Summary
This summary helps you find your way. It does not replace the policy below.
- Oxagen collects account details, billing details, and the records of your agents’ runs. By default, run records include the content of prompts, model responses, and tool calls.
- Your organization controls the data in its account. For that data, Oxagen acts as your organization’s service provider.
- Oxagen does not sell personal data, and does not train AI models on your data.
- When you use an AI feature, a model provider processes your prompt. With your own key, your agreement with that provider applies.
- The oxagen.sh website uses Google Analytics and the LinkedIn Insight Tag. If your browser sends a Global Privacy Control signal, the site skips the LinkedIn tag.
- To see, correct, delete, or export your personal data, write to privacy@oxagen.sh.
Scope
This privacy policy covers personal data that Oxagen, Inc. (“Oxagen”) handles in these cases.
- You visit oxagen.sh, docs.oxagen.sh, or another Oxagen website.
- You sign up for or use the Oxagen web app, desktop app,
oxagencommand line tool, API, MCP server, agent wrappers, or relay (the “Services”). - You fill out a form on an Oxagen website, ask for a demo or the field manual, or contact Oxagen.
Oxagen plays two roles, and the role decides who makes choices about the data.
- Controller. For account details, billing details, website and marketing data, and security logs, Oxagen decides how and why the data is used. This policy describes that use.
- Service provider. For Customer Data, which is the data your organization, its members, and its agents put into the Services, Oxagen acts as a processor or service provider for your organization. Your organization decides what to collect and how long to keep it, and Oxagen follows its instructions. The section on data your organization controls explains what this means for you.
This policy does not cover third-party services that you connect to Oxagen, such as GitHub or a model provider. Their own privacy policies apply. The terms of service define the other words this policy uses, such as agent, run, and governed action.
Data Oxagen collects
Data you give Oxagen
- Account details. Your name, work email address, password (stored only as a hash), profile picture, and two-factor authentication settings. If you sign in with Google or GitHub, Oxagen receives your name, email address, and profile picture from that service. If your organization uses single sign-on or SCIM provisioning, Oxagen receives your name, email address, and group memberships from your identity provider.
- Organization details. Your organization’s name, workspaces, members, roles, and settings, and the email addresses of people you invite.
- Billing details. Your plan and billing contact. Stripe collects your payment card. Oxagen stores only the card brand, the last four digits, the expiry date, and Stripe’s customer and subscription IDs.
- Support and feedback. What you send when you email Oxagen or report a problem, and the ratings and notes you give replies from Stella, the AI agent built into the Oxagen app.
- Website forms. When you ask for a demo or the field manual, Oxagen collects what you enter. That is your name, email address, job title, company, and company size, plus your phone number, location, how you heard about Oxagen, and your message if you give them. Oxagen also records the page you were on, the campaign code in the link you followed, and whether you agreed to marketing email. When Oxagen sends you an ebook link, it records your IP address and browser details.
Data collected when your agents work
When you wrap an agent with Oxagen, the wrapper sends Oxagen a record of each run. This is Customer Data, which your organization controls. A run record can include the following.
- Content. Prompts, model responses, tool inputs and results, MCP tool arguments and results, and the model requests and responses that pass through Oxagen’s local proxy, up to 1 MiB per item. Recording content is on by default. A workspace can switch to keeping only digests and metadata.
- Code and files. The paths of files the agent reads or writes, the commands it runs, and a list of changed files with line counts. The content above can include source code and file contents.
- Context. The working directory, the git branch and commit, a hash of the git remote address, whether the working tree had uncommitted changes, the run’s title, and where the agent tool keeps its local transcript.
- Device details. The operating system and its version, a hashed computer name, a hashed operating system user name, the agent tool’s process ID and program path, and settings and environment details that the agent tool reports.
- Accounts and usage. Your Oxagen identity and email address, account and organization IDs that the agent tool reports (such as an Anthropic account ID), model names, token counts, estimated cost, and counts of lines changed, files read and written, commands, commits, and pull requests.
