1. Overview
Ops Center is an executive communication and operations platform operated by Ops Center ("we", "us", "our") for authorized personnel of the subscribing organization. This policy describes how we collect, use, store, and protect information within the platform.
2. Information We Collect
- Account information: Name, email address, and profile photo from your identity provider (for example, Google Workspace or Microsoft 365).
- Integration data: When you connect third-party services (for example, Google Workspace, Microsoft 365, Slack, HubSpot, QuickBooks, Plaid, or Calendly), we access data from those services to display or sync it within Ops Center. We store OAuth tokens or API credentials securely to maintain your connection. You can disconnect integrations at any time from Settings.
- Content you create: Messages, requests, projects, CRM records, documents, and other content you submit through the platform.
- AI interaction data: Prompts, responses, and derived learnings from in-product AI features (chat, avatars, knowledge graph, semantic search) when you use those features.
- Usage data: Login timestamps, feature usage, and performance telemetry to maintain reliability and improve the platform.
3. How We Use Your Information
- To provide and maintain Ops Center and its features.
- To authenticate your identity and enforce tenant- and entity-level access controls.
- To display and sync data from connected third-party integrations.
- To power in-product AI features, including personalized responses and tenant-scoped knowledge retrieval.
- To send notifications you have opted into (mentions, request updates, alerts).
- To monitor performance, detect errors, and improve reliability and user experience.
4. AI Features & Model Providers
Ops Center includes AI-powered features such as chat assistants, avatars, semantic search, knowledge graph, voice transcription, and automated workflows. When you use these features, relevant context (for example, your prompt, recent conversation, and tenant-scoped knowledge snippets) may be sent to third-party AI providers to generate a response.
- Providers we use: Anthropic (Claude), OpenAI (GPT, Whisper), and other model providers configured for your workspace. Some tenants may supply their own API keys (BYOK) and pay providers directly.
- Tenant isolation: AI retrieval and memory are scoped to your organization's tenant. One customer's data is not exposed to another customer's AI context.
- No model training on your data: We do not use your platform content to train foundation models. Data sent to AI providers is used only to fulfill your request in the product, subject to each provider's API terms and data-use policies.
- Knowledge retention: Preferences, SOPs, and learnings you or your admins save may be stored in your tenant's knowledge graph to improve future AI responses within your organization. Your administrator can manage or delete this content.
5. AI Development Tools
Ops Center may use AI-assisted software development tools (for example, Cursor Cloud Agents) to build and maintain Ops Center. These tools operate on our source code repository, not on your live production workspace data.
- What they see: Application source code, configuration files, documentation, and development logs in our repo.
- What they do not see by default: Your organization's live messages, CRM records, payroll data, integration tokens, or other production tenant data stored in our database.
- Your responsibility: Do not paste sensitive customer or employee data into development chats, commit secrets to the repository, or export production data into files unless your organization has approved that workflow.
6. Data Sharing & Subprocessors
We do not sell, rent, or share your personal information with third parties for their marketing purposes. We share data only as necessary to operate the platform, with service providers bound by confidentiality and data-protection obligations, including:
- Infrastructure: Vercel (hosting), Supabase (database, auth, storage)
- AI providers: Anthropic, OpenAI, and other model vendors enabled for your workspace
- Integrations you connect: Google, Microsoft, Slack, HubSpot, Plaid, QuickBooks, and other services you authorize
- Communications: Email and notification providers (for example, Resend, Twilio) when those features are enabled
7. Data Security
All data is transmitted over HTTPS. OAuth credentials and API keys are stored encrypted. Access to the platform is restricted to authorized users via identity provider sign-in and invitation-based access control. Row-level security policies enforce tenant and entity isolation at the database level.
8. Data Retention
We retain your data for as long as your account or tenant subscription is active. You may request deletion of your data by contacting your organization administrator or admin@opcenter.app. Integration tokens can be revoked at any time from the Integrations settings page.
9. Google API Disclosure
Ops Center's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.