Privacy Policy
Last updated September 24, 2026
The short version
- We collect what we need to run your account and your workspace, and nothing for advertising.
- We don't sell or share your personal information, and we never have.
- No analytics, no tracking pixels, no advertising cookies — so no cookie banner.
- We don't use your content to train AI models.
- You can export or delete everything yourself, any time, in Settings → Account & data.
1. Who we are
CMD-OS (cmd-os.app) is operated by the operator of CMD-OS (“we”, “us”). For the personal data described in this policy as ours, we are the controller (the “business” under California law). Contact us about privacy at the contact address on our Contact page.
2. Our role: controller and processor
There are two kinds of personal data in CMD-OS, and we play a different role for each.
- Your account data — who you are, how you sign in, your subscription. We decide how it is used, so we are the controller, and this policy governs it.
- What you put in your workspace — your clients and contacts, leads, notes, emails, invoices, content drafts, and what visitors submit through your booking pages and lead forms. You decide what goes in and why, so you are the controller and we process it on your behalf, under our Data Processing Addendum. If you are someone whose details a CMD-OS customer holds, please contact that customer first; we will help them respond.
3. What we collect
| Category | What | Where it comes from |
|---|---|---|
| Account | Name, email address, password (stored only as a bcrypt hash), workspace name | You, at sign-up |
| Billing | Subscription status and Stripe customer ID. Card details, billing address and tax ID are collected and held by Stripe, not by us. | You, via Stripe Checkout |
| Workspace content | Everything you create or import: projects, tasks, notes, clients, contacts, emails, proposals, invoices, content drafts, files | You, and services you connect |
| Connected services | Access tokens for Google (Calendar, Gmail), GitHub and IMAP mailboxes, encrypted at rest; the data you choose to sync from them | You, when you connect them |
| Agent access (MCP) | Names of the AI apps you authorise, when they connected and were last used, hashed tokens | You, when you approve an app |
| Security and technical | Session records (created, expires), security events on your integrations, and web server logs our host keeps (IP address, browser, time, page) | Your device, automatically |
| Visitors to your public pages | Lead form: the answers submitted, plus IP address and browser, which we clear after 30 days. Proposal acceptance: the signer's name, email, IP address and browser, kept as evidence of acceptance. Link-page clicks: the referring site and country only — no IP address. | The visitor, when they submit or click |
| Support | What you tell us when you write to us | You |
We don't collect special-category data (such as health or religion) on purpose. If you store it in your workspace, it is your content and processed only to provide the service.
4. How we use it, and our legal bases
Under GDPR and UK GDPR we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Create and run your account and workspace, and provide every feature you use | Contract (Art. 6(1)(b)) |
| Take payment and keep accounting records | Contract; legal obligation (Art. 6(1)(c)) |
| Keep the service secure: sign-in, rate limiting, spam filtering, fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)) in a secure, reliable service |
| Answer support requests and send essential service emails (billing, security, changes to these terms) | Contract; legitimate interests |
| Connect third-party services and AI apps you choose | Contract, at your request |
| Comply with law and respond to lawful requests; establish or defend legal claims | Legal obligation; legitimate interests |
We don't send marketing email without your consent, don't build advertising profiles, and don't make decisions about you by automated means that have legal or similarly significant effects.
5. AI features
AI features are off until you turn on the AI module in your workspace. When they are on, the content needed to answer each request is sent to an AI provider listed on our Subprocessors page. We don't use your content to train AI models. Apps you connect through Agent access (such as Claude or ChatGPT) are services you choose; what they do with data is governed by your agreement with them.
6. Who we share it with
- Service providers (subprocessors) that host and run CMD-OS for us, under contracts that limit them to our instructions. They are listed, with locations, on the Subprocessors page.
- Services you connect — Google, GitHub, your mail provider, AI apps — receive what you instruct CMD-OS to send them.
- People you send things to, such as a client opening a proposal or invoice link you shared.
- Authorities, when the law requires it. We push back on requests that are overbroad and tell you unless we are legally prevented.
