Legal

Privacy Policy

This Privacy Policy explains how OWeb collects, uses, stores, shares, and protects personal and workspace data — including Google user data and SMS messaging information.

Last updated July 18, 2026Terms of ServiceSecurity

1. Introduction

OWeb is an AI workspace for business operators. When you use our service, you may provide account details, create workspace content, connect third-party apps (including Google services), and — if enabled — send or receive voice and SMS communications.

We wrote this policy to be specific about those practices so you can make informed decisions, and so our disclosures meet requirements for Google API verification and A2P messaging registration. If you do not agree with this policy, please do not use OWeb.

2. Who we are

OWeb ("OWeb," "we," "us," or "our") operates the website and application available at oweb.one.

Privacy requests and data-subject inquiries: privacy@oweb.one.

Support: support@oweb.one.

3. Scope

This policy applies to:

  • Visitors to our marketing site and users of the OWeb application at oweb.one
  • Account holders, workspace members, and administrators
  • Personal data processed when you connect integrations (including Google APIs) or use OWeb Communications (voice/SMS)
  • End users who receive SMS or calls from a customer using OWeb, to the extent we process that data as a service provider

This policy does not govern third-party websites, apps, or services you connect to OWeb. Those providers have their own privacy terms. When a workspace customer instructs OWeb to message or call their contacts, that customer is typically the controller of recipient data and is responsible for their own notices and consent.

4. Information we collect

Depending on how you use OWeb, we may collect:

4.1 Account & profile

  • Name, email address, and authentication credentials
  • Workspace/organization name, membership, and role
  • Profile preferences and settings you configure

4.2 Workspace content

  • Chats, prompts, agent instructions, and conversation history
  • Files, documents, memory entries, and artifacts you upload or create
  • Workflows, approvals, inbox items, and automation configurations
  • Notes, labels, and other content stored in your workspace

4.3 Connected apps & integration data

  • OAuth tokens, refresh tokens, and connection metadata
  • Data retrieved from services you authorize (for example email, calendar, files, CRM, ads platforms), used to perform actions you request
  • Tool invocation logs needed for reliability, billing, and audit

4.4 Communications data (voice & SMS)

  • Business and end-user phone numbers
  • SMS/MMS content, delivery status, and related metadata
  • Call recordings, transcripts, summaries, and disposition notes (when enabled)
  • Opt-in, opt-out, and suppression records for messaging programs
  • A2P brand/campaign registration details submitted for carrier compliance

4.5 Billing & usage

  • Stripe customer/subscription identifiers and invoice history
  • Credit balances, plan tier, and metered usage (models, tools, communications)
  • Payment method details are handled by Stripe; we do not store full card numbers

4.6 Device, log & product telemetry

  • IP address, browser/user-agent, approximate location derived from IP
  • Pages visited, feature usage, error logs, and performance metrics
  • Cookies or local storage used for session and preferences (see Cookies)

4.7 OWeb Browser Relay (Chrome extension)

  • When you install and connect the OWeb Browser Relay extension, we receive authentication tokens that link the extension to your OWeb account and workspace
  • Tabs you place in the OWeb tab group may be driven by agents you authorize. Page URLs, titles, readable text, selections you share, and screenshots captured through the relay may be processed to fulfill your requests
  • The extension uses Chrome's debugger API only while an agent session is actively automating a shared tab; we do not browse tabs you have not shared

5. How we collect information

  • Directly from you — when you sign up, configure a workspace, upload content, or contact support
  • From your team — when a workspace admin invites you or shares content according to role permissions
  • From connected services — when you authorize OAuth integrations and agents retrieve or write data on your behalf
  • From communications providers — delivery receipts, inbound messages, call events, and similar telephony metadata
  • Automatically — through logs, cookies, and product analytics as you use the service

6. How we use information

We use personal and workspace data to:

  • Provide, operate, and secure the OWeb workspace
  • Run Super Agent, tools, workflows, and approvals you enable
  • Deliver voice and messaging features you configure
  • Authenticate users and manage workspace membership
  • Meter credits, process payments, and prevent fraud or abuse
  • Troubleshoot, monitor reliability, and improve product quality
  • Send transactional account notices (billing, security, product changes)
  • Comply with law, enforce our Terms, and respond to lawful requests
We do not sell personal data. We do not use Google user data or SMS opt-in data for third-party advertising, data brokerage, or credit decisions.

