Privacy Policy
o8 and Symon are local-first apps: your code, your prompts, and your voice stay on your own Mac. This site, o8.run, is a plain marketing site that runs no analytics, no ad pixels, and no cross-site trackers. The only personal data we ever handle is what you hand us on purpose — an email if you opt into the newsletter — plus the standard server logs every website's host keeps to stay online and secure. That's the whole story. The rest of this page spells it out.
The short version
Local-first: how the o8 and Symon apps handle your data
o8 is a macOS desktop application — a governance layer for autonomous AI engineering agents. It is built to be local-first. Your app data (settings, agent sessions, approvals, and organizational memory) is stored locally on your own Mac in a SQLite database at ~/.o8. Your code, prompts, and the work your agents produce are never uploaded to us. The one thing the app does send is the coarse, opt-out usage analytics described in the next section — counts and feature names only, never any of that content.
o8 connects to AI providers — for example Anthropic, OpenAI, or Google — using your own API keys or subscriptions. Your code, prompts, and the work your agents produce stay on your machine and are sent only to the AI providers you choose to configure. We do not operate a cloud that receives or retains your source code.
Symon, our companion macOS dictation and voice app from the same team, is also local-first. Your voice is transcribed and processed through the providers you configure — it isn't routed to or stored by us.
Because these apps talk directly to the providers you set up, those providers' own privacy policies and data practices apply to the data you send them. We encourage you to review the policy of whichever AI provider you connect.
Usage analytics in the o8 app
To understand how o8 is used and where to improve it, the desktop app sends us a small stream of coarse usage events. This is deliberately minimal and contains no content of any kind.
What it includes: which features are used and how often — for example that the app was opened, that an agent was dispatched (and which runtime, such as Codex or Claude), that an agent's work was merged, that the Engineering Brain was asked a question, or that a repository was connected. Alongside each event we send small flags and counts, such as whether a merge was pushed to a remote.
What it never includes: your source code, your prompts, the contents of your files, your repository names, branch names, file paths, or anything your agents read or write. We don't collect any of it, and the events have nowhere to put it.
How it's identified: on first launch the app provisions a free account credential tied to a random install identifier (for example, "install:" followed by a random string). That id lets us count distinct installs and, if you later opt into managed inference, meter that usage. It is not your name, your email, or anything that identifies you personally.
Where it goes: these events are sent to our own usage server (hosted on Railway) — never to a third-party analytics or advertising service. We run no Google Analytics, PostHog, ad pixels, or behavioral trackers anywhere, on the site or in the app.
Turning it off: it is on by default, and you can switch it off at any time in the app under Settings → Account → Privacy ("Share usage data"). When it is off, nothing is sent.
What this website collects
o8.run is a marketing and informational site, statically hosted on Vercel. The data it handles is limited to two things:
Two other data-touching things on this site: downloading the app and the optional Founding Operator checkout both ask you to sign in with GitHub via Clerk (checkout additionally uses Stripe for payment) — the details you give those services are governed by their own privacy practices, and we don't see or store your card details. When you create a download account we may note which page brought you here (for example the stream link) and send the occasional o8 product update to your account email — every one carries an unsubscribe, and we never sell or share your email.
That's the complete list. We don't ask for, and the site doesn't gather, anything else about you.
What this website does not collect
We deliberately keep this site clean. Specifically:
We don't build a profile of you, and there's nothing here designed to follow you around the web.
Cookies
This site does not set advertising or cross-site tracking cookies. Any cookies that exist are strictly essential and operational — for example, minimal cookies the hosting provider may set so the site functions correctly.
Because we use no tracking cookies, there is no cookie consent banner. There's nothing to consent to that you wouldn't already expect from a basic, well-behaved website.
App downloads
Downloads of the o8 app are served from GitHub Releases, at github.com/hurttlocker/o8-releases. When you visit GitHub to download, GitHub's own privacy policies and practices govern that visit — that interaction is between you and GitHub.
We don't receive special tracking information about your download beyond what GitHub makes available to any project that hosts releases there.
Paid features in the o8 app (optional)
o8 is free with your own API keys. The app, its governance features, and your organizational memory cost nothing and don't require an account.
There is one paid option today: the Founding Operator edition, a one-time purchase made through this site that turns on the managed layer — conveniences that cost us money to provide on your behalf, such as managed AI inference (so you don't have to bring your own API keys). The principle is simple: you pay only when o8 spends money for you. If you never buy it, the app stays free.
If you do purchase, payment is handled by Stripe and sign-in by Clerk, and their own privacy practices apply to the details you give them. Your payment card details are processed by Stripe and are not stored by us. If you never opt in, none of this applies to you.
Third parties we rely on
We keep our list of third parties short and name them plainly:
We do not sell your personal data to anyone, and we don't share it for advertising.
No accounts on this website
You don't need an account to read anything on o8.run — no profile, no password, no sign-in to browse. Signing in with GitHub happens in two places: when you download the app (the free account your setup and license bind to) and in the optional Founding Operator checkout (so your purchase ties to your license). Beyond those, the only piece of personal information the site can hold about you is a newsletter email you chose to submit.
Your rights
Because we collect so little, exercising your rights is simple:
To make any of these requests, contact us using the details below. We'll handle it promptly.
Note that the server logs Vercel keeps for security and reliability are standard infrastructure records held by our hosting provider; we treat them as operational data and don't use them to identify or profile individual visitors.
Children
o8 and Symon are developer tools intended for adults, and this site is not directed at children. We do not knowingly collect personal information from children. If you believe a child has submitted personal information (for example, a newsletter email), contact us and we will delete it.
Changes to this policy
If we change how we handle data, we'll update this page and revise the effective date at the top. Because our whole posture is built on collecting as little as possible, any change here would be a notable event — not a quiet expansion of data collection. If we ever introduced something materially different, we'd say so clearly.
Contact
Questions about this policy, or a request to access or remove your data? Reach us at hello@o8.run.
This policy is provided by Rainwater Logic LLC ("o8") and is governed by the laws of the Commonwealth of Pennsylvania, United States.
Effective date: July 8, 2026.