1. Who We Are
911 DevOps LLC (“911 DevOps,” “we,” “us,” or “our”) operates the OpsPilot platform. This Privacy Policy explains how we collect, use, store, and share information when you use OpsPilot or our website at 911devops.com.
2. Information We Collect
2.1 Account Information
When you register for OpsPilot, we collect:
- Email address;
- Organization name;
- Password (stored as a bcrypt hash — we cannot recover it);
- Payment information processed by Stripe (we do not store card numbers).
2.2 Agent and System Metadata
When you install an OpsPilot agent on a server, the agent registers with our control plane and sends:
- Hostname, operating system, CPU architecture, and agent version;
- Heartbeat timestamps (to determine online/offline status);
- Output from diagnostic commands you authorize, transmitted to complete your request.
We do not read, store, or analyze the contents of your files, databases, application code, or any data beyond what is directly necessary to respond to queries you initiate.
2.3 Audit Logs
We maintain audit logs of every command dispatched through the Service, including the command text, risk classification, exit code, and duration. These logs are accessible to you through the dashboard and are retained for 90 days on the hosted plan.
2.4 Usage and Diagnostic Data
When you use the dashboard, we collect:
- IP address and browser user-agent (for security and abuse detection);
- Pages visited and features used (aggregated, not linked to individual queries);
- Error and performance metrics to improve reliability.
2.5 Contact and Support Data
If you contact us via the website contact form or email, we retain your message to respond to your inquiry.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service;
- Authenticate you and enforce access controls;
- Process payments and manage subscriptions through Stripe;
- Send transactional emails (account confirmation, API key delivery, invoices);
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations;
- Respond to support requests.
We do not use your data to train AI models. We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
4. AI Processing
When you send a natural-language query through OpsPilot, that query (and the diagnostic output gathered in response) may be transmitted to a third-party AI provider depending on your configured backend:
- Ollama (local): All processing happens inside your own infrastructure. Nothing is sent to 911 DevOps or any third party.
- Amazon Bedrock: Queries are processed by Amazon Web Services under AWS’s data processing terms. AWS does not use this data to train models.
- OpenAI-compatible endpoints: Queries are subject to the privacy policy of the provider you configure (e.g., OpenAI, Groq, Together AI).
You are responsible for ensuring your use of these AI backends complies with applicable privacy laws and your own data classification policies. We recommend using local Ollama for air-gapped or sensitive environments.
5. Data Sharing and Third Parties
We share information only as follows:
- Stripe: Payment processing. Subject to Stripe’s Privacy Policy.
- Amazon Web Services: Infrastructure hosting (email via SES, potential future services). Subject to AWS’s Data Processing Addendum.
- Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of 911 DevOps, its users, or the public.
- Business transfer: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, with notice to you.
6. Data Retention
- Account data is retained for the life of your account plus 30 days after deletion;
- Audit logs are retained for 90 days on hosted plans;
- Payment records are retained as required by financial regulations (typically 7 years);
- Backups may retain data for up to 30 additional days after deletion.
7. Security
We implement industry-standard security measures including TLS encryption in transit, bcrypt password hashing, JWT-based authentication with expiry, and network segmentation between services. However, no system is perfectly secure. You are responsible for securing your API keys and session credentials.
8. California Privacy Rights (CCPA / CPRA)
This section applies to California residents under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA/CPRA”).
8.1 We Do Not Sell Your Data
We do not sell your personal information and have not done so in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising.
8.2 Your California Rights
- Right to Know (§ 1798.110 / 1798.115): Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to Delete (§ 1798.105): Request deletion of personal information we have collected from you, subject to exceptions. Safety audit logs and consent records are retained indefinitely as legal evidence under Cal. Civ. Code § 1798.105(d)(9) — deletion would constitute spoliation of evidence and is therefore not available for this data category.
- Right to Correct (§ 1798.106): Request correction of inaccurate personal information.
- Right to Opt-Out of Sale / Sharing (§ 1798.120): We do not sell or share personal information, so this right does not currently apply. We will provide prior notice if this ever changes.
- Right to Limit Sensitive PI (§ 1798.121): We do not use sensitive personal information for purposes beyond providing the Service.
- Right to Non-Discrimination (§ 1798.125): We will not discriminate against you for exercising any CCPA/CPRA right.
8.3 How to Submit a Request
Email privacy@911devops.com with subject line “California Privacy Request.” We will respond within 45 days. We may need to verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf with written proof of authorization.
9. Your Rights (Other Jurisdictions)
For users outside California, depending on your jurisdiction you may have the right to:
- Access: request a copy of the personal data we hold about you;
- Correction: update inaccurate information via the dashboard;
- Deletion: request deletion of your account and associated data (note: safety audit logs are exempt as legal evidence);
- Portability: receive your data in a machine-readable format;
- Objection: object to processing in certain circumstances.
To exercise these rights, email privacy@911devops.com. We will respond within 45 days.
10. Children
The Service is not directed to children under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us immediately.
11. Changes to This Policy
We will notify you of material changes to this Privacy Policy via email or in-app notification at least 30 days before the changes take effect. The effective date at the top of this page indicates when the current version took effect.
12. Contact
For privacy-related questions, requests, or complaints: privacy@911devops.com