1. Scope and roles
This notice covers ProjectOS visitors, applicants, beta participants, account holders, and support contacts. SmartTeddy Inc is the controller of account, commercial, security, and support data. When an organisation submits project content for its own purposes, that organisation may be the controller and SmartTeddy Inc may act as its processor under the ProjectOS Data Processing Addendum.
2. Information we collect
- Account data, including email address, authentication identifiers, consent records, and account status.
- Project data, including objectives, charters, Project Roles, tasks, sources, instructions, questions, decisions, outputs, artifacts, evidence, budgets, usage records, exports, and attestations.
- Optional integration data, including repository identifiers, proposed code changes, pull-request metadata, and integration status.
- Commercial data, including plan, subscription, invoice, tax, and payment-status information. Payment-card details are handled by the payment processor and are not stored by ProjectOS.
- Support and beta reports, including messages, fault descriptions, and bounded incident references.
- Technical and security data, including timestamps, IP-derived request information, browser and device information, diagnostic events, and security logs.
3. How we use information
We use information to authenticate users; create, plan, execute, resume, export, and verify projects; enforce authority and spending limits; provide integrations; operate billing; prevent abuse; diagnose incidents; support users; improve reliability; comply with law; and enforce agreements.
4. AI-provider processing
ProjectOS does not send project content to an AI provider until the account holder accepts the in-product provider disclosure. When consent is active, ProjectOS sends the disclosed project context to OpenRouter, which routes it to the selected model provider. Usage records identify the run and model. Withdrawing consent prevents new AI calls but cannot retract prior provider processing.
5. Legal bases
Where applicable, we rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing ProjectOS, consent for AI-provider disclosure where required, and compliance with legal obligations.
6. Sharing and subprocessors
We share only what is needed with infrastructure and service providers: Supabase for database and authentication; Vercel for application hosting; SiteGround for business email; OpenRouter and the selected model provider for consented AI work; GitHub for explicitly approved repository work; Stripe for approved commercial billing; and professional advisers or authorities where legally required. We do not sell personal information or use project content for targeted advertising.
7. Retention and deletion
Active and archived account records remain available until the account holder deletes the account or the agreement requires earlier deletion. The application provides complete account export and permanent account deletion. Deletion removes live ProjectOS application records but cannot retract data already processed by an AI provider, erase an external pull request, recover a downloaded file, or immediately remove encrypted infrastructure recovery copies. Recovery copies age out under provider schedules and are not restored except for disaster recovery.
8. International processing
ProjectOS is operated by a United States company and may process data in the United States and other countries used by its providers. Where required, transfers use contractual or other lawful safeguards. Organisational customers may request the Data Processing Addendum.
9. Security
ProjectOS uses private authentication, row-level ownership controls, bounded provider consent, hard cost ceilings, security headers, restricted integrations, durable audit records, encrypted provider infrastructure, and tested backup and recovery procedures. No system is perfectly secure; contact us immediately if you suspect misuse.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, and to withdraw consent. The application provides export, consent withdrawal, and deletion controls. We may need to verify identity and may retain limited information where law requires it.
11. Children
ProjectOS is a business service and is not intended for anyone under 18. We do not knowingly create accounts for children.
12. Changes
We may update this notice as ProjectOS or applicable requirements change. We will post the effective date and provide additional notice where a material change requires it.
13. Contact
Privacy requests: admin@smartteddy.ai
Support: support@smartteddy.ai
SmartTeddy Inc
2261 Market Street, STE 88876
San Francisco, CA 94114
United States