7. AI processing

OWeb uses large language models and related AI systems to generate responses, draft content, summarize information, and call tools. When you ask an agent to work with workspace or connected-app data, relevant content may be sent to the model provider(s) you select through our AI gateway solely to fulfill that request.

  • Model providers process prompts and tool results as subprocessors to deliver the feature you requested
  • You should not submit sensitive data you are not authorized to process with AI tools
  • Autonomous agents can make mistakes; review outputs before relying on them in production systems
  • We do not use Google user data obtained via restricted scopes to train generalized AI/ML models in a manner prohibited by Google's Limited Use requirements

8. Google API Services user data

When you connect Google accounts or Google Ads to OWeb, we access Google user data only after you grant permission through Google's OAuth consent screen. Our use of that data is limited to the practices disclosed in this policy.

8.1 Google data we may access

  • Gmail — email metadata and content needed to read, draft, organize, label, or send messages you request
  • Google Calendar — events and scheduling data to view, create, or update calendar items
  • Google Drive & Sheets — files and spreadsheet data you authorize agents to read or write
  • Google Ads — advertising account, campaign, and reporting data via the Google Ads API for analysis and management you initiate
  • Google Analytics — property and reporting data when you connect that toolkit
  • Basic profile — account identifiers needed to maintain the connection (where granted)

8.2 How we access it

Google user data is retrieved through official Google APIs — either directly (for example Google Ads OAuth) or via authorized integration providers such as Composio — using tokens stored for your workspace. We request only the scopes needed for the features you enable and prefer incremental authorization in context where possible.

8.3 How we use it

We use Google user data solely to provide and improve user-facing OWeb features that are prominent in the product interface, including agent chat, inbox, automations, scheduling, document workflows, and Google Ads tools you enable. Secondary uses that are not disclosed here are not permitted.

8.4 How we store it

OAuth tokens and any Google user data cached or persisted for your workspace are stored with our infrastructure providers (including Supabase) under workspace isolation controls. Tokens are treated as sensitive credentials. Data is retained while the connection or related workspace content remains active, subject to security, backup, and legal retention needs.

8.5 How we share it

Google user data is shared only as needed to operate features you use:

  • With infrastructure and integration subprocessors that process requests for us
  • With model providers you select when you ask agents to process Google-sourced content
  • When required for security investigations or to comply with law
  • As part of a merger, acquisition, or asset sale only with explicit prior user consent where Google Limited Use rules require it

We do not transfer Google user data to advertising platforms, data brokers, or information resellers. We do not use Google user data for retargeting, personalized ads, or lending/credit decisions.

8.6 Human access

OWeb personnel do not read Google user data unless: (a) you give affirmative agreement for a specific support case; (b) it is necessary to investigate abuse, a bug, or a security incident; (c) it is required to comply with applicable law; or (d) the data (including derivations) is aggregated for internal operations consistent with applicable privacy law.

OWeb's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8.7 Revoking access

You can revoke Google access at any time in your Google Account permissions and by disconnecting the integration in OWeb. Revoking access stops further API retrieval; you may still need to delete related workspace content separately. If we change how we use Google user data, we will update this policy and obtain any required consent before using data in a new way.

9. SMS messaging & A2P

If you or your organization use OWeb Communications or connected messaging tools to send application-to-person (A2P) text messages — including US A2P 10DLC programs — the following applies.

9.1 Information collected for messaging

We may collect mobile phone numbers, opt-in and opt-out status, message content, delivery metadata, campaign identifiers, and related consent records needed to send and receive SMS/MMS on your behalf and to meet carrier and TCR requirements.

9.2 How messaging data is used

Message data is used to deliver the communications you configure (for example customer support, appointment reminders, account alerts, or other disclosed program types), enforce consent and suppression rules, meter usage, troubleshoot delivery, and maintain audit logs for compliance and security.

9.3 Consent, frequency & rates

Recipients should only be messaged after providing appropriate consent for that specific program and sender. Where website or product opt-in is used, disclosures should include that the recipient agrees to receive recurring text messages from the identified business or brand, that message frequency varies, that message and data rates may apply, and how to get help or opt out. Consent is not transferable to unrelated third parties for their marketing.

