Oversine
PlatformsPersonalPricingDocumentation
Book a demo
PlatformsPersonalPricingDocumentation
Book a demo

Privacy policy

  • Summary
  • Who we are
  • What we collect
  • Why, and on what basis
  • Who receives your data
  • What platforms get
  • How long we keep it
  • International transfers
  • Your rights
  • Security
  • Agents and automated decisions
  • Children
  • Changes

Legal

Privacy policy

Oversine is a sign-in identity for people and their AI agents. This policy explains what we collect when you use it, who receives it, how long we keep it, and the choices you have. Effective September 10, 2026.

Summary

  • We hold your name, email address, and profile picture, and a record of which platforms you or your agent signed in to and when.
  • We never see or store your password. Authentication is handled by Clerk, our identity processor.
  • Platforms you sign in to receive a stable identifier and, if they ask, your email and name. They never receive your Oversine credentials, cookies, or tokens.
  • Your agent can only do what you have approved: sign in to platforms that offer “Sign in with Oversine”, and use the partner tools you selected. Write tools you newly grant access to run automatically by default. You can choose “Ask each time” to review each write before it runs. Existing tool permissions keep their saved setting until you change it.
  • We do not sell personal data, run advertising, or use analytics trackers.

Who we are

Oversine, Inc. (“Oversine”, “we”, “us”, or “our”) is the data controller for the personal data described in this policy. We are a Delaware corporation with our principal place of business at 2261 Market Street STE 68058, San Francisco, CA 94114, United States, and we operate the Oversine service at https://auth.oversine.com. Questions, requests, and complaints go to privacy@oversine.com.

When a platform uses “Sign in with Oversine” or exposes tools through Oversine, that platform is a separate controller of whatever it does with the data it receives. Its own privacy policy covers that.

What we collect

Account data

When you create an Oversine account, Clerk collects and verifies the credentials you choose (email and password, a passkey, a one-time code, or a sign-in with another provider) and holds your profile. Oversine reads from it:

  • your primary email address and whether it is verified;
  • your first and last name, and username if you set one;
  • your profile picture, if you uploaded one;
  • a stable Oversine user id, which is the identifier platforms see.

Oversine does not receive or store your password, passkey, or second factor. If you sign up with another provider such as Google, Clerk receives what that provider shares; Oversine reads only the fields above.

Sign-in records

Each time you or your agent signs in to a platform through Oversine we record:

  • which platform, identified by its client id;
  • your Oversine user id;
  • whether an AI agent completed the sign-in;
  • the time.

When an agent signs in, we also keep the one-time request it approved: the request code, the platform’s name and callback origin, the scopes requested, the status of the request, which account, connected agent app and OAuth grant approved it, and the timestamps. The request record supports the audit log you see in your dashboard.

Connected apps and permissions

When you connect an agent host (Claude, ChatGPT, Claude Code, or another client) we record the app, the permission you granted it, and the refresh and access tokens that keep it connected. When a platform exposes tools through Oversine, we record which of those tools you allowed each connected app to use.

Approved actions

When your agent asks to use a partner tool that changes something, Oversine holds the exact tool name and arguments so you can review and approve them, then forwards the call and holds the result so the agent can read it. Arguments and results are whatever your agent and the partner exchanged, so they can include anything you asked the agent to do on that platform. See How long we keep it for when these are removed.

Platform owner data

If you register a platform or submit an integration in the dashboard, we store the registration you enter: name, redirect URIs, endpoint, tool definitions, client credentials, the revisions you submit, and the review decisions. This is linked to your Oversine account as the owner.

Technical data

Requests to the Oversine service are logged with the time, method, path, request headers, and the connecting IP address. The query string is dropped, and the authorization, cookie, referrer, set-cookie, and location headers are redacted before the log is written, so credentials and authorization codes do not reach the logs. IP addresses are also used transiently, in memory only, for rate limiting.

