Skip to main content

Security and privacy

Different surfaces.
Different data paths.

Desktop local workflows keep source media on your PC. Web, marketing forms, and public O Copilot are online services with separate data paths.

Surface by surface

What happens to your data.

Controlled Beta · local workflows

Windows Desktop Beta

Media
Source media and outputs from Desktop local workflows stay on the supported Windows computer.
AI Packs
Local AI Packs run on the computer after installation. Downloading or importing a pack is a separate network or file-transfer action.
Local retention
You control source files and outputs. Normal uninstall does not delete them. Structured log archives are kept for seven days; the redacted local crash journal is kept for 14 days. Projects, Library state, settings, and AI Packs can remain until app data is explicitly removed.

Authenticated Web Beta

O Studio Web

Data path
The Desktop local-media guarantee does not cover O Studio Web.
Current scope
Web and Desktop are separate surfaces. A Desktop workflow is not a Web workflow unless Web explicitly shows and supports it.
Retention
Web data follows any enabled tenant policy or written pilot agreement. O Studio does not publish one universal Web retention period.

Online services

Marketing forms and O Copilot

Forms
Vercel hosts the marketing path. Resend delivers the fields you submit to our current Google/Gmail inbox (tarifsayed7@gmail.com). Marketing forms do not accept customer media.
O Copilot
Public O Copilot sends your prompt, necessary recent context, generated reply, and a random session safety identifier to OpenAI for inference and safety screening. It accepts text, not customer media.
Training and retention
We do not use these submissions to train generalized or shared AI models without separate opt-in. Under OpenAI’s default API controls, Copilot prompts and responses may remain in abuse-monitoring logs for up to 30 days.
Analytics
Custom analytics events must not contain form values, free-text prompts, customer media, email addresses, or customer identifiers.

Separately agreed scope

Teams and archive pilots

Before media moves
The team and O Studio agree where representative media is processed and stored, who can access it, and how long it is kept.
Rights
The team providing media must have authority to use it for the agreed evaluation. Public examples do not use customer archives.
Agreement
Any pilot-specific security, privacy, support, or deletion terms belong in a separately signed agreement.

Team and archive pilots

Agree on the data path before media moves.

A pilot starts after the team and O Studio answer four practical questions.

  1. 01Where will representative media be processed and stored?
  2. 02Who can access source media, outputs, and workflow records?
  3. 03How long will each category be kept, backed up, and deleted?
  4. 04Which rights, confidentiality, support, and incident terms are required?

Choose the surface that fits your media.

Use Desktop for local media workflows. Read the Privacy Policy for online data paths, or contact us before starting a team pilot.