- Requests and answers. Each request an agent makes through Oxagen, the rule that answered it, the answer (allowed, denied, or routed to a person), and the person who approved it, if any.
Before storing content, Oxagen removes common credential formats, such as private keys, cloud and code host tokens, model provider API keys, and bearer tokens. It does not remove personal data or other sensitive information that appears in prompts, code, or files. Keep regulated data, such as health records and payment card numbers, out of runs that Oxagen records.
Data from services you connect
- GitHub and GitLab. If you install the Oxagen GitHub App or connect GitLab, Oxagen receives installation details and can read the repositories you choose. With push custody on, Oxagen creates a short-lived GitHub token for each push your rules allow, uses it once, and revokes it.
- Slack. If you connect Slack, Oxagen receives the workspace details that the Slack feature you turn on needs.
- Model gateways. If Oxagen supplies model access, it creates an OpenRouter key for your organization. The key’s label includes your organization’s short name and the email address of the person who created it, so OpenRouter receives that email address.
Data collected automatically
- Sign-in and security events. When you sign in, sign out, reset a password, or verify an email address, Oxagen records your user ID, IP address, browser details, and sign-in method.
- Service logs. Oxagen’s servers log requests to the Services, including IP addresses, and record errors.
- Website analytics. oxagen.sh uses Google Analytics and the LinkedIn Insight Tag. They collect the pages you view, the site that sent you, your approximate location, and details about your device and browser, and they set cookies. The cookies section lists them.
- Command line telemetry. Unless you turn it off, the
oxagencommand line tool sends one anonymous event per command. The event holds a random install ID, the tool’s version, your operating system and processor type, the command name, a few on or off flags for the features it used, tool names with call counts, the step count, the duration, and a coarse error category. It does not hold code, prompts, file paths, model names, or keys. To turn it off, runoxagen telemetry off, or setOXAGEN_TELEMETRY=0orDO_NOT_TRACK=1. - Desktop app updates. The desktop app checks GitHub’s release feed for new versions, so GitHub receives your IP address when it checks.
Uses of data
Oxagen uses personal data for these purposes.
- Provide the Services. Run your account, record runs, answer your agents’ requests with your rules, show spend, and run the AI features you use.
- Bill. Meter governed actions and usage credits, charge your payment method, and keep financial records.
- Keep the Services secure. Detect and stop abuse, fraud, and unauthorized access, and investigate incidents.
- Support you. Answer questions, fix problems, and send notices about your account, such as security alerts, receipts, and changes to the terms.
- Improve the Services. Learn which features people use and where errors happen, mostly from aggregated or de-identified data.
- Market Oxagen. Send the field manual, follow up on demo requests, and send product news if you agreed to it. You can unsubscribe at any time with the link in the email or by writing to privacy@oxagen.sh.
- Measure the website and ads. Count visits, and see which ads lead people to the website.
- Meet legal duties. Meet tax, accounting, and other legal duties, answer lawful requests, and enforce the terms.
Oxagen does not make decisions that have legal or similarly significant effects on you based only on automated processing.
AI and model providers
Some features send data to AI models. These include Stella, the AI agent built into the Oxagen app, and the summaries Oxagen writes for you. Here is where that data goes.
- Model access that Oxagen supplies. Oxagen sends the request through a model gateway, OpenRouter or Vercel AI Gateway, which passes it to a model provider. The gateway and the provider handle the request under their own terms and privacy policies.
- Your own key. If you bring your own key, requests go to the provider you choose, under your agreement with that provider. Oxagen stores your key encrypted and does not show it again after you save it.
- Your agents’ own model calls. Agents such as Claude Code and Codex call their model providers with your own accounts. Oxagen’s local proxy can record those calls, but it sends them to the provider directly, not through Oxagen’s servers.
Oxagen does not train AI models on Customer Data. When you rate a reply from Stella, Oxagen keeps the rating and any note for up to 365 days. Oxagen staff may read that reply and the turn behind it to fix problems and improve Stella.
