Privacy Notice

Effective July 17, 2026. This Notice describes how MLDSAI Inc. collects, uses, stores, and shares information through the OpenAdapt website, open-source software interactions, and hosted service.

MLDSAI Inc. ("OpenAdapt," "we," or "us") is accountable for the practices described here and operates the OpenAdapt website and optional hosted service. Contact hello@openadapt.ai with privacy questions. The open-source engine is separate software operated by the person or organization that installs it.

1. Local Engine and Artifacts

The open-source engine records screenshots and GUI input on the operator's machine to compile and replay a workflow. Local recordings, compiled bundles, machine reports, screenshots, identity evidence, parameters, and checkpoints can contain personal information, credentials, or PHI. Compilation does not de-identify them. Installing or running the engine does not by itself create an OpenAdapt account or send those artifacts to the hosted service.

The optional sanitation command creates a transformed copy; it does not mutate or make the source safe. Supported text and still images are inventoried, transformed, rescanned, reviewed under the selected policy, and approved by exact archive hash. Unsupported, unresolved, changed, or unknown content is refused. The original remains inside the operator's boundary. The separate report-break path sends a minimized diagnostic without screenshots, typed values, intents, reasons, errors, or report text.

2. Hosted Service

The hosted service can collect account and organization records, authentication identifiers, contact and support messages, billing references, subscription state, workflow configuration, approved artifact archives and manifests, run status, usage, reports, logs, and audit records. The explicit artifact-ingest path accepts an approved sanitized derivative, not the sensitive local source, and checks the exact submitted bytes and destination policy.

Managed browser recording is separate from sanitized artifact ingest. When a user starts a managed recording session, browser frames and input events are captured inside the hosted authoring boundary, and the resulting raw recording can be stored in private service storage for compilation. It is not sanitized merely by capture or compilation. Managed execution can also observe live application data and produce reports after a design-time artifact was sanitized. Workflows that necessarily expose PHI or other restricted runtime data require a separately qualified, customer-controlled boundary.

3. Model Calls and Governed Execution

Healthy deterministic replay makes no model calls. Model-assisted repair is optional and off by default. If an operator explicitly enables a local or remote model endpoint, relevant target crops, screenshots, identity evidence, intents, OCR, or expected state can be sent to that configured endpoint. A remote model provider then receives data under its own terms and the operator's selected boundary. Model output is a proposal; it does not bypass identity, risk, postcondition, effect, or policy checks.

4. Current Service Providers

Current product paths use Netlify for website hosting and forms; Supabase for hosted authentication, database, and private object storage; Modal for managed browser recording and run compute, plus optional hosted compilation only when explicitly enabled; Stripe for Checkout, billing, and subscription state; PostHog for launch-funnel analytics when configured; Cal.com for booking; and GitHub for source links, repository widgets, and public repository data. These providers can receive network and service data needed for the selected interaction and process it under their own terms and privacy policies, potentially outside the visitor's province or country depending on provider and project configuration. A customer-controlled deployment can use a different approved provider set documented in its scope.

5. Website Forms, Booking, and Analytics

Contact and update forms can collect a name, email address, company, role, workflow description, and message through Netlify. We use those submissions for the requested communication, workflow qualification, support, and product updates. Opening the booking flow loads Cal.com; name and email are passed as booking prefill only when the visitor supplied them. Stripe receives payment and billing details when a visitor enters enabled Checkout.

If a PostHog key is configured, the site sends page views and named launch-funnel clicks. The current code disables autocapture, persistent browser storage, and session recording and does not send form contents, emails, or free text to PostHog. Without a PostHog key, that analytics path is a no-op. Analytics data is marketing-site data, not workflow runtime data.

6. Retention and Deletion Boundaries

Local artifact retention is controlled by the operator; the engine does not automatically delete raw recordings, bundles, machine reports, or checkpoints. The hosted service persists account and organization data, managed recordings, approved artifacts, bundles, reports, run and usage records, and billing references in its configured stores. Short-lived signed runner URLs limit object access but do not delete the stored objects. The self-serve service currently publishes no fixed retention, backup-deletion, or recovery period. Do not send data that requires a specific schedule until that schedule and deletion process are documented in a qualified written deployment scope. Providers can retain billing, security, or service records under their own obligations.

7. Security Boundaries

Declared browser password and secret fields are injected at replay rather than written into recording events or bundles. Other typed values, screenshots, identity evidence, bundles, and reports remain sensitive and need appropriate access, encryption, retention, endpoint, backup, and deletion controls. Runtime observations can reintroduce sensitive data after sanitation. No transmission or storage method is completely secure. Review the current security and data-boundary page before evaluating consequential or regulated work.

8. Children's Privacy

Our products and services are not intended for use by children under the age of 13. We do not knowingly collect personal information from children.

9. Changes and Contact

We may update this Notice as product paths, providers, or legal requirements change. We will publish the effective date and provide any notice required by applicable law. Questions, complaints, or requests to access, correct, or delete personal information can be sent to hello@openadapt.ai. We will verify and respond to requests as required by applicable law.