Privacy Notice

Effective July 17, 2026. Last updated July 27, 2026. This Notice describes how MLDSAI Inc. collects, uses, stores, and shares information through the OpenAdapt website, open-source software interactions, and hosted service.

MLDSAI Inc. ("OpenAdapt," "we," or "us") is accountable for the practices described here and operates the OpenAdapt website and optional hosted service. Contact hello@openadapt.ai with privacy questions. The open-source engine is separate software operated by the person or organization that installs it.

1. Local Engine and Artifacts

The open-source engine records screenshots and GUI input on the operator's machine to compile and replay a workflow. Local recordings, compiled bundles, machine reports, screenshots, identity evidence, parameters, and checkpoints can contain personal information, credentials, or PHI. Compilation does not de-identify them. Installing or running the engine does not by itself create an OpenAdapt account or send those artifacts to the hosted service.

The optional sanitation command creates a transformed copy; it does not mutate or make the source safe. Supported text and still images are inventoried, transformed, rescanned, reviewed under the selected policy, and approved by exact archive hash. Unsupported, unresolved, changed, or unknown content is refused. The original remains inside the operator's boundary. The separate report-break path sends a minimized diagnostic without screenshots, typed values, intents, reasons, errors, or report text.

2. Hosted Service

The hosted service can collect account and organization records, authentication identifiers, contact and support messages, billing references, subscription state, workflow configuration, approved artifact archives and manifests, run status, usage, reports, logs, and audit records. The explicit artifact-ingest path accepts an approved sanitized derivative, not the sensitive local source, and checks the exact submitted bytes and destination policy.

Managed browser recording is separate from sanitized artifact ingest. When a user starts a managed recording session, browser frames and input events are captured inside the hosted authoring boundary, and the resulting raw recording can be stored in private service storage for compilation. It is not sanitized merely by capture or compilation. Managed execution can also observe live application data and produce reports after a design-time artifact was sanitized. Workflows that necessarily expose PHI/PII or other restricted runtime data require a separately qualified, customer-controlled boundary.

3. Model Calls and Governed Execution

Healthy deterministic replay makes no model calls. Model-assisted repair is optional and off by default. If an operator explicitly enables a local or remote model endpoint, relevant target crops, screenshots, identity evidence, intents, OCR, or expected state can be sent to that configured endpoint. A remote model provider then receives data under its own terms and the operator's selected boundary. Model output is a proposal; it does not bypass identity, risk, postcondition, effect, or policy checks.

4. Current Service Providers

The inventory below separates customer-controlled execution from managed authoring, the hosted control plane, and the public sales journey. Providers receive only the data needed for the selected lane, process it under their own terms and privacy policies, and may process it outside the visitor's province or country. A qualified customer-controlled deployment can use a different approved provider set documented in its scope.

Customer-controlled execution

Browser, native, RDP, and Citrix recordings, screenshots, input events, live observations, bundles, and machine evidence stay in infrastructure controlled by the customer. Optional microphone narration is off by default and transcribed locally; waveform retention is separately opt-in, while transcripts remain sensitive customer-controlled capture data. OpenAdapt Cloud receives only an explicitly admitted sanitized derivative or schema-minimized control-plane metadata unless the deployment authorizes another destination.

Managed browser authoring and execution

This is a separate hosted lane. During an approved managed browser session, raw frames and input events are processed by the managed runner and may be stored in private service storage for compilation. Capture and compilation do not sanitize that recording. Workloads whose live screens necessarily expose restricted data use a qualified customer-controlled boundary.

Hosted control plane

The control plane operates accounts, organizations, access, billing, approved artifacts, workflow configuration, run status, usage, audit records, transactional invitations, product analytics, and bounded operational error reporting. Customer-controlled runtime screenshots and report bodies are not deliberately attached to analytics or error events; error messages and stacks are pattern-scrubbed and truncated but must still be treated as potentially sensitive.

Public website and sales journey

The public site handles page visits, site-wide interaction autocapture when configured, bounded CTA and conversion events, contact forms, booking, checkout entry, and public repository metadata. It is not a workflow-runtime or customer-evidence surface.

