Egoist Machines, Inc. ("Egoist," "we," "our," or "us") operates the OreCloud website, console, APIs, SDK and CLI endpoints, hosted MCP endpoints, and related online services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Services or otherwise interact with us online.
1. Information we collect
We may collect the following categories of information:
- Contact and account information, such as your name, email address, password, organization details, invite codes, and API token metadata.
- Billing information, such as your plan, billing status, and transaction records. Payments are handled by our payment processor; we do not store full payment-card numbers.
- Customer Content: the documents, memories, metadata, and vectors your application stores in the Services on behalf of its end users, together with optional provenance identifiers (such as agent and run ids) your application attaches.
- Communications, such as access requests, support messages, and other information you send to us.
- Device and usage information, such as IP address, browser type, pages viewed, events, session identifiers, analytics identifiers, and error or diagnostic information.
- Service telemetry: request counts, byte sizes, latency, resource identifiers, and timestamps. Error monitoring may additionally receive exception types, messages, stack traces, and request identifiers. None of these paths read stored document text, queries, or embeddings.
- Cookie and similar technology data, including data collected through analytics tools such as PostHog.
2. How we use information
We may use the information we collect to:
- operate, maintain, secure, and improve the Services;
- process Customer Content solely to provide the Services: embedding, indexing, serving, backing up, restoring, and exporting it on your instructions;
- manage accounts, invites, tokens, plans, and billing;
- respond to questions, requests, and support inquiries;
- protect against spam, fraud, abuse, unauthorized access, and security issues;
- comply with legal obligations and enforce our agreements.
We do not use Customer Content to train machine-learning models, and we do not use it for advertising. We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising.
3. Customer Content
Customer Content belongs to our customers. Each end user's store is its own isolated database instance. Serving reads of stored text require both a key scoped for text access and the store's text-exposure flag (memory stores enable that flag when they are provisioned); whole-store exports require a text-scoped credential, and signed-in members of your organization can read exposed text in the console. Our telemetry and audit logs record counts, sizes, latency, identifiers, and timestamps, and error reports carry exception details, never your stored documents.
For Customer Content, we act as a processor or service provider on the customer's instructions; the customer is responsible for its own privacy notices to its end users. Customers control when data is deleted; the service's retention windows are platform defaults. Committed snapshots stay restorable for 14 days by default, and deleted stores and organizations stay restorable for 7 days. Deletion takes effect immediately for serving and completes asynchronously: residual copies in historical snapshots, ingest segments, and transient caches are purged within those windows. The erase option removes a store's restore window immediately. Customers can export unencrypted stores at any time; encrypted stores are served but cannot currently be downloaded directly.
4. How we share information
We may share information with:
- service providers that help us with cloud hosting and infrastructure, databases and storage, payment processing, email delivery, analytics, error monitoring, and website operations;
- third-party services you choose to connect, such as MCP clients, agent tools, or websites reached through outbound links;
- professional advisors such as lawyers, auditors, accountants, and insurers;
- government authorities, regulators, or law enforcement where required by law or to protect rights, safety, and security;
- a buyer, investor, or successor in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
5. Cookies and similar technologies
We use cookies and similar technologies to keep the site and console working, understand engagement, and improve performance. A session cookie is essential for console sign-in and lasts up to seven days. Analytics cookies and identifiers, including PostHog's, help us understand usage and may persist in local storage and cookies for up to a year. You can use browser settings to block or delete cookies, though some Services may not work properly. Where required by law, we will provide additional cookie or tracking choices.
6. Your choices
- We do not currently send marketing email. If we begin doing so, every marketing message will include an unsubscribe link.
- You can contact us to request access, correction, or deletion where applicable law provides those rights.
- You can delete stores or your whole organization from the console, CLI, or API at any time; the fixed production and testing environments delete with the organization.
To submit a privacy request, email privacy@ego.ist from the address associated with your account, or include that address in your request. We may need to verify your identity before acting on the request. If your information is in Customer Content stored by one of our customers, we may refer your request to that customer.
7. California privacy rights
If you are a California resident, you may have rights under California law, including the right to know what personal information we collect, use, disclose, sell, or share; request access to or portability of personal information; request deletion; request correction; opt out of sale or sharing; limit certain uses of sensitive personal information; and not be discriminated against for exercising your rights. We collect the categories described in Section 1 for the purposes described in Section 2 and disclose them to the recipients described in Section 4. To submit a privacy request, contact us at privacy@ego.ist.
8. EEA and UK users
If you are in the European Economic Area or the United Kingdom, you may have additional rights under applicable data protection law. Egoist Machines, Inc. is the controller of account, billing, usage, and communications information, and processes Customer Content on the instructions of the customer that stored it. Our legal bases may include your consent, our legitimate interests (operating and securing the Services, preventing abuse, understanding usage), performance of a contract, and compliance with legal obligations. Subject to applicable law, you may have the right to request access, correction, deletion, restriction, or portability, to object to certain processing, and to withdraw consent. You may also lodge a complaint with your local data protection authority. We are based in the United States, and information may be processed in the United States or other countries where we or our service providers operate; where required by law, we use appropriate safeguards for international transfers.
9. Data retention
We retain account, billing, usage, and communications information for as long as reasonably necessary for the purposes described in this Policy, including security, legal obligations, disputes, and agreement enforcement. Customer Content follows the retention windows described in Section 3; deletion completes asynchronously within those windows.
10. Security
We use reasonable administrative, technical, and organizational measures to protect information, including HTTPS encryption for browser and API traffic to our services. No method of transmission over the internet or method of storage is completely secure, and we cannot guarantee absolute security.
11. Children's privacy
Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If we do, we will post the updated version here and revise the effective date above.
13. Contact us
Questions about this Policy reach us at the address below.