openserve

openserve.com · Effective August 25, 2026 · Last updated August 25, 2026

Privacy Notice

This Privacy Notice explains how Openserve Holdings, LLC (“Company,” “we,” “us”) collects, uses, discloses and otherwise processes personal information in connection with IJR.ai, open.ijr.ai, and the IJR product subdomains, including our websites, browser service, mobile and desktop applications, AI services, creation studio, collaboration tools, hosted projects and growth/marketing features. Such services specifically include any and all products and services available through the OpenServe platform. A negotiated enterprise DPA may separately govern data we process solely on behalf of a business customer.

1. Information We Collect

  • ·Account/profile data: name, email, username, authentication data, organization, role, profile image and preferences.
  • ·Customer content and AI interaction data: prompts, queries, documents, code, files, images, audio/video, messages, collaboration content, projects, connected-source data, model selections, and saved/processed outputs.
  • ·Billing/transaction data: plan, subscription, invoices, tax information and limited payment metadata; full payment credentials are generally handled by the payment processor or app store.
  • ·Usage/technical data: IP address, device/browser identifiers, operating system, app version, features used, timestamps, logs, crash/performance data, security events, and approximate location derived from IP.
  • ·Device-permission data where enabled: selected local files/folders, contacts, calendar, reminders, photos/media library, approximate location, camera, microphone, notifications, clipboard (desktop application), screen capture (desktop application), or other OS permissions you choose to grant.
  • ·Integration data from connected services such as cloud storage, code repositories, productivity suites, ad accounts, analytics, CRM, email or other services, limited to permissions granted.
  • ·Marketing/support data: tickets, surveys, event data, marketing preferences and interactions with communications.
  • ·Information from public/third-party sources such as security/fraud vendors, app stores, referral partners and publicly available sources where lawful.

Google user data (Limited Use). OpenServe’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features you request (for example, triaging your inbox or scheduling on your calendar), is not used for advertising, and is not transferred to third parties except as necessary to provide those features, for security, or to comply with law.

2. How We Use Information

  • ·Provide, personalize, maintain and support the Services; authenticate users; synchronize workspaces; process prompts; generate output; host projects; and carry out requested actions.
  • ·Route requests to model providers and vendors; operate integrations; meter usage; process subscriptions; provide support.
  • ·Secure the Services; detect fraud, malware, abuse, policy violations and technical issues; enforce terms; protect users and third parties.
  • ·Analyze performance and usage; debug; improve UX; develop features; and, only as disclosed and permitted by settings/contracts, improve AI systems.
  • ·Communicate about accounts, security, support, service changes and marketing consistent with choices and law.
  • ·Comply with law, sanctions/export obligations, tax/accounting requirements and legal process.

3. AI Providers, Training and Improvement

Prompts, files, connected data and related context may be transmitted to third-party AI/model providers when you select or are routed to those models. The Third-Party Models & AI Notice identifies current providers and routes. Providers process data under our commercial/API arrangements and applicable policies or terms.

We do not use Customer Content - including prompts, conversations, files and connected-account data - to train our own or third parties’ AI models. If we introduce an optional model-improvement program in the future, participation will require explicit opt-in through a clearly disclosed setting, and Business/Enterprise content will remain excluded by default. Security/abuse logs and de-identified or aggregated usage data may be used for safety, reliability and product improvement where permitted.

4. Company-Branded Model

The Services may offer one or more Company-branded models (currently OpenServe Genius and OpenServe Nexus). Company-branded models are not separate foundation models: they consist of Company-configured routing, prompting, safety and orchestration over third-party models accessed by API, as identified in the Third-Party Models & AI Notice. We do not fine-tune or self-host the underlying models. Material dependencies and applicable license/policy information are disclosed in the Third-Party Models & AI Notice.

5. Sharing and Disclosure

The Company may share and disclose certain data to the following, as described herein:

  • ·Service providers/subprocessors that host, secure, support, analyze, bill, communicate or help operate the Services.
  • ·Model providers and AI infrastructure vendors needed to process prompts and generate outputs.
  • ·Integrations and third parties at your direction when you connect an account, publish/share content, invite collaborators or launch a campaign.
  • ·Organization administrators for managed workspaces, subject to administrative permissions and agreements.
  • ·Professional advisers, auditors, insurers, financing sources and corporate transaction counterparties under appropriate confidentiality.
  • ·Authorities, regulators or other parties where reasonably necessary for law, legal process, rights, safety or security.
  • ·Business successors in a merger, acquisition, financing, reorganization, bankruptcy or asset sale.

We expressly do not sell personal information for money.

