1. Introduction
Cloudgeni AS (Org. number 934642791, Norway) ("we," "our," or "us") provides Opengeni and respects your privacy. This privacy policy explains how we collect, use, and safeguard your information when you use our website at opengeni.ai and our hosted AI agent platform at app.opengeni.ai, where agents carry out tasks for you in sandboxes and in the services you connect (together, the "Service"). We are the controller of the personal data described in this policy. When an organization uses Opengeni, we process the personal data it puts into its workspaces on its behalf, and the organization can request a data processing agreement at support@opengeni.ai.
The Service is intended for people aged 18 or over. Opengeni is also open-source software. If you use an Opengeni deployment that we do not operate, the organization that runs it decides how your data is handled, and this policy does not apply to it. Your use of the Service is also governed by our Terms of Service.
2. Information We Collect
2.1 Personal Information
- Name, email address, and the organization name you give when you set up Opengeni
- Account credentials and authentication data: a hashed password, or your basic profile (name, email, picture, account ID) if you sign in with Google or GitHub
- Your organizations, workspaces, roles, and the invitations you send or receive
- Payment and billing information. Stripe collects your payment details, and we store your Stripe customer ID, purchase history, and credit balance. We never receive full card numbers.
2.2 Your Content
- Prompts, messages, instructions, and files you upload
- Everything agents produce or use while working for you: responses, tool calls and results, commands and their output, and generated files, documents, images, and sites
- Knowledge, skills, scheduled tasks, secrets, and variables you add
- Voice recordings, if you use voice input
- Data from services you connect, such as GitHub, Slack, Google, Microsoft 365, or MCP servers, which agents read or change within the access you grant. We store the access tokens for these services encrypted.
- Web pages, screenshots, and browser activity when an agent operates a browser for you, including through the Opengeni Browser extension, and website logins you save for agents to use
2.3 Technical Information
- IP address and browser user agent of each signed-in session
- Service logs, error reports, and audit records of important actions
- Usage records, such as which models were used and the credits a task consumed
- Analytics data, as described in section 10
3. How We Use Your Information
- Provide the Service: run agents, send your content to the AI model selected for the task, run sandboxes, and use the services you connect
- Create your account, sign you in, and manage your organization and workspaces
- Process payments, manage credits, and keep accounting records
- Send account emails, such as email verification, password resets, invitations, and notices when your sign-in methods change
- Keep the Service secure and reliable, and prevent abuse and fraud
- Understand how the Service is used so we can improve it
- Respond to your support requests and comply with the law
We do not sell your personal data or use your content to train AI models, and the Service shows no ads. If you accept cookies on opengeni.ai, the Reddit pixel helps us measure our ads on Reddit (see section 10). Authorized staff access your content only when needed to support you, fix problems, investigate abuse, or comply with the law.
4. Data Security and Cloud Infrastructure
We protect your data with measures including:
- Encryption in transit (TLS) and encryption at rest by our hosting providers
- Additional application-level encryption for access tokens, secrets, and variables
- Isolated sandboxes for agent work, and permission checks on workspace access
- Hosting on Microsoft Azure in the European Union (North Europe, Ireland)
When an agent runs commands or works with files, it uses a cloud sandbox at Modal (see section 6), which stores snapshots of the workspace so work can continue later. If you connect your own computer as a Connected Machine, agents run commands there with the permissions of the account that runs the Opengeni agent, and files and output from that computer are sent to the Service. If you install the Opengeni Browser extension, the open tab titles and addresses, and the content and screenshots of tabs an agent operates, are also sent to the Service.
Your content is processed on our servers and sent to model providers, so it is not end-to-end encrypted. Opengeni accounts do not currently support multi-factor authentication. No system is 100% secure. If you find a security issue, tell us at support@opengeni.ai.
5. AI and Machine Learning
Our AI agents send your content (messages, relevant history, files, tool results, and Knowledge) to the AI model selected for each task. Which company processes it depends on that model. Unless you choose a model, new work uses your workspace default, then a subscription you connected, then GPT-6 Luna while your organization has credits (including trial credits), and otherwise the free model.
- Models paid with Opengeni credits. GPT-6 Luna, GPT-6.1 Sol, and GPT-6 Astra run on Microsoft Azure OpenAI, and DeepSeek V4.1 Flash runs on DeepSeek's own API through Vercel AI Gateway. Section 6 lists where each one processes data. DeepSeek has not committed to zero data retention or to not training on your data.
- The free model. NVIDIA Nemotron 3 Super is accessed through OpenRouter's free endpoint in the United States. OpenRouter and NVIDIA log prompts and outputs and may use them for training and to improve their products. Do not send confidential information or personal data to the free model or to DeepSeek.
- Your own subscriptions. If you or your organization connect a ChatGPT (Codex) or SuperGrok subscription, or a model provider key, your content is sent to OpenAI, xAI, or that provider under the account that connected it, which may belong to another member of your organization or workspace. That provider's terms and privacy policy govern that processing. Voice dictation is transcribed through these subscriptions.
