openFactoryAI
How it worksThe catchThe boardFAQToolsBlogSign inGet a seat
How it worksThe catchThe boardFAQToolsBlogSign inGet a seat
Legal

Privacy Policy

Last updated 2026-08-03

Privacy Policy

Effective date: 2026-08-03

Plain-English summary. openFactory runs on your machine, so your source code and the prompts you send to coding agents do not pass through our servers. What we do hold is small: an account record, a subscription record (your card is handled by Paddle, not by us), support conversations, and — only if you turn it on — diagnostic telemetry that counts events rather than capturing content. We do not sell your data and we do not train models on your code. This summary is not the policy; the sections below are.

This policy explains how Kalmantic Inc., a Delaware corporation ("Kalmantic", "we", "us"), handles personal data in connection with openFactory, the OpenFactoryAI website at openfactoryai.co, and our hosted APIs. Kalmantic is the controller of the personal data described here.

1. The local-first boundary

This is the most important fact about your privacy with openFactory, so it comes first.

openFactory is a desktop application that runs on your own computer. Your repositories, source files, prompts, and the responses returned by coding agents are processed locally. When an agent calls a model provider, your machine sends that request directly to the provider using the credentials you configured. Kalmantic is not in that path and does not receive a copy.

Two exceptions, both narrow and both under your control:

  • Agents operated by Kalmantic. If you use a coding agent that we operate (for example, one covered by preloaded credit included with your plan), requests for that agent are routed through our inference gateway. Those requests contain the prompt context the agent needs, which may include source code. We process it to serve the request and to bill it, we retain it only as long as §6 allows, and we do not train on it.
  • Features you explicitly enable that require our servers, such as sharing an evidence record with a teammate. Anything of this kind is opt-in and labelled.

2. What we collect

Account data. Your name, email address, sign-in identifier, the authentication provider you used, organisation or team name, seat assignment and role, and the timestamps of account creation and last sign-in.

Billing data. Your subscription status, seat count, renewal date, invoice history, and the country and tax treatment applied to your purchase. Payment card details are collected and processed by Paddle, our merchant of record — not by us. We receive from Paddle a transaction identifier, the amount, the currency, the billing country, and the last four digits and brand of the card. We never see or store your full card number.

Support data. The content of emails, forms, and support conversations you send us, including anything you choose to attach.

Website data. When you visit openfactoryai.co we process your IP address, browser user-agent, referring page, and the pages you view, for security and aggregate traffic measurement. See the Cookie Policy.

Enquiry data. If you contact us through the partner or team enquiry form, we collect the fields you submit and use them only to respond to you about that enquiry.

Diagnostic telemetry (opt-in). If you turn telemetry on in openFactory, we collect operational events — application version, operating system and architecture, feature and command names invoked, error types and stack traces, and timing and token counts. We do not collect the content of prompts, responses, source code, file contents, file paths, branch names, repository names, or environment variable values. Telemetry is off unless you enable it, and you can turn it off again at any time in application settings.

What we never ask for. We do not collect special-category data (health, biometrics, race, religion, political opinions, sexual orientation), and you should not send it to us.

3. How we use it

PurposeData used
Provide openFactory and your accountAccount data
Bill your subscription and remit taxBilling data (via Paddle)
Answer your support requestsSupport data, account data
Keep the Service secure, prevent fraud and abuseAccount data, website data, telemetry
Diagnose crashes and fix defectsDiagnostic telemetry
Meet legal, tax, and accounting obligationsBilling data, account data
Send service and billing notices you cannot opt out ofAccount data
Send product news, if you opted inAccount data

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your code, prompts, or output to train, fine-tune, or evaluate models.

4. Legal basis (GDPR and UK GDPR)

If you are in the EEA, the UK, or Switzerland, we rely on:

  • Contract (Art. 6(1)(b)) — to provide openFactory, run your account, and bill you.
  • Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, and improve reliability. We have assessed that these interests do not override your rights.
  • Consent (Art. 6(1)(a)) — for optional diagnostic telemetry and for marketing email. You can withdraw consent at any time; withdrawal does not affect processing already carried out.
  • Legal obligation (Art. 6(1)(c)) — to keep tax and accounting records.

