This Privacy Policy explains how Opsentry LLC (“opSentry”) collects, uses, shares, and protects personal data in connection with the Service. It covers (a) personal data of our own account holders and users, and (b) personal data contained in Customer Data that customers provide or connect (including data about their partners and their partners’ personnel). For most Customer Data, opSentry acts as a processor/service provider on the customer’s behalf; the customer is the controller/business responsible for its own privacy notices and lawful basis. For account and website data, opSentry is the controller.
a. Account & profile: name, email, hashed password, workspace/business name, role.
b. Team & workspace: member emails, roles, invitations.
c. Customer-provided partner data: partner/customer names, integration scopes, status, notes, and any custom fields you upload (which may include your partners’ personnel names and contact details).
d. Connected-tool content: data ingested from tools you connect — e.g., commit/release text (GitHub), issues/sprints/versions (Jira), and, where connected, support-ticket subjects, descriptions, and recent conversation/comment history (HubSpot; Zendesk where enabled).
e. Ingested changelog text: raw text you or your systems submit.
f. Usage, device & security data: session tokens, log-in timestamps, IP address, and technical logs. We do not use third-party advertising or analytics trackers; the only browser storage is a small number of strictly-necessary localStorage values (sign-in session and basic UI state), none used for tracking.
g. Integration configuration: webhook URLs and encrypted credentials/tokens for connected tools.
h. Billing data: handled by our payment processor (Stripe); we store only subscription/customer identifiers, not card numbers.
i. Sensitive data. We do not seek to collect, and ask that you not submit, special-category or sensitive personal data (such as government identifiers, health, financial-account, biometric, or precise geolocation data). If such data appears in Customer Data you connect, you are responsible for ensuring you have a lawful basis to provide it.
We use the information we collect to provide, operate, secure, and improve the Service; to generate alerts and AI-assisted analysis; to run Partner Tests you initiate or configure; to send transactional and opt-in notification emails; to process payments; to enforce our Terms and AUP and protect against misuse; and to comply with law.
2A. Legal Bases (EEA/UK). Where the GDPR or UK GDPR applies to processing for which opSentry is a controller, we rely on: performance of a contract (to provide the Service and account functions); our legitimate interests (to secure, operate, and improve the Service, prevent misuse, and communicate about the Service), balanced against your rights and freedoms; compliance with legal obligations; and consent where required (which you may withdraw at any time). Where opSentry acts as a processor for Customer Data, the customer (as controller) is responsible for establishing the lawful basis for that processing.
To provide AI features, we transmit certain Customer Data to our AI sub-processor, OpenAI, L.L.C. This includes changelog/commit/issue text and, where you connect a support tool, support-ticket subject, description, and recent conversation/comment content, as well as prompts used to draft suggested replies. We apply input-sanitization before transmission, but you should not submit content you are not authorized to disclose. AI processing cannot be separately disabled while using AI features; rule-based (non-AI) alerting is available. AI output is advisory (see Terms § 4).
3.1 No solely automated decisions with legal effect. opSentry does not use AI features to make decisions that produce legal or similarly significant effects about individuals without human involvement. AI output is advisory and is reviewed by you before you act on it (see Terms § 4).
We share personal data with the following categories of recipients:
We also receive your verified email and name from your identity provider (Google, Microsoft, or GitHub) if you use social sign-in. A current sub-processor list is available on request. We provide advance notice of new sub-processors to customers who have a DPA with us, as described in the DPA.
For Partner Tests, we collect and log: verified domains; the host/target of requests (host-level; we do not retain full URLs or request bodies beyond what is necessary to operate the feature); run metadata (timestamp, status, latency, result summary, partner/workspace); and domain-authorization events (acting user, timestamp, action, domain(s), whether the authorization attestation was accepted, and the AUP version/hash accepted). Response snippets are scrubbed of secrets and internal IP literals. See § 7 for retention.
