# Privacy Policy (/privacy)



Last updated and effective: September 15, 2026

This Privacy Policy explains how Superagent Technologies, Inc. ("Superagent," "we," "us," or
"our") handles personal information in connection with OpenMetal. OpenMetal includes the website,
documentation, dashboard, application programming interfaces, software development kits, command
line interface, Agent Skill, and related support services (collectively, the "Service").

Superagent Technologies, Inc. is a Delaware corporation located at 1111B S Governors Ave, Suite
3232, Dover, DE 19904, United States. For privacy questions or requests, contact
[privacy@superagent.sh](mailto:privacy@superagent.sh).

## 1. Scope and our role [#1-scope-and-our-role]

This Policy applies when Superagent decides why and how personal information is processed, such as
account, billing, website, support, security, and Service usage information. For this information,
Superagent acts as a controller or business under applicable privacy law.

Organizations may submit code, files, environment values, command input and output, logs, webhook
content, and other data to run workloads through OpenMetal ("Customer Data"). The organization
decides what Customer Data to submit and why. When Customer Data contains personal information,
Superagent generally processes it on the organization's behalf as a processor or service provider.
The organization is responsible for its own privacy notices, permissions, and instructions. Where
required, a separate data processing agreement will govern that processing. Contact
[privacy@superagent.sh](mailto:privacy@superagent.sh) to request one.

This Policy does not apply to a third party service that you access under a separate account or
agreement, including a compute provider used with your own credentials.

## 2. Information we collect [#2-information-we-collect]

We collect the following categories of information.

### Information you provide [#information-you-provide]

* **Account and profile information.** Name, email address, profile image, authentication method,
  account preferences, and organization membership.
* **Organization information.** Organization and project names, member and invitation details,
  roles, API key names and prefixes, and account settings.
* **Billing information.** Billing contact information, purchase amounts, credit balances, payment
  status, receipts, invoice links, payment method brand and last four digits, and automatic top up
  settings. Stripe processes full payment card details. We do not store full card numbers.
* **Configuration and support information.** Provider configuration, webhook destinations,
  communications, feedback, and information you send when requesting support.
* **Customer Data.** Workload source references, resource requirements, code, files, commands,
  process input and output, environment values, secret references, endpoint details, metadata, and
  other content submitted to or generated through the Service. Secret values and provider
  credentials are treated as sensitive Customer Data.

### Information collected automatically [#information-collected-automatically]

* **Device and network information.** Internet Protocol address, browser and device type,
  operating system, language, request time, referring page, and similar connection information.
* **Service activity.** Pages and features used, authentication events, API and CLI requests,
  project and sandbox actions, process and filesystem operations, webhook delivery results, error
  details, and timestamps.
* **Operational and billing telemetry.** Resource identifiers, selected provider, routing and
  fallback decisions, resource configuration, lifecycle state, runtime, usage measurements,
  estimated and actual provider cost, customer charges, request identifiers, and audit events.
* **Cookie and local storage information.** Session, security, and preference values needed to keep
  you signed in and remember interface settings.

### Information from other sources [#information-from-other-sources]

* **Authentication providers.** If you sign in with Google or GitHub, we receive basic profile
  information authorized by you, such as your name, email address, profile image, and provider
  account identifier. We do not request access to your email, repositories, or files merely
  because you use social sign in.
* **Payment processor.** Stripe returns transaction, customer, payment status, receipt, invoice,
  and limited payment method information.
* **Compute providers.** Providers return resource status, identifiers, usage, cost, logs, errors,
  and other information needed to operate, meter, troubleshoot, and secure a workload.
* **Organization administrators.** An administrator may provide your email address to invite you
  to an organization and may manage your role and access.

## 3. How we use information [#3-how-we-use-information]

We use personal information to:

* create, authenticate, and administer accounts, organizations, projects, and permissions;
* provision, route, operate, monitor, pause, resume, and destroy compute resources;
* execute commands, transfer files, expose requested endpoints, and deliver webhooks;
* process purchases, maintain credit balances, perform automatic top ups, meter usage, calculate
  charges, issue receipts, and reconcile provider costs;
* send authentication messages, invitations, receipts, security notices, policy updates, and other
  Service communications;
* provide support and respond to requests;
* detect fraud, abuse, unauthorized access, security incidents, and violations of our Terms;
* debug, maintain, analyze, and improve the reliability and usability of the Service;
* enforce agreements, establish or defend legal claims, and comply with law; and
* create aggregated or deidentified information that cannot reasonably identify an individual.

