Effective June 3, 2026
How OS x collects, uses, shares, and protects personal data.
This policy explains how OS x handles personal data when you use the Service. OS x is operated as a business tool: most data is processed on behalf of the organization (the “tenant”) whose workspace you belong to, and that organization is the controller of its workspace data.
Account and identity data: your name, email, organization membership, and role.
Workspace content: the documents, clients, invoices, contracts, bookings, files, timecards, tasks, and messages you and your organization create or upload.
Usage and technical data: log data, device/browser information, and security events needed to operate and protect the Service.
Billing data: handled by our payment processor (Stripe); we do not store full card numbers.
We use personal data to provide, secure, support, and improve the Service; to authenticate users and enforce roles; to process billing; to send transactional messages (such as invitations and notifications); and to comply with law. We do not sell personal data, and we do not use your workspace content for advertising.
When you use AI features, the relevant prompt and the workspace context needed to answer it are sent to our AI provider (Anthropic) to generate a response. Requests run as your own access-scoped session, so the AI can only retrieve data you are already permitted to see.
We do not use your workspace content to train our own models. Anthropic processes API inputs and outputs under its own terms; where your organization supplies its own Anthropic API key, those requests are governed by your organization’s agreement with Anthropic. See Anthropic’s Usage Policy and Privacy Policy, linked from our Subprocessors page.
The Service is multi-tenant. Every workspace record carries an organization identifier and is protected by database-level row-level security, so one organization’s users cannot read or write another organization’s data. This isolation is enforced at the database layer, not merely in application code.
We use a small set of vendors to operate the Service (hosting, database/storage, email, payments, SMS, video, AI). Each is bound by contract to appropriate confidentiality and security obligations. The current list is on our Subprocessors page.
We retain workspace data for as long as your organization’s account is active or as needed to provide the Service. Many user-deleted items are soft-deleted and recoverable for 24 hours before they are purged. On account closure, data is deleted or de-identified after a reasonable wind-down period, except where retention is required by law.
Depending on your location, you may have rights to access, correct, delete, export, or restrict the processing of your personal data. Because most data is controlled by your organization, please direct requests to your organization’s administrator; we will assist them as the processor. You can also update your profile in the Service.
We use only strictly necessary cookies for authentication and session management, plus minimal local-storage preferences. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for details.
Our subprocessors may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
The Service is a workplace tool and is not directed to children under 18. We do not knowingly collect personal data from children.
We may update this policy and will communicate material changes through the Service or by email. For privacy questions, contact your OS x operator at [CONTACT EMAIL].