Legal bases
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, Oxagen relies on these legal bases when it acts as controller.
| Purpose | Legal basis |
|---|---|
| Provide the Services and bill for them | Performing a contract with you or your organization |
| Keep the Services secure and prevent abuse | Oxagen’s legitimate interest in running a secure service |
| Improve the Services | Oxagen’s legitimate interest in understanding and improving its product |
| Answer demo and field manual requests | Oxagen’s legitimate interest in answering business inquiries |
| Send marketing email | Your consent, or Oxagen’s legitimate interest where the law allows email to business contacts |
| Measure the website and its ads | Oxagen’s legitimate interest in knowing how people find and use its website |
| Meet legal duties | Complying with a legal obligation |
Where Oxagen relies on a legitimate interest, you can object, as the section on your rights explains.
Service providers
These companies process personal data for Oxagen.
| Provider | What it does for Oxagen |
|---|---|
| Amazon Web Services | Hosting, databases, file storage, and logs |
| Google Cloud | Hosting for API services and databases |
| Vercel | Model gateway (Vercel AI Gateway) and file storage |
| Inngest | Background jobs |
| OpenRouter | Model gateway for model access that Oxagen supplies |
| Model providers | Process prompts for AI features, reached through a gateway or through your own key |
| Stripe | Payments and billing |
| Resend | Account email, such as verification and notices |
| Google Workspace, ImprovMX, and SendGrid | Oxagen’s own email, forwarding, and delivery |
| Attio | Records of sales contacts from website forms |
| Google Analytics | Website analytics on oxagen.sh |
| Ad measurement on oxagen.sh | |
| GitHub | Desktop app downloads and updates |
Oxagen updates this list when it adds or replaces a provider. A customer with a data processing agreement gets notice of a new provider as that agreement sets out.
Retention
Oxagen keeps personal data only as long as it needs it for the purposes in this policy, or as long as the law requires. These are the main periods.
| Data | How long Oxagen keeps it |
|---|---|
| Account and organization details | While the account is open, then deleted or de-identified as described below |
| Run records and their content | Up to 7 years after the run ends, or until your organization deletes them or closes its account. A workspace can choose to keep only digests and metadata. |
| Event details from wrapped agents | 13 months |
| Run summaries with your email address and opening prompt | 2 years |
| Stella conversations | Until you or your organization delete them, or the account closes |
| Ratings and notes on Stella replies | 365 days |
| Security events and audit logs | 7 years |
| Server logs and traces | 30 days in active storage, then up to 14 years in archive storage for security investigations and legal claims |
| Error reports | 90 days |
| Command line telemetry | 1 year |
| Billing records and the usage ledger | At least 7 years, as tax and accounting law requires |
| Sales contacts from website forms | Until you ask Oxagen to delete them |
| Database backups | 35 days |
Deletion
An owner can close the organization’s account. You can ask Oxagen to delete your personal data by writing to privacy@oxagen.sh. When you ask, Oxagen signs you out of every device right away. It then deletes or de-identifies your data within the time the law sets, which is one month in the EEA and the UK and 45 days in California. Oxagen staff carry out some deletion steps by hand. Oxagen keeps the data it must keep for legal, tax, or security reasons, such as billing records and security logs, for the periods above. Deleted data can stay in backups until those backups expire.
Security
Oxagen uses technical and organizational measures designed to keep personal data secure.
- Data that travels over the internet to and from Oxagen is encrypted with TLS.
- Databases, disks, and stored run content are encrypted at rest. Run content is stored separately for each organization.
- Model provider keys you save are encrypted with AES-256-GCM. Oxagen does not show a key again after you save it.
- Each organization’s data is kept apart in Oxagen’s databases, and access inside an organization follows roles.
- Sign-in supports two-factor authentication and single sign-on, and passwords are stored only as hashes.
- Oxagen records security events and keeps audit logs.
- Oxagen staff access personal data only when they need to run, support, or secure the Services, or when the law requires it.
No system is perfectly secure. If Oxagen learns of a breach that affects your personal data, it will notify you and the authorities as the law requires. To report a vulnerability, write to security@oxagen.sh.