We do not sell personal information. We do not share personal information for cross context
behavioral advertising, and we do not use Customer Data to train artificial intelligence models.
We do not make decisions about individuals that produce legal or similarly significant effects
using automated processing.

## 4. Legal bases for processing [#4-legal-bases-for-processing]

If European, United Kingdom, or similar data protection law applies, our legal bases are:

* **Contract.** We process account, configuration, workload, usage, and billing information to
  provide the Service and perform our Terms of Service.
* **Legitimate interests.** We process information to secure, support, maintain, analyze, and
  improve the Service; prevent fraud and abuse; collect amounts due; and protect our rights and
  users. We consider and balance these interests against individual rights.
* **Legal obligation.** We process information to satisfy tax, accounting, sanctions, law
  enforcement, and other legal requirements.
* **Consent.** We rely on consent where the law requires it. You may withdraw consent at any time,
  without affecting processing that occurred before withdrawal.

When we process Customer Data for an organization, the organization determines the applicable legal
basis.

## 5. How we disclose information [#5-how-we-disclose-information]

We disclose information only as needed for the purposes described above:

* **Infrastructure and platform providers.** Hosting, database, authentication, realtime,
  networking, storage, monitoring, and security vendors process information needed to operate the
  Service. The codebase currently uses Supabase for authentication, database, and realtime
  services.
* **Compute providers.** We send workload configuration and Customer Data to the provider selected
  by you or by OpenMetal routing. Supported providers may include Blaxel, Cloudflare, CodeSandbox,
  Daytona, E2B, Freestyle, Modal, Northflank, Runloop, and Vercel. The provider used for a workload
  appears in Service records. Available providers can change.
* **Payment and email providers.** Stripe processes payments. Resend delivers authentication and
  Service email.
* **Authentication providers.** Google or GitHub processes information when you choose its sign in
  option.
* **Your organization and integrations.** Organization owners, administrators, and authorized
  members can access organization information according to their role. We send event data to
  webhook destinations configured by your organization.
* **Professional advisers.** Lawyers, accountants, auditors, insurers, and similar advisers may
  receive information subject to professional or contractual duties.
* **Legal and safety recipients.** We may disclose information to comply with valid legal process,
  enforce agreements, investigate fraud or abuse, protect rights and safety, or respond to an
  emergency.
* **Business transaction recipients.** Information may be transferred as part of a financing,
  merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject
  to appropriate confidentiality protections.
* **At your direction.** We disclose information when you direct us or give consent.

Service providers may process information only for the contracted service and under applicable
confidentiality and data protection obligations.

## 6. International transfers [#6-international-transfers]

Superagent is based in the United States, and the Service uses providers that may process
information in the United States and other countries. Customer workloads may run in the provider
and region selected by you or OpenMetal routing. Data protection laws in those locations may differ
from those where you live.

Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we
use an available lawful transfer mechanism, such as an adequacy decision, approved standard
contractual clauses, or another recognized safeguard. You may request information about relevant
safeguards by emailing [privacy@superagent.sh](mailto:privacy@superagent.sh).

## 7. Retention [#7-retention]

We keep information only for as long as reasonably necessary for the purposes described in this
Policy, including to provide the Service, meet legal and accounting duties, resolve disputes,
prevent fraud, and enforce agreements.

Current product behavior includes:

* account and profile information is generally kept while the account is active;
* organization and project deletion removes active access, while durable billing, security, and
  audit records may be retained;
* completed process event output is ordinarily removed from the OpenMetal control plane after
  seven days;
* sandbox resources and data stored in them are subject to the configured lifecycle and the
  selected provider's deletion process;
* purchase, payment, credit, ledger, usage, and tax records are retained as required for accounting,
  legal compliance, dispute handling, and fraud prevention; and
* backups and provider systems may retain residual copies for a limited period according to their
  backup and deletion cycles.