The marketing site at oversine.com is static. It sets no cookies, loads no analytics or third-party scripts, and serves its fonts from its own origin.

Cookies

The Oversine service uses only cookies it needs to function, all of them first-party and marked Secure and HttpOnly:

  • Clerk’s session cookies on the sign-in page, which keep you signed in;
  • the OpenID Connect session cookie, which remembers that you signed in so you are not asked again on every platform, for up to 14 days;
  • the dashboard session cookie, signed and valid for 12 hours, and a 10-minute login state cookie used while you are signing in to the dashboard.

There are no advertising, analytics, or cross-site tracking cookies. Because we do not track you across other sites, we do not change our behaviour in response to browser “Do Not Track” signals; there is nothing to turn off.

Why we use it, and on what basis

PurposeDataLegal basis
Operating your account and signing you in to platformsAccount data, session cookies, tokensPerformance of our contract with you
Letting your agent sign in and use tools you approvedConnected apps, permissions, action recordsPerformance of our contract with you; your selected execution permissions and individual approvals where required
Showing you where you and your agent signed in, and letting you revoke itSign-in records, agent request logPerformance of our contract with you
Detecting abuse, replayed codes, and unauthorized accessSign-in records, agent request log, request logs, IP addressOur legitimate interest in keeping the service secure
Showing platform owners how many sign-ins their platform receivedSign-in records, aggregated to countsOur legitimate interest in operating the platform program
Reviewing and publishing partner integrationsPlatform owner dataPerformance of our contract with the platform owner
Answering your requests and complying with lawWhatever the request concernsLegal obligation; legitimate interest

We do not use your data for advertising, profiling, or training models, and we do not sell it or share it for others to do so.

Who receives your data

Processors working for us

  • Clerk (Clerk, Inc., United States) authenticates you and stores your account profile and credentials.
  • Amazon Web Services (Amazon Web Services, Inc., United States) hosts the Oversine service and its database, which store the records described above.
  • Cloudflare (Cloudflare, Inc., United States) serves the static marketing site and, as with any content delivery network, sees the IP address of visitors.

Each processor acts only on our instructions under a data processing agreement. We will update this list before adding a processor that handles personal data.

Platforms and partners you choose

When you or your agent signs in to a platform, or your agent uses a partner’s tool, that platform receives the data described in the next section because you directed us to send it. From that point the platform is responsible for it.

Your agent host

The agent app you connected receives your Oversine name and email through the connection, so it can fill in sign-up forms as you, together with the results of any tool calls it made. The agent host’s own privacy policy governs what it does with that.

Business transfers

If Oversine is involved in a merger, acquisition, financing, reorganisation, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

Legal requests

We disclose data when the law requires it, to comply with a subpoena or court order, or to protect the rights, property, and safety of Oversine, our users, or others. We tell affected users when we are permitted to.

What platforms get, and what they do not

A platform that uses “Sign in with Oversine” receives:

  • your stable Oversine user id (the sub claim), always;
  • your email address, verification status, name, username, and picture, only for the scopes it requested and you saw on the consent screen;
  • whether an agent completed the sign-in (the amr claim), if it asked.

A partner whose tool your agent calls receives:

  • a signed token, valid for sixty seconds and usable only by that partner, naming your Oversine user id;
  • the tool call and arguments your agent prepared and, for writes, you approved.

Platforms and partners never receive:

  • your password or any Clerk credential;
  • your Oversine access or refresh tokens, or your cookies;
  • the list of other platforms you use;
  • who signed in to a platform: owners see aggregate counts only.

