Privacy Policy

We keep the bare minimum it takes to run OpenShore, and we tell you exactly what that is.

Last updated 11 October 2026.

The short version

Your devices talk over your own private network. A cloud model answers only when you pick it or place it. YOUR PRIVATE NETWORK · TAILSCALE Computer engine, runs the models encrypted Phone remote control, viewer local work and keys stay here your pick Cloud your key only when picked No telemetry. No analytics. No ads.
What stays, what leaves. Everything inside your private network stays yours. What leaves is a short, published list: turns for a cloud model you pick or place, on your own key or account; the words of a web search, once you allow it; update checks and the model list; and, if you sign in, your account and a few preferences.

1. Who we are

OpenShore is made by Open Shore, LLC ("we", "us"), which decides how the little data described here is used. Write to us at support@openshore.ai. This policy covers the OpenShore apps we build and ship for iPhone, iPad, macOS, Windows, and Linux, and this website. A build you or others make from the open source code is outside it.

2. What we never collect

We do not collect your prompts, chats, model answers, code, files, Vault notes, API keys, contacts, location, photos, video, audio, or usage analytics. We do not keep IP addresses in our own records. Our sign-in service, run by Supabase, keeps a log of sign-ins; we keep one week of it, and clear the network address and browser name from sign-in sessions each day. No analytics, crash-reporting, advertising, or tracking code runs in the app or on this website, and this website sets no cookies. If you sign in on this website, your sign-in session is kept in your own browser's storage.

3. What we keep, why, and for how long

Only if you create an account, or turn on a feature that needs it:

When you connect GitHub, GitLab, or Bitbucket, the sign-in passes through our server because those services require a secret only a server can hold. Your access token passes through when you connect and each time it is refreshed; we keep no copy and log none of it.

OpenShore sells nothing. We take no payments and keep no purchase records. The code is open source under the Apache License 2.0.

4. What your device sends to others, at your direction

These go straight from your device to the service, not through us, under that service's own privacy policy:

5. Who processes data for us

Like any web service, these providers see your IP address in transit and keep short operational logs under their own policies. Our database is in the United States. If you are elsewhere, your account data is transferred there, under these providers' standard contractual protections; mail you send us is held by Proton, a Swiss company, under its own encrypted-storage terms. We never sell your data and never share it for advertising.

6. Why we are allowed to

Your account, preferences, and notifications are kept to provide the service you asked for. Notifications only run with your permission, which you can take back in your phone's settings. Blocked-request records and enforcement are kept for our legitimate interest in keeping the product from being used for abuse, and to meet legal duties to report child sexual abuse material.

7. Your rights

We answer within 30 days.

8. Security

Everything we send travels over TLS. On your device, chats, settings, and session journals are encrypted at rest (AES-256) under a key in your system's keychain; your Vault notes and code stay plain files you own. Our database lets each account read only its own rows. Desktop updates are checked against our signing keys before they install. If something goes wrong, we will tell the people affected.

9. Children

OpenShore is not for children under 13, or under 16 in the European Economic Area and the United Kingdom, and we do not knowingly hold their data. If you believe a child has an account, write to us and we will delete it.

10. Law enforcement

We hand over data only when the law requires it, and we hold very little: never a prompt or its content. A report we are required to make carries the account, the category, and the hash.

11. Changes and contact

We will update this policy when the product changes, change the date above, and say so in the app for any material change.

Privacy questions and requests support@openshore.ai