Operon Holdings LLC
Privacy Policy
Effective July 7, 2026 · Last updated July 7, 2026
This Privacy Policy explains how Operon Holdings LLC ("Operon," "we," "us," or "our") collects, uses, shares, and protects information in connection with our software and services for owner-led businesses — including AI opportunity audits, done-for-you company-brain installs, and custom automations — marketed as "Operon" and "Operon AI" (the "Services"). The Services are accessible through operon-ai.io.
This policy applies to:
- Visitors to our public website (
operon-ai.io) - Authorized users of businesses and organizations that have engaged Operon as a service provider ("Customers")
- Individuals whose information is processed by the Services on behalf of a Customer (e.g., customers, contacts, vendors)
A note on roles. When we operate the Services on behalf of a Customer (such as a business that engages us to run its company brain), the Customer is the *controller* of the personal information of its own members and prospects, and Operon acts as a *processor* under that Customer's instructions. If you are an individual whose information a Customer holds and have questions about how it is used, please contact that Customer directly. This policy describes what Operon does with that information when it flows through our Services.
1. Information We Collect
Information you provide to us
- Account information for Customer staff (name, email, role, organization, login credentials).
- Business information the Customer enters into the Services (customer and contact records, quotes and balances, vendor terms, communications history).
- Communications you send us (emails, support messages, demo requests, feedback).
- Payment information for paid Customers (handled by our payment processor; we do not store full card numbers).
Information collected automatically
- Usage data (pages viewed, features used, timestamps, approximate location based on IP).
- Device data (browser type, operating system, device identifiers).
- Log data (IP address, request timestamps, error events).
- Cookies and similar technologies on
operon-ai.iofor session management, authentication, and basic analytics. We do not currently use third-party advertising cookies.
Information from third parties
- Email providers (Google Workspace / Gmail) when a Customer connects their email account through OAuth so the Services can send communications on the Customer's behalf.
- Accounting providers (e.g., QuickBooks) when a Customer connects an accounting account for billing reconciliation.
2. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Services.
- Generate communications, briefs, alerts, and reports for Customers.
- Authenticate users and protect against unauthorized access.
- Communicate with Customers about their account, support requests, security incidents, and product changes.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our agreements.
- Develop, test, and improve the Services, including evaluating product performance.
We do not sell personal information, and we do not use Customer business information to train third-party generative AI models.
3. How We Share Information
We share information only as necessary to operate the Services or as required by law:
- Service providers that support the Services under contract and confidentiality obligations:
- Hosting and infrastructure (Hetzner Cloud).
- Email delivery (SendGrid).
- Workflow / agent orchestration (Paperclip).
- Accounting integration (Intuit QuickBooks, when connected by Customer).
- Email sending (Google Gmail API, when connected by Customer).
- Payment processing (Stripe, when payment features are active).
- Customers and their authorized users — information you submit through the Services is visible to authorized users of your Customer organization.
- Legal and safety — we may disclose information if required by law, subpoena, court order, or to protect rights, safety, and property.
- Business transfers — in the event of a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of the transaction; you will be notified of any change in ownership.
- With your consent — we share information for any other purpose disclosed at the time of collection.
4. Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect information, including:
- TLS encryption in transit
- Access controls limiting Operon staff access to information on a need-to-know basis
- Regular security review of dependencies, configurations, and logs
- Server-side authentication tokens scoped to the minimum permissions necessary
No system is perfectly secure. If we become aware of a security incident materially affecting your information, we will notify affected Customers and, where required by law, individuals.
5. Data Retention
- Active Customer data is retained for as long as the Customer's account is active.
- Logs are retained for up to 90 days for operational and security purposes.
- Backups are retained for up to 30 days and rotated automatically.
- After termination of a Customer relationship, we retain information for up to 60 days to allow account reactivation and data export, after which we delete or anonymize it, except where retention is required by law (e.g., tax records).
A Customer may request earlier deletion of its account data by contacting us at the address below.
6. Your Rights
Depending on your relationship to Operon, your rights differ:
- Customer staff and direct users. You have the right to access, correct, or delete your account information. To exercise these rights, contact your administrator or email us at the address below.
- Individuals whose information is processed on behalf of a Customer. Operon acts as a processor on behalf of the Customer. Please direct privacy requests to the Customer (the business or organization that holds your information). We will assist Customers in responding to such requests under our service agreements.
State-specific rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you may have additional rights under those laws, including the right to:
- Confirm whether we process your personal information
- Access and obtain a copy of that information
- Correct inaccuracies
- Request deletion
- Opt out of certain processing (we do not "sell" personal information or use it for cross-context behavioral advertising)
To exercise these rights, contact us at the address below. We will not discriminate against you for exercising any of these rights.
7. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.
8. International Users
Operon operates from and stores information in the United States. By using the Services, you understand that your information will be transferred to and processed in the United States, which may have data protection laws different from those in your jurisdiction.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Customers by email or through the Services and update the "Last Updated" date above. Your continued use of the Services after the effective date of the updated policy constitutes acceptance of the changes.
10. Contact Us
For privacy questions or to exercise any of your rights:
Operon Holdings LLC 5300 Sherwood Road Little Rock, AR 72207 Email: privacy@operon-ai.io (preferred) Alternate: inquiries@operon-ai.io
If you contact us about a privacy request, please describe the request clearly and provide enough information for us to verify your identity and respond.