OpenWorld

Privacy policy

This policy explains what data OpenWorld collects, why, and how to have it deleted.

Effective
August 31, 2026
Last updated
August 31, 2026
Interim policy — preview release. OpenWorld is an early-stage product and is not yet operated by an incorporated company. This policy is a good-faith placeholder covering our early testing users. Once we incorporate, it will be replaced by a policy issued by that company, and we will post the replacement here before it takes effect.

1. Who we are

OpenWorld is a governed context layer: organizations publish skills and datasets, and OpenWorldserves that context into AI assistants such as Claude, ChatGPT, or Cursor. It is currently operated by the small team building it, who can be reached at [email protected]. There is no incorporated entity behind it yet.

2. What we collect

  • Sign-in data. There is no password login. When you sign in with a Google Workspace or Microsoft work account, we receive your email address, your name, whether your email is verified, the stable user identifier your provider assigns, and your organization’s domain or tenant ID. We store the claims your provider sends in the sign-in token.
  • Content you upload. Datasets, skill instructions, and files you add, plus any output an assistant saves back. What this contains is entirely your choice.
  • Activity records. A log of which tool was called, by which token, against which object, with timing and outcome. Free-text values such as search terms and notes are replaced with [redacted] before the log is written.
  • Cookies. Only what is needed to keep you signed in. They are HTTP-only, signed, and expire within 12 hours for the console and 7 days for the account portal. We use no analytics, advertising, or tracking cookies.

We use your IP address only in memory, to rate-limit sign-in attempts. It is not stored in our database.

3. How we use it

We use this data solely to run the service: to sign you in, to map you to the right workspace, to enforce permissions, to serve your content to the assistants you authorize, to give you an audit trail, and to keep the service secure and working.

We do not sell your data, we do not use it for advertising, and we do not use your content to train AI models.

4. Google and Microsoft account data

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request only your basic profile and email so we can identify you and match you to your organization. We do not transfer that data to anyone except as needed to provide the service, and we never use it for advertising or sell it. The same applies to data received from Microsoft.

5. Who else sees it

  • Google and Microsoft, who authenticate you under their own privacy policies.
  • Our hosting and storage providers, who process data on our behalf to run the service.
  • The AI assistants you authorize. When an assistant requests your content, we return it to that assistant. From that point it is handled under that provider’s terms, not ours.
  • Anyone holding a share link. Deliverables can be shared through public links that work without signing in, and stay live until revoked. Treat a share link as sensitive as its contents.

We may also disclose data if the law requires it.

6. Keeping and deleting data

We keep data while your workspace is active. Deleting a dataset removes its table and uploaded file, and deleting a workspace removes its projects, datasets, users, and tokens.

To have your data deleted at any time, email [email protected] and we will remove it. Because this is a preview, we may also delete data or shut down the service with reasonable notice.

7. Security

Traffic is encrypted in transit, API token secrets are stored only as hashes, session cookies are signed and short-lived, and every query is scoped to your workspace. That said, this is preview software from a pre-incorporation team and we cannot guarantee its security. Please do not upload confidential, regulated, or sensitive personal data during the preview. Report any vulnerability to [email protected].

8. Your choices

You can ask us what we hold about you, correct it, export it, or delete it. Email [email protected] and we will respond as promptly as we can. If the data sits inside an organization’s workspace, contact that organization first, since they control it.

9. Children

OpenWorld requires a work account and is not intended for anyone under 16. We do not knowingly collect data from children.

10. Changes and contact

We will update this policy as the product changes, and the date at the top will reflect the current version. See also our Terms of service. Questions go to [email protected].