1. Information we collect
Account information
Your name and email address. If you sign up with a password, we store only a salted scrypt hash of it, never the password itself. If you sign in with Google, we receive your name, email address and Google account identifier from Google.
Workspace content
Everything you and your team put into Osco: workspaces, projects, documents, folders, tasks, acceptance criteria, features, API collections and endpoints, environments and their values, comments and links between them. You decide what goes in.
Activity records
To give workspaces an audit trail, Osco records actions such as edits, status changes, shares, role changes and deactivations, along with who made them and when. These records are visible to people in your workspace with the right permissions.
API tokens
When you create a personal API token for a coding agent, we store only a hash of it. The full token is shown to you once and can be revoked at any time.
Technical data
Like any web service, our servers process your IP address, browser type and request details to deliver pages, keep the service secure and investigate errors or abuse.
2. Cookies and browser storage
Osco does not use advertising cookies or third-party analytics. We use your browser’s local storage for things the app needs: your sign-in session, your theme, and view preferences such as list or board layout. Personal tokens you enter for API requests stay in your browser and are not sent to us. Clearing your browser storage signs you out and resets these preferences.
3. How we use information
- To provide, maintain and improve Osco, including sign-in, collaboration, sharing and search.
- To enforce access control: workspace isolation, roles and project-level permissions.
- To keep the service secure, prevent abuse and debug problems.
- To contact you about your account, security issues or important changes to the service.
- To meet legal obligations.
We do not sell your personal information, we do not show ads, and we do not use your workspace content to train AI models.
4. Coding agents and MCP
If you connect a coding agent (for example Claude Code, Cursor or VS Code) to Osco with an API token, the agent acts as you: it can read and change whatever your role allows. Content the agent reads is sent to that agent and its model provider, and is handled under their terms and privacy policies, not this one. Only connect agents you trust, and revoke tokens you no longer use.
5. Sharing
We share information only in these cases:
- Within your workspace. Members see content according to their role and project access.
- Share links you create. A document or endpoint shared publicly can be viewed by anyone with the link until it expires or is revoked.
- Service providers that host our servers and databases for us, bound by confidentiality and data protection obligations.
- Google, if you choose Google sign-in, to authenticate you.
- Legal reasons. When required by law, or to protect the rights, safety and security of our users, the public or us.
- Business transfers. If Redshot Labs is involved in a merger or acquisition, with this policy continuing to apply to your information.
6. Security
Every query is scoped to your workspace on the server, so other workspaces cannot reach your data. Passwords and API tokens are stored hashed, secret environment values are withheld from people who cannot edit them, and administrators can deactivate members and sign them out everywhere. No system is perfectly secure, but we work to protect your information and will notify affected users of a breach as required by law.
7. Retention and deletion
We keep your information for as long as your account or workspace is active. Deleted documents go to the workspace trash, where they can be restored until they are permanently removed. When you ask us to delete your account or workspace, we delete the associated data within 30 days, except where we must keep something to meet legal obligations. Copies in backups are removed as those backups expire.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to or restrict certain processing. To make a request, email support@redshotlabs.com from the address on your account. We will respond within 30 days. If you are in the EEA or UK, you may also complain to your local data protection authority.
If your workspace is managed by your employer, they control the workspace content and may be the right first contact for requests about it.
9. International transfers
Osco may be hosted and operated in countries other than yours. When we transfer information across borders, we protect it as described in this policy and as required by applicable law.
10. Children
Osco is a tool for professional teams and is not directed at children under 16. We do not knowingly collect their information.
11. Changes to this policy
We may update this policy as Osco changes. We will change the “last updated” date above, and for significant changes we will notify you in the app or by email before they take effect.
12. Contact
Questions about privacy or this policy: support@redshotlabs.com.