Privacy Policy
How OpenResearch collects, uses, and protects your information, and the choices you have.
Last updated: September 14, 2026
1. Overview
This Privacy Policy explains what information openresearch.lol ("we", "us") collects when you use the website, the account area, and the OpenResearch service, why we collect it, and the choices you have.
2. Information we collect
We keep the data we collect to the minimum needed to run the service.
- Account data from Google sign-in: your name, email address, profile image URL, and the Google account identifier.
- Subscription and billing data: your plan, billing interval, subscription status, and identifiers issued by our payment processor. We never receive or store your full card number.
- Service usage data: credits consumed, features used, and technical events needed to keep the service reliable.
- Technical data: IP address, browser and device type, and timestamps, collected in server logs for security and abuse prevention.
3. Data in your research workspace
OpenResearch is local-first. Projects, conversations, experiments, runs, logs, code, and artifacts live on your own machine. We do not receive them, and we do not read your repositories, files, or prompts.
Official release builds send opt-out, coarse usage events tied to a random installation ID. These events exclude code, prompts, file contents and paths, repository names, tokens, emails, and project or experiment identifiers. You can disable them with orx telemetry off.
4. How we use your information
We use the information described above to create and secure your account, to provide and meter the service, to process subscription payments, to answer support requests, to detect abuse and fraud, and to comply with legal obligations.
5. Cookies and local storage
We use essential cookies and local storage to keep you signed in, to remember your preferences, and to protect forms against cross-site request forgery. You can clear them in your browser, but signing in depends on them.
6. Service providers
We share limited data with the providers that make the service work. Each provider processes data under its own terms and only for the purposes we describe.
- Google - sign-in and account identity.
- Stripe - subscription billing, invoices, and payment method handling.
- Cloud hosting and database providers - running this website and storing account records.
- Compute providers - only when you explicitly launch a run on managed compute from the compute marketplace.
7. Retention
We keep account and billing records for as long as your account exists, and afterwards only as long as we need them for accounting, tax, dispute resolution, and legal compliance. Server logs are kept for a short operational window and then deleted.
8. Security
We use encryption in transit, access controls, and least-privilege practices to protect your data. No system is perfectly secure, so we cannot promise absolute security, but we limit what we store to reduce the impact of any incident.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to certain processing, and to lodge a complaint with a supervisory authority.
To exercise these rights, email support@openresearch.lol. We may need to verify that the request comes from the account owner.
10. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
11. Children
The service is not intended for children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes and contact
We may update this policy as the service evolves. Material changes are reflected by the "Last updated" date above.
Questions about privacy can be sent to support@openresearch.lol.