1. Who we are & what this covers
This Privacy Policy explains how OpenEng (“OpenEng”, “we”, “us”, or “our”) handles personal information across our products and services (collectively, the “Services”):
By using the Services you agree to this Policy. If you do not agree, please do not use the Services.
2. Information we collect
2.1 Account information (when you sign in)
Signing in is handled by Google Sign-In through Firebase Authentication (a Google service). When you choose to sign in, we receive from your Google account: your name, email address, profile picture, and a unique account identifier. We do not receive your Google password. We use this to create and secure your OpenEng account and to identify you across the Services.
2.2 Preferences & sync data (optional)
If you are signed in to the desktop app, a limited set of preferences — such as your theme and accent settings, your plan status, and a device-session record — may be stored in Google Firestore so they can sync across your devices. This is tied to your account identifier and contains no content from your terminals, agents, or files.
2.3 Website analytics
This website uses Google Analytics for Firebase to understand usage — for example, which pages are viewed, the approximate region derived from your IP address, and your device and browser type. This is collected via cookies and similar identifiers and is used in aggregate to improve the site. It is separate from the desktop app and CLI, which contain no analytics.
2.4 Subscription & payment information
If you subscribe to OpenEng Pro, payment is processed by Razorpay. We do not receive or store your card or bank details — Razorpay handles them under its own privacy policy. We receive and store your subscription status (plan, trial state, subscription identifier, and billing events) so we can unlock Pro features across your devices.
2.5 Communications
If you email us (for example, support or a security report), we receive your email address and the contents of your message.
3. What stays on your device (and is never collected)
OpenEng is designed to be local-first. The following live in your operating system’s application-data directory on your own machine and are never transmitted to or collected by us:
- terminal sessions, command history, and saved commands;
- agent definitions, episodic memory, RAG indexes, and chat threads;
- notes, projects, diary, bookmarks, calendar, and whiteboards;
- your code, files, and working directories;
- API keys and secrets stored in the encrypted vault; and
- the locally-run (embedded / local) models and their output.
The desktop app and the engine ship no analytics SDKs, no crash beacons, and no telemetry. The engine stores its sign-in session only on your machine (under ~/.openeng/) and, once signed in, operates fully offline.
4. How we use information
- to authenticate you and provide, maintain, and secure the Services;
- to sync the preferences you choose to sync across your devices;
- to respond to your requests and provide support;
- to detect, prevent, and address security incidents, fraud, or abuse;
- to understand and improve this website (in aggregate); and
- to comply with legal obligations.
Where required by law (e.g., in the EEA/UK), we rely on the following legal bases: performance of a contract (to provide the Services you request), your consent (e.g., for analytics cookies, withdrawable at any time), and our legitimate interests (to secure and improve the Services).
5. How information is shared
We do not sell your personal information. We share it only as follows:
- Service providers. We use Google Firebase (Authentication, Firestore, Hosting, and Analytics) to operate the Services. Google processes this data on our behalf under its own terms; see Google’s Privacy Policy.
- Payment processing. Pro subscriptions are billed through Razorpay, which processes your payment details under its own Privacy Policy. We share with Razorpay only what is needed to create and manage your subscription (such as your account identifier and email).
- Legal & safety. We may disclose information if required by law or to protect the rights, safety, and security of our users, the public, or OpenEng.
- Business transfers. If OpenEng is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy.
6. Third-party services you choose to use
Some features connect to services you configure. When you use them, your data goes directly from your machine to that provider under their privacy terms — not through us:
- Cloud AI models (bring-your-own-key). If you add a cloud model provider key, your prompts and the key are sent directly to that provider when you use that model.
- Agent cells. Agent cells are deployed to your own cloud account; OpenEng does not host them or receive their data.
- On-device models. The bundled model suite runs on your hardware, isolated in a sandbox, and sends nothing externally.
7. Data security
We use industry-standard safeguards: encryption in transit (TLS), an encrypted vault with a hardware/OS-backed master key for secrets stored on your device, a restrictive Content Security Policy in the desktop app, least-privilege access controls, and input validation at every trust boundary. No method of storage or transmission is 100% secure, but we work to protect your information and to keep as much of it as possible on your own device.
8. Data retention
We retain account information for as long as your account is active or as needed to provide the Services. You can delete your account and associated data at any time by contacting us (see below); we will delete or anonymize it within a reasonable period, except where we must retain it to comply with legal obligations or resolve disputes. On-device data is removed when you delete it or uninstall the app; signing out of the engine removes its local session.
9. Your rights & choices
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- export your information (data portability);
- object to or restrict certain processing; and
- withdraw consent (e.g., disable analytics) at any time.
Because we sell no personal information and run no targeted advertising, there is no “sale” or “sharing” to opt out of under the CCPA. To exercise any right, email hello@openeng.ai. We will not discriminate against you for exercising your rights, and you may lodge a complaint with your local data-protection authority.
10. International data transfers
Our service providers (notably Google) operate globally, so your account and analytics information may be processed in countries other than your own, including the United States. Where required, such transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
11. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Cookies
This website uses cookies and similar technologies for analytics as described in section 2.3. You can control cookies through your browser settings. The desktop app and CLI do not use advertising or tracking cookies.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of the Services after an update means you accept the revised Policy.
14. Contact us
For any privacy question, request, or security report, email hello@openeng.ai. We respond to security disclosures within 72 hours. See also our Terms of Service.