Onsites AI is 100% free forever — 3 seats and 100 MB included. Start free →

Privacy Policy

Last updated: 2026. This policy covers our website, our cloud (SaaS) service, and our commercial relationship with self-hosted customers. The short version: your workspace data is yours, we don't sell it, we don't train shared models on it, and in self-hosted mode we never see it at all.

1. Two delivery models, one principle

Cloud (SaaS): the software runs on Onsites infrastructure. We process your account data and your workspace content to provide the service — we act as a data processor, and you remain the controller of the customer data you bring into the workspace. A Data Processing Agreement (DPA) is available on request for customers who need one.

Self-hosted: the software runs on your own LAN or in your own cloud account. The data inside your instance — conversations, contacts, documents, backups — stays on infrastructure you control and we have no access to it by default. This policy applies to what we do receive in that model: your licensing and billing contact details, license activation data, and anything you deliberately share with us through support.

2. What we collect

Website and contact forms

If you contact us or request an evaluation, we receive what you submit: your name, work email, organization and message. We use it to reply and nothing else.

Cloud (SaaS) workspaces

Account data: work email, company name, seat assignments and settings. Workspace content: the conversations, contacts, quotes, orders, invoices, contracts, files and catalog data your team puts in. Usage and billing data: which features you use, storage consumed, AI credits spent, invoices and payment status. Payments themselves are handled by our payment provider; we do not store full card numbers.

Self-hosted customers

Licensing contact, billing details, and minimal license activation data (license key, deployment identifier) needed to validate your subscription. We do not receive the content inside your instance.

3. How we use it

To operate, secure and support your workspace; to bill for seats, storage and AI credits; to communicate service updates you need to know about; and to improve the product in aggregate. We do not sell personal data, and we do not use it for third-party advertising.

4. AI processing

AI features (Copilot and Harness) process workspace content only when you or your team trigger them — a draft, a translation, a question answered with sources. Your data is not used to train shared or public models, and it is not shared with other customers. AI output is generated automatically and may contain errors; review it before it reaches your customers.

In self-hosted mode, AI runs through a model endpoint you provide — your own API key, an internal model or an air-gapped deployment. That processing happens between your instance and your model; it does not pass through Onsites.

The built-in spam, phishing and harmful-mail filter runs automatically on incoming email in the cloud. It classifies messages to protect the inbox and is included free; it does not consume credits and its classifications are not used to train shared models.

5. Sub-processors

We keep the list short: infrastructure hosting for the cloud service, a payment provider (Stripe) for billing, and email delivery for transactional mail. We do not disclose personal data to anyone else except as required by law or with your instruction. The current sub-processor list is available on request.

6. Data location and security

Cloud data is encrypted in transit and at rest on Onsites infrastructure, with automated backups on paid workspaces and seat-based access controls. Free-tier workspaces are not backed up server-side — use the export in settings to keep your own copies. Self-hosted deployments run entirely within your network under your security controls; see Security for what we do on both tracks.

7. Retention and deletion

Cloud workspaces: export or delete your data at any time from settings, or ask us. When you delete a workspace, its data is deleted within 30 days and purged from backups within 90 days. Self-hosted: your data never leaves your infrastructure, so deletion is entirely in your hands — removing the deployment removes the data.

8. Your rights

You can access, correct, export or delete your personal data. If you are in the EU, UK or a jurisdiction with similar law (such as CCPA in California), you have additional statutory rights — to object, to restrict processing, and to lodge a complaint with your regulator. Where data is transferred internationally, we rely on recognized safeguards such as standard contractual clauses. Email support@onsitesai.com and we will respond within 30 days.

9. Cookies

We use only what the product needs: session cookies to keep you signed in and a preference cookie or two. No advertising trackers, no cross-site profiling, no third-party analytics scripts on this marketing site.

10. Children

Onsites AI is a business product and is not directed at children under 16. We do not knowingly collect their personal data.

11. Changes

If we change this policy in a way that matters, we will tell you — by email for paid customers and on this page for everyone — before the change takes effect.

12. Contact

Onsites AI · support@onsitesai.com