PRIVACY POLICY

Privacy Policy

Last updated July 21, 2026

This policy explains what The Commons collects, how we use it, and the choices you have — including the non-identifying analytics we record and how Content Gap Detection is anonymized.

The Commons is currently in Beta. The Service is provided on an “as is” and “as available” basis, and you use it at your own risk. Features may change, be interrupted, or contain errors while we build with early teams. See the relevant section below for the full terms.

This Privacy Policy describes how [Legal entity name] (“we”, “us”), the operator of The Commons (the “Service”) at aiopshq.app, collects and uses information. It should be read alongside our Terms of Service. Because the Service is in Beta and provided on a use-at-your-own-risk basis, please also review the Beta terms there.

1. Information we collect

  • Account & organization data — such as your name, email address, role, and the organization you belong to, used to provide the Service and control access.
  • Content you submit — the assets, drafts, tags, approvals, questions, and related material you and your organization create in the Service.
  • Usage & analytics data — non-identifying information about how the Service is used, described in Section 3.
  • Technical data — standard information such as IP address, browser type, and timestamps, used for security and to operate the Service.

2. How we use information

We use the information above to:

  • provide, maintain, secure, and improve the Service;
  • operate the AI-assisted features (pre-flight quality scoring, approval briefs, semantic search, “Ask the Commons,” and digests), which are advisory only;
  • understand product usage through non-identifying analytics; and
  • communicate with you and comply with legal obligations.

3. Product analytics (non-identifying)

We record non-identifying product analytics to understand how the Service is used and where it can be improved — for example, whether the library actually answers people's questions and whether published assets get used. We use a third-party analytics provider for this, and we have deliberately configured it to be privacy-preserving:

  • No content of your library, questions, or free text is sent to analytics. Analytics events never include the text of an “Ask the Commons” question, an asset's name or body, tags, feedback notes, or gap-theme summaries.
  • No automatic click/keystroke capture and no session recording. Autocapture, session replay, heatmaps, and dead-click capture are all switched off, so we do not record your screen or the on-page text you interact with.
  • Identified only by an internal identifier. Where events are associated with a user, that association uses an internal account identifier and your organization identifier — not your name or email. Gap-related events are attributed to an organization only, never to an individual.
  • You can opt out at the browser level. Analytics honor standard tracker-blocking tools, and we do not use analytics data to identify you personally.

We may disable analytics entirely at any time; when disabled, no analytics events are collected.

4. Content Gap Detection

The Commons includes a feature called Content Gap Detection, whose purpose is to help your organization's administrators understand recurring needs that your shared library does not yet cover — by analyzing certain prompts and questions to find generalized, anonymized themes, never by exposing what any individual person typed.

4.1 The two sources of signals

(a) “Ask the Commons” questions — always analyzed. When you use “Ask the Commons” to query your organization's library, that question may be used as a gap signal when the library does not already contain an adequate answer. Because Ask is a feature you use to query the library on purpose, this analysis applies to every organization and is not subject to a separate opt-in.

(b) Claude Code / Cowork prompts — opt-in only. Prompts you submit while working in Claude Code or Cowork are analyzed only if both your organization has enabled Content Gap Detection and you have personally opted in. Both are off by default, and you can withdraw at any time in your settings. Withdrawing this opt-in does not stop analysis of the questions you deliberately ask in “Ask the Commons.”

4.2 What is collected, filtered, and how long it is kept

For each eligible prompt or question we generate a numeric embedding (a mathematical representation of meaning) and temporarily retain the raw text. Before anything is retained we discard content that is off-topic or unrelated to your organization's work, content the library already adequately covers, and content outside a basic length range.

  • Raw text is held only briefly, in an access-restricted staging area used solely to group similar signals together. It is not accessible through any part of the application or to any administrator, and it is deleted immediately after a theme is evaluated and in any case within 48 hours, regardless of outcome.
  • Embeddings and match-quality metadata (never raw text) are retained while a theme is still forming and deleted within 14 days after the related theme is resolved.
  • Generalized theme summaries are retained as part of your organization's account for administrators to act on.

4.3 What administrators can and cannot see

Administrators never see your raw prompts or questions — not the exact wording, not a paraphrase attributable to you, and not who submitted any given input. They see only generalized theme summaries drawn from multiple people (for example, “Several people are looking for guidance on structuring customer renewal emails”). A theme is surfaced only once enough distinct people share it that it cannot reasonably be traced to any single individual, and an automated relevance check first removes anything personal or unrelated to organizational work. Theme summaries are generated to exclude names, client names, project codenames, figures, file paths, code, or other identifying specifics.

5. Service providers (sub-processors)

We rely on a small set of service providers to operate the Service. They process data solely to perform services on our behalf and not for their own purposes:

  • Supabase — database, authentication, and storage.
  • Vercel — application hosting.
  • OpenAI — generating embeddings for search and gap detection.
  • Anthropic — producing AI-assisted output and generalized, anonymized theme summaries.
  • Resend — transactional and digest email.
  • Slack — notifications, for organizations that connect it.
  • PostHog — the non-identifying product analytics in Section 3.

The AI providers above process this data to perform these operations on our behalf and do not use it to train their models. We do not sell your data.

6. Data retention

We retain account and content data for as long as your organization uses the Service and as needed to comply with our legal obligations. Content Gap Detection data follows the shorter retention windows described in Section 4.2.

7. Security

We use technical and organizational measures — including row-level access controls, hashed and revocable access tokens, and restricted service-role access to sensitive data — to protect your information. However, because the Service is in Beta and provided “as is,” no method of transmission or storage is completely secure, and you use it at your own risk.

8. Your choices and rights

  • You may turn Claude Code / Cowork prompt analysis on or off at any time in your personal settings, and organization administrators may disable that source for the whole organization.
  • You may use standard browser tools to block analytics.
  • Depending on where you live, you may have rights to access, correct, delete, or object to the processing of your personal data. To exercise them, contact us at [privacy/legal contact email]. Because raw gap-detection text is deleted within 48 hours and remaining signals are anonymized, we may be unable to identify data relating to a specific individual after that window.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice where required.

10. Contact

Questions about this policy or your data can be directed to us at [privacy/legal contact email].

Commons

The governed library for your team's AI skills, prompts, and guardrails.

PRODUCT
LibraryComing soonApprovalsComing soonAnalyticsComing soonPluginComing soon
COMPANY
AboutComing soonSecurityComing soonCareers
RESOURCES
DocsComing soonBlogComing soonContact
© 2026 Commons. All rights reserved.