What stays on your device, what connected services process, and the choices you have.
Updated · Wega Labs Inc
October is operated by Wega Labs Inc, based in the United States. This policy explains how we handle personal information through our website, October Desktop, companion experiences, and hosted services that link to this policy. Contact us at harsh@wegalabs.com.
October brings people, terminals, AI agents, repositories, and connected machines into a shared workspace. Different features have different data flows. Running a tool locally does not make every connected feature offline.
Local repositories, files, terminals, settings, and agent sessions are handled on your device or the remote machine where you run them. Agents and integrations may read files, run commands, or contact services within the access you give them.
When you use collaboration, remote access, cloud workspaces, or sharing, the relevant workspace information passes through the services supporting that feature. It can include canvas state, participant details, messages, terminal output, files, and previews. People you grant access to may see or interact with that shared content. Public links and exports can reach a wider audience.
We obtain this information from you, your use of the service, collaborators sharing with you, and providers supporting sign-in, payments, or connected features. Account and payment information is needed for features that require authentication or a purchase.
Universal Chat, voice-command understanding, Runs, and other AI features may send your instructions and relevant context to a model provider. Context can include conversation history, selected files, workspace state, tool results, or terminal output, depending on the feature and your request.
Hosted assistant requests are logged. October’s assistant service stores request and response text, alongside account, model, timing, and usage information, for diagnostics and service operation. This is separate from product analytics. Our inference gateway’s operational logging is designed to record usage and request metadata rather than prompt and response content; upstream providers still process the requests routed to them.
Providers and routers, including services such as Anthropic and OpenRouter, apply their own processing, retention, and model-improvement policies. A provider you connect through your own account also applies its own terms and settings. We do not promise zero retention or training restrictions across every model or provider.
On-device speech recognition processes audio on your device. Online recognition sends audio to the selected speech service, such as Deepgram. A transcript used as an assistant command may still be sent for online interpretation even when speech recognition happened locally.
October Bus coordinates independent agents through peer information, messages, shared tasks, delivery records, and requests for human input. The local reference runtime stores coordination data on the machine running it and does not require an October-hosted control service. Messages and attachments can contain personal information or code that participants choose to share.
Self-hosting October Bus, October Harness, or another open-source project does not, by itself, send us everything you do with it. Data flows depend on the version, configuration, hosting, telemetry, and providers you connect. Using an October-hosted feature from open-source software brings that feature’s processing within this policy. Another operator’s hosting and privacy practices are their responsibility.
Public issues, discussions, and contributions are visible according to the repository host’s settings. Avoid putting private project data or credentials in public contributions.
Website analytics. We use PostHog for selected events such as page views, downloads, and sign-in or purchase activity. Website autocapture and session recording are disabled. Anonymous browser analytics use in-memory persistence; signed-in activity may be associated with your account, email, and profile. Events may include campaign attribution and technical request information.
Desktop diagnostics. Desktop builds send selected product and reliability events to PostHog, including app and platform information, session identifiers, feature counts, timings, and error categories. Signed-in activity may be linked to your account and email. These events are designed to exclude ordinary prompt text, file contents, credentials, and repository paths. Information you deliberately submit in an access request or support conversation is processed for that request.
Visit and purchase measurement. Infinite, operated by Ultima Inc., receives page path, host, referring host, browser classification, and a secret-keyed visit identifier that rotates every 30 minutes. That visit measurement does not send raw IP addresses or full user-agent strings to Infinite. Purchase events can include checkout references, offer details, amount, currency, and a visit reference when available.
We use browser or device storage for sign-in, preferences, cached information, and analytics choices. Support tools such as Intercom process messages you submit and relevant visitor or device information. External media and embedded content may make requests to their own providers when loaded; external links take you to services with their own policies.
We use information to provide requested features, coordinate shared work, authenticate accounts, process payments, measure and improve reliability, provide support, and prevent abuse. We also keep records to meet legal obligations and resolve disputes.
We share information with the people and integrations you choose, and with providers supporting hosting, storage, authentication, collaboration, AI, speech, payments, analytics, and support. Examples include Supabase, Vercel, Liveblocks, cloud workspace providers, Stripe, PostHog, Infinite, Intercom, and the AI or speech providers used by a feature. We may disclose information when legally required, to protect rights and safety, or in a business transfer with appropriate protections. We do not sell your personal information.
Where a legal basis is required, we rely on performing our agreement with you, legal obligations, legitimate interests in operating and securing the service, or consent where required. You can object to processing based on legitimate interests and withdraw consent where processing depends on it.
Retention depends on the information’s purpose: providing an active service, maintaining purchase and usage records, investigating issues, preventing abuse, or meeting legal obligations. Cloud workspace retention and export windows are disclosed with the relevant plan or offer. Keep copies of work you need beyond those windows.
Assistant diagnostic logs currently have no automatic expiry and are not automatically removed when an account is deleted. Contact us to request deletion of account information, hosted content, or assistant logs. We assess requests under applicable law; necessary billing, security, legal, and backup records may need to be retained. Deleting a local project does not automatically delete copies already shared with another person or provider.
We use access controls and protected connections to help secure hosted services. Security also depends on your devices, credentials, collaborators, and connected tools. No system can guarantee absolute security.
Information may be processed in the United States and other countries where our providers operate. Applicable privacy protections continue to apply. Contact us for information about relevant processing locations and transfer safeguards.
You can choose which tools and providers to connect, manage workspace access, revoke supported device or integration access, and control microphone permissions through your operating system. These choices may limit the features that depend on that access.
Use the browser analytics control below to stop PostHog product events from this browser. This does not disable essential service processing, server-side usage or billing records, or every other provider’s analytics. Website PostHog respects supported Do Not Track settings. Infinite’s page-visit measurement excludes requests with Do Not Track or Global Privacy Control signals. Desktop diagnostics can be disabled by launching the app with OCTOBER_ANALYTICS_DISABLED=1; contact us if you need help applying that setting.
Depending on where you live, you may have rights to access, correct, delete, or export information; restrict or object to processing; withdraw consent; or appeal a decision about a privacy request. Email harsh@wegalabs.com to make a request. We may need to verify your identity or an authorized agent’s authority. We will respond within the period required by applicable law and will not discriminate against you for exercising protected rights. You may also complain to the privacy authority where you live.
October is not intended for children under 13 or anyone below the minimum age required by local law. If you believe a child has provided personal information without the required authorization, contact us so we can investigate and address it.
We update this policy as the product and our practices change. The date above identifies this version. We will provide notice of material changes and obtain consent where the law requires it. Questions about any part of this policy can be sent to harsh@wegalabs.com.