Legal

Privacy Policy

Last updated July 8, 2026

o8 and Symon are local-first apps: your code, your prompts, and your voice stay on your own Mac. This site, o8.run, is a plain marketing site that runs no analytics, no ad pixels, and no cross-site trackers. The only personal data we ever handle is what you hand us on purpose — an email if you opt into the newsletter — plus the standard server logs every website's host keeps to stay online and secure. That's the whole story. The rest of this page spells it out.

The short version

Your work stays with you. The o8 desktop app keeps your settings, sessions, approvals, and organizational memory in a local database on your Mac (~/.o8). We do not run a cloud that ingests or stores your source code.
We don't track you on this website. No Google Analytics, no Meta Pixel, no PostHog, no advertising or social tracking pixels of any kind.
No account needed to browse the site. Two things ask you to sign in with GitHub (via Clerk): downloading the app, and the optional Founding Operator checkout (which also uses Stripe for payment). Nothing else here asks you to sign up, apart from the optional newsletter.
The only personal data we collect on this site is your email, and only if you submit the newsletter form yourself. You can unsubscribe or ask us to delete it at any time.
The o8 desktop app sends us coarse, opt-out usage analytics — which features get used and how often, never your code, prompts, repo names, or file contents. You can switch it off in the app's settings. Details below.

Local-first: how the o8 and Symon apps handle your data

o8 is a macOS desktop application — a governance layer for autonomous AI engineering agents. It is built to be local-first. Your app data (settings, agent sessions, approvals, and organizational memory) is stored locally on your own Mac in a SQLite database at ~/.o8. Your code, prompts, and the work your agents produce are never uploaded to us. The one thing the app does send is the coarse, opt-out usage analytics described in the next section — counts and feature names only, never any of that content.

o8 connects to AI providers — for example Anthropic, OpenAI, or Google — using your own API keys or subscriptions. Your code, prompts, and the work your agents produce stay on your machine and are sent only to the AI providers you choose to configure. We do not operate a cloud that receives or retains your source code.

Symon, our companion macOS dictation and voice app from the same team, is also local-first. Your voice is transcribed and processed through the providers you configure — it isn't routed to or stored by us.

Because these apps talk directly to the providers you set up, those providers' own privacy policies and data practices apply to the data you send them. We encourage you to review the policy of whichever AI provider you connect.

Usage analytics in the o8 app

To understand how o8 is used and where to improve it, the desktop app sends us a small stream of coarse usage events. This is deliberately minimal and contains no content of any kind.

What it includes: which features are used and how often — for example that the app was opened, that an agent was dispatched (and which runtime, such as Codex or Claude), that an agent's work was merged, that the Engineering Brain was asked a question, or that a repository was connected. Alongside each event we send small flags and counts, such as whether a merge was pushed to a remote.

What it never includes: your source code, your prompts, the contents of your files, your repository names, branch names, file paths, or anything your agents read or write. We don't collect any of it, and the events have nowhere to put it.

How it's identified: on first launch the app provisions a free account credential tied to a random install identifier (for example, "install:" followed by a random string). That id lets us count distinct installs and, if you later opt into managed inference, meter that usage. It is not your name, your email, or anything that identifies you personally.

Where it goes: these events are sent to our own usage server (hosted on Railway) — never to a third-party analytics or advertising service. We run no Google Analytics, PostHog, ad pixels, or behavioral trackers anywhere, on the site or in the app.

Turning it off: it is on by default, and you can switch it off at any time in the app under Settings → Account → Privacy ("Share usage data"). When it is off, nothing is sent.

What this website collects

o8.run is a marketing and informational site, statically hosted on Vercel. The data it handles is limited to two things:

Server and access logs. Our hosting provider, Vercel, keeps standard logs — such as your IP address, a timestamp, and your browser's user-agent string — for security, reliability, and to keep the site running. This is ordinary infrastructure logging, not behavioral tracking.
Newsletter email. If, and only if, you voluntarily submit the optional newsletter form, we collect the email address you provide so we can send you updates. This is strictly opt-in. You can unsubscribe at any time, and you can ask us to remove your email whenever you want.

