Privacy Policy
Effective Date: August 25, 2026
This Privacy Policy explains how Panoramic Solutions, LLC, the company that operates OpenDecision ("OpenDecision," "we," "us," or "our"), collects, uses, shares, and protects information in connection with our websites, the Otis AI assistant, decision space functionality, and related services (the "Services"). This Policy is incorporated into our Terms of Service.
Panoramic Solutions, LLC is the data controller for the personal information described in this Policy. You can reach us by email at matt@opendecision.com. Full contact details are in Section 12.
1. Information We Collect
a. Account Information
When you create an account, we collect your email address and, if you sign in with a third-party provider (Google, Microsoft, Apple), your name and profile image from that provider. We do not receive your password from OAuth providers.
b. Your Content
We collect the content you create or submit to the Services, including decision profiles, criteria and weights, Otis AI conversation messages, notes, uploaded files, and feedback. You retain ownership of Your Content as described in our Terms.
c. Automatically Collected Information
When you use the Services, we automatically collect certain technical information, including:
- IP address, browser type, operating system, and device identifiers
- Pages viewed, links clicked, and features used
- Timestamps of requests and sessions
- Referrer URLs, including whether you arrived from an AI answer engine (Perplexity, ChatGPT, Gemini, Claude, Bing Copilot)
- Anonymous session identifiers for users who have not signed in
d. Cookies and Similar Technologies
We use cookies and similar technologies, including browser storage, for session management, authentication, product analytics, error diagnostics, and bot protection. What is set today:
od_ai_source: a cookie recording which AI answer engine referred you, used for conversion analytics- Your sign-in session, which Supabase keeps in your browser's local storage under the key
sb-open-decision-auth-tokenrather than in a cookie. Clearing site data for this domain signs you out - Analytics cookies and browser storage set by PostHog (US Cloud) to measure product usage, set on your first visit
- Browser storage used by Sentry to tie together the events belonging to one browsing session when an error is reported (see Section 3)
- Cookies and tokens set by Cloudflare Turnstile to verify that requests come from a real browser
- Cookies set by Google when the Google sign-in script loads, which it does on every page of the app. This is described in Section 1e, because it is the one worth reading
These are not all set in the same place. Product analytics, error diagnostics, and the Google sign-in script run in the OpenDecision app at app.opendecision.com. Our marketing site at www.opendecision.com loads no analytics or error-reporting software of its own: the only thing it sets is the od_ai_source cookie, which the app reads once you cross over to it.
We do not currently show a cookie consent banner, so the analytics and error-diagnostic technologies above load on your first visit rather than after you agree to them. You can control cookies through your browser settings and block them for this site, though disabling required cookies may prevent you from signing in or using parts of the Services. If you are in the EEA or UK, see Section 11a for what this means for you.
e. Google Sign-In and One Tap
The app loads Google's Identity Services script from accounts.google.com/gsi/client as part of nearly every page, on first paint, before you sign in and whether or not you ever do. Because the script is requested from Google, Google receives your IP address, your browser and device details, and the page you are on, it can see whether you are already signed in to a Google account, and it can set its own cookies in your browser. None of that waits for you to click anything.
If you are signed out and using a desktop browser, the script also shows Google One Tap. It is configured to select an account automatically, so a returning visitor with an active Google session can be signed in to OpenDecision without pressing a sign-in button. We do not load the script at all on shared-link pages. The One Tap prompt is not shown on mobile or to anyone already signed in, though on those visits the script itself still loads and Google still receives the request. Google's handling of this information is governed by the Google Privacy Policy. To prevent it entirely, block third-party scripts from accounts.google.com in your browser.
f. Messages You Send Us
When you send us a message through a contact form, we collect your name, your email address, the category you selected, your message, and the page you sent it from. We store the message in our database and also deliver it by email, through Resend, to an internal OpenDecision address so that a person can read and reply to it. We use it to answer you and to keep a record of the exchange.
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Services
- Authenticate you and keep your account secure
- Generate AI-powered decision matches and responses through Otis AI (see Section 4 below)
- Send transactional messages (sign-in codes, account notifications)
- Analyze usage patterns to improve product quality and relevance
- Detect, prevent, and respond to fraud, abuse, and security issues
- Comply with legal obligations and enforce our Terms
We do not sell your personal information. We do not use Your Content to train our own foundation AI models.
