Privacy Policy
o8 and Symon are local-first apps: your repositories, sessions, approvals, and memory stay on your own machine. o8 mobile connects to its paired desktop directly or through an end-to-end encrypted relay that cannot read the application payload. Requests go to the AI provider path you choose, including o8's hosted inference when you use it. This site, o8.run, uses Vercel's cookieless Web Analytics and Speed Insights to count visits and measure page performance. We do not run ad pixels, use browser fingerprinting, or track people across sites.
The short version
Local-first: how the o8 and Symon apps handle your data
o8 is a desktop application — a governance layer for autonomous AI engineering agents. It is built to be local-first. Your app data (settings, agent sessions, approvals, and organizational memory) is stored locally on your own machine in a SQLite database at ~/.o8. The app does not upload your code, prompts, or agent work merely because you open or use a local workspace. Content leaves only through a provider or managed feature you invoke, or through a manual feedback report you deliberately send.
o8 connects to AI providers — for example Anthropic, OpenAI, or Google — using your own API keys or subscriptions. Your code, prompts, and the work your agents produce stay on your machine unless you choose a provider or managed feature that needs that content, or deliberately include visible workspace content in a manual feedback screenshot. The destination and controls for each path are described below.
Symon, our companion macOS dictation and voice app from the same team, is also local-first. Your voice is transcribed and processed through the providers you configure — it isn't routed to or stored by us.
Because these apps talk directly to the providers you set up, those providers' own privacy policies and data practices apply to the data you send them. We encourage you to review the policy of whichever AI provider you connect.
How o8 mobile handles your data
o8 mobile is a companion control surface for the o8 desktop app. Pairing host and port information, drafts, preferences, and recent app state are stored in the app's private storage. Pairing credentials, the mobile device credential, a free-account credential, and a random install identifier are stored in the iOS Keychain. Unpairing clears the saved desktop connection; deleting the app clears app-private storage, while iOS controls whether Keychain items survive a reinstall.
Direct connection: when the phone can reach the paired Mac, operator instructions, conversations, repository summaries, diffs, approvals, terminal traffic, and chosen attachments travel directly to that Mac over the local or private network address selected during pairing. This connection can use local HTTP and WebSocket transport because its endpoint is the user's Mac.
Managed relay: when direct reach is unavailable and relay access is enabled, the phone and Mac may connect through relay.o8.run. The application payload is end-to-end encrypted between those two devices. The relay routes opaque ciphertext and cannot read prompts, code, diffs, terminal data, attachments, or the pairing credentials inside the encrypted channel. It processes a derived routing identifier, Mac presence, connection timing and status, and ordinary network information needed to operate and secure the service.
Anonymous hosted allowance and managed Ask: the first time you invoke an o8-hosted model, the app sends a random install identifier to the o8 service and obtains an install-scoped credential. This happens on demand, not on first launch, and does not require your name, email, or sign-in. We retain the identifier and credential record to recognize the installation, secure and operate the service, and enforce limits. When you use managed Ask, the request, required conversation context, chosen attachments, and repository evidence you deliberately include are sent to the o8 managed service and its AI provider. Requests routed through the paired desktop follow the provider configuration on that Mac.
Symon voice and other permissions: starting a Symon voice session sends microphone audio and its conversation instructions to the configured realtime AI provider using a short-lived session credential. Camera frames used to scan a pairing QR code are processed on the device and are not retained by o8. Photos and files leave the phone only after you choose them. Notification and Live Activity tokens are sent to the paired Mac so Apple can deliver the updates you enable.
The mobile app contains no third-party advertising SDK, does not use the advertising identifier, and does not track people across other companies' apps or websites. The random install identifier, relay metadata, and service-use records are used for app functionality, security, entitlement enforcement, and aggregate service operation, not advertising.
Crash reports in the o8 app
When o8 breaks, a crash report tells us what broke and where. It is a separate choice from usage analytics, and it is off until you turn it on. The app asks once, on first run, and shows you a real example of what a report contains before you decide.
What it includes: the error and the stack trace showing which parts of o8 were running, the app version, and your operating system version.
What it never includes: your source code, prompts, file contents, repository names, file paths, your identity, or your machine's identity. Reports are scrubbed before they leave your machine, and if scrubbing ever fails the report is discarded rather than sent.
Where it goes: to Sentry, an error-tracking service, under our account. Nowhere else, and never to an advertising service.
Your choice: off by default, changeable at any time in the app's settings. Declining costs you nothing — the app behaves identically either way.
Manual feedback reports in the o8 app
Manual feedback is separate from automatic crash reporting. Nothing is sent merely because the report window opens. A report is sent only when you press Send and the app's data-sharing control is enabled.
What it can include: the report text and category you enter; an optional screenshot; the app version, operating system, Node version, current route, timestamp, and an optional project label; and, when diagnostics are included, relevant client state, recent app crash traces, console details, and repository paths needed to investigate the problem. Review the report choices before sending if the workspace is sensitive.
How it is authenticated: the desktop sends the report to our hosted service on Railway with a signed installation credential. That credential is used to validate and rate-limit the request. It is not placed in the report body, forwarded to Discord, or embedded in the desktop app as a Discord credential.
Where it goes: after validation and bounded sanitization, the hosted service forwards the report to a private Discord intake channel used by the o8 maintainers. The report is not posted publicly. If a later fix is published, the public update can use the local report identifier and reporter credit without publishing the original private report.