9.4 Opt-out & help

Recipients can opt out at any time by replying STOP (or another keyword disclosed for that program). Reply HELP for assistance, or contact support@oweb.one. After an opt-out we suppress further program messages to that number except a single confirmation where required. Workspace customers are responsible for honoring opt-outs across their messaging programs.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subprocessors that provide support services (such as our messaging infrastructure provider) is permitted solely to operate the service. Text messaging originator opt-in data and consent are not shared with any third parties for their own marketing use.

9.5 Carrier & registration

Carriers are not liable for delayed or undelivered messages. Messaging over US local numbers may require A2P brand and campaign registration. Features may be unavailable or blocked until registration is approved. See also the SMS section in our Terms of Service.

10. Cookies & similar technologies

We use cookies, local storage, and similar technologies to keep you signed in, remember preferences, protect against abuse, and understand product usage. You can control cookies through your browser settings; disabling certain cookies may affect authentication or core functionality.

11. When we share information

We share personal data only in these situations:

  • Workspace members — content is visible to teammates according to role and sharing settings
  • Service providers / subprocessors — who host, process payments, deliver messages, connect apps, or run models on our behalf under contractual obligations
  • Legal & safety — if required by law, or to protect rights, security, and integrity of users and the service
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to applicable consent requirements (including Google Limited Use where relevant)
  • With your direction — when you connect a third-party integration or expressly ask us to share data

12. Subprocessors

We use carefully selected subprocessors to operate OWeb. Categories and primary examples include:

ProviderRole
SupabaseDatabase, authentication, and storage
VercelApplication hosting and edge delivery
StripePayments and billing
TwilioVoice and SMS infrastructure (when enabled)
ComposioConnected-app integration broker
AI model providersInference for agents you run (per selected models)

More detail on controls is available on our Security page. Enterprise customers may request a current subprocessor list via privacy@oweb.one.

13. Retention

We retain personal data for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Typical patterns:

  • Account and workspace content — retained while the account/workspace is active
  • Integration tokens — retained until you disconnect the integration or the account is deleted
  • Messaging consent and suppression records — retained as needed for compliance and to honor opt-outs
  • Billing records — retained as required for tax, accounting, and dispute resolution
  • Security logs — retained for a limited period for investigation and abuse prevention

When you delete content or close an account, we remove or anonymize data from active systems within a reasonable period, subject to backup cycles and legal holds.

14. Security

We take reasonable administrative, technical, and organizational measures to protect user data in transit and at rest, including TLS in transit, encryption at rest via our infrastructure providers, access controls, workspace isolation, and encryption of sensitive credentials. No method of transmission or storage is 100% secure. See our Security overview for current posture and controls.

15. International transfers

OWeb is operated with infrastructure that may process data in the United States and other countries where our subprocessors maintain facilities. If you access the service from outside those regions, you understand that your information may be transferred to, stored, and processed in those locations. Where required, we use appropriate safeguards for cross-border transfers.

16. Your choices & rights

Depending on your location and role, you may be able to:

  • Access, update, or correct account profile information
  • Export or delete workspace content you control
  • Disconnect integrations, including Google connections
  • Manage messaging consent and suppression for numbers you control
  • Opt out of non-essential marketing emails (transactional mail may continue)
  • Request account deletion by contacting privacy@oweb.one

If you are an end user of a customer who uses OWeb to contact you, please contact that organization first — they typically control your relationship data. We will assist customers with verified deletion or access requests as appropriate.

Where privacy laws grant additional rights (such as access, deletion, portability, or objection), contact privacy@oweb.one. We may need to verify your identity before fulfilling a request.

17. Children

OWeb is a business service and is not directed to children under 13 (or under 16 where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it. Messaging programs are intended for recipients 18+ unless a program expressly states otherwise.

18. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice (such as an in-product notice or email). If we change how we use Google user data, we will update this policy and obtain any required consent before using that data in a new way.

19. Contact

Questions about this Privacy Policy or our data practices: privacy@oweb.one.

Related documents: Terms of Service · Security · support@oweb.one