Other operational records are retained according to their sensitivity, operational need, and legal
requirements. We may keep deidentified information that cannot reasonably be linked to an
individual.

To request account deletion, email [privacy@superagent.sh](mailto:privacy@superagent.sh). Deleting
an organization in the dashboard does not by itself delete your authentication account or all
records that we must retain.

## 8. Cookies and similar technologies [#8-cookies-and-similar-technologies]

OpenMetal currently uses cookies and browser storage that are necessary for authentication, session
security, and interface preferences such as theme. We do not currently use advertising cookies or
third party analytics cookies on the OpenMetal website or dashboard.

Google and GitHub may use their own cookies when you choose social sign in. Their privacy notices
govern those services. You can block or delete cookies through your browser, but blocking necessary
cookies may prevent sign in or other Service functions.

We honor legally required browser based opt out preference signals if our practices become subject
to them. Because we do not currently sell or share personal information for targeted advertising,
such a signal does not change current advertising practices.

## 9. Security [#9-security]

We use administrative, technical, and physical safeguards designed to protect information. These
include scoped access controls, tenant authorization checks, encryption in transit, protected
secret storage, hashed API keys, limited credential display, log redaction, finite resource
lifetimes, audit events, and security testing. No method of transmission or storage is completely
secure, and we cannot guarantee absolute security.

You are responsible for protecting your account, API keys, provider credentials, webhook secrets,
and local CLI credential files. Notify [info@superagent.sh](mailto:info@superagent.sh) if you believe
credentials or Customer Data have been compromised. Security vulnerabilities should be reported
through our
[private GitHub Security Advisory](https://github.com/superagent-ai/openmetal/security/advisories/new).

## 10. Your privacy rights [#10-your-privacy-rights]

Depending on your location and subject to legal exceptions, you may have the right to:

* know whether and how we process your personal information;
* access and receive a portable copy of personal information;
* correct inaccurate personal information;
* delete personal information;
* restrict or object to certain processing;
* withdraw consent;
* opt out of a sale, targeted advertising, or certain profiling;
* appeal our refusal of a request; and
* receive equal service and pricing without unlawful discrimination for exercising a right.

We do not sell personal information or share it for cross context behavioral advertising. We have
not done so in the preceding twelve months. We do not use or disclose sensitive personal
information to infer characteristics about individuals.

To exercise a right, email [privacy@superagent.sh](mailto:privacy@superagent.sh) or mail your
request to:

Superagent Technologies, Inc., 1111B S Governors Ave, Suite 3232, Dover, DE 19904, United States

Please describe your request and the OpenMetal account or organization involved. We may verify your
identity by matching account information, asking you to authenticate, or requesting additional
information. An authorized agent may submit a request with proof of authority, and we may still
verify the request directly with you. If we deny an appeal, you may contact the regulator or
attorney general in your jurisdiction.

European Economic Area residents may complain to their local data protection authority. A list is
available from the
[European Data Protection Board](https://www.edpb.europa.eu/about-edpb/about-edpb/members_en).
United Kingdom residents may contact the
[Information Commissioner's Office](https://ico.org.uk/make-a-complaint/data-protection-complaints/).
Swiss residents may contact the
[Federal Data Protection and Information Commissioner](https://www.edoeb.admin.ch/en).

## 11. Children [#11-children]

OpenMetal is a business and developer service. It is not directed to children, and you must be at
least 18 years old to create an account. We do not knowingly collect personal information from
children. If you believe a child has provided personal information, contact
[privacy@superagent.sh](mailto:privacy@superagent.sh).

## 12. Changes to this Policy [#12-changes-to-this-policy]

We may update this Policy as the Service or law changes. We will post the updated version and
change the date above. If a change materially reduces your rights or materially expands how we use
personal information, we will provide additional notice through the Service or by email when
required.

## 13. Contact [#13-contact]

For privacy requests or questions:

Superagent Technologies, Inc., 1111B S Governors Ave, Suite 3232, Dover, DE 19904, United States

[privacy@superagent.sh](mailto:privacy@superagent.sh)

For general OpenMetal questions, email
[info@superagent.sh](mailto:info@superagent.sh).