How long we keep it

DataKept for
Account profile (at Clerk)Until you delete your account
Authorization codes60 seconds, then kept briefly only to detect replay
Access and ID tokens1 hour
Refresh tokens, grants, and sign-in sessions14 days from last use, or until you revoke them
Agent sign-in request codesValid for 5 minutes; the record stays in your audit log
Approved action arguments and resultsApproval window of 10 minutes; payloads are deleted within 24 hours after the action completes or expires. A hash and the tool name remain in the audit record.
Sign-in records and the agent audit logWhile your account exists, then deleted within 30 days of account deletion
Tool permissions for connected appsUntil you change them, disconnect the app, or delete your account
Platform and integration registrationsUntil the owner deletes them or the owning account is deleted
Request logs30 days

We may keep specific records longer when the law requires it or to resolve an ongoing dispute or security incident, and we will limit use to that purpose.

International transfers

Oversine is based in the United States, and the service providers listed above process your data there. If you are in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to a country that may not provide the same level of protection as your own. Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) with each service provider, and on adequacy decisions where they apply. You can request a copy of the relevant safeguards by contacting us.

Your rights and choices

Depending on where you live, you have some or all of the following rights:

  • Access and portability. Get a copy of the data we hold about you, in a machine-readable format for the data you gave us.
  • Correction. Fix your name, email, or picture. You can do this yourself from your Oversine account.
  • Deletion. Delete your account. This removes your profile at Clerk and, within 30 days, your sign-in records, audit log, permissions, connected apps, and pending actions. Platforms you signed in to keep their own copy of your account until you delete it there.
  • Restriction and objection. Ask us to limit or stop a use that rests on legitimate interest.
  • Withdraw consent. Disconnect an agent app, revoke a platform, or change tool permissions at any time in your dashboard. Withdrawing does not undo sign-ins already completed.
  • Lodge a complaint. You may complain to the data protection or supervisory authority where you live or work. We would rather hear from you first at privacy@oversine.com.

Most of these you can do yourself in your dashboard at https://auth.oversine.com/dashboard. For anything else, email us. We will verify that the request comes from the account holder, respond within 30 days, and will not treat you differently for exercising a right.

California residents. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the past twelve months. The categories we collect are identifiers, account and profile information, internet activity limited to sign-in and request records, and the content of tool calls you approve. You may designate an authorized agent to make requests for you.

Security

  • All traffic to the Oversine service is encrypted in transit and HTTPS is enforced.
  • Tokens are short-lived: authorization codes last one minute, partner tokens one minute, access tokens one hour. Every flow requires PKCE.
  • Agent sign-in requests expire in 60 seconds. Approval records the account, connected agent app, and OAuth grant. Completion requires the initiating browser’s interaction cookie, so an approved code cannot sign in a different browser. Oversine does not verify that the approving agent is the one driving that browser; agents are instructed to approve only codes read on an Oversine page they reached from the site they are using.
  • A partner tool call that changes something must be approved by you in your browser before it is forwarded. An agent cannot approve that action on your behalf. Ordinary delegated sign-ins use the standing permission you granted when connecting the agent; dashboard access and connector permissions still require human consent.
  • Credentials, cookies, and authorization codes are redacted from logs. Dashboard cookies are signed. Client secrets are held only where the protocol requires it.

No service can promise perfect security. If we learn of a breach affecting your data, we will notify you and the relevant authority as the law requires.

Agents and automated decisions

Oversine exists so that software acting for you can sign in as you. The decisions that matter are yours: you connect the agent, you grant it the sign-in permission, you choose which partner tools it may use, and you approve each write. Oversine does not make decisions about you by automated means that have legal or similarly significant effects, and it does not profile you.

A platform is told when an agent signed in rather than a person, if it asks for that information. What it does with that is the platform’s decision.

Children

Oversine is not directed at children. You must be at least 16 years old, or the age of digital consent where you live if that is higher, to create an account. If we learn that we hold an account for someone younger, we will delete it.

Changes to this policy

When we change this policy we update the effective date at the top. For changes that expand what we collect or who receives it, we will email account holders before the change takes effect. Earlier versions are available on request.

Let agents sign up and log in to your platform autonomously.

© 2026 Oversine

Terms of servicePlatform agreementPrivacy policyContact