6. Cookies, SDKs, Analytics and Advertising

We and vendors may use cookies, local storage, pixels, SDKs and similar technologies for authentication, security, preferences, analytics, attribution and, if used, advertising. Where required, non-essential technologies are used only with consent. See the Cookie Notice and preference center.

7. Retention and Deletion

We retain personal information only as reasonably necessary for the Services and legitimate business/legal purposes, considering sensitivity, account status, contracts, security and law. The table below sets out typical retention periods. Backups may persist for a limited period after deletion before overwrite. We may retain data for fraud prevention, legal holds, disputes, accounting or compliance.

Data categoryTypical retentionPurpose
Account/profile dataLife of the account; deleted or anonymized within 30 days of account deletionProvide and secure the Services
Chats and prompt historyUntil you delete them or delete your account (no automatic expiry)Provide the Services; your history remains under your control
Deleted chats and trashed contentPurged within 30 days of deletionRecovery window
Workspace files and uploadsLife of the account; trashed files purged after 30 days; deleted with the accountProvide the Services
Usage and security logsWhile the account is active; deleted with the accountSecurity, fraud and abuse prevention, billing accuracy
Support recordsAs needed to resolve the matter, plus any legally required periodCustomer support
Billing recordsAs required by tax and accounting law (maintained with our payment processor)Legal compliance
BackupsA limited period after deletion before overwrite, per provider cyclesResilience

Account holders may delete their account directly in the product at Settings > Account > Delete account (openserve.com/settings/account), which also provides a full data export, or may request deletion by emailing [email protected]. Account deletion initiates deletion of associated personal information and user-generated content except where retention is legally required/permitted or needed for security, fraud prevention, disputes or enterprise administrator obligations. We will instruct processors to delete where required by contract or law.

8. Privacy Rights and Choices

Depending on location, you may have rights to access, correct, delete, port, restrict/object, withdraw consent, opt out of targeted advertising or certain sale/sharing, and appeal a decision. Submit requests through [email protected]. We may verify identity and accept authorized-agent requests where required. Marketing opt-outs are available through unsubscribe links/settings.

9. International Transfers

We and vendors may process information in the United States and other countries. Where required for EEA/UK/Swiss transfers, we use recognized mechanisms such as adequacy decisions, EU Standard Contractual Clauses, the UK Addendum or other lawful safeguards. Enterprise processing is addressed further in the DPA.

10. Security

We use administrative, technical and organizational safeguards designed to protect information, but no system is completely secure. Current safeguards include encryption in transit (TLS with HTTP Strict Transport Security), application-layer AES-256-GCM encryption of connected-account credentials, authentication through a dedicated identity provider with no Company-stored passwords, role-based administrative access with audit logging, continuous automated security testing in our development pipeline (static analysis, dependency and supply-chain scanning, secret scanning and weekly dynamic scans), and monitored error and abuse alerting. Additional controls - including SOC 2 alignment, a formalized incident-response plan and disaster-recovery drills - are in progress on our security roadmap. Users remain responsible for credentials, endpoint security, secrets and workspace permissions.

11. Children

The Services are not directed to children under 18, and we do not knowingly collect personal information from children below the applicable minimum age without legally sufficient authorization. Contact [email protected] if you believe this occurred.

12. United States Privacy Rights

12.1 Scope

We currently offer the Services broadly within the United States. The Services are not presently offered for general availability in the European Economic Area or European Union. Accordingly, this Section describes rights that may be available to residents of the United States under applicable federal and state privacy laws.

Depending on where you reside, the nature of our relationship with you, the Personal Data involved, and whether an applicable law applies to us or to the relevant processing activity, you may have some or all of the rights described below. Certain laws contain exemptions, exceptions, thresholds, and limitations, and a right described in this Section may therefore not apply in every circumstance.

Where permitted, we may voluntarily honor certain privacy requests even when we are not legally required to do so. Doing so does not constitute an admission that a particular privacy law applies to us, to you, or to the Personal Data at issue.

