Privacy policy.
How we collect, use, and protect data on AutoOps.AI. This page is for everyone — the formal DPA for enterprise customers is at /legal/dpa.
Last updated: July 23, 2026
Who we are
AutoOps AI ("we", "us") operates autopsai.com, a business tool for manufacturers. We wear two hats: for your account and billing data, we decide how it's processed (this policy governs). For the content you and your organization put into the product, we process it on your organization's behalf — the Data Processing Addendum governs that.
What we collect
- Account data — name, email, a hash of your password (never the password itself), your role, organization membership, and when you last signed in.
- Billing data — your subscription tier and status, and Stripe customer and subscription identifiers. Card numbers go directly to Stripe and never touch our servers.
- Content — files you upload (with their names, types, and sizes), chat conversations, generated reports, FMEA / CAPA / escalation / playbook records, and — if your organization connects SAP — the records we sync on its behalf.
- Invitations — the email addresses of teammates you invite.
- Security records — an append-only audit log of actions in your organization, including the IP address each action came from. Org admins can review it in Settings.
- Short-lived tokens — email-verification tokens (expire after 24 hours) and password-reset tokens (expire after 1 hour or first use).
Analytics and error monitoring
We use cookie-less Umami analytics to measure page views and bounded product events. Depending on configuration, this can include event name, page, referrer, device/browser characteristics, and coarse country information; chat text, file names, and report contents are excluded from analytics events. Sentry error monitoring runs only when enabled and can receive error context and device information. We use no advertising trackers and do not sell data.
Cookies
These are the only cookies we set:
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| app_session_id | Keeps you signed in (server-side session) | Essential · HTTP-only | Up to 1 year |
| oauth_state | CSRF protection during Google or Microsoft sign-in | Essential · HTTP-only | 10 minutes |
Both are strictly necessary to run the product. Umami is configured without an analytics cookie. Appearance, navigation, tour state, and some UI preferences are stored in browser localStorage.
How we use data
To provide and secure the Services, power AI features, send transactional email through Resend (verification, password resets, invitations, and notifications you configure, like escalations), process billing through Stripe, respond to support requests, and meet legal obligations. We never use your data to train AI models — ours or anyone else's — without your explicit written consent.
AI processing
AI features use Anthropic's Claude. When you use them, your prompts, messages, and — when present — a small (~2 KB) SAP context summary are sent to Anthropic's API for that request. Under Anthropic's standard API terms, your data is not used to train Anthropic's models. For Anthropic's own data-handling practices, see Anthropic's privacy documentation.
How we share data
- Sub-processors who help us run the Services — the full list is at /legal/sub-processors.
- People in your organization who have permission to see it, per your org's roles.
- Authorities, when required by law. We resist overbroad requests.
We do not sell your data. We do not share it with advertisers.
Where your data lives
Hosting and provider regions depend on the production environment and are verified in the sub-processor inventory before contracting. The service is US-first. We do not accept EU/UK customer data under an uncompleted transfer mechanism; completed SCC annexes, a transfer assessment, and the UK Addendum are required before that launch.
How long we keep it
Live content remains while the account is active. Authentication tokens purge after expiry; application and security logs target 90 days; Umami analytics target 12 months; and organization audit logs target 24 months after termination. Billing and tax records follow applicable accounting rules. Deleted database and storage backups age out within the verified provider window rather than instantaneously.
Your rights
Depending on where you live (GDPR, UK GDPR, CCPA), you have rights to access, correct, delete, and port your data, and to restrict or object to some processing. Access, deletion, and portability are self-serve — see the next section. For anything else (or if you can't sign in), email contact@autopsai.com from your account email address — we verify identity that way — and we'll respond within 30 days. We don't sell data or share it for cross-context behavioral advertising, so there's nothing to opt out of under the CCPA, and we will never discriminate against you for exercising your rights. If you're in the EEA or UK, you can also complain to your supervisory authority.
Deleting or exporting your account
Both are self-serve in Settings → Account, no email required.
- Export. "Download JSON" gives you one file with your profile, conversations and messages, reports, quality records, and time-limited (1-hour) download links for your uploaded files and generated PDFs. Each export is recorded in the audit log.
- Deletion. "Delete account" asks you to confirm (and re-enter your password on password accounts), cancels any active Stripe subscription, removes live database records, and submits stored objects to a durable cleanup queue with retries. Provider backups age out on their verified schedules. If you're the only member of an organization, the organization and its data are deleted with you; if you're the only owner of an organization that still has other members, deletion is blocked until you transfer ownership or remove them.
What survives deletion: append-only audit logs (kept for security, as described above) and the billing records Stripe must retain for tax and accounting law. Prefer to do it by email? Write to contact@autopsai.com from your account address and we'll handle it within 30 days.
Security
Passwords are hashed with bcrypt (cost 12). SAP credentials are encrypted at rest with AES-256-GCM. Files live in private storage buckets reachable only through short-lived signed URLs. Access is scoped by organization roles, traffic is encrypted in transit, and an append-only audit log records changes. The full picture — including what's still on the roadmap — is on the security page. If a breach affects your data, we will notify you without undue delay.
Children
AutoOps is a business tool, not directed at children under 16, and we don't knowingly collect their data.
Changes to this policy
For material changes we'll email your account address before they take effect, and the "Last updated" date at the top always reflects the current version.
Contact
Privacy questions or requests: contact@autopsai.com.