- Live voice and video. If you talk to an agent with an Opengeni voice model, your audio and the session's history are sent through Vercel AI Gateway to OpenAI or xAI. Video generation paid with Opengeni credits, if your workspace turns it on, sends your prompt and any reference images or videos through Vercel AI Gateway to ByteDance's Seedance model.
- Web search queries go to the search service of the model or subscription in use. For GPT-6 Luna this is a Microsoft search service that may process queries outside the EU. Image prompts go to the image model of the provider in use.
We do not train AI models on your content. AI output can be wrong, so review it.
7. Google User Data
Opengeni's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7.1 What We Access
- Google sign-in ("openid", "email", "profile"): your name, email address, profile picture, and Google account ID, used to create your account, sign you in, and show who you are to people in your workspaces.
- Google Drive sync ("drive.readonly"): the folders or shared drives you select, and the names, metadata, content, and revisions of supported files in them. Nothing is imported until you turn on synchronization, and we cannot change your files through this connection. Publishing an Opengeni document to Drive uses the "drive.file" scope, which covers only files Opengeni creates or you open with it.
- Google Drive for agents ("drive", "openid", "email", "profile"): if you add Drive as an integration, agents can list, read, create, update, organize, and share files in that account when you ask them to.
- Gmail ("gmail.readonly", "gmail.compose", "gmail.modify"): agents can search and read your email. Creating drafts, sending email, and changing labels each require your approval first, and there is no tool to delete email. Gmail access depends on Google's Developer Preview program.
7.2 How We Use, Store, and Share It
- We use Google user data only to provide the features you turned on: signing in, syncing and searching the Drive folders you selected, and letting agents work with your Drive and Gmail when you ask them to.
- We store OAuth tokens encrypted on our servers and never show them in your browser. Synced documents are stored in your workspace on Microsoft Azure in the EU.
- We share Google user data only with the service providers needed for those features: Microsoft Azure (hosting, and search embeddings for synced documents), Modal (sandboxes where agents work with files), and the AI model provider running the task. We also share it with the people you share your workspace with, or when required by law.
- We do not sell Google user data, use it for advertising or credit checks, or use it to develop, improve, or train generalized AI or machine learning models.
- Our staff do not read your Google user data unless you ask us to (for example in a support request), it is needed for security such as investigating abuse, or the law requires it.
You can pause Drive sync or disconnect Google Drive or Gmail in the app at any time, which stops our access, and you can also revoke access in your Google Account permissions. Synced documents and their search index stay in your workspace until you delete them. Google data that an agent used in a conversation stays in that conversation until you delete it, and is removed from service logs after 30 days. You can ask us to delete your Google user data, including stored tokens, by emailing support@opengeni.ai, and we do so within 30 days.
8. Data Retention
We retain your data only as long as necessary to provide the Service and comply with legal obligations:
- Account information and content are kept until you delete them or ask us to delete your account. Some sessions cannot be deleted while they are running or have outputs or forks, and can be archived instead.
- Voice recordings are deleted shortly after transcription. Unfinished recordings are deleted after about 24 hours.
- Service logs are kept for 30 days.
- Server-side usage analytics are kept for up to 400 days.
- Billing records are kept as long as accounting and tax laws require.
Deleted data can remain in backups and earlier storage versions for a period.
9. Legal Basis for Data Processing
We process personal data primarily to fulfill our contract with you (running the Service and your account), to comply with legal requirements (such as bookkeeping), and based on our legitimate interests in keeping the Service secure, preventing abuse, and understanding and improving how it is used. Browser analytics in the app (PostHog and Reo.dev), and Google Analytics and the Reddit pixel on our website, rely on your consent, which you can withdraw at any time without affecting processing before the withdrawal. Our website host's basic visit statistics, and the content-free usage records we keep on our servers, rely on our legitimate interest in running and improving the Service. You must give us your name and email address to create an account, and we cannot provide the Service without them. Other information is optional, although some features need it, such as payment details to buy credits. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
11. Your Rights
You have the right to:
- Access, correct, or delete your personal information
- Receive a copy of your data in a portable format
- Object to or request restriction of data processing
- Withdraw consent, for example to analytics
- Opt out of marketing communications. We do not currently send marketing emails.
- Lodge complaints with a data protection authority, such as the Norwegian Data Protection Authority (Datatilsynet) or the authority where you live
There is no self-service account deletion or data export in the app yet. To use any of these rights, email support@opengeni.ai from the address on your account.
12. International Data Transfers
We store the Opengeni app's data in the European Union, but some providers in section 6 process data in the United States or other countries. For these transfers we rely on the European Commission's adequacy decisions, including the EU-U.S. Data Privacy Framework, or on Standard Contractual Clauses. You can ask us for a copy at support@opengeni.ai. If you choose DeepSeek V4.1 Flash, your content may be sent to DeepSeek in China, which these safeguards do not cover, because the transfer is necessary to carry out your request.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If significant changes are made, we will inform you through email or via a prominent notice on our platform.
14. Contact Us
For questions about this privacy policy or to exercise your rights, contact Cloudgeni AS, Falkeveien 2A, 1476 Rasta, Norway, at support@opengeni.ai.