Last updated July 2026

Your data,
your terms.

We collect only what we need, share only with your permission, and delete when you ask. No fine print tricks, no data sold.

How we handle your information

Every section below is written in plain language. No legalese, no surprises.

Information We Collect

We collect what you give us directly: account details (email, name), project data you upload or enter, chat messages sent via CopilotKit, and preferences you set.

We also collect technical data automatically: IP address, browser type, device identifiers, pages visited, and feature usage patterns. This helps us improve the product and prevent abuse.

How We Use Your Data

  • Provide, maintain, and improve OpenLotus
  • Process chat messages and AI responses via CopilotKit
  • Send essential service communications
  • Detect and prevent unauthorized access or abuse
  • Analyze anonymized usage trends to improve the product

Data Sharing

We do not sell your personal data. Period.

We may share data with service providers — hosting (Vercel), AI inference (CopilotKit, OpenAI) — all bound by strict data processing agreements. We will also comply with legal obligations if required by law.

Data Retention & Deletion

We retain your data for as long as your account is active. Chat messages and project data persist until you delete them or close your account.

You can request full deletion at any time by contacting us. We will fulfill deletion requests within 30 days.

Cookies & Tracking

Essential cookies run for authentication and core service operation. With your consent, analytics cookies help us understand usage patterns so we can build a better product.

You can manage your preferences at any time via the consent banner at the bottom of the page.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your data (“right to be forgotten”)
  • Object to or restrict processing
  • Data portability
  • Withdraw consent at any time

Security first

We implement industry-standard measures including encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls, and regular security audits. No method of transmission over the internet is 100% secure, but we invest heavily in minimizing risk.

TLS 1.3AES-256SOC 2

Get in touch

Have a question about your data? Our Data Protection Officer responds within 48 hours.