12.2 Your Privacy Rights

  • ·Access and Know. You may request confirmation of whether we process Personal Data about you and request access to that Personal Data. You may also have the right to obtain information regarding the categories of Personal Data we have collected, the categories of sources from which we collected it, the purposes for which we use it, and the categories of third parties to whom we disclose it.
  • ·Obtain Specific Personal Data. Where required by applicable law, you may request the specific pieces of Personal Data that we maintain about you.
  • ·Correct. You may request that we correct inaccurate Personal Data that we maintain about you, taking into account the nature of the Personal Data and the purposes for which we process it.
  • ·Delete. You may request deletion of Personal Data that we have collected from or about you. We may retain certain information where permitted or required by law, including where reasonably necessary to provide the Services, maintain security and integrity, prevent fraud or abuse, comply with legal obligations, resolve disputes, enforce our agreements, protect legal rights, or maintain records permitted by applicable law.
  • ·Data Portability. Where required by applicable law, you may request a copy of certain Personal Data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without unreasonable impediment.
  • ·Opt Out of Sale. If we "sell" Personal Data as that term is defined under applicable state privacy law, you may have the right to opt out of that sale.
  • ·Opt Out of Sharing or Targeted Advertising. If we "share" Personal Data for cross-context behavioral advertising, or process Personal Data for "targeted advertising," as those terms are defined under applicable state law, you may have the right to opt out of that processing.
  • ·Opt Out of Certain Profiling. Residents of certain states may have the right to opt out of certain forms of automated profiling performed in furtherance of decisions that produce legal or similarly significant effects concerning the individual.
  • ·Limit Certain Uses of Sensitive Personal Data. Where applicable law provides such a right, you may request that we limit certain uses or disclosures of Sensitive Personal Data. In jurisdictions that require consent before certain Sensitive Personal Data may be processed, we will seek consent where legally required.
  • ·Withdraw Consent. Where our processing of Personal Data is based on consent and applicable law provides a right of withdrawal, you may withdraw that consent, subject to applicable legal limitations.
  • ·Non-Discrimination. We will not unlawfully discriminate against you for exercising a privacy right. For example, we will not deny you Services, charge you different prices, provide a different level or quality of Services, or retaliate against you solely because you exercised a privacy right, except where a difference is reasonably related to the value of your Personal Data or is otherwise permitted by applicable law.

12.3 Exercising your Rights

You may submit a privacy request by:

  • ·Email: [email protected]
  • ·Online: through your account at openserve.com/settings/account (data export and account deletion)
  • ·Telephone: a toll-free number for privacy requests is available upon request by emailing [email protected].

You may also be able to exercise certain rights through the settings or privacy controls available within your account or the Services.

Please describe the right you wish to exercise and provide sufficient information for us to reasonably identify you and process your request.

We will respond within the period required by applicable law. Where permitted by law, we may extend the response period when reasonably necessary and will notify you of the extension and the reason for it.

We generally will not charge a fee to process a privacy request. We may, however, charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, repetitive, or otherwise subject to an exception under applicable law.

12.4 Verification of Requests

To protect your Personal Data, we may need to verify your identity before fulfilling certain requests. The verification information that we request will depend upon the nature of your request, the sensitivity of the Personal Data involved, and the information that we maintain about you.

Verification may include confirming control of the email address associated with your account, authenticating through your account, confirming information previously provided to us, or using another reasonable verification method.

If we cannot reasonably verify your identity or authority to make a request, we may be unable to fulfill the request. We will not request more Personal Data than reasonably necessary to verify a request.

12.5 Authorized Agents

Where permitted by applicable law, you may designate an authorized agent to submit a privacy request on your behalf.

We may require the authorized agent to provide proof that you authorized the agent to act for you. We may also require you to verify your identity directly with us and, where permitted by law, confirm that you provided the agent permission to submit the request.

These requirements do not apply where applicable law requires us to recognize a valid power of attorney or other legally sufficient authorization without further verification.

12.6 Appeals

Residents of states that provide a right to appeal may appeal our refusal to take action on a privacy request by contacting us at [email protected] and including the words “Privacy Appeal” in the subject line.

Please identify the original request and explain why you believe our decision should be reconsidered.

We will review and respond to your appeal within the period required by applicable law. If an appeal is denied, we will provide any additional information regarding complaint or regulatory review mechanisms that applicable law requires us to provide.

12.7 Sale, Sharing, Targeted Advertising, and Universal Opt Out Signals

State privacy laws define terms such as “sale,” “sharing,” and “targeted advertising” differently, and certain disclosures that do not involve monetary payment may nevertheless qualify as a sale or sharing under some laws. While we do not proactively sell any data for money, we may disclose certain identifiers, device information, internet or electronic activity information, and similar information to advertising, analytics, or marketing partners in circumstances that may constitute a “sale,” “sharing,” or use for “targeted advertising” under certain state privacy laws. Where applicable, you may opt out by using our cookie preference center - available through the “Cookie settings” link in the website footer and “Cookie preferences” in account Settings - or by emailing [email protected] with the subject “Privacy Opt-Out”.

Where applicable law requires us to recognize a browser-based or device-based universal opt-out preference signal, such as the Global Privacy Control (“GPC”), we will process a valid signal as an opt-out request for the browser or device through which the signal is communicated, as required by applicable law. If you are logged into your account and applicable law requires us to associate the signal with your account, we will do so where reasonably feasible.