International transfers
Oxagen is based in the United States and stores data mainly in the United States. Its service providers may process data in other countries. When Oxagen moves personal data out of the EEA, the UK, or Switzerland to a country that those places have not found to protect data adequately, it relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer method. To ask for a copy, write to privacy@oxagen.sh.
Your rights
Depending on where you live, you may have the right to do the following.
- Learn what personal data Oxagen holds about you, and get a copy.
- Correct data that is wrong.
- Delete your data.
- Get your data in a portable format, to move it to another service.
- Object to or limit how Oxagen uses your data, including for direct marketing.
- Opt out of the sale or sharing of your data for targeted advertising.
- Withdraw consent where Oxagen relies on it. Withdrawing does not affect use before you withdrew.
- Use these rights without being treated differently.
- Appeal a decision Oxagen makes about your request.
Oxagen honors these requests from everyone, wherever they live, to the extent the law allows.
Making a request
You can change your profile details in the app. For anything else, write to privacy@oxagen.sh from the email address on your account. Oxagen may ask for more information to confirm who you are. Someone you authorize can make a request for you with your signed permission. Oxagen answers within the time the law sets, which is one month in the EEA and the UK and 45 days in California, and will tell you if it needs more time.
If Oxagen denies your request, you can appeal by replying to the denial. If you live in a US state that gives a right to appeal and Oxagen denies your appeal, you can contact your state attorney general. If you are in the EEA, the UK, or Switzerland, you can also complain to your data protection authority.
Data your organization controls
If you use Oxagen through your employer or another organization, that organization controls the Customer Data in its account, including the records of runs you operate. Oxagen processes that data for the organization. Send requests about that data to your organization. If you send them to Oxagen, Oxagen will pass them on to your organization where it can. Your organization’s own privacy notice explains how it uses that data.
Notice for US residents
This section adds details that the California Consumer Privacy Act and similar laws in other US states require. In the last 12 months, Oxagen collected these categories of personal information.
| Category | Examples | Disclosed for business purposes to |
|---|---|---|
| Identifiers | Name, email address, IP address, account IDs | Service providers, model gateways and providers, services you connect |
| Commercial information | Plan, purchases, and use of GAUs and usage credits | Service providers |
| Internet or network activity | Pages viewed, sign-in events, service logs, run events | Service providers, Google Analytics, LinkedIn |
| Professional information | Job title, company, company size | Service providers |
| Approximate location | Country, state, or city from a form or an IP address | Service providers, Google Analytics, LinkedIn |
| Account credentials | Password hash and two-factor settings | Not disclosed |
| Content you send | Prompts, model responses, code, and files in run records, and support messages | Service providers, model gateways and providers |
- Sources. You, your organization, your agents and their tools, services you connect, identity providers, and your browser.
- Purposes. The purposes listed in uses of data.
- Sale and sharing. Oxagen does not sell personal information for money. The LinkedIn Insight Tag on oxagen.sh lets LinkedIn measure Oxagen’s ads, which some state laws treat as sharing for cross-context behavioral advertising or as targeted advertising. To opt out, turn on Global Privacy Control in your browser, or write to privacy@oxagen.sh. Oxagen does not knowingly sell or share the personal information of anyone under 16.
- Sensitive personal information. Oxagen collects your password only to sign you in. It does not use sensitive personal information to infer things about you.
- Retention. The retention section gives the periods.
This policy is Oxagen’s notice at collection.
Children
The Services and websites are for businesses and are not directed to children. Oxagen does not knowingly collect personal data from anyone under 18. If you believe a child has given Oxagen personal data, write to privacy@oxagen.sh, and Oxagen will delete it.
Changes to this policy
Oxagen may update this policy. The “Last updated” date at the top of this page shows when it last changed. For a material change, Oxagen will tell account owners by email or in the app before the change takes effect.
Contact
- Privacy questions and requests
- privacy@oxagen.sh
- Security reports
- security@oxagen.sh
- Oxagen, Inc., 2261 Market Street STE 87168, San Francisco, CA 94114, United States
Oxagen, Inc. Privacy policy. Effective October 1, 2026.