Legal
Privacy Policy
Effective July 16, 2026
OpenCode Superapp is designed to work without a product account. This policy explains the limited information MedHue Labs LLC processes to provide downloads, payments, licensing, recovery, support, and encrypted Remote connectivity.
Local application data
Your projects, OpenCode configuration, sessions, and local application runtime remain on your computer. OpenCode Superapp does not upload that data to our licensing service. Requests to AI providers are sent to the provider you select under that provider’s terms.
Purchases and licensing
Stripe processes payment and billing information. Our licensing database stores Stripe purchase identifiers, entitlement status, an HMAC of the normalized purchase email, anonymous installation activations, and hashed one-time tokens. It does not store the plaintext purchase email, a password, a computer name, or a hardware serial number.
Email and recovery
Resend processes the destination email only to deliver purchase and recovery messages. We store Resend delivery identifiers and status for operational reliability. Recovery throttling stores keyed HMAC values rather than raw IP addresses.
Remote companions
Remote Web and the iPhone, iPad, and Android companions connect through an end-to-end encrypted relay. The desktop app is the trusted host. The relay stores hashed installation and device routing identifiers, a renewable entitlement-grant expiry, and operational timestamps; it cannot decrypt your prompts, responses, project paths, or session contents, and it does not persist encrypted message frames. The native companion stores its revocable device credential and encryption material in iOS Keychain or Android Keystore-backed secure storage. Camera access is used only to scan a pairing QR code; camera images are not stored or uploaded by OpenCode Superapp.
Hosted Voice trial
If you choose to start the free hosted Supe Voice trial, live audio and realtime conversation events pass transiently through a Cloudflare relay to xAI for processing. OpenCode Superapp does not store or log the audio, transcript, tool arguments, task content, project paths, or Voice prompt. Cloudflare and xAI process this traffic under their applicable service terms and privacy policies, including xAI’s configured retention setting. We store an anonymous secure-store-backed public identity, keyed eligibility metadata, claimed-session count, whole-second usage, normalized close and failure codes, and estimated cost. Nonces are retained for up to 24 hours, keyed IP abuse counters for up to 30 days, and session metadata for up to 90 days. The anonymous quota record is retained while the lifetime trial program operates to prevent repeated trials. See Cloudflare’s Privacy Policy and xAI’s Privacy Policy.
No advertising tracking
We do not launch with marketing analytics, advertising pixels, cross-site tracking, or cookie-based behavioral profiles.
Service providers and retention
We use Stripe, Supabase, Vercel, Resend, Cloudflare, and xAI to operate the service. Purchase and entitlement records are retained for accounting, fraud prevention, support, and legal obligations. Expired one-time tokens and operational records may be deleted on a rolling basis.
Your choices
You may request access, correction, or deletion where applicable by contacting support@opencodesuper.app. Some transaction records must be retained to meet legal obligations and prevent duplicate license use.