Privacy Policy
Effective July 16, 2026
DirectOps (“DirectOps,” “we,” “us”) is a multi-tenant orchestration platform: you install our Operator agent on your own machines, and our hosted Director plans and coordinates work across them. This policy explains what data we collect through directops.io and the Operator/Director system, why we collect it, who we share it with, and the choices you have. It applies to visitors of directops.io and to customers using the DirectOps product.
1. Information We Collect
We collect the following categories of data:
Account information. When you sign up, our authentication provider (Clerk) collects your email address and, if you sign in with Google, your name and profile information from Google. We do not receive or store your password — Clerk handles credential storage directly.
Fleet and execution data. This is the core of what DirectOps processes on your behalf: the goals and instructions you submit, the hostnames, OS info, and IP addresses of connected Operator machines, the commands generated to carry out your goals, and the output (stdout/stderr) those commands produce. This data is inherently sensitive — it can include information about your infrastructure and whatever your commands touch — and it transits our hosted Director in order for the product to work, regardless of whether you supply your own AI model keys (BYOK).
API credentials (BYOK). If you provide your own Anthropic or Mistral API key, it is encrypted at rest (Fernet symmetric encryption) before storage and is never logged or displayed in plaintext after you save it.
Usage and audit data. We keep an append-only audit log of account actions (goal submissions, approvals, policy changes) including timestamp and IP address, and short-lived telemetry events from connected Operators, for security, billing, and product-reliability purposes.
Payment information. DirectOps does not currently process payments directly. If we introduce paid billing, it will be handled by a dedicated payment processor — we will not store your full card number.
2. How We Use Information
We use the data above to:
- Operate the product — plan, dispatch, and report on the goals you submit.
- Authenticate you and enforce tenant isolation, so your data is never visible to another account.
- Maintain security — detect abuse, enforce host policies, and investigate incidents.
- Send account-related email (approvals, quota warnings, failure notifications for scheduled checks).
- Improve reliability and, where relevant, meet SOC 2 compliance obligations we hold ourselves to.
We do not use your fleet or execution data to train AI models, and we do not sell your data.
4. Data Retention
Active chat/goal history is retained while your account is active — we don't delete it on a fixed clock. When you delete a chat or task, it is marked for deletion and permanently purged after 365 days. Operator telemetry events are purged after 90 days. The audit log is retained for 1 year to support security investigations. Revoked Operator tokens are retained for 30 days after revocation, then deleted. A background job enforces these windows automatically.
If you close your account and request full deletion, we will delete your operational data on a verified request rather than waiting out the standard retention window — see “Your Rights” below.
5. Security
Every request, task, and stored record is scoped to your account (and organization, for team accounts) at the database level — no cross-account access exists in normal operation. Connections between the Operator and Director are encrypted in transit. BYOK API keys are encrypted at rest. Access to production infrastructure is restricted to the founder and logged. No system is perfectly secure, but we design DirectOps with tenant isolation and least-privilege access as first-class requirements, not afterthoughts.
7. Your Rights and Choices
You can access, correct, or delete most of your own data directly from the product — chats, tasks, connected Operators, and stored API keys can all be removed from the dashboard. For anything you can't self-serve, including full account deletion, contact us (below) and we will act on a verified request. Depending on where you live, you may also have additional rights under laws like the GDPR or CCPA — we honor these requests regardless of jurisdiction.
8. Children's Privacy
DirectOps is a developer/infrastructure tool and is not directed at, or knowingly used by, children. We do not knowingly collect data from anyone under 16.
9. International Data Transfers
Our infrastructure is primarily hosted in the United States, with the Mistral AI execution model hosted in the European Union. If you are located outside the country where a given sub-processor operates, your data may be transferred internationally as part of normal operation, under that provider's data protection agreements.
10. Changes to This Policy
We may update this policy as the product changes. If we make a material change, we will update the effective date above and, for significant changes, notify account holders by email.
11. Contact Us
DirectOps is operated by Isaac Rivera. For privacy questions, data requests, or to ask for our full sub-processor list, contact hello@directops.io.