3. How We Share Information
We share information only with service providers ("subprocessors") who help us operate the Services, and only for the purposes listed. Each subprocessor is contractually bound to protect your data. Our current subprocessors are:
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Google LLC (Gemini API) | Large language model inference for Otis AI and research | United States |
| Langfuse | AI observability and tracing for Otis conversations, including your message and your account identifier | United States |
| Google LLC (Identity Services) | Sign-in with Google and Google One Tap. The script loads on every app page, before sign-in, and can set its own cookies (Section 1e) | United States |
| Microsoft Corporation | Sign-in with Microsoft (Entra ID) | United States |
| Resend | Transactional email delivery (sign-in codes, notifications) and delivery of contact-form messages to us | United States |
| PostHog | Product analytics and usage measurement | United States (US Cloud) |
| Sentry | Error monitoring and crash diagnostics, including masked session replay recorded when an error occurs | United States |
| Redis cache host | In-memory cache and rate limiting. Holds IP addresses for abuse prevention and embedding vectors keyed by a one-way hash. It never stores your message or prompt text | United States |
| Vercel | Frontend hosting and edge delivery | United States |
| DigitalOcean | Backend API and pipeline hosting | United States |
| Cloudflare | DNS, CDN, email routing, bot protection (Turnstile) | Global |
Error Monitoring and Session Replay
We use Sentry to detect and diagnose errors in the Services. When something breaks, Sentry receives an error report containing the technical details of the failure, such as the page you were on, the browser you used, and a stack trace. Sentry also records a session replay, but only for the session in which an error occurred: we never record a sample of ordinary sessions. Replays are captured with text masking and media blocking turned on, which means the text on the page is replaced with placeholder blocks and images and video are not recorded. A replay shows us layout, clicks, and navigation, not what you or anyone else wrote. On our backend, Sentry is configured not to send default personally identifiable information such as IP addresses. Sentry processes this information as our subprocessor in the United States.
Cloudflare Turnstile
We use Cloudflare Turnstile to protect the Services from bots and abuse. Turnstile runs invisibly in your browser and analyzes signals such as IP address, user-agent, browser characteristics, and interaction patterns to verify that requests come from legitimate users. No CAPTCHA-style challenge is shown to most visitors. Cloudflare processes this information as our subprocessor under its Turnstile Privacy Addendum, which is incorporated by reference into this Policy.
We may also disclose information (i) with your consent, (ii) to comply with valid legal process or government requests, (iii) to protect the rights, property, or safety of OpenDecision, our users, or the public, or (iv) in connection with a merger, acquisition, or sale of assets, with notice to you where practical.
4. AI Processing Disclosure
OpenDecision's Otis AI assistant and research features use third-party large language models, currently Google Gemini. When you interact with Otis AI, your messages, decision criteria, and related inputs are transmitted to Google for inference. Google acts as a subprocessor and is subject to Google's AI Gemini API terms which prohibit use of paid-API data for training Google's foundation models.
a. What Reaches the Model
The prompt we send to Gemini can contain more than the sentence you typed, so it is worth being precise about what travels with it:
- Your message, your criteria and their weights, and the products in your decision space
- Uploaded documents: we extract the text on our own servers using standard document libraries, with no third party involved, and send the extracted text to Gemini. The file name and any note you attached to the upload go with it
- Uploaded images: sent to Gemini whole, as the image itself. We run no text recognition of our own, so whatever is legible in the picture is read by Gemini rather than by us
- The names and email addresses of the people in your decision space. Your own identity is replaced with the word "you", but your colleagues are named, and their email address appears next to their name
- Notes written on products in your space, but only when you ask Otis for a summary or to catch you up. Ordinary chat turns do not carry notes. When a summary turn does include them, each note is trimmed to its first 200 characters and carries its author's name
b. Links You Add to a Decision Space
If you put links in a decision space's objectives, our servers fetch those pages so that Otis can read them: up to five links per space, identifying themselves with the user agent OpenDecision-Otis/1.0. Two consequences are worth stating plainly. The site you linked receives a request from our infrastructure rather than from your browser, so it learns that someone using OpenDecision linked to it. And up to 2,000 characters of the page are placed into the prompt sent to Gemini. We cache what we fetch for seven days. Please do not link to pages you would not want fetched and summarized, including private documents that are reachable by anyone holding a secret URL.
c. Web Search Grounding
Otis can answer questions about products that are not already in our catalog, and it can check a requirement against the products it is comparing. In both cases it uses Gemini's grounding with Google Search: a query is sent to Google Search and the results are returned to the model before it answers. That query can be your own question. When Otis is checking a requirement, the query we build quotes the requirement exactly as you wrote it, alongside the product names. Treat anything you type to Otis as capable of reaching a web search.
