Privacy Policy
Last updated: September 27, 2026
This policy explains how CommandGPT handles information when you use the website, account service, OAuth connection, MCP tools, and local Agent.
Information we process
- Account information: email address, verification status, authentication records, subscription status, and account settings.
- Device information: device name, platform, Agent protocol/version information, connection state, pairing and revocation state.
- Tool data: file paths and requested file contents, command inputs and bounded outputs, Git/project metadata, process/window information, clipboard text, screen captures, and other data you explicitly ask a CommandGPT tool to access.
- Security and audit information: action type, outcome, device association, and limited operational metadata used to protect accounts and review activity.
- Billing information: subscription and checkout status. Payment-card details are processed by our payment provider and are not stored by CommandGPT.
How we use information
We use this information to authenticate users, connect authorized devices, execute the tools you request, enforce permissions and plan limits, provide billing and support, prevent abuse, and maintain service reliability.
Local computer data
Normal tool execution relays requested data between ChatGPT, the CommandGPT cloud service, and your authorized local Agent. CommandGPT does not store file contents, clipboard contents, shell output, or screen captures in its primary account database as part of normal tool execution. The local Agent enforces its configured roots and access mode.
Service providers and recipients
We use infrastructure, email, and payment providers to operate CommandGPT. When you connect CommandGPT to ChatGPT, OpenAI receives the tool inputs and results needed to fulfill your requests under your OpenAI account and applicable OpenAI policies.
Retention
- Structured CommandGPT audit events are retained for up to 30 days.
- Browser sign-in sessions expire after 7 days and revoked/expired browser sessions are pruned.
- Authentication rate-limit records are pruned after approximately 2 days.
- Approved device-pairing records are pruned after approximately 24 hours; expired pending pairings are pruned after expiry.
- Account, subscription, authorized-device, and OAuth authorization records are retained while needed to provide the service, until revoked/expired where applicable, or longer when required for security, fraud prevention, legal compliance, or dispute resolution.
Your controls
You can revoke device access and OAuth/app connections. You can also contact us to request access, correction, or deletion of account information, subject to legal and security retention requirements.
Contact
Privacy and support requests: support@commandgpt.app.