How we collect, use and protect personal data across the Ovrin platform — including exactly how agent prompts and sandbox content are handled.
This Privacy Policy explains how Ovrin, Inc. ("Ovrin," "we," "us") collects, uses, discloses and protects information when you use ovrin.app, api.ovrin.dev, our dashboard, and the sandbox compute platform (together, the "Service"). It applies to visitors, registered account holders ("Customers"), and individuals whose personal data Customers process using the Service. If you are a Customer's end user or employee and have a question about data a Customer submitted, please contact that Customer directly — we act as their service provider for that data.
Capitalized terms not defined here have the meaning given in our Terms of Service or Data Processing Agreement.
Account information. Name, email address, organization name, and authentication credentials when you register. If you sign in via a third-party identity provider, we receive the profile fields that provider shares under its permission scope.
Billing information. Billing address and tax identifiers. Card and bank details are collected and stored directly by our payment processor, Stripe — Ovrin does not store full payment card numbers.
Usage and platform data. API requests and responses metadata, sandbox lifecycle events (create, run, kill timestamps), resource consumption (vCPU-seconds, GiB-seconds, egress bytes), template selection, error and crash logs, and IP address / user agent for security and abuse monitoring.
Sandbox content. The code, files, commands, and agent prompts/output that flow through a sandbox you create ("Customer Content"). This is Customer's data, not Ovrin's — see Section 3 for how we process it and Section 8 for retention.
Marketing site analytics. Standard web analytics (page views, referrer, approximate location from IP, device type) collected via cookies and similar technologies on ovrin.app. See Section 12.
Support communications. Content of support tickets, emails, or messages you send us.
The Service's core function is provisioning isolated compute so a coding agent (Claude Code, Codex, Gemini CLI, DeepSeek Harness, or a custom process you run) can execute inside it. This section explains specifically how that agent-related data moves.
You bring your own model access. Ovrin does not operate the underlying language models. When you create a sandbox with a template like claude-code, you supply your own API key for that provider (e.g. ANTHROPIC_API_KEY). Prompts and completions for that session are sent directly from the sandbox to the model provider under your account and their terms — Ovrin's network layer permits that specific egress but does not sit in the middle of, log the content of, or use those prompts/completions for its own purposes.
What Ovrin does process. We process Customer Content only as needed to operate the sandbox: allocating compute, enforcing the egress allowlist, streaming stdout/stderr back to your client, and — only if you explicitly call memory.add() — storing the text you chose to persist. We do not read, inspect, or use sandbox filesystem contents for any purpose other than fulfilling your API calls, and we do not train any model on Customer Content.
No training on your data. Ovrin does not use Customer Content, API traffic, or persisted memory to train, fine-tune, or evaluate machine learning models, ours or anyone else's.
Agent-directed actions are yours. Because an agent inside your sandbox acts on instructions you or your integration provide, any data it reads, generates, or transmits (subject to the egress policy) is Customer Content under your control, not data Ovrin collects independently.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (operating the Service you signed up for); legitimate interests (security monitoring, abuse prevention, product analytics), balanced against your rights; consent (marketing communications, non-essential cookies); and legal obligation (tax, accounting, law enforcement requests). Where Ovrin processes personal data within Customer Content as a processor on a Customer's behalf, the Customer determines the legal basis and our DPA governs that processing.
We do not sell personal data. We share information with:
Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Compute infrastructure, sandbox hosting, object storage | United States (us-east-1, us-west-2), European Union (eu-west-1) — region selectable by customer |
| Google Cloud Platform | Backup infrastructure and select regional capacity | United States, European Union |
| Anthropic, PBC | Processes prompts/output when a customer selects the claude-code template and supplies an Anthropic API key | United States |
| OpenAI, L.L.C. | Processes prompts/output when a customer selects the codex template and supplies an OpenAI API key | United States |
| Google LLC (Gemini API) | Processes prompts/output when a customer selects the gemini-cli template and supplies a Gemini API key | United States |
| DeepSeek | Processes prompts/output when a customer selects the deepseek-harness template and supplies a DeepSeek API key | People's Republic of China, Singapore |
| Stripe, Inc. | Payment processing and billing | United States |
| PostHog / analytics provider | Product usage analytics for the dashboard and marketing site | United States, European Union |
Ovrin is headquartered in the United States and uses infrastructure providers with regions in the United States and European Union. If you are located in the EEA, UK, or Switzerland, your data may be transferred to and processed in countries that have not received an adequacy decision. Where that occurs, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with our sub-processors, incorporated by reference into our DPA, as the transfer mechanism.
Enterprise customers with data residency requirements can request that sandbox compute and object storage be pinned to a specific supported region; contact sales@ovrin.app.
memory.add()) — retained until you delete it or close your account, then purged within 30 days.We protect information with encryption in transit (TLS 1.2+) and at rest (AES-256), gVisor kernel isolation between sandboxes, default-deny network egress, role-based access control on internal systems, and audit logging of administrative access to production infrastructure. Full detail is published at /security. No system is perfectly secure; see Section 11 of the Terms of Service for disclaimers.
Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; export it in a portable format; restrict or object to certain processing; and withdraw consent where processing is consent-based. California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale" or "sharing" — Ovrin does not sell or share personal data for cross-context behavioral advertising.
To exercise any of these rights, email privacy@ovrin.app. We will verify your request and respond within the time required by applicable law (typically 30 days). If a Customer submitted your data to the Service, we will generally direct your request to that Customer, who controls it, and support them in responding.
You may also lodge a complaint with your local data protection authority.
The Service is intended for business and professional use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@ovrin.app and we will delete it.
The marketing site (ovrin.app) uses strictly necessary cookies (session, load balancing) and, with consent where required, analytics cookies to understand aggregate traffic. The dashboard and API (api.ovrin.dev) use only strictly necessary session cookies/tokens for authentication — there is no third-party advertising tracking anywhere on the Service.
We may update this policy as the Service evolves or the law requires. Material changes will be announced by email to account holders or a notice on the dashboard at least 14 days before taking effect. The "Last updated" date above always reflects the current version.
Ovrin, Inc. · privacy questions: privacy@ovrin.app · data protection officer: dpo@ovrin.app · general: legal@ovrin.app