d. AI Observability
We use Langfuse, a US-hosted AI observability service, to record traces of Otis conversations so that we can debug and improve answer and match quality. A trace covers a whole conversation turn: it includes the message you sent, in the words you wrote it, the prompt built around it, and your account identifier, which means a trace is linkable back to you rather than anonymous. Tracing is controlled by a server setting and is not enabled in every environment.
e. Voice Input
The microphone button in the app uses the speech recognition built into your browser (the Web Speech API), not a service we operate. In Chrome the audio is sent to Google and in Safari it is sent to Apple, under that browser vendor's own privacy terms rather than ours. We never receive or store the audio. We receive only the text your browser transcribes, which we then treat exactly like text you typed. If you would rather not send audio to your browser vendor, type instead of using the microphone.
AI-generated responses may contain errors, biases, or omissions. You should independently verify information used to make material business decisions. We do not use Your Content to train our own models.
5. International Data Transfers
Our infrastructure and subprocessors are primarily located in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States. For users in the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission as the lawful basis for these transfers.
6. Data Retention
- Active accounts: we retain Your Content for as long as your account is active
- Anonymous sessions: automatically deleted 90 days after last activity
- Deleted accounts: Your Content is permanently deleted within 30 days of deletion request, except as required by law
- Backups: encrypted backups are retained for up to 35 days for disaster recovery
- Analytics: aggregated, de-identified analytics data may be retained indefinitely
- Transactional records: retained as required for tax, accounting, and legal compliance (typically 7 years)
7. Your Rights
Regardless of your jurisdiction, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your account and Your Content
- Object to or restrict certain processing
- Request a portable copy of Your Content in a common format
- Withdraw consent where processing is based on consent
To exercise these rights, email matt@opendecision.com. We will respond within the time required by applicable law (typically 30 days).
8. Security
We use industry-standard security measures to protect your information, including TLS encryption in transit, encryption at rest for stored data, role-based access controls, audit logs, and regular security reviews. No system is perfectly secure; you are responsible for protecting your account credentials and we recommend using a strong, unique password or an OAuth provider with multi-factor authentication enabled.
9. Children
The Services are not directed to children and are intended for business use. You must be at least 18 years old to use the Services. We do not knowingly collect personal information from anyone under 18. If we discover that we have, we will delete it promptly and close the account.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated by email or in-product notice at least 14 days before taking effect. The "Effective Date" at the top of this page indicates when the most recent changes were made.
August 25, 2026: named the data controller and its mailing address; added Sentry, Langfuse, and our cache host to the subprocessor list; disclosed the Google sign-in script that loads on every app page, Gemini's grounding with Google Search, the pages our servers fetch from links you add, what an uploaded document or image actually sends, whose names and email addresses appear in a prompt, and the speech recognition your browser performs; corrected the description of how your sign-in session is stored; separated what runs on the app from what runs on the marketing site; and covered messages sent through our contact form.
11. Jurisdiction-Specific Rights
a. European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent laws, including the right to lodge a complaint with your local supervisory authority. The legal bases we rely on are:
- Contract: processing necessary to provide the Services to you
- Legitimate interest: product improvement, security, and fraud prevention
- Consent: where you actually give it, for example by opting in to marketing communications
- Legal obligation: to comply with applicable laws
We do not currently operate a cookie consent banner, so the analytics and error-diagnostic technologies described in Section 1d are set on your first visit. You can prevent them: our analytics honours your browser's Do Not Track setting, you can block or clear cookies for this site in your browser, and you can write to matt@opendecision.com to have the analytics data associated with you deleted. We are adding a consent control for visitors in the EEA and the UK.
b. California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information. To exercise your rights, contact us using the information in Section 12.
c. Other US State Residents
Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have similar rights under their state privacy laws, including the right to access, correct, delete, and opt out of targeted advertising. We do not engage in targeted advertising or the sale of personal information as defined by these laws. To exercise your rights, contact us using the information in Section 12.
d. Canada, Australia, and Other Jurisdictions
Users in Canada, Australia, and other jurisdictions have rights under their applicable privacy laws (PIPEDA, Privacy Act 1988, and others). Contact us to exercise them.
12. Contact Us
Questions about this Privacy Policy or your personal information? Email matt@opendecision.com.
The data controller responsible for your personal information is Panoramic Solutions, LLC. Written requests, including requests to exercise the rights in Section 7 and Section 11, can be sent to the email address above, and we will provide a postal address on request.