiki content, approvals, agent outputs, and support communications.
  • Connected-service information: OAuth credentials, account and workspace identifiers, permission grants, and data retrieved or changed when you ask opencompany to use a connected service.
  • Usage and technical information: feature activity, browser and device information, IP address, diagnostics, error reports, security events, and service logs.
  • Billing information: subscription, invoice, and transaction records. Payment-card details are handled by our payment provider rather than stored directly by opencompany.

Slack data

When you connect your personal Slack account, we receive your Slack user and workspace identifiers, profile details made available during authorization, the scopes you granted, and an OAuth credential. When an agent uses Slack for your request, Slack may return messages, channels, threads, canvases, files, reactions, profiles, membership information, and related metadata that your Slack account is allowed to access.

Slack applies your existing visibility and permissions. Connecting one person’s account does not grant another person access to their private conversations. The personal integration uses Slack’s hosted MCP server, and the OAuth credential remains encrypted and server-side.

The separately administered workspace bot receives direct messages sent to the bot, replies in threads where it participates, delivery metadata, user and workspace identifiers, and the public-channel information needed to post and reconcile messages. It does not join channels on its own.

We do not use Slack data to train AI models. We do not continuously copy Slack into a separate message archive. Slack content selected for an agent request may be saved in the resulting opencompany conversation, task, workflow output, or artifact so that you can review and continue the work.

How we use information

  • Provide, operate, personalize, and improve opencompany.
  • Authenticate users and connect requested third-party services.
  • Run agent requests, tasks, workflows, approvals, and connected-service actions.
  • Maintain service reliability, prevent abuse, investigate errors, and protect security.
  • Process subscriptions and communicate about service, support, and policy updates.
  • Comply with legal obligations and enforce our agreements.

AI processing

To run an agent request, opencompany sends the prompt and the selected context needed for that request to the model or agent provider configured for the session. That context may include content retrieved from Slack or another connected service. The provider processes it to generate the requested result or tool decision.

AI outputs can be inaccurate or incomplete. opencompany provides permission controls for connected tools, and sensitive reads or write actions may require approval based on your settings.

How we share information

We share information only as needed for the following purposes:

  • With infrastructure, authentication, model, payment, analytics, monitoring, and support providers that help us operate opencompany.
  • With connected services when you ask opencompany to retrieve data or take an action.
  • With other members of your opencompany workspace according to your workspace and content settings.
  • When required by law, to protect rights and safety, or in connection with a merger, financing, acquisition, or sale of assets.

We do not sell personal information.

How long we keep information

  • Account, workspace, and saved product content is kept while the relevant account or workspace is active, unless you delete it sooner or request deletion.
  • A Slack or other connected-service OAuth credential is kept for the life of that connection. Disconnecting the personal integration removes its stored integration record and credential from the active service.
  • Connected-service data saved in a conversation, task, workflow output, wiki page, or artifact is kept for the life of that content or workspace.
  • Temporary request data and caches are kept only as long as needed to complete and reliably deliver the request.
  • Billing, security, fraud-prevention, support, and legal records are kept as long as reasonably necessary for those purposes or as required by law. Deleted data may remain for a limited period in restricted backups until normal rotation completes.

Your choices and rights

You can manage connected services and their permission modes from opencompany. You can also revoke opencompany from Slack’s app management settings. Workspace admins control workspace membership and workspace-level integrations.

You may request access to, correction of, export of, or deletion of your personal information by emailing support@opencompany.cloud. You may also object to or ask us to restrict certain processing where applicable. We may need to verify your identity and authority over the relevant account or workspace before completing a request.

Security and international processing

We use administrative, technical, and organizational measures designed to protect information, including access controls and encryption for stored integration credentials. No method of storage or transmission is completely secure.

opencompany and its service providers may process information in countries other than the one where you live. Where required, we use appropriate safeguards for these transfers.

Children

opencompany is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this policy as the product or legal requirements change. We will update the date above and provide additional notice when a change materially affects your rights or how we use personal information.

Contact us

Contact us at support@opencompany.cloud with privacy questions or data requests. You can also visit our support page.