A universal opt-out signal generally does not prevent processing that is necessary to provide the Services or other processing that applicable law does not treat as a sale, sharing, or targeted advertising activity.

12.8 California Residents

If you are a California resident and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), applies to our processing of your Personal Information, you may have the rights described in this Section 12, including the right to know and access Personal Information; request deletion; request correction of inaccurate Personal Information; opt out of the sale or sharing of Personal Information; limit certain uses or disclosures of Sensitive Personal Information where the statutory right applies; and exercise your rights without unlawful discrimination.

For purposes of this Section, “Personal Information,” “Sensitive Personal Information,” “Sell,” and “Share” have the meanings assigned to those terms by the CCPA.

Categories of Personal Information: During the preceding twelve (12) months, we may have collected categories of Personal Information described elsewhere in this Privacy Notice, which may include identifiers; customer-record information; commercial information; internet or other electronic network activity; geolocation information at a level permitted by your device and settings; audio, electronic, visual, or similar information when you choose to provide or enable it; professional or employment-related information; inferences derived from other Personal Information; and Sensitive Personal Information to the extent you provide it to us or its processing is necessary to provide a feature you request.

The specific categories actually collected depend upon how you interact with the Services and which features you use.

We collect these categories from the sources described in this Privacy Notice and use them for the business and commercial purposes described in this Privacy Notice.

We may disclose these categories to the categories of recipients described in this Privacy Notice, including service providers, AI and infrastructure providers, integration providers, professional advisers, transaction counterparties, governmental or legal recipients where required, and other recipients at your direction.

We have not sold Personal Information, as “sale” is defined by the CCPA, during the preceding twelve (12) months.

We have not shared Personal Information for cross context behavioral advertising, as “sharing” is defined by the CCPA, during the preceding twelve (12) months. The Company may add additional services including those relating to marketing and advertising, at which point the Company will undertake an additional Cookie, SDK, Analytics and Advertising Review, and update this Section accordingly.

If applicable, the categories of Personal Information shared or sold and the categories of third parties receiving that information are described in this Privacy Notice, the Cookies and Similar Technologies Notice, or the Your Privacy Choices page.

Sensitive Personal Information: We do not use or disclose Sensitive Personal Information for purposes requiring a California consumer to be offered a right to limit such use or disclosure. If our practices change such that the CCPA requires us to provide a right to limit the use or disclosure of Sensitive Personal Information, we will provide the required mechanism before engaging in such processing.

California Authorized Agents: California residents may use an authorized agent to submit a request as described in Section 12.5. We may require written proof of the agent’s authority and may independently verify the resident’s identity as permitted by the CCPA.

12.9 Other U.S. State Privacy Laws

Residents of states with comprehensive consumer privacy laws may have additional or substantially similar rights under their applicable state law, including rights concerning access, correction, deletion, portability, sale of Personal Data, targeted advertising, certain profiling, Sensitive Personal Data, consent, appeals, and recognized universal opt-out mechanisms.

We will process requests and provide rights in accordance with the law applicable to the requesting resident and the relevant processing activity. Nothing in this Privacy Notice is intended to limit any non-waivable privacy right available under applicable law.

12.10 Information Processed on Behalf of Business Customers

Certain portions of the Services may be used by companies, employers, organizations, or other business customers that provide or make Personal Data available to us for processing on their behalf.

Where we process Personal Data solely on behalf of a business customer in our capacity as its service provider or processor, the business customer generally determines the purposes and means of the relevant processing and is responsible for responding to requests from the individuals whose Personal Data it controls.

If you submit a privacy request to us concerning Personal Data that we process solely on behalf of a business customer, we may direct you to the relevant business customer or assist that customer in responding to your request as required by applicable law and our agreement with that customer.

12.11 U.S.-Focused Availability

The Services are currently intended for launch and general availability in the United States. We may restrict access to the Services from jurisdictions in which we have not elected to offer them, including the European Union and European Economic Area.

The fact that a person located outside the United States is technically able to access a website, download information, or otherwise interact with us does not mean that we offer or direct the Services to that jurisdiction.

If we expand the Services into additional jurisdictions, we may update this Privacy Notice and provide any additional notices, rights, contractual protections, or other measures required by applicable law before or in connection with that expansion.

13. Changes and Contact

We may update this Notice and will post the updated version with a new Last Updated date and additional notice where required. Contact: Openserve Holdings, LLC, 5911 N Honore Ave, Suite 104, Sarasota, FL 34243. Contact for Privacy: [email protected]; Contact for Legal: [email protected]; Contact for Support: [email protected].

Privacy Notice — OpenServe