Privacy Policy
Operater is an agentic operating system. You connect your tools, and autonomous agents act inside them on your behalf. That means we handle two quite different things: the small amount of data we need to run an account, and the far more sensitive workspace data your agents touch in order to do work. This policy separates them, because the commitments we make about each are different.
1 · What we collect
We collect only what the Service needs to function.
- Account data. Your name, work email, company name, and authentication credentials. Passwords are stored as salted hashes; we never see them in plain text.
- Connection credentials. The OAuth tokens that let agents act in the tools you connect, such as Gmail, Slack, HubSpot or Notion. These are encrypted at rest with per-workspace keys.
- Workspace data. The messages, documents, records and files your agents read or write in order to complete a task. The scope is set by the permissions you grant, and by nothing else.
- Execution data. A log of what each agent did: the task, the tools it called, the actions it took, the result, and the credits consumed.
- Billing data. Plan, usage and invoices. Card details go directly to our payment processor; we never receive or store full card numbers.
- Technical data. IP address, browser and device type, and error diagnostics, collected automatically when you use the Service.
2 · How we use it
- To run the Service: authenticate you, execute agent tasks, and show you what happened.
- To meter usage and bill you accurately.
- To keep the Service secure, detecting abuse, fraud and unauthorised access.
- To support you when you ask for help, which may involve looking at specific execution logs with your permission.
- To send service messages. Product and marketing email is opt-in and unsubscribable in one click.
- To comply with legal obligations.
We do not train models on your workspace data. We do not use it to improve any model, our own or a third party's, and we do not permit our model providers to train on it. Aggregated, fully de-identified statistics about how the product is used, such as task volumes, latency and error rates, may inform product decisions.
3 · Who we share it with
We do not sell personal information, and we never have. We share it in four circumstances only.
- Infrastructure providers who host and run the Service, under contract and confidentiality obligations.
- AI model providers that process the content of a task in order to execute it. Their retention is contractually limited and training on your data is contractually prohibited.
- Tools you connect, to the exact extent your agents need in order to act in them. You choose these, and you can disconnect any of them at any time.
- Authorities, where we are legally compelled. Where we are permitted to tell you, we will.
If Operater is ever acquired or merged, your data may transfer as part of that transaction. You will be told before it happens, and this policy continues to apply until you are given notice of a replacement.
4 · Agent autonomy and your control
Agents act without asking you first. That is the point of the product, so the controls that bound them matter more than usual.
- Every agent runs with the narrowest set of permissions that lets it do its job. You nominate the channels; it cannot reach beyond them.
- Every read and write is logged and attributable to a specific agent and task. You can audit any action an agent has ever taken.
- You can revoke any connection in one click. Agents that depend on it stop within seconds, and the work they already produced remains yours.
- You decide which actions require your approval before they execute.
5 · Retention
- Workspace data and agent memory are kept while your account is active.
- Execution logs are kept for 12 months, which is what makes auditing an agent's past behaviour possible.
- After you close your account, we delete your data within 30 days, except where law requires us to keep records, invoices being the obvious example.
- You can request earlier deletion at any time.
6 · Security
Data is encrypted in transit with TLS and at rest. Connection credentials are additionally encrypted with per-workspace keys. Access to production systems is restricted, logged, and requires multi-factor authentication. No system is perfectly secure, and we will not claim otherwise. But if a breach affects your data, we will tell you promptly and tell you what we know.
7 · Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal information, to object to certain processing, and to withdraw consent. Exercise any of them by writing to [email protected]. We respond within 30 days and we do not charge for it. If you are unhappy with our response you may complain to your local data protection authority.
- EU/UK (GDPR). Access, rectification, erasure, restriction, portability, objection.
- Saudi Arabia (PDPL). Access, correction, destruction, and the right to be informed.
- Turkey (KVKK). The rights set out in Article 11, including learning whether your data is processed and requesting its deletion.
8 · International transfers
We are a MENA-first company with customers and infrastructure in several countries, so your data may be processed outside the country you are in. Where the law requires a transfer safeguard, such as standard contractual clauses, we put one in place.
9 · Children
Operater is a business product and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us data, write to [email protected] and we will delete it.
10 · Changes
We may update this policy. The date at the top always reflects the current version. If a change materially affects your rights, we will give you notice by email or in the product before it takes effect.
11 · Contact
Privacy questions, requests and complaints: [email protected]. Anything else: [email protected].
Also read: Terms of Service