Last Updated: May 27, 2026
Odigos ("we", "our", or "us") respects your privacy. This Privacy Policy explains what we collect, how we use it, and what choices you have.
This policy applies to visitors to odigos.one, customers of our managed hosting service, and consulting clients. It does not apply to self-hosted deployments of the open source software -- see Section 6.
We collect only what is necessary to operate the service. We do not collect information for resale or for advertising.
When you create an account, we collect your email address and a bcrypt hash of your password. We never store your plaintext password, and we do not store payment card numbers -- those are held by our payment processor (see Section 7).
When you log in, we issue a session cookie. The cookie identifier is opaque and is revoked when you log out.
Each managed hosting account runs in its own isolated container with its own database. Odigos personnel have operational access to the underlying infrastructure for support, debugging, and maintenance, but we do not routinely read agent memory or conversation contents.
When you visit the site, we collect standard server logs: IP address, browser type, requested pages, and timestamps. We use this data to operate the site, debug issues, and detect abuse.
If you self-host Odigos under the MIT license, your data remains on your own infrastructure. We have no access to your deployed agent's memory, database, or API traffic.
To deliver the hosted service, we rely on the following sub-processors:
We are not responsible for sub-processors' handling of your data beyond reasonable selection and oversight.
You may request access to, export of, correction of, or deletion of your personal data. Contact us via the contact form. We aim to respond within 30 days. Some jurisdictions (the EU, California, and others) provide statutory rights. We honour these requests voluntarily for all users, regardless of jurisdiction.
We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising. We do not use third-party trackers for advertising purposes.
The service is not directed to users under 16. If we discover an account belongs to a user under 16, we will delete it.
If we discover a security incident that materially affects your personal data, we will notify affected users without unreasonable delay.
We may refuse requests that would compromise other users' data, the security of our systems, or our ability to operate the service.
If you have questions about this Privacy Policy or want to exercise a right, please reach out via our contact form.