OpenAdapt service providers, purposes, data classes, and product data-flow lanes
ProviderPurpose and dataProduct laneActivation
NetlifyHosts the public website and Cloud web application and processes public website form submissions. Network and request data; form fields a visitor intentionally submits; application delivery logs.Hosted control plane; Public website and sales journeyCurrent hosting path
SupabaseProvides hosted authentication, the tenant-scoped database, and private object storage. Account and organization records, approved artifacts, reports, and private managed-authoring recordings. Customer-controlled live runtime frames are outside this lane.Managed browser authoring and execution; Hosted control planeCurrent hosted-service path
ModalRuns approved managed browser recording and execution compute, and hosted compilation when that path is explicitly enabled. Managed-session frames and input events, compilation inputs, live observations, and bounded execution outputs for the selected managed workflow.Managed browser authoring and executionSelected managed workflows
StripeProvides Checkout, payment processing, billing, and subscription state. Payment and billing details entered in Stripe plus customer, subscription, price, and entitlement references used by OpenAdapt Cloud.Hosted control plane; Public website and sales journeyPaid hosted-service path
ResendDelivers transactional organization-invitation email when configured. Invitee email, organization name, role, inviter display identity, and the non-secret sign-in link. No workflow payload or runtime evidence.Hosted control planeEnvironment-gated
PostHogMeasures the public acquisition funnel and privacy-bounded Cloud activation outcomes when configured. The website sends public-page views, site-wide click/interaction autocapture, and named CTA/conversion events; optional website replay is off by default and masks inputs when enabled. Cloud disables autocapture and replay and sends scrubbed paths, opaque user/organization IDs, organization business name, role/admin flags, enums, counts, and durations. Cloud does not identify users by email or deliberately attach screenshots, record contents, or report bodies.Hosted control plane; Public website and sales journeyEnvironment-gated; Do-Not-Track respected
Google Analytics 4Measures route page views across the public site and Cloud, plus selected public-site conversions, when configured. Route/page and bounded campaign or conversion metadata. Google signals and ad-personalization signals are disabled; no workflow payload or runtime evidence.Hosted control plane; Public website and sales journeyOptional; Do-Not-Track respected
Meta PixelMeasures public-site page views and lead, contact, or booking conversions during an explicitly configured campaign. Public marketing page and bounded conversion events; never product runtime or customer evidence data.Public website and sales journeyOptional campaign path; Do-Not-Track respected
Sentry-compatible error service (GlitchTip)Receives bounded server error and operational anomaly events from OpenAdapt Cloud when configured. Route name, pattern-scrubbed and truncated error message/stack text, opaque run/organization/workflow IDs, and numeric counts. Callers are required not to attach request or response bodies, headers, cookies, query strings, screenshots, or report bodies. Pattern scrubbing is defense in depth, not proof that arbitrary error text is de-identified.Hosted control planeEnvironment-gated
Cal.comProvides the public booking flow. Booking details entered by the visitor and optional name/email prefill the visitor already supplied.Public website and sales journeyCurrent booking path
GitHubHosts public source, releases, advisories, and repository metadata used by the website. Public repository and release data plus ordinary network/request data when a visitor follows a GitHub link.Public website and sales journeyCurrent open-source path

5. Website Forms, Booking, and Analytics

Contact and update forms can collect a name, email address, company, role, workflow description, and message through Netlify. We use those submissions for the requested communication, workflow qualification, support, and product updates. Opening the booking flow loads Cal.com; name and email are passed as booking prefill only when the visitor supplied them. Stripe receives payment and billing details when a visitor enters enabled Checkout.

If a PostHog key is configured, the public site sends page views, bounded CTA events, and autocaptured interactions across the public site using in-memory persistence. Public-site session replay is off by default and masks all input text if explicitly enabled. OpenAdapt Cloud uses a stricter PostHog path: autocapture and replay are disabled, page URLs are stripped of query strings and hashes, and product events use opaque identifiers, organization business name, role/admin flags, enums, counts, and durations. Cloud does not identify users to PostHog by email or deliberately attach screenshots, record contents, or report bodies. Optional GA4 and Meta measurement are environment-gated, and all three browser analytics paths honor Do-Not-Track. Analytics is never workflow execution evidence.

6. Retention and Deletion Boundaries

Local artifact retention is controlled by the operator; the engine does not automatically delete raw recordings, bundles, machine reports, or checkpoints. The hosted service persists account and organization data, managed recordings, approved artifacts, bundles, reports, run and usage records, and billing references in its configured stores. Short-lived signed runner URLs limit object access but do not delete the stored objects. The self-serve service currently publishes no fixed retention, backup-deletion, or recovery period. Do not send data that requires a specific schedule until that schedule and deletion process are documented in a qualified written deployment scope. Providers can retain billing, security, or service records under their own obligations.

7. Security Boundaries

Declared browser password and secret fields are injected at replay rather than written into recording events or bundles. Other typed values, screenshots, identity evidence, bundles, and reports remain sensitive and need appropriate access, encryption, retention, endpoint, backup, and deletion controls. Runtime observations can reintroduce sensitive data after sanitation. No transmission or storage method is completely secure. Review the current security and data-boundary page before evaluating consequential or regulated work.

8. Children's Privacy

Our products and services are not intended for use by children under the age of 13. We do not knowingly collect personal information from children.

9. Changes and Contact

We may update this Notice as product paths, providers, or legal requirements change. We will publish the effective date and provide any notice required by applicable law. Questions, complaints, or requests to access, correct, or delete personal information can be sent to hello@openadapt.ai. We will verify and respond to requests as required by applicable law.