Privacy Policy
Effective 2 September 2026
onstaff (“onstaff”, “we”, “us”) is operated from Melbourne, Australia. This policy explains what information we collect when you use onstaff at app.onstaff.app, how we use it, and the choices you have. We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles.
What onstaff does
onstaff runs a team of AI agents on your behalf inside a private workspace. To do useful work, agents read the information you give them and, where you connect other services, information from those services. Agents draft and propose; actions that reach outside your workspace (sending an email, publishing content, opening a pull request) happen only after a person in your workspace approves them.
Information we collect
- Account details — your name, email address and a password (stored as a one-way hash), plus workspace membership and role.
- Workspace content — messages you send to agents, files and images you upload, tasks, proposals, the “brain” entries agents and people write, and the transcripts of agent runs.
- Connected services — if you connect Google (Gmail, Calendar, Drive, Sheets, Analytics, Search Console), GitHub or other services, agents access those services within the permissions you grant. Details for Google data are below.
- Credentials you choose to provide — API keys or subscription tokens for AI providers, and connector tokens. These are encrypted at rest and used only to run your workspace's agents.
- Technical data — server logs (IP address, browser, pages requested) kept for security and debugging, and a session cookie that keeps you signed in. We do not use advertising or tracking cookies.
How we use information
- To provide the service: run agents on your requests and schedules, store your workspace, and show your team what needs their attention.
- To process content with AI models. Your prompts, workspace content and relevant connected-service data are sent to our AI provider (currently Anthropic) to generate agent responses. We do not use your content to train models, and our providers process it under terms that prohibit training on it.
- To send transactional email — invitations, password resets, and notifications you request. No marketing email without your consent.
- To keep the service secure, meter usage, and diagnose problems.
Google user data
When you connect a Google account, onstaff requests only the scopes needed for the products you enable (for example read-only Gmail access and draft creation, Calendar events, Drive/Sheets reading, Analytics and Search Console reporting). We use that data solely to perform the work you ask your agents to do — reading and summarising email, drafting replies you approve before sending, reading documents and spreadsheets, and reporting on analytics. We store the minimum needed: encrypted OAuth refresh tokens, and any content you or your agents deliberately save to your workspace (for example a brain entry or an extracted figure). We do not sell Google user data, use it for advertising, or let humans read it except with your permission, for security purposes, or where required by law.
onstaff's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google at any time from your workspace's Connectors page, or revoke access at myaccount.google.com/permissions. Disconnecting deletes the stored token.
Who we share information with
- AI providers (Anthropic; or a provider whose credentials you supply) — to generate agent responses.
- Services you connect (Google, GitHub and others) — data flows to and from them only as your agents act within the permissions you granted and, for external actions, after your approval.
- Infrastructure providers — our servers and database are hosted with DigitalOcean in Sydney, Australia; transactional email is sent through an email delivery provider.
- Legal requirements — if required by law or to protect the rights and safety of onstaff or others.
We do not sell personal information.
Storage, security and retention
Data is stored in Australia. Connections use TLS. Credentials and tokens are encrypted at rest. Access to production systems is limited to the people who operate onstaff. We keep your information for as long as your workspace exists; deleting a workspace permanently removes its content, agents, brains, conversations and connector credentials. Server logs are rotated automatically.
Your rights and choices
You can access and correct your account details in the app, disconnect services, remove members, and delete your workspace. Under Australian privacy law you may request access to or correction of the personal information we hold about you, or make a complaint, by emailing privacy@onstaff.app. We will respond within a reasonable time. If you are not satisfied with our response you may contact the Office of the Australian Information Commissioner.
Children
onstaff is a business tool and is not directed at children under 16. We do not knowingly collect their information.
Changes
We will post any changes to this policy here and update the effective date. Material changes will be announced in the app.
Contact
Questions about privacy: privacy@onstaff.app.