Privacy Policy
Last updated: June 24, 2026
OSAgent (“OSAgent,” “we,” “us”) is a workspace-intelligence platform operated by OptimagineAI. It observes the work signals you explicitly connect — messages, pull requests, documents, and meetings — and turns them into a traceable, citation-backed memory of your team’s decisions, ownership, risks, and progress. This policy explains exactly what we access, why, how we protect it, and how you can delete it at any time.
Our governing principle is minimum necessary data: we request the least access required to build useful memory, and we never collect personal content we don’t need.
1. Information we collect
Account information. When you or your administrator create a workspace, we store your name, email address, and a securely hashed password.
Data from sources you connect. You (or a workspace administrator) explicitly authorize each integration. We only ingest data from sources you connect, and only the data types listed below:
- Google. Your Google account identity (email and name, via OpenID Connect) and read-only Google Calendar event metadata (event title, time, organizer, and attendees) for meetings your workspace is invited to, via the calendar.events.readonly scope.
- Slack. Messages in channels the OSAgent bot is explicitly added to, plus channel and author identity (Slack user id and profile email) for ownership mapping.
- GitHub. Pull requests, reviews, CI/workflow runs, deployments, releases, and repository metadata for the repositories you install the app on.
- Documents you upload and URLs you paste, when you choose to add them as knowledge.
2. What we explicitly do NOT access
We deliberately do not request invasive scopes. Specifically, OSAgent does not:
- access Google Drive or any of your files;
- read your Gmail, inbox, or email content;
- write to, modify, or create events on your calendar;
- read Slack direct messages or private channels the bot isn’t added to;
- obtain any write access to GitHub (no comments, no status changes).
3. Google API Limited Use disclosure
OSAgent’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use Google Calendar data only to provide and improve OSAgent’s user-facing features; we do not sell it; we do not use it for advertising; and we do not use it to train generalized/AI models or transfer it to others for those purposes. Human access to this data occurs only where required for security, to comply with law, or with your explicit consent.
4. How we use your information
- To build your workspace’s memory and intelligence — decisions, risks, ownership, dependencies, and status — where every derived fact is traceable back to its source.
- To answer your questions about your own workspace (“Ask PM”) and produce briefings.
- To operate, secure, debug, and improve the service.
We never sell your data, never use it for advertising, and never use your content to train generative AI models.
5. How your data is stored and secured
Data is stored in an access-controlled PostgreSQL database. Integration tokens and secrets are encrypted at rest. Data is partitioned per workspace and every query is scoped to your workspace. We process content through an LLM provider under a no-retention agreement when generating intelligence.
6. Data retention and deletion
We retain your data only while your workspace is active. You can disconnect any integration at any time (which stops further ingestion and revokes the stored token) and delete the dataa connector brought in — OSAgent provides a per-connector deletion that removes that source’s raw events and the memory derived from them. You may also request full deletion of your workspace by contacting us.
You can additionally revoke OSAgent’s access to your Google account at any time from your Google Account permissions.
7. Sharing and sub-processors
We do not sell or rent your data. We share data only with infrastructure sub-processors that help us run the service (e.g. cloud hosting and a no-retention LLM provider), and only as needed to operate OSAgent, or where required by law.
8. Your rights
You may request access to, correction of, or deletion of your personal data. To exercise these rights, contact us at the address below.
9. Contact
Questions about this policy or your data? Email getosagent@gmail.com.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.