OPPEN
ManifestoWhitepaperAnswersTermsPrivacy
PRE-ALPHA
oppen.xyz · legal

Privacy Policy

Last updated 2026-09-04

Summary

oppen is local-first software. It has no backend, no accounts and no telemetry. The application does not send us your keys, your positions, your orders, your agent's reasoning, or anything else. There is no server of ours for it to send them to.

This page exists to say exactly what that means, and to be honest about the two places where visiting this website is not quite nothing.

01

The application collects nothing

oppen runs entirely on your machine.

  • Private keys are generated locally and stored in your operating system's keychain. They are never transmitted anywhere.
  • Your positions, orders, fills, guardrail settings and decision ledger are stored locally, in a database on your own disk.
  • Your agent's model API key, if you use a hosted model, is stored locally and sent only to the model provider you chose. We never see it.
  • There is no crash reporting, no usage analytics, no update ping and no licence check.

When oppen connects to a trading venue, it connects directly from your machine to that venue. We are not in the path and cannot observe it. What the venue records is governed by the venue's own policy, not ours.

02

What this website sees

This site is three static pages. It has no forms, sets no cookies, and stores nothing in your browser. There is no login and nothing to sign up for.

Two things are still worth disclosing.

Hosting. The site is served by Cloudflare. As the host and network provider, Cloudflare processes your IP address, user agent and request details in order to deliver the page and to protect the site from attack. This is ordinary server logging that every website has. We do not receive an identifiable record of individual visits from it. Cloudflare's own privacy documentation governs what it retains.

Fonts. None. The two typefaces, Space Mono and Archivo, are served from this domain. They were previously loaded from Google Fonts, which disclosed every visitor's IP address to Google, and we removed that: a site claiming no telemetry should not quietly make a third-party request on your behalf.

Cloudflare Web Analytics. Our host currently injects a small analytics script into pages. Our own Content Security Policy blocks it from running, so it collects nothing, but the request is still attempted. We are removing it; it should not have been on a site that says it has no telemetry. When it is gone, loading any page here will contact exactly one host, the one you typed into the address bar.

03

No tracking

We do not use advertising networks, tracking pixels, session recording, fingerprinting, or cross-site identifiers. We do not sell or share personal data, because we do not hold any.

04

Children

oppen is not directed at anyone under 18 and should not be used by them.

05

Your rights

Depending on where you live you may have rights to access, correct, export or delete personal data held about you. In our case the answer is short: we hold none, so there is nothing to produce or erase. If you believe otherwise, write to us and we will look into it properly.

06

Changes

If this policy changes we will update the date at the top. Material changes will be noted in the project's release notes rather than applied silently.

07

Contact

Security reports: see /.well-known/security.txt.

Privacy questions: [email protected].

oppen.xyz · 2026 ← back to oppen.xyz