Privacy Policy
This policy explains how The Dean of Big Data LLC ("we", "us") handles your information when you use OkComputer: the desktop application, the website, and the subscription service behind them. In brief: OkComputer is local-first, so your conversations and notes are kept on your own computer by default; our servers hold your account and billing records and the metadata we need to meter usage; and optional cloud features, such as Automations, store the documents and results you choose to put in the cloud on our servers, encrypted at rest. We do not sell your information, and we do not use your content to train AI models. The sections below describe each of these in detail.
1. What is stored on your computer
OkComputer is local-first. By default, your conversations, memory notes, library documents, dashboards, templates, and workflows are stored in files and folders on your own machine, not on our servers. If you delete a locally stored item, it is gone from your machine and we keep no copy of it. Your login session is also kept locally on your device. The exceptions are the optional cloud features described in Section 3: when you use them, the content you choose to place in the cloud is stored on our servers so that it is available to runs that happen while the application is closed.
2. What our servers process but do not keep
When you chat using the built-in engine, the application sends your prompt and the context needed to answer it through our servers to our model routing provider, OpenRouter, which passes it to the provider of the AI model you selected - such as OpenAI, Google, xAI, Meta, Mistral, or DeepSeek, depending on your choice. Our servers handle this content in memory only, to forward the request and return the response. We do not store it, log it, or use it to train models. What we record about each request is metadata only: which model was used, token counts, the cost, the AI actions charged, a request identifier, and a timestamp.
Once your request leaves our servers, OpenRouter and the provider that runs your chosen model handle the prompt and the response under their own privacy and data-use policies, which we do not control. These policies vary by model: some providers do not retain your prompts, while others - particularly many lower-cost and free models - may retain prompts and responses or use them to improve or train their models. If this matters to you, choose models from providers whose data policies you are comfortable with; OpenRouter publishes the data policy for each model.
When you switch a conversation to an engine you subscribe to separately, such as Codex or Grok, the conversation goes directly from your computer to that provider under your own account. It never touches our servers at all, and the provider's own privacy policy applies to it.
3. Cloud documents, Automations, and connected apps
Some optional features run in the cloud so they can work while OkComputer is closed. The main one is Automations, available on paid plans, which runs an instruction you define against documents on a schedule. To make this possible, the following are stored on our servers:
- Cloud documents you create or upload for an automation to work on, including their text and, for file types such as PDF or Word, the file itself.
- Automation definitions - the instruction you write, any system prompt, the schedule, and which documents the automation operates on.
- Run results - the output of each run and a transcript of what the automation did, including any new document a run produces.
This content is encrypted at rest. It is stored only under your own account and is used only to run your automations and show you their results; it is not used for advertising or to train AI models. You can delete cloud documents, automations, and their results from within the application at any time, and deleting your account removes them. When an automation sends content to an AI model to do its work, that content is processed by the model provider under the same terms described in Section 2.
Connected apps. You can optionally connect a third-party account - such as Gmail - so that OkComputer can act on it for you, for example reading or sending email when you ask it to. These connections are brokered by our integration provider, Composio, which securely holds the authorization on our behalf and carries out the actions you request against the connected account. We request access to a connected account only to perform the tasks you direct, and the data returned is used only to complete those tasks and is processed by the AI model that runs them under the same terms described in Section 2. You can disconnect an account at any time from within the application, and the connected provider's own terms and privacy policy continue to govern your account with them.
4. What we collect and store
- Account information. Your email address and a hash of your password. We never store the password itself.
- Email tokens. Hashed one-time tokens used for email verification and password resets.
- Billing records. Your plan, subscription status, and a customer reference with Stripe. Payments are processed by Stripe; we never see or store your full card number.
- Usage records. Per-request metadata listed above, kept so your AI action balance and our billing stay accurate and auditable.
- Cloud documents and automation results. If you use Automations, the documents, definitions, and run results described in Section 3, encrypted at rest.
- Support correspondence. Emails you send us.
- Crash and bug reports. If the app crashes, an automatic technical error report (no conversation content). If you submit a bug report from within the app, the details you write, your account email, and - unless you opt out in the report form - the conversation you are reporting on, so we can reproduce the problem.
5. What we do not do
- We do not sell your information or share it for advertising.
- We do not run analytics trackers, and this website sets no tracking cookies. The embedded product demo runs entirely in your browser and sends nothing to us.
- We do not store the content of your conversations on our servers, except a conversation you choose to attach to a bug report (see Section 6) and content you place in a cloud feature such as Automations (see Section 3).
- The Dean of Big Data does not use your content to train AI models. Note, however, that the third-party providers that run the model you select may retain or train on your prompts and responses under their own policies - this depends on the model you choose (see Section 2).
6. Service providers
We share data only with the providers needed to run the Service:
- Stripe processes payments.
- OpenRouter routes built-in engine requests to the AI model providers (such as OpenAI, Google, xAI, Meta, Mistral, and DeepSeek).
- Composio brokers the optional app connections you choose to set up (such as Gmail): it securely holds the authorization for the connected account and carries out the actions you ask OkComputer to perform against it.
- Resend delivers verification, password-reset, and billing-receipt emails.
- DigitalOcean hosts our servers in the United States.
- Sentry receives crash and bug reports so we can fix failures. Automatic crash reports contain only technical diagnostics - no conversation content. A bug report you submit from within the app also includes the details you provide, your account email, and, unless you uncheck the option in the form, the conversation you are reporting on, so we can reproduce the issue.
Each provider processes data only to provide its service to us. The AI model providers reached through OpenRouter process your prompts under their own policies in order to generate responses.
7. Retention and deletion
We keep account and usage records while your account exists, together with any cloud documents, automations, and run results you have created. You can delete cloud documents, automations, and their results individually from within the application. You can delete your account from the application's settings; doing so cancels any subscription and permanently deletes your account record, sessions, usage records, credit history, and any cloud documents, automations, and run results from our database. Records held by Stripe are retained as financial regulations require. You can also email us to request deletion or a copy of the data we hold about you. Depending on where you live (for example the EU, UK, or California), you may have additional statutory rights to access, correct, port, or restrict the use of your personal data, and to complain to your local data-protection authority; we honor these requests at the same address.
8. Security
Connections to our servers use TLS. Passwords are stored as bcrypt hashes, email tokens are stored hashed, and cloud documents and automation results are encrypted at rest. No system is perfectly secure, but we keep the amount of data we hold small, which keeps the stakes of any failure small too.
9. Children
The Service is intended only for adults: our Terms require account holders to be at least 18 years old, and the Service is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, contact us and we will delete it.
10. Where data is processed
Our servers are located in the United States. If you use the Service from elsewhere, your information is transferred to and processed in the United States. Where we transfer personal data of users in the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards for that transfer, such as the European Commission's Standard Contractual Clauses, and our service providers (including Stripe) maintain their own transfer mechanisms.
If the GDPR or UK GDPR applies to you, our legal bases for processing are: performing our contract with you (to provide the Service and process payments), our legitimate interests (to secure, operate, and improve the Service and prevent abuse), and compliance with our legal obligations (such as financial record-keeping).
11. Changes to this policy
We may update this policy as the Service evolves. If a change is material, we will give notice through the website, the application, or email before it takes effect. The effective date at the top always reflects the current version.
12. Contact
The Dean of Big Data LLC
[email protected]