Privacy Policy
Last updated: September 2026
OpsAgent is operated by MSApps. We respect your privacy and only collect what we need to run the service. This page explains what we collect, why, where it lives, and how to reach us.
1. What we collect
- Account data — name, work email, company. Provided by you when you sign up or fill the intake form.
- Operational data — content you ask OpsAgent to process (leads, candidates, invoices, messages). Stored only as long as needed to deliver the workflow.
- Usage data — this website uses four analytics and monitoring services: Google Analytics 4 (page views), PostHog (product analytics and session replay — a recording of your visit, hosted in the United States), Mixpanel (product analytics for the public hero funnel; client project token in page HTML), and Creeper RUM Vitals (page-speed measurements). Between them these receive your IP address, browser user-agent, language, time zone, device memory, the pages you visit and a randomly generated session identifier. Session replay masks the contents of form fields; other on-page text is recorded. We do not use any of this to build advertising profiles and we do not sell it.
- Cookies, browser storage and your choice — on your first visit we ask whether to allow analytics. Until you choose Accept analytics, Google Analytics, PostHog (including session replay), Mixpanel and Creeper do not start, anywhere in the world: the Google Analytics script is not even loaded, so no request reaches Google and no
_gacookie is set (Google Consent Mode, basic implementation). If you choose Essential only, or withdraw consent later, Google Analytics stays off on this and every later page and its cookies are removed. Once you accept, the services above set cookies and browser-storage keys, including a per-session identifier. We store your choice in your browser (oa_consent) for up to 12 months. You can change it at any time: Privacy settings. - Global Privacy Control — if your browser sends a Global Privacy Control signal (the
Sec-GPC: 1header, exposed to pages asnavigator.globalPrivacyControl), we treat it as Essential only, wherever you are: Google Analytics sets no analytics cookies, and PostHog, Mixpanel and Creeper do not start. We do not show the consent banner in that case, and we do not store a choice for you, so turning the signal off returns you to the normal flow. If you still want to allow analytics, you can choose Accept analytics under Privacy settings; that choice applies only while you have made it with the signal on.
2. What we don't do
- We don't sell personal data.
- We don't use customer data to train third-party models without explicit opt-in.
- We don't share your data across customers.
3. Where data lives
The OpsAgent application runs on Google Cloud (primary region: us-central1). This website is served by Firebase Hosting (Google) behind the Fastly CDN. Subprocessors include Anthropic (Claude API), Google (Cloud Run, Firebase Hosting, Google Fonts, Google Analytics, Gmail/Calendar), Fastly (CDN), PostHog (product analytics and session replay, United States), Mixpanel (product analytics, United States), Creeper SEO Audit (page-speed monitoring) and jsDelivr (script delivery). Each subprocessor processes this data under the terms it publishes for its own service.
4. Your rights
You can ask us to access, correct, export, or delete your data at any time. Email privacy@opsagents.agency and we'll respond within 30 days. EU/UK residents have GDPR rights; California residents have CCPA rights — both are honored.
5. Security
OpsAgent follows the SOSA framework — Secure Operations & Safety Assurance. See the SOSA whitepaper for the full controls. TL;DR: least-privilege agent permissions, full audit log of every tool call, encrypted secrets, no plaintext credentials in code.
6. Contact
Questions, requests, or concerns: privacy@opsagents.agency or michal@opsagents.agency.