Legal
Privacy Policy
Last updated August 16, 2026
This policy describes how OpenDoor collects and uses data when you use the dashboard, API, playground, or public assistant pages.
What we collect
- Account data: name, email, organization, role, and authentication records (including SSO identifiers when you use SSO).
- Billing data: plan, Stripe customer and subscription IDs, credit ledger, and invoices. Card numbers are handled by Stripe, not stored by us.
- Usage telemetry: model id, token counts, latency, cost, status codes, API key prefix, and timestamps for each gateway request.
- Optional content: prompts and completions may be stored when you use the playground, assistants, workflows, or when your org enables request logs for audit.
- Product analytics: page views and feature events via PostHog, using a project key configured for this product.
- Device inventory (optional, consent only): whether this machine has Metal or a GPU, usable memory, Ollama status, and local model tags. We do not read this until you allow it. Lawful basis is consent (GDPR Art. 6(1)(a)). You can withdraw in Models or Devices. We do not sell this data.
How we use it
We use this data to authenticate you, route and bill requests, enforce policies and spend limits, show usage in the dashboard, and keep the platform reliable. We do not sell personal data. Prompts forwarded to a model provider are processed under that provider’s terms.
Retention
Account and billing records are kept while the organization is active and as required for tax and fraud prevention. Request logs follow your org retention settings. You can revoke API keys and delete assistants from the dashboard; ask us to close an organization at hello@opendoor.ai. You can withdraw device-inventory consent at any time from Models or Devices; we then stop reading this machine.
Sharing
We share data with infrastructure processors (database, object storage, email, payments, analytics) and with the model providers you call. We disclose data if required by law.