- A buyer or successor, if the business is sold or merged, bound by this policy; we will tell you before your data moves to a different policy.
We do not sell your personal information or share it for cross-context behavioural advertising, and have not done so in the past 12 months.
7. International transfers
CMD-OS is hosted in the location shown on our Subprocessors page, and some subprocessors are in the United States or elsewhere outside the UK and EEA. When personal data leaves the EEA or the UK we protect it with an adequacy decision where one exists (including the EU–US Data Privacy Framework and its UK Extension, for recipients certified under it), or with the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the security measures described on our Security page. Ask us for a copy of the relevant safeguards at the contact address on our Contact page.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account and workspace content | Until you delete it, or your account. Deleting your account erases it immediately from the live database. |
| Database backups | Up to 30 days, then overwritten |
| Sign-in sessions | 30 days, or until you sign out |
| Lead-form IP address and browser | 30 days, then cleared; the submission itself stays until you delete it |
| Integration security events | 180 days |
| Billing and tax records (held by Stripe and in our accounts) | As long as tax and accounting law requires, typically 6–10 years |
| Server logs kept by our host | According to the host's standard retention, typically 30 days or less |
| Support emails | Up to 2 years after the conversation ends |
9. Your rights (EU, EEA and UK)
Under GDPR and UK GDPR you have the right to:
- access your personal data and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent where we rely on it, without affecting earlier processing;
- complain to a supervisory authority — in the EU, the authority where you live or work (see the list of EU authorities); in the UK, the Information Commissioner's Office.
Do it yourself, instantly: Settings → Account & data lets you download everything as JSON and delete your account and all its data. For anything else, write to the contact address on our Contact page. We answer within one month (we may extend by two months for complex requests, and will tell you why), free of charge, and may ask you to confirm your identity first.
10. California privacy notice
This section is our notice at collection and privacy policy under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). It applies to California residents.
Categories of personal information we collect
| CCPA category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email address, account ID, IP address | Hosting and database providers, Stripe |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, billing address, payment details (held by Stripe) | Stripe |
| Commercial information | Subscription plan and payment history | Stripe |
| Internet or network activity | Server logs, sign-in sessions, security events | Hosting provider |
| Professional information | Business details you add to your workspace | Hosting and database providers; AI provider if you turn on AI |
| Sensitive personal information | Account login (email and password) | Hosting and database providers, only to run your account |
Sources: you, your devices, and services you connect. Purposes: those in section 4. Retention: as in section 8.
Sale and sharing: we do not sell personal information or share it for cross-context behavioural advertising, and have not in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We use sensitive personal information only for purposes the CCPA permits (providing the service and keeping it secure), so the right to limit its use does not apply.
Your rights: to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); and not to be discriminated against for exercising any of these rights. Use Settings → Account & data, or write to the contact address on our Contact page. We verify requests by confirming control of your account email. An authorised agent may make a request for you with your signed permission; we may still ask you to verify your identity directly.
Global Privacy Control: we honour GPC signals as a request to opt out of sale and sharing. Because we do neither, a GPC signal changes nothing about how we treat your data — it is already the default.
Shine the Light (Cal. Civ. Code § 1798.83): we don't disclose personal information to third parties for their direct marketing.
11. Cookies
We use only strictly necessary cookies and browser storage — to keep you signed in, protect sign-in with Google, and remember your light or dark theme. There is no analytics or advertising tracking on the website or in the app. See Cookies for the full list.
12. Security
Workspaces are isolated from each other by the database itself, passwords are hashed, credentials for connected services are encrypted, and all traffic is encrypted in transit. Details are on our Security page. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires.
13. Children
CMD-OS is a business tool and isn't directed to children. You must be at least 16 to create an account. We don't knowingly collect personal data from anyone under 16; if you believe we have, contact us and we will delete it.
14. Changes to this policy
We will post any change here and update the date above. If a change is material, we will email account holders at least 30 days before it takes effect.
15. Contact
the operator of CMD-OS
Privacy: the contact address on our Contact page