Two other data-touching things on this site: downloading the app and the optional Founding Operator checkout both ask you to sign in with GitHub via Clerk (checkout additionally uses Stripe for payment) — the details you give those services are governed by their own privacy practices, and we don't see or store your card details. When you create a download account we may note which page brought you here (for example the stream link) and send the occasional o8 product update to your account email — every one carries an unsubscribe, and we never sell or share your email.

That's the complete list. We don't ask for, and the site doesn't gather, anything else about you.

What this website does not collect

We deliberately keep this site clean. Specifically:

No third-party analytics. No Google Analytics, PostHog, or any equivalent.
No advertising or social tracking pixels. No Meta Pixel, no ad networks, no retargeting.
No cross-site tracking, no behavioral profiling, no selling or sharing of personal data for advertising.

We don't build a profile of you, and there's nothing here designed to follow you around the web.

Cookies

This site does not set advertising or cross-site tracking cookies. Any cookies that exist are strictly essential and operational — for example, minimal cookies the hosting provider may set so the site functions correctly.

Because we use no tracking cookies, there is no cookie consent banner. There's nothing to consent to that you wouldn't already expect from a basic, well-behaved website.

App downloads

Downloads of the o8 app are served from GitHub Releases, at github.com/hurttlocker/o8-releases. When you visit GitHub to download, GitHub's own privacy policies and practices govern that visit — that interaction is between you and GitHub.

We don't receive special tracking information about your download beyond what GitHub makes available to any project that hosts releases there.

Paid features in the o8 app (optional)

o8 is free with your own API keys. The app, its governance features, and your organizational memory cost nothing and don't require an account.

There is one paid option today: the Founding Operator edition, a one-time purchase made through this site that turns on the managed layer — conveniences that cost us money to provide on your behalf, such as managed AI inference (so you don't have to bring your own API keys). The principle is simple: you pay only when o8 spends money for you. If you never buy it, the app stays free.

If you do purchase, payment is handled by Stripe and sign-in by Clerk, and their own privacy practices apply to the details you give them. Your payment card details are processed by Stripe and are not stored by us. If you never opt in, none of this applies to you.

Third parties we rely on

We keep our list of third parties short and name them plainly:

Vercel — hosts this website and keeps the standard server logs described above.
GitHub — hosts the app release downloads (github.com/hurttlocker/o8-releases).
Railway — hosts our usage server, which receives the coarse app analytics described above and, if you opt into managed inference, meters that usage.
Stripe and Clerk — only relevant if you purchase the one-time Founding Operator edition (payment processing and sign-in, respectively).
AI providers you configure (such as Anthropic, OpenAI, or Google) — these receive the prompts and content you send through the apps using your own keys or subscriptions. They are chosen and controlled by you.

We do not sell your personal data to anyone, and we don't share it for advertising.

No accounts on this website

You don't need an account to read anything on o8.run — no profile, no password, no sign-in to browse. Signing in with GitHub happens in two places: when you download the app (the free account your setup and license bind to) and in the optional Founding Operator checkout (so your purchase ties to your license). Beyond those, the only piece of personal information the site can hold about you is a newsletter email you chose to submit.

Your rights

Because we collect so little, exercising your rights is simple:

Access. You can ask us what personal data we hold about you. In practice this is limited to a newsletter email, if you submitted one.
Removal. You can ask us to delete your email from the newsletter list, or unsubscribe directly using the link in any newsletter message.

To make any of these requests, contact us using the details below. We'll handle it promptly.

Note that the server logs Vercel keeps for security and reliability are standard infrastructure records held by our hosting provider; we treat them as operational data and don't use them to identify or profile individual visitors.

Children

o8 and Symon are developer tools intended for adults, and this site is not directed at children. We do not knowingly collect personal information from children. If you believe a child has submitted personal information (for example, a newsletter email), contact us and we will delete it.

Changes to this policy

If we change how we handle data, we'll update this page and revise the effective date at the top. Because our whole posture is built on collecting as little as possible, any change here would be a notable event — not a quiet expansion of data collection. If we ever introduced something materially different, we'd say so clearly.

Contact

Questions about this policy, or a request to access or remove your data? Reach us at hello@o8.run.

This policy is provided by Rainwater Logic LLC ("o8") and is governed by the laws of the Commonwealth of Pennsylvania, United States.

Effective date: July 8, 2026.