We use administrative, technical, and physical safeguards including: bcrypt password hashing; Fernet (authenticated) encryption at rest for integration secrets and tokens; TLS in transit; per-workspace tenant isolation with role-based access control; session expiry and invalidation; and brute-force lockout. The Service is hosted in the United States. We do not currently hold a SOC 2 attestation or offer multi-factor authentication, and we do not represent otherwise. No method of transmission or storage is 100% secure.
We retain personal data for as long as needed to provide the Service and as required by law. Following a verified account-deletion request to support@opsentry.ai, we will begin deletion or de-identification within 30 days (subject to legal holds and rolling backups overwritten within 30 days). Exception: Partner Tests domain-authorization and configuration audit records are append-only and retained for legal-defensibility purposes for no longer than twenty-four (24) months, even after a domain or check is removed, and are deleted on workspace deletion subject to law.
Categories of personal data we process, and with whom we share. The categories of personal data we process are listed in § 1. We share personal data with the categories of recipients listed in § 4 (our AI provider, payment processor, email provider, hosting/infrastructure providers, your connected tools at your direction, and legal/safety recipients).
Texas residents (TDPSA). You may: confirm whether we process your personal data and access it; correct inaccuracies; delete it; obtain a portable copy; and opt out of targeted advertising, the sale of personal data, or certain profiling. opSentry does not sell personal data and does not use it for targeted advertising. How to submit a request: email support@opsentry.ai. We will respond within 45 days, and may extend once by an additional 45 days where reasonably necessary (with notice). Appeals: if we decline a request, you may appeal by emailing support@opsentry.ai; we will respond to an appeal within 60 days. If your appeal is denied, you may submit a complaint to the Texas Attorney General at the address/form the Attorney General provides.
California (CCPA/CPRA) and EU/UK (GDPR/UK GDPR) residents have the corresponding rights under those laws (access, correction, deletion, portability, opt-out, and, for the EU/UK, objection/restriction). For Customer Data where opSentry acts as a processor/service provider, we will refer requests to the relevant customer (controller/business) and assist as required. We will not discriminate against you for exercising your rights. You may use an authorized agent to submit a request on your behalf, subject to our verification of the agent’s authority and your identity.
The Service is operated in the United States. Where we transfer personal data from the EEA/UK/Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses. See the DPA.
If we become aware of a breach of security involving sensitive personal information, we will notify affected individuals and, where applicable, regulators as required by law, including Texas Business & Commerce Code § 521.053 (notice without unreasonable delay and no later than 60 days after determination; notice to the Texas Attorney General within 30 days where 250 or more Texas residents are affected). Where opSentry holds data on behalf of a customer (as processor), we will notify the customer without undue delay after discovery.
The Service is directed solely to business users who are at least 18 years old and is not intended for or directed to children. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from a person under 18, we will delete it.
We send transactional and relationship emails (e.g., verification, password reset, account and subscription notices) and, only to addresses that have opted in, alert-notification emails. These are not marketing emails, and we will not use false or misleading header information or deceptive subject lines in any email we send. If we later send commercial email, it will comply with the CAN-SPAM Act, including a valid physical address and a working opt-out. You can unsubscribe from alert notifications by managing subscribers in-product or contacting us.
12A. Cookies and Local Storage. We do not use third-party advertising or analytics cookies. The only browser storage we use is a small number of localStorage values that are strictly necessary to keep you signed in and to remember basic in-product state (such as whether you have dismissed a panel); none are used for tracking or advertising. Because we do not track users across third-party sites, we do not respond to browser “Do Not Track” signals.
We may update this Policy and will post the new effective date; material changes will be notified. You can identify the current version by the “Last updated” date at the top.
Contact:
Opsentry LLC
5473 Blair Rd, Ste 100, #590615, Dallas, TX 75231
support@opsentry.ai
Privacy questions may be directed to privacy@opsentry.ai.