OpenMetal

Privacy Policy

How OpenMetal collects, uses, discloses, and protects personal information.

Last updated and effective: September 15, 2026

This Privacy Policy explains how Superagent Technologies, Inc. ("Superagent," "we," "us," or "our") handles personal information in connection with OpenMetal. OpenMetal includes the website, documentation, dashboard, application programming interfaces, software development kits, command line interface, Agent Skill, and related support services (collectively, the "Service").

Superagent Technologies, Inc. is a Delaware corporation located at 1111B S Governors Ave, Suite 3232, Dover, DE 19904, United States. For privacy questions or requests, contact privacy@superagent.sh.

1. Scope and our role

This Policy applies when Superagent decides why and how personal information is processed, such as account, billing, website, support, security, and Service usage information. For this information, Superagent acts as a controller or business under applicable privacy law.

Organizations may submit code, files, environment values, command input and output, logs, webhook content, and other data to run workloads through OpenMetal ("Customer Data"). The organization decides what Customer Data to submit and why. When Customer Data contains personal information, Superagent generally processes it on the organization's behalf as a processor or service provider. The organization is responsible for its own privacy notices, permissions, and instructions. Where required, a separate data processing agreement will govern that processing. Contact privacy@superagent.sh to request one.

This Policy does not apply to a third party service that you access under a separate account or agreement, including a compute provider used with your own credentials.

2. Information we collect

We collect the following categories of information.

Information you provide

  • Account and profile information. Name, email address, profile image, authentication method, account preferences, and organization membership.
  • Organization information. Organization and project names, member and invitation details, roles, API key names and prefixes, and account settings.
  • Billing information. Billing contact information, purchase amounts, credit balances, payment status, receipts, invoice links, payment method brand and last four digits, and automatic top up settings. Stripe processes full payment card details. We do not store full card numbers.
  • Configuration and support information. Provider configuration, webhook destinations, communications, feedback, and information you send when requesting support.
  • Customer Data. Workload source references, resource requirements, code, files, commands, process input and output, environment values, secret references, endpoint details, metadata, and other content submitted to or generated through the Service. Secret values and provider credentials are treated as sensitive Customer Data.

Information collected automatically

  • Device and network information. Internet Protocol address, browser and device type, operating system, language, request time, referring page, and similar connection information.
  • Service activity. Pages and features used, authentication events, API and CLI requests, project and sandbox actions, process and filesystem operations, webhook delivery results, error details, and timestamps.
  • Operational and billing telemetry. Resource identifiers, selected provider, routing and fallback decisions, resource configuration, lifecycle state, runtime, usage measurements, estimated and actual provider cost, customer charges, request identifiers, and audit events.
  • Cookie and local storage information. Session, security, and preference values needed to keep you signed in and remember interface settings.

Information from other sources

  • Authentication providers. If you sign in with Google or GitHub, we receive basic profile information authorized by you, such as your name, email address, profile image, and provider account identifier. We do not request access to your email, repositories, or files merely because you use social sign in.
  • Payment processor. Stripe returns transaction, customer, payment status, receipt, invoice, and limited payment method information.
  • Compute providers. Providers return resource status, identifiers, usage, cost, logs, errors, and other information needed to operate, meter, troubleshoot, and secure a workload.
  • Organization administrators. An administrator may provide your email address to invite you to an organization and may manage your role and access.

3. How we use information

We use personal information to:

  • create, authenticate, and administer accounts, organizations, projects, and permissions;
  • provision, route, operate, monitor, pause, resume, and destroy compute resources;
  • execute commands, transfer files, expose requested endpoints, and deliver webhooks;
  • process purchases, maintain credit balances, perform automatic top ups, meter usage, calculate charges, issue receipts, and reconcile provider costs;
  • send authentication messages, invitations, receipts, security notices, policy updates, and other Service communications;
  • provide support and respond to requests;
  • detect fraud, abuse, unauthorized access, security incidents, and violations of our Terms;
  • debug, maintain, analyze, and improve the reliability and usability of the Service;
  • enforce agreements, establish or defend legal claims, and comply with law; and
  • create aggregated or deidentified information that cannot reasonably identify an individual.

We do not sell personal information. We do not share personal information for cross context behavioral advertising, and we do not use Customer Data to train artificial intelligence models. We do not make decisions about individuals that produce legal or similarly significant effects using automated processing.

If European, United Kingdom, or similar data protection law applies, our legal bases are:

  • Contract. We process account, configuration, workload, usage, and billing information to provide the Service and perform our Terms of Service.
  • Legitimate interests. We process information to secure, support, maintain, analyze, and improve the Service; prevent fraud and abuse; collect amounts due; and protect our rights and users. We consider and balance these interests against individual rights.
  • Legal obligation. We process information to satisfy tax, accounting, sanctions, law enforcement, and other legal requirements.
  • Consent. We rely on consent where the law requires it. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.

When we process Customer Data for an organization, the organization determines the applicable legal basis.

