Privacy policy
What Operatica collects, what it infers, who else touches it, how long any of it lasts, and how you take it back. Whatever this policy says, the product does exactly that.
We do not sell your data, we run no third-party advertising trackers, and nothing you keep in a workspace trains a model. Available in the United States only, for adults 18 and over.
What this policy covers
Operatica holds some of the most sensitive information an organization has: your work, your clients' confidential material, your commercial and financial records, and the inferences the intelligence draws over time. This policy covers all of it, in the product and on this website.
One design rule sits under everything below: protection is uniform. Every payload in a workspace gets the strictest handling described here, so no classifier ever has to be right for your data to be safe.
Who we are, and which hat we wear
Operatica LLC, New Jersey, United States, is responsible for the product. Reach us at legal@operatica.ai.
For your own account and your own workspace, we decide how the information is handled and we handle it as described here.
For a workspace that belongs to an organization, the organization decides. It is the controller of what its members put there, and we are the processor acting on its instructions. If you are a member of someone else's workspace and want to know how they use it, ask them first, and ask us if you cannot get an answer.
What we collect
- Account information: your name, email address, your age attestation, and your plan.
- Workspace content: the spaces, flows, modules, documents, notes, decisions, plans, logs, wires, canon, and brain entries you and the intelligence create, and files you upload.
- Conversation: what you say to Verdi and to principals, and what they say back.
- Connected services: what a service you connect makes available to your workspace, on the scope you granted.
- Operational records: sign-ins, confirmations of actions, machine runs, errors, and the security logs that keep the account safe.
- Billing details, handled by our payment processor. We see the plan, the invoice, and the last four digits, never the full card.
We do not buy information about you, and we never enrich what you told us from outside sources.
Sensitive categories, and consent that stands alone
Spaces are yours to name and shapes are minted as you need them, so nothing in the product decides for you what counts as sensitive. Before your first module is written you see a plain-language screen, separate from accepting the Terms, that names the categories you may choose to place here, financial and commercial records, confidential client material, personal data about other people, and the inferences drawn from them, what the intelligence does with them, and who processes them.
That consent is asked for on its own. Nothing is pre-checked, nothing is bundled, no permission is inferred from silence, and declining costs you nothing except the feature that genuinely needs the data. We ask again when the purposes change.
What the intelligence works out about you
Operatica learns patterns from what you keep here so its guidance is about your actual work rather than a generic case. A learning in your canon, an entry in a brain, an estimate against an actual, a digest on a module: these are inferences, and we treat them as regulated information, not as a byproduct.
A derived claim carries the sensitivity of what it came from. An inference drawn from a client’s confidential material is confidential material, even though nobody typed it.
Every inference shows its source, and you can see it, dispute it, and correct it. Corrections supersede rather than overwrite, so the history of what the system believed stays visible to you.
Where estimates are compared with actuals in a shared workspace, that is a measurement of the work. It is never presented as a rating of a person and never feeds an automated decision about anyone.
Why we use it
- (a)To run the product: to compose your canvases, answer you, keep your record, and do the work you asked for.
- (b)To keep it secure and reliable: authentication, abuse prevention, backups, and debugging.
- (c)To bill you, and to send the transactional messages an account needs.
- (d)To meet a legal obligation, or to protect someone from harm.
Support staff reach workspace content only when you ask us to look at something, or when an urgent security or integrity problem requires it. Those accesses are logged.
The AI pipeline, and who processes for us
Operatica is built on named third parties: a database host, a hosting layer, a model routing layer with the model providers behind it, an email sender, and a payment processor. When the intelligence works on something, the relevant content is sent to a model provider to compute the answer.
Every one of them is under contract to process only for us, on terms that exclude training on your content. Routing is pinned to vetted providers, and a provider cannot be added silently. Each is named, with what it does and what it can reach, in the Subprocessor list, which we keep current.
An outside application you authorize is not one of our subprocessors. It is a recipient you directed, it reads only what you may read, and once data leaves that way it is outside our control. Grants and their revocation live in your settings.
What we never do
- We do not sell or share your information, and we run no advertising business.
- We do not use your content or your inferences to train or evaluate a model, ours or a vendor's.
- We do not let inferences leave the workspace that made them, in identifiable form or aggregated for anyone else's benefit.
