Data we collect
- Account and Workspace identifiers from Clerk, including Member ID, organization ID, role, and sign-in email used for account access.
- Files uploaded by Workspace Members, including Company Files and Personal Files uploaded by an individual Member.
- File metadata, object keys, search-index metadata, MCP tool-call inputs, and operational logs needed to run and debug the service.
How we use data
- To authenticate Members, enforce Workspace membership, and scope each request to the selected Workspace.
- To store files in the correct Company File or Personal File scope.
- To index uploaded files and return relevant passages or full file text through read-only MCP tools.
- To provide support, investigate abuse, maintain reliability, and comply with legal obligations.
Recipients
- Cloudflare hosts the web app, Worker, R2 file buckets, AI Search index, and runtime used by CompanyOS.
- Clerk provides authentication and organization management.
- PostHog EU Cloud provides privacy-conscious frontend web analytics, error tracking, masked session replay for the signed-in app, feedback collection, and support conversations through in-app chat and email tickets.
- OpenAI ChatGPT or another MCP client receives only the specific passages, file IDs, or file text returned by a tool call initiated in that client.
Frontend telemetry
- CompanyOS uses PostHog EU Cloud to understand public-site visits, app-page activity, support-link clicks, client-side errors, API-failure counts, and in-app feedback reports.
- Session replay is enabled only in the signed-in app. Inputs and visible page text are masked, and sensitive file-list areas can be excluded from capture.
- Telemetry excludes file names, folder names, file contents, document text, upload-body text, MCP query text, object keys, authorization headers, cookies, bearer tokens, and raw request or response bodies.
- CompanyOS sends Clerk Member ID and sign-in email for support correlation, plus Clerk organization ID and organization slug for Workspace grouping. Organization names are not sent to PostHog in this phase.
- Local development hosts and dev.companyos.cc disable PostHog by default to avoid collecting development sessions.
Support and feedback
- When you contact us through in-app support chat or by emailing support@companyos.cc, your messages, including your name, email address, and what you send, are processed and stored on our behalf by PostHog EU Cloud so we can operate our support inbox and reply.
- A support conversation may be linked to a recording of your app session, as described under Frontend telemetry, to help us diagnose the issue.
- We do not use support-message contents for advertising. Please do not include passwords, API keys, or confidential file or Workspace contents in support messages.
- You can request access to, or deletion of, this data by emailing support@companyos.cc.
Retention
Workspace files are kept while the Workspace is active or until an authorized Member deletes them. Search-index entries are derived from stored files and may persist until the next index sync after deletion. Operational logs are retained only as needed for security, debugging, and service operation.
Member controls
- Workspace Owners can upload and delete Company Files.
- Members can upload and delete their own Personal Files.
- Members can revoke MCP access from the connected client and can request export or deletion by emailing support@companyos.cc.
Product boundaries
- CompanyOS does not request payment-card data, government identifiers, health data, passwords, API keys, or MFA codes through MCP tools.
- CompanyOS Knowledge Tools and Integration tools are read-only and cannot post, send messages, modify source files, or delete data.
- Owner-only Procedure Authoring Tools can create or update CompanyOS Procedure content. They cannot edit source files or connected systems, and the first publication remains an Owner action in the web app.
- CompanyOS does not sell personal data and does not serve advertising in the ChatGPT app surface.
Contact
Questions, deletion requests, export requests, and security concerns can be sent to support@companyos.cc.