5. How we disclose information

We disclose information only as needed for the purposes described above:

  • Infrastructure and platform providers. Hosting, database, authentication, realtime, networking, storage, monitoring, and security vendors process information needed to operate the Service. The codebase currently uses Supabase for authentication, database, and realtime services.
  • Compute providers. We send workload configuration and Customer Data to the provider selected by you or by OpenMetal routing. Supported providers may include Blaxel, Cloudflare, CodeSandbox, Daytona, E2B, Freestyle, Modal, Northflank, Runloop, and Vercel. The provider used for a workload appears in Service records. Available providers can change.
  • Payment and email providers. Stripe processes payments. Resend delivers authentication and Service email.
  • Authentication providers. Google or GitHub processes information when you choose its sign in option.
  • Your organization and integrations. Organization owners, administrators, and authorized members can access organization information according to their role. We send event data to webhook destinations configured by your organization.
  • Professional advisers. Lawyers, accountants, auditors, insurers, and similar advisers may receive information subject to professional or contractual duties.
  • Legal and safety recipients. We may disclose information to comply with valid legal process, enforce agreements, investigate fraud or abuse, protect rights and safety, or respond to an emergency.
  • Business transaction recipients. Information may be transferred as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality protections.
  • At your direction. We disclose information when you direct us or give consent.

Service providers may process information only for the contracted service and under applicable confidentiality and data protection obligations.

6. International transfers

Superagent is based in the United States, and the Service uses providers that may process information in the United States and other countries. Customer workloads may run in the provider and region selected by you or OpenMetal routing. Data protection laws in those locations may differ from those where you live.

Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use an available lawful transfer mechanism, such as an adequacy decision, approved standard contractual clauses, or another recognized safeguard. You may request information about relevant safeguards by emailing privacy@superagent.sh.

7. Retention

We keep information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, meet legal and accounting duties, resolve disputes, prevent fraud, and enforce agreements.

Current product behavior includes:

  • account and profile information is generally kept while the account is active;
  • organization and project deletion removes active access, while durable billing, security, and audit records may be retained;
  • completed process event output is ordinarily removed from the OpenMetal control plane after seven days;
  • sandbox resources and data stored in them are subject to the configured lifecycle and the selected provider's deletion process;
  • purchase, payment, credit, ledger, usage, and tax records are retained as required for accounting, legal compliance, dispute handling, and fraud prevention; and
  • backups and provider systems may retain residual copies for a limited period according to their backup and deletion cycles.

Other operational records are retained according to their sensitivity, operational need, and legal requirements. We may keep deidentified information that cannot reasonably be linked to an individual.

To request account deletion, email privacy@superagent.sh. Deleting an organization in the dashboard does not by itself delete your authentication account or all records that we must retain.

8. Cookies and similar technologies

OpenMetal currently uses cookies and browser storage that are necessary for authentication, session security, and interface preferences such as theme. We do not currently use advertising cookies or third party analytics cookies on the OpenMetal website or dashboard.

Google and GitHub may use their own cookies when you choose social sign in. Their privacy notices govern those services. You can block or delete cookies through your browser, but blocking necessary cookies may prevent sign in or other Service functions.

We honor legally required browser based opt out preference signals if our practices become subject to them. Because we do not currently sell or share personal information for targeted advertising, such a signal does not change current advertising practices.

9. Security

We use administrative, technical, and physical safeguards designed to protect information. These include scoped access controls, tenant authorization checks, encryption in transit, protected secret storage, hashed API keys, limited credential display, log redaction, finite resource lifetimes, audit events, and security testing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your account, API keys, provider credentials, webhook secrets, and local CLI credential files. Notify info@superagent.sh if you believe credentials or Customer Data have been compromised. Security vulnerabilities should be reported through our private GitHub Security Advisory.

10. Your privacy rights

Depending on your location and subject to legal exceptions, you may have the right to:

  • know whether and how we process your personal information;
  • access and receive a portable copy of personal information;
  • correct inaccurate personal information;
  • delete personal information;
  • restrict or object to certain processing;
  • withdraw consent;
  • opt out of a sale, targeted advertising, or certain profiling;
  • appeal our refusal of a request; and
  • receive equal service and pricing without unlawful discrimination for exercising a right.

We do not sell personal information or share it for cross context behavioral advertising. We have not done so in the preceding twelve months. We do not use or disclose sensitive personal information to infer characteristics about individuals.

To exercise a right, email privacy@superagent.sh or mail your request to:

Superagent Technologies, Inc., 1111B S Governors Ave, Suite 3232, Dover, DE 19904, United States

Please describe your request and the OpenMetal account or organization involved. We may verify your identity by matching account information, asking you to authenticate, or requesting additional information. An authorized agent may submit a request with proof of authority, and we may still verify the request directly with you. If we deny an appeal, you may contact the regulator or attorney general in your jurisdiction.

European Economic Area residents may complain to their local data protection authority. A list is available from the European Data Protection Board. United Kingdom residents may contact the Information Commissioner's Office. Swiss residents may contact the Federal Data Protection and Information Commissioner.

11. Children

OpenMetal is a business and developer service. It is not directed to children, and you must be at least 18 years old to create an account. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact privacy@superagent.sh.

12. Changes to this Policy

We may update this Policy as the Service or law changes. We will post the updated version and change the date above. If a change materially reduces your rights or materially expands how we use personal information, we will provide additional notice through the Service or by email when required.

13. Contact

For privacy requests or questions:

Superagent Technologies, Inc., 1111B S Governors Ave, Suite 3232, Dover, DE 19904, United States

privacy@superagent.sh

For general OpenMetal questions, email info@superagent.sh.

On this page