What this covers
This policy describes what data Operator (getoperator.dev) collects when you request access or create an account, where that data lives, and how to get it deleted. Operator is in beta and run by a small team — we collect the minimum we need to run the service, and this page is the complete list.
Data we collect
- Email address — when you request early access or create an account. We use it to send your invite, sign you in, and contact you about the service.
- Password — stored only as a scrypt hash. We never store or log your password in plaintext, and we cannot read it back.
- Usage analytics — when analytics is enabled, we record product events (e.g. signed up, started a task) via PostHog, keyed by your account id. We use this to understand how the product is used and where it breaks.
- Operational logs — standard server logs (requests, errors) that we keep to run and debug the service.
- Session cookie — a single first-party cookie (
orch_session, a signed JWT) that keeps you signed in. That is the only cookie we set — there are no third-party advertising or tracking cookies.
Where your data lives
- Our servers — your account and your instance run on our server in an EU data center (Hetzner).
- Cloudflare — sits in front of the service as CDN and proxy, so traffic to getoperator.dev passes through it.
- PostHog — processes the usage analytics described above.
Your Anthropic account stays yours. You connect your own Anthropic/Claude account to your instance. The OAuth login it produces is stored inside your isolated instance volume — we never see, store, or transmit your Anthropic credentials anywhere else.
What we do not do
- We do not sell your data. To anyone, for anything.
- We do not train models on your code or your data.
- We do not access your repositories or the contents of your instance, except for operations or debugging — and then only with your consent.
Data deletion
Email ishan.mi96@gmail.com and we will delete your account and associated data. Deleting an account deletes the instance volume — everything inside your instance (repositories, sessions, credentials) is removed with it.
Changes to this policy
If this policy changes in a way that matters, we will update the date at the top and notify account holders by email.
Contact
Questions about privacy: ishan.mi96@gmail.com.