Your data,
your terms.
We collect only what we need, share only with your permission, and delete when you ask. No fine print tricks, no data sold.
How we handle your information
Every section below is written in plain language. No legalese, no surprises.
Information We Collect
We collect what you give us directly: account details (email, name), project data you upload or enter, chat messages sent via CopilotKit, and preferences you set.
We also collect technical data automatically: IP address, browser type, device identifiers, pages visited, and feature usage patterns. This helps us improve the product and prevent abuse.
How We Use Your Data
- Provide, maintain, and improve OpenLotus
- Process chat messages and AI responses via CopilotKit
- Send essential service communications
- Detect and prevent unauthorized access or abuse
- Analyze anonymized usage trends to improve the product
Data Sharing
We do not sell your personal data. Period.
We may share data with service providers — hosting (Vercel), AI inference (CopilotKit, OpenAI) — all bound by strict data processing agreements. We will also comply with legal obligations if required by law.
Data Retention & Deletion
We retain your data for as long as your account is active. Chat messages and project data persist until you delete them or close your account.
You can request full deletion at any time by contacting us. We will fulfill deletion requests within 30 days.
Cookies & Tracking
Essential cookies run for authentication and core service operation. With your consent, analytics cookies help us understand usage patterns so we can build a better product.
You can manage your preferences at any time via the consent banner at the bottom of the page.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your data (“right to be forgotten”)
- Object to or restrict processing
- Data portability
- Withdraw consent at any time
Security first
We implement industry-standard measures including encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls, and regular security audits. No method of transmission over the internet is 100% secure, but we invest heavily in minimizing risk.
Get in touch
Have a question about your data? Our Data Protection Officer responds within 48 hours.