5. Who we share it with

We share personal data only with the service providers below, each under a written contract that restricts them to processing on our instructions. The full list, with the categories of data and processing locations, is maintained in the Data Processing Addendum.

  • Paddle — merchant of record: payment processing, invoicing, subscription management, and global tax calculation and remittance.
  • Google (Firebase and Google Cloud) — authentication, application data storage, and website hosting.
  • Model inference providers — only for agents operated by Kalmantic, and only for the request being served.
  • Email delivery — to send transactional and account email.

We also disclose data when required by law (a valid subpoena, warrant, or court order), to establish or defend legal claims, to protect the rights and safety of users or the public, or to a successor in a merger, acquisition, or sale of assets — in which case we will give notice before your data becomes subject to a different policy.

6. International transfers and retention

Kalmantic is based in the United States, and our providers operate globally, so your data may be processed outside your country. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with the transfer safeguards our providers maintain.

Retention.

DataKept for
Account dataThe life of your account, then deleted within 90 days of closure
Billing and invoice records7 years, to meet tax and accounting obligations
Support conversations24 months from the last message
Diagnostic telemetry13 months
Website server logs90 days
Inference requests to Kalmantic-operated agents30 days for abuse and billing investigation, then deleted

We may keep data longer where a legal hold, an unresolved dispute, or a regulatory obligation requires it.

7. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to processing, to portability in a machine-readable format, to withdraw consent, and to not be discriminated against for exercising any of these.

Exercise any of them by emailing privacy@kalmantic.com from the address on your account. We respond within 30 days (extendable by 60 days for complex requests, with notice). We do not charge for a request unless it is manifestly unfounded or excessive.

California residents (CCPA/CPRA): you have the rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the request channel above is open to you.

Complaints. If you are in the EEA, the UK, or Switzerland and are not satisfied with our response, you may lodge a complaint with your local supervisory authority. We would prefer the chance to fix it first.

8. Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, email privacy@kalmantic.com and we will delete it.

9. Security

We protect data with encryption in transit (TLS) and at rest, least-privilege access controls with mandatory multi-factor authentication for staff, hashed and salted API credentials, audit logging of administrative actions, and periodic review of access.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law and without undue delay. Report a suspected vulnerability to security@kalmantic.com; see §6 of the Acceptable Use Policy for our security-research position.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, within the meaning of Article 22 of the GDPR.

Automated systems do flag accounts for fraud or abuse review, and may temporarily rate-limit or restrict an account. Any suspension or termination decision that follows is reviewed by a person, and you can contest it by emailing legal@kalmantic.com.

Note that openFactory itself is an agent-coordination tool: the decisions it automates are about software, not about people.

11. Changes to this policy

We may update this policy. Material changes are notified by email or in the application at least 30 days before they take effect, and the date at the top of this page changes.

12. Contact

Privacy questions and data-subject requests: privacy@kalmantic.com. General contact: hello@openfactoryai.co.

Kalmantic Inc., a Delaware corporation, is the data controller.

Kalmantic Inc. operates OpenFactoryAI and openFactory. This policy was last updated on 2026-08-03.

Related:Terms of ServiceRefund PolicyCookie PolicyDPAAcceptable UseEULA
openFactoryAI
The local-first workspace for agent-built software. One outcome, visible ownership, human authority, and evidence behind the result.
Product
How it worksThe catchPricingFor your roleTokenTopper
Trust
The boardThe ledgerAcademy ↗Blog
Engage
Get a seatSign inTalk to the teamLegalhello@openfactoryai.coGitHub ↗
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseEULADPARefund Policy
Coding agents, coordinated.© 2026 Kalmantic Inc. All rights reserved.