Privacy Policy
Last updated 1 October 2026
This policy explains what Opswren (the Android app and the service at https://opswren.inqloop.com) stores about you and your team, why, and what you can do about it. Opswren is operated by the operator of this Opswren service ("we").
What we store
- Your account: name, email address, your role in your team, and your password as a one-way bcrypt hash (nobody can read it).
- Servers you connect: their names and addresses, operating system details, and health metrics (CPU, memory, disk, load), kept for 7 days. Diagnostic commands you run and terminal sessions you open are kept as an audit log for your team.
- Code you work on: details of the repositories you import, and for each change: the request, the AI's plan, the diff, test output and deployment results. Working copies of repositories are deleted when a change is merged or abandoned.
- Credentials you add: Git tokens, AI provider keys, SSH keys or passwords and connection secrets. Each is encrypted (AES-256-GCM) with a key that belongs to the person who added it. Only that person can reveal it, after re-entering their password; the service decrypts it only at the moment it uses it, and records each use.
- Work from connected sources: when your team connects Slack, Microsoft Teams, email, WhatsApp, GitHub, GitLab, spreadsheets or alerting tools, the messages and items they send become work items, including the sender's name, address or number.
- Technical data: our web server logs IP addresses and request details for security and troubleshooting. Failed sign-ins are counted in memory for 15 minutes to block password guessing.
How we use it
Only to provide Opswren to you and your team: to show your servers and work, run the changes and deployments you approve, send results back to where requests came from, and keep the service secure. We don't sell your data, we don't show ads, and the app contains no advertising or analytics trackers.
AI providers
When you ask for an investigation, a code change, a chat answer or a terminal command, Opswren sends what that task needs (your request, relevant code, diagnostics) to the AI provider your team has connected (for example Anthropic, OpenAI or Google), using your team's own key. That provider processes it under its own terms and privacy policy. Opswren does not call any AI provider you haven't connected.
Other services
Opswren talks to the services your team connects (GitHub, GitLab, Slack, Microsoft, Meta's WhatsApp, Google, your email provider) only to fetch and answer the work you've asked it to handle.
Security
Traffic is encrypted with TLS. Passwords are hashed, secrets are encrypted per person, screens showing secrets block screenshots, and sign-in tokens on your phone are encrypted with a key held by the Android Keystore. Only workspace admins can approve merges and deployments, open terminals, or manage servers and keys.
How long we keep it
Metrics: 7 days. Everything else: for as long as your team uses Opswren, or until it's deleted. When you delete your account, your personal data and secrets are erased right away (see below).
Your choices
- Delete your account in the app (Settings → Delete account) or as described on this page.
- Access, correct or export your data: change your name and password in the app, or contact the administrator who invited you to Opswren.
- Admins can remove members, servers, keys and connections at any time.
Children
Opswren is a tool for professionals and isn't meant for anyone under 16.
Changes
If we change this policy, we'll update the date above, and tell you in the app if the change is significant.
Contact
Questions about privacy: the administrator who invited you to Opswren.