OpenCraftPrivacy Policy
Effective 23 September 2026
This describes how OpenCraft, operated by Reprompt, handles the product data you provide when you use opencraft.so, and what you can do about it. It is written to be read, not to be survived.
The short version: we do not sell your personal data, we do not run advertising, and we do not use your conversations to train models. We store what the product needs to work and bill you correctly, and we hand your prompts to whichever model provider you asked for.
What we collect
- Account
- Your email address and authentication identifiers, held by Supabase Auth. If you start as a guest, the account is anonymous and has no email until you sign up; signing up attaches your email to that same account. We use it to sign you in, and to send a welcome note, a link to a reply that finished after you left, and the occasional request for feedback. Every one of those has an unsubscribe link.
- Conversations
- The messages you send and the replies you receive, stored in our Supabase Postgres database with row-level security so only your account can read them.
- Uploads and artifacts
- Files and images you attach, and the files models produce for you, stored in Supabase Storage. Small artifacts are additionally held inline with the message they belong to so they render instantly.
- Sandbox workspaces
- When a turn runs code, the working files live in a temporary Vercel sandbox and are synced to Supabase Storage so they survive between turns.
- Usage and billing
- One record per turn — model, token counts, cost, timestamp — plus your credit ledger. We do not store card numbers; Stripe does.
- Connections
- If you connect a third-party tool over MCP, we store the server address and the access token that connection issued — encrypted, never in plain text — so the tool keeps working between sessions.
- Product analytics and session replay
- We use PostHog to understand navigation and interactions and replay interface behavior to diagnose usability problems. These records are linked to your account identifier, including guest accounts. Replay text and form inputs are masked, media and embedded artifacts are blocked, and network bodies, headers, and console recording are disabled. PostHog stores a browser identifier to connect visits; analytics and recordings follow our PostHog project retention settings. We also measure completed signups and payments with PostHog and Google Analytics, using account and browser identifiers, referral and campaign information, and purchase amounts and transaction identifiers. These events do not include your email, chat content, or payment card details. Conversion reporting helps us understand which advertising brings users to OpenCraft.
- Operational telemetry
- Agent traces and error records — system instructions, the conversation messages and file parts sent to models, model replies, tool-call inputs and results, timings, identifiers, and error messages — sent to Logfire so we can understand turns and fix failures. Standard server logs (IP address, user agent) are kept by our host, Vercel.
Product service providers
Some product features rely on outside providers. For example:
- Model providers, via Vercel AI Gateway
- Your prompt, the conversation history the model needs, and any files attached to the turn are routed through Vercel AI Gateway to the provider of the model you selected. Which company that is depends on your model choice, and it changes as you change models. Dictated audio goes the same way, to a transcription model.
- Serper
- When a turn searches the web, the search query is sent to Serper, which runs it against Google and returns results. Serper receives the query, not your conversation.
- Stripe
- Payment details for a top-up go directly to Stripe. We receive the result — that a payment succeeded, for how much — and never see your card number.
- Resend
- Delivers our emails. It receives your address and the message we send, which may quote the start of a reply of yours.
- Supabase
- Database, authentication, and file storage.
- Vercel
- Hosting, the code sandbox, durable job execution, and the AI Gateway above.
- Logfire (Pydantic)
- Agent traces and error records, including the model-facing content and tool calls described above.
- MCP servers you connect
- A tool you connect yourself receives whatever a turn sends it. That is your choice and your relationship with that provider; disconnect it in settings to stop it.
Beyond those, we share personal data only when the law requires it, or as part of a merger or acquisition — in which case this policy travels with the data and you will be told. We never sell it, and we never rent it out.
Google user data
If you connect a Google account to OpenCraft, the assistant can work with your Google Docs, Sheets, and Slides, and with Drive files it created for you, through Google’s official APIs. It has no access to your email and cannot browse or search the rest of your Drive. This section describes exactly how the data it does reach is handled.
- Access. OpenCraft reads or changes your Google data only when a turn you send asks for it — creating a document, spreadsheet, or presentation, or reading and editing one you point it at. Nothing runs in the background, and nothing is accessed speculatively. We deliberately do not request Gmail access or permission to read your Drive at large, so neither is available to the assistant at all.
- Use. Data retrieved from Google is used for one purpose: answering the request you just made. Results become part of that conversation, stored like any other message, and are shown to the model serving that turn — the same path your own prompts take. We do not use Google user data for advertising, do not sell it, and do not use it to train AI models, generalized or otherwise.
- Storage. Results retrieved from Google become part of the conversation record above. The model-facing content and tool results may also be retained for weeks in operational agent traces on Logfire, as described above. Your Google authorization token is stored in our database encrypted at rest (AES-256-GCM, key held outside the database), is used only to call Google on your behalf, and is deleted — and revoked with Google — when you disconnect.
- Sharing. Google data is shared with the model provider serving your request and with Logfire for operational agent tracing, as described above. No human at Reprompt reads it except with your permission, to understand or debug agent behavior, for security or abuse investigation, or where the law requires.
- Revoking access. Disconnect Google in OpenCraft, or revoke OpenCraft’s access at myaccount.google.com/permissions, and access stops immediately. Deleting a conversation deletes its Google-derived content from our conversation database; copies in operational telemetry expire on Logfire’s retention schedule.
OpenCraft’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
- Conversations and messages. Deleting a conversation in the app deletes it and every message in it from our database immediately.
- Uploaded files, synced workspace files, and generated artifacts are kept in storage for as long as your account exists — deleting the conversation they came from does not delete them. To have them removed, email support@opencraft.so and ask; we will delete them along with your account if that is what you want.
- Sandboxes are temporary compute: one is destroyed about half an hour after it starts, and nothing in it survives except the workspace files synced to storage, which follow the line above.
- Usage and ledger records outlive the conversation they describe, because they are our billing history and we need them for accounting.
- Telemetry is retained on Logfire’s and Vercel’s own retention schedules — weeks, not years.
Your choices
- Delete any conversation from the app, whenever you like.
- Disconnect an MCP connection in settings.
- Unsubscribe from our emails with the link at the bottom of any of them. Sign-in and password emails still arrive.
- Ask for a copy of your data, or for your account and its contents to be deleted, by emailing support@opencraft.so. We aim to act within 30 days.
Depending on where you live you may have further rights over your personal data — to correct it, to object to certain processing, or to complain to a regulator. Write to us at the address above and we will honour them.
Security
Data is encrypted in transit and at rest by our providers, conversation rows are protected by owner-only row-level security, and sandbox workspaces are namespaced per conversation with an HMAC so one conversation cannot address another’s. No system is perfect; if you find a hole, tell us at support@opencraft.so before you tell anyone else.
Children
OpenCraft is not intended for anyone under 13, and we do not knowingly collect their data. If you believe a child has an account, email us and we will remove it.
International transfers
Our providers operate in the United States and elsewhere, so using OpenCraft means your data is processed outside your own country, including in the US.
Changes
We will update this policy as the product changes. The effective date at the top says when it last changed.
Contact
Reprompt — support@opencraft.so. See also our Terms of Service.