- We do not reuse a customer's client material anywhere but that customer's workspace.
- We claim no certification we do not hold, and no security standard we cannot evidence.
How long we keep things
We will not tell you the product forgets by default, because it does not. It is built to remember what matters about your work. What bounds that memory is four mechanics, and they are commitments rather than settings:
- The transcript is never the record. Conversation turns compact away; what persists is the distillation that attached to something.
- The fences hold. Residue from a private flow never promotes into shared memory.
- Old state ages. Closed work archives and compacts against an explicit budget instead of accumulating forever.
- You can purge by source. Everything that came from one connection, one space, or one client relationship can be removed together.
Operational and billing records are kept as long as the law requires, and no longer.
Deletion is real
Inside the product, the system never deletes your work on its own judgment. It supersedes, archives, and lets things fade. That is a design rule about the software, not a limit on your rights.
When you ask us to delete, we delete. The workspace is purged, the purge cascades through backups on a documented schedule, and we tell you when it is complete. Deletion is complete or it is not deletion: no mirror, wire, digest, canon or brain entry, calibration record, or provenance trail is left pointing at erased content.
Scope follows the role. Purging a whole workspace belongs to its owner, ending one client relationship purges that space, and leaving a workspace removes you and the residue attributable to you without destroying the team's record. We offer no litigation hold, and we do not slow-walk a request on the chance that someone might want the data later.
Export is as real as deletion
You can take everything, in a usable format, whenever you want: spaces, flows, modules and their contents, wires, mirrors as references, schemas, canons, brains, logs, decisions, the record of what you confirmed, provenance, and the inferences.
The export format advances with every change that adds a new kind of your data, so a new feature cannot quietly fall outside it. Owner export covers the whole workspace; member export covers what that member may see and what is theirs.
Your rights, and where the buttons are
You can see what we hold, correct it, export it, delete it, withdraw a consent, and revoke a grant. Every one of those has a working control in settings rather than a form to fill in, and we complete requests within 45 days.
We honor universal opt-out signals, including Global Privacy Control. Since we sell and share nothing, there is little for the signal to do, and we honor it anyway.
Depending on where you live you may have further rights, including the right to appeal a refusal. Write to legal@operatica.ai and we will answer. Exercising a right never costs you service or a worse price.
People who never signed up
Your workspace will hold your own record of other people: colleagues, clients, and people inside a client's organization. We hold that record and nothing more. We never enrich a profile of someone from outside sources, never build one beyond what you put there, and never contact anyone except through an action you confirmed.
Headcounts, org charts, attendance records, and performance material about a client's people are personal data belonging to people who never agreed to be here. They get the same strict handling as your own, they stay in the space that holds them, and they are included in its purge.
Operatica is for adults, and children's data does not belong in a workspace. If we learn we hold information about someone under 18, we delete it.
Security
Content is encrypted in transit and at rest. Access is separated at the database row so one workspace cannot reach another, that separation is tested on every change, and internal access is least privilege and logged. Code the intelligence writes runs sandboxed, with no network and no filesystem.
No system is perfect, and we do not use words like military grade or bank grade. Report a vulnerability to legal@operatica.ai and we will work with you.
Where your data lives
Operatica is offered in the United States only, and content is stored and processed in the United States. Each processing location is stated in the subprocessor register.
Your clients can be anywhere, so material you bring may carry rules from its own home. Our design bar is set above the strictest law we plausibly meet, which is what makes that survivable.
Legal process, and what we do when asked
We require valid legal process, we narrow the scope of what we hand over, we notify you unless we are prohibited from doing so, and we log every response. A private flow is not an evidence surface we can open, and we do not offer workspace owners access to their members' private flows.
If something goes wrong
If your information is exposed, we will tell you and the regulators the law requires, within the windows the law sets, with what we know and what we are doing about it. Business customers get what they need to meet their own notification duties.
Changes to this policy
When we change how we handle your information we update this policy, move the date above, and tell you if the change is material. Where a change needs your consent, we ask for it rather than assuming it from your continued use.
Contact us
Operatica LLC, New Jersey, United States. Privacy questions, rights requests, and appeals reach us at legal@operatica.ai. We read what you send.