Privacy Policy

Effective date: 30 May 2026

1. Who we are

OPC Suite (“OPC”, “we”, “our”) is operated by TSA AI. Our registered contact address for privacy matters is support@tsa-ai.com.

2. What data we collect

  • Account data — name, email, organisation, role, hashed password, and authentication provider identifiers (Google, GitHub, etc.).
  • Workspace business data — records you create or upload (CRM contacts, deals, invoices, products, journals, employees, payroll runs, expense claims, documents, projects). This is your data; we store it on your behalf so you can access it from the OPC app and connected AI agents.
  • Operational telemetry — request logs, audit trails of API calls (including AI-agent calls via MCP), error reports, performance metrics, and security events.
  • Billing data — Stripe customer ID, subscription status, invoices. Card numbers are never sent to OPC; they are handled directly by Stripe.

3. How AI agents and MCP connections access your data

OPC exposes a Model Context Protocol (MCP) server at /api/mcp. Connections from agents (Claude, Codex, Cursor, Cline, Hermes, openclaw, openHuman, Pi, etc.) authenticate using either:

  • a Personal API Token you generated in Settings → Developer, or
  • an OAuth 2.1 access token issued via our consent screen at /oauth/authorize.

Each token is scoped to your workspace, can be revoked instantly from Settings, and every call is recorded in the audit log with the agent identifier (OPC_AGENT_KIND). We do not share your data with the agent vendor; the agent talks directly to OPC.

4. Where data is stored

Application data is stored in Supabase (PostgreSQL) with row-level security so that one customer cannot access another customer’s rows. Files (receipts, attachments, exports) are stored in Supabase Storage. Hosting infrastructure runs on Vercel (compute) and Supabase (database / storage). We do not sell, rent, or trade personal data.

5. How long we keep data

Workspace data is retained while your subscription is active and for up to 90 days after cancellation, after which we delete it on request or automatically. Audit logs are retained for 12 months. Backups roll off within 30 days.

6. Your rights

You may export, correct, or delete your workspace data at any time from Settings → Data, or by emailing support@tsa-ai.com. If you are in the EU/UK you also have rights under GDPR (access, rectification, erasure, portability, restriction, objection). California residents have rights under the CCPA.

7. Security

All connections use TLS 1.2+. API tokens are stored hashed; OAuth tokens use timing-safe comparison and PKCE. Passwords are hashed with bcrypt. We follow industry-standard practices and undergo regular dependency and configuration audits.

8. Sub-processors

  • Supabase — database, storage, authentication
  • Vercel — application hosting
  • Stripe — payments
  • Resend / Postmark — transactional email
  • Anthropic, OpenAI, Google — only when you Bring-Your-Own-Key for AI features; we do not relay your data through our own LLM accounts

9. Changes to this policy

Material changes will be announced via in-app notice and email at least 30 days before they take effect. Last updated: 30 May 2026.