1EOne Engineer

Privacy Policy

Last updated: August 4, 2026.

Data we collect

Account data (name, email, organization), billing data processed by our payment provider, the content of your conversations, task requests, generated artifacts, configured connections, and standard operational logs.

How we use it

To provide and operate the Service: answering your requests, connecting to the systems you authorize, metering usage, improving reliability and safety, preventing abuse, and supporting your account. We do not use your code, logs, or prompts to train models.

Connection secrets

Tokens and keys you provide are encrypted at rest, scoped to your organization, and used only to perform the actions you request. Secrets are not displayed back to users after storage. You can remove a connection at any time.

Subprocessors

We use subprocessors to operate the Service, including infrastructure hosting, payment processing, transactional email, analytics or monitoring, and model providers. Our current public subprocessor list is available on the Subprocessors page. Enterprise customers may request notification and objection terms for material subprocessor changes through a data-processing agreement.

Retention

Unless your plan, signed agreement, legal hold, or product setting says otherwise, One Engineer uses these baseline production retention periods:

  • Account, organization, role, and connection metadata: while the account is active, then up to 90 days after closure.
  • Task records, conversations, run artifacts, workspace outputs, and generated files: 30 days after the task or job becomes terminal, unless you delete or pin them earlier through available product controls.
  • Audit and security records: 90 days by default, and longer when needed for fraud prevention, abuse investigation, legal compliance, billing disputes, or security incident response.
  • Billing, invoice, subscription, tax, and payment records: retained as required for accounting, tax, dispute, and legal obligations, generally up to seven years.
  • Connection secrets: deleted when you remove the connection, subject to backup overwrite cycles and legal-retention requirements.
  • Production database backups: retained on a rolling 30-day schedule. Deleted data may remain in encrypted backups until the backup expires and is overwritten.

Backups are isolated and used for disaster recovery, reliability, and security purposes; they are not used to reintroduce deleted customer content into active accounts except as part of a recovery operation. You may request deletion of your data, subject to legal retention requirements and technically necessary backup expiration windows.

Security and incident notice

We use technical and organizational safeguards including encryption in transit, encryption at rest for sensitive secrets, tenant-scoped access controls, audit logging, and production change controls. If we confirm that a security incident affects customer personal data or customer content, we will notify affected organization owners or security contacts without undue delay and, where legally required, within 72 hours after confirmation. Notices will include the nature of the incident, affected data categories, known impact, mitigation steps taken, recommended customer actions, and a contact path for follow-up when that information is available. We will provide reasonable updates as the investigation progresses.

International transfers and enterprise terms

The Service may process data in countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms. Enterprise customers may request a data-processing agreement that describes controller/processor roles, transfer mechanisms, subprocessor commitments, and security obligations.

Regulated data

Self-service plans are not intended for protected health information, PCI cardholder data, government ID numbers, children's data, special-category data, export-controlled data, or other regulated data unless your plan and written agreement explicitly authorize that use. Customers that need HIPAA, PCI, financial-services, public-sector, or other regulated-data terms should contact us before connecting those systems or uploading that content.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. Contact [email protected] to exercise them.

Security

See our Security overview for how we protect your data.

Contact

Privacy questions: [email protected].