Privacy Policy
We keep the bare minimum it takes to run OpenShore, and we tell you exactly what that is.
Last updated 11 October 2026.
The short version
- Your prompts, chats, code, files, and API keys never reach an OpenShore server. They leave your device only for a service you choose, listed in section 4: a cloud model sees the turns it answers, and each API key is stored only on the device you add it to and sent only to its provider.
- You can chat without an account. If you create one, we keep your email, a few preferences, and what is listed below, and nothing else.
- No telemetry, no analytics, no advertising, no tracking, and no selling or sharing of your data with anyone.
- Everything the app sends off your device is listed in the app, under Settings, Privacy, What leaves this device.
- You can delete your account in the app at any time.
1. Who we are
OpenShore is made by Open Shore, LLC ("we", "us"), which decides how the little data described here is used. Write to us at support@openshore.ai. This policy covers the OpenShore apps we build and ship for iPhone, iPad, macOS, Windows, and Linux, and this website. A build you or others make from the open source code is outside it.
2. What we never collect
We do not collect your prompts, chats, model answers, code, files, Vault notes, API keys, contacts, location, photos, video, audio, or usage analytics. We do not keep IP addresses in our own records. Our sign-in service, run by Supabase, keeps a log of sign-ins; we keep one week of it, and clear the network address and browser name from sign-in sessions each day. No analytics, crash-reporting, advertising, or tracking code runs in the app or on this website, and this website sets no cookies. If you sign in on this website, your sign-in session is kept in your own browser's storage.
3. What we keep, why, and for how long
Only if you create an account, or turn on a feature that needs it:
- Your account: your email address, a password hash, and an account id, so you can sign in. Kept until you delete your account.
- Eight preferences (your appearance, effort, Humanize Writing, Chain of Thought, notices, and voice settings), so they follow you to your other devices. Never your chats, prompts, projects, keys, or addresses. Kept until you delete your account.
- A record of a blocked request, if our safety guardrail blocks something while you are signed in: its category, tier, time, a keyed one-way hash of the request, and whether a local or cloud model was in play. Never the request itself and never the name of anyone it was about. Kept for 180 days, longer only under a legal hold. Enforcement steps taken on an account are kept for two years.
- A notification token, only if you allow notifications on your iPhone, so we can tell you when work on your computer finishes or needs you. It is stored with your account id. For each notification we relay only a session id, its kind, and a number to Apple, never the words of a chat. Our log of sent notifications is kept for 2 days, and a token not refreshed in 180 days is deleted.
- After you delete your account, we keep only two things, and only when they apply: a one-way hash of your email if we had ended the account for abuse, so it cannot return under the same address (two years); and any record under a legal hold, until the hold ends.
When you connect GitHub, GitLab, or Bitbucket, the sign-in passes through our server because those services require a secret only a server can hold. Your access token passes through when you connect and each time it is refreshed; we keep no copy and log none of it.
OpenShore sells nothing. We take no payments and keep no purchase records. The code is open source under the Apache License 2.0.
4. What your device sends to others, at your direction
These go straight from your device to the service, not through us, under that service's own privacy policy:
- Web search: the words of a search, and the network address any web request carries, to DuckDuckGo unless you add a key for Brave, Tavily, or Perplexity, or point the desktop engine at your own search server. Never the rest of your chat, never your files. Off until you allow it: the app asks the first time a model wants to search, and you can change it in Settings, Web search. Once a local model in a chat has read a private note, or its project pins one, each search it writes shows its words and asks first. Crew routines on your computer follow the same choice, while your computer is on, and only search; they never open pages.
- Web pages: on your computer, a page the coding agent opens, to that site. It asks first unless you set Opening web pages to Always in Settings, Approvals, and a page on your own network always asks.
- Cloud models: your chat, and the notes and files it draws on, to Anthropic, OpenAI, Google, Moonshot, or Perplexity on your own key, or to a model server you connect. Only when you pick a cloud model or place one in your Stack, and only on the turns it answers; on your computer, the coding agent asks first in each task. OpenShore never sends private notes to a cloud model. A command you run or allow, or a change you allow, can still carry their words to one. An Ollama model whose tag says cloud (like kimi-k3:cloud) runs on ollama.com under your own Ollama account, so it counts as a cloud model.
- Photos and video: a photo or screenshot you attach goes only to the model that reads it. A video is turned into still frames on your device first; the video itself, and its sound, are never sent.
- Model downloads: a request for the model you picked, to Hugging Face or Ollama. For a model that runs on your computer, nothing about you rides along.
- Your repositories: to GitHub, GitLab, or Bitbucket, on your own access.
- Your computer: your phone talks to your own computer over your own Tailscale network.
- Updates: the desktop app asks GitHub whether a newer version exists (your version and network address), at launch and every 30 minutes. Nothing downloads until you click Update.
- The model list: when you open Stack, at most once a day, the app reads the list of available models from openshore.ai. Nothing about you rides along; the server sees your network address, as any website does.
- Speech: on iPhone and iPad it is turned into text on the device, and the audio never leaves it. On the desktop and the web, the mic uses the speech service built into the app or your browser (Google's, in Chrome and the desktop app).
5. Who processes data for us
- Supabase runs our account service and database on Amazon Web Services in the United States (East US, North Virginia), and sends the sign-up and password emails.
- Apple delivers notifications and distributes the iPhone app.
- Cloudflare serves this website and the model list, and forwards mail sent to support@openshore.ai.
- Proton hosts the mailbox where we read and answer that mail.
- GitHub hosts the desktop downloads and answers update checks.
Like any web service, these providers see your IP address in transit and keep short operational logs under their own policies. Our database is in the United States. If you are elsewhere, your account data is transferred there, under these providers' standard contractual protections; mail you send us is held by Proton, a Swiss company, under its own encrypted-storage terms. We never sell your data and never share it for advertising.
6. Why we are allowed to
Your account, preferences, and notifications are kept to provide the service you asked for. Notifications only run with your permission, which you can take back in your phone's settings. Blocked-request records and enforcement are kept for our legitimate interest in keeping the product from being used for abuse, and to meet legal duties to report child sexual abuse material.
7. Your rights
- Delete: in the app, Settings, Account, Delete account. It erases your account from our server.
- See and take a copy: email us and we will send everything we hold about you.
- Correct or object: email us.
- On your devices: your chats and files are yours to clear in the app or by uninstalling it.
- Complain: you may complain to your local data protection authority.
We answer within 30 days.
8. Security
Everything we send travels over TLS. On your device, chats, settings, and session journals are encrypted at rest (AES-256) under a key in your system's keychain; your Vault notes and code stay plain files you own. Our database lets each account read only its own rows. Desktop updates are checked against our signing keys before they install. If something goes wrong, we will tell the people affected.
9. Children
OpenShore is not for children under 13, or under 16 in the European Economic Area and the United Kingdom, and we do not knowingly hold their data. If you believe a child has an account, write to us and we will delete it.
10. Law enforcement
We hand over data only when the law requires it, and we hold very little: never a prompt or its content. A report we are required to make carries the account, the category, and the hash.
11. Changes and contact
We will update this policy when the product changes, change the date above, and say so in the app for any material change.
Privacy questions and requests support@openshore.ai