What stays local: the app records the report identifier and basic delivery receipt in its local report ledger. If the hosted service does not return a matching receipt, the app shows an error and does not record the report as delivered.
Usage analytics in the o8 app
To understand how o8 is used and where to improve it, the desktop app can send a small stream of coarse usage events. It is off unless you choose to turn it on. The stream is deliberately minimal and contains no content of any kind.
What it includes: which features are used and how often — for example that the app was opened, that an agent was dispatched (and which runtime, such as Codex or Claude), that an agent's work was merged, that the Engineering Brain was asked a question, or that a repository was connected. Alongside each event we send small flags and counts, such as whether a merge was pushed to a remote.
What it never includes: your source code, your prompts, the contents of your files, your repository names, branch names, file paths, or anything your agents read or write. We don't collect any of it, and the events have nowhere to put it.
How it's identified: when you first invoke an o8-hosted model, the app provisions an install-scoped credential tied to a random install identifier (for example, "install:" followed by a random string). This happens on demand, not on first launch. The id lets us recognize an installation and meter eligible hosted usage. It is not your name or email. If you separately enable coarse usage analytics, those events follow the controls and exclusions above.
Where it goes: these events are sent to our own usage server (hosted on Railway), never to an advertising service. The website separately uses Vercel's cookieless Web Analytics and Speed Insights for aggregate traffic and page-performance reporting.
Your choice: it is off by default. The app asks once, on first run, and shows you the exact list of events it would send before you decide. Declining is a normal answer and the app does not ask again. You can change your mind either way at any time under Settings → Account → Privacy ("Share usage data"). When it is off, nothing is sent.
What this website collects
o8.run is a marketing and informational site hosted on Vercel. Its public browse, download, newsletter, and community-join paths handle five categories of data:
Optional account-backed services use Clerk for sign-in. The Pro checkout additionally uses Stripe for payment and is labeled Founding Operator for the first 250-member cohort. The details you give those services are governed by their own privacy practices, and we do not see or store your card details.
That is the complete list for the public browse, download, newsletter, and community-join paths. Optional signed-in and paid services handle only the additional account and payment data described above.
What this website does not collect
We deliberately keep this site clean. Specifically:
We don't build a profile of you, and there's nothing here designed to follow you around the web.
Cookies
This site does not set advertising or cross-site tracking cookies. Any cookies that exist are strictly essential and operational — for example, minimal cookies the hosting provider may set so the site functions correctly.
The Discord join flow sets one HTTP-only security cookie containing a random authorization state. It expires after ten minutes and is deleted when the callback finishes. It contains no Discord profile, access token, or account identifier.
Because Vercel Web Analytics and Speed Insights do not use analytics cookies, they do not require a cookie consent banner. Essential cookies may still support hosting, security, Discord authorization, and the optional signed-in flows.
App downloads
Downloads of the o8 app are served from two GitHub release repositories: macOS from github.com/hurttlocker/o8-releases, and Windows and Linux from github.com/hurttlocker/o8. When the public o8.run endpoint redirects you to a release file, GitHub's own privacy policies and practices govern that file request.
We record the limited download event described above, and GitHub provides aggregate release-asset download counts. Neither requires an o8 account.
Paid features in the o8 app (optional)
o8 is open source and free forever with the model subscriptions and keys you already use. The app, its governance features, and your organizational memory do not require a paid plan.
Every installation receives a limited hosted model allowance, provisioned on demand when an o8-hosted model is first invoked; sign-in is not required. There is one paid option today: Pro. During the first 250-member cohort it is a one-time purchase, labeled Founding Operator at checkout, and provides our most generous daily fair-use limits plus portable account-backed services. If you never buy it, the full app and source stay free with your own subscriptions and keys.
If you do purchase, payment is handled by Stripe and sign-in by Clerk, and their own privacy practices apply to the details you give them. Your payment card details are processed by Stripe and are not stored by us. If you never opt in, none of this applies to you.
Third parties we rely on
We keep our list of third parties short and name them plainly:
We do not sell your personal data to anyone, and we don't share it for advertising.
Accounts are optional
You don't need an account to browse o8.run, download the app, open local repositories, use installed and bring-your-own model tools, or invoke the limited install-scoped hosted allowance. Sign in only for portable account-backed services such as sync, the web console, mobile relay, or Pro. Discord authorization is separate, optional, and does not create an o8 account. The newsletter is also separate and subscribes you only when you submit its form.
Your rights
Because we collect so little, exercising your rights is simple:
To make any of these requests, contact us using the details below. We'll handle it promptly.
Note that the server logs Vercel keeps for security and reliability are standard infrastructure records held by our hosting provider; we treat them as operational data and don't use them to identify or profile individual visitors.
Children
o8 and Symon are developer tools intended for adults, and this site is not directed at children. We do not knowingly collect personal information from children. If you believe a child has submitted personal information (for example, a newsletter email), contact us and we will delete it.
Changes to this policy
If we change how we handle data, we'll update this page and revise the effective date at the top. Because our whole posture is built on collecting as little as possible, any change here would be a notable event — not a quiet expansion of data collection. If we ever introduced something materially different, we'd say so clearly.
Contact
Questions about this policy, or a request to access or remove your data? Reach us at hello@o8.run.
This policy is provided by Rainwater Logic LLC ("o8") and is governed by the laws of the Commonwealth of Pennsylvania, United States.
Effective date: August 30, 2026.