Privacy policy
Opsight is operated by Forecight, a Canadian company. This policy explains what we collect, why, where it is stored and what you can do about it.
Last updated September 2025
Who is responsible
For the business data you upload, your business is the controller and Opsight is the processor: we handle it on your instructions. For account data (your name, email and sign in records) Opsight is the controller. Contact: privacy@forecight.com.
What we collect
- Account data: name, email address, hashed password, two step verification factors, and the businesses you belong to.
- Business data: the files you upload or push through the API, and the records derived from them (inventory, sales, expenses, payroll, employees).
- Product data: tasks, insights, conversations with the assistant, agent definitions and their run transcripts.
- Operational records: audit log entries, AI usage counts (tokens, model id, a hash of the system prompt), and standard server logs.
We do not use advertising trackers or third party analytics scripts, and we do not sell data.
How we use it
- To run the product: answer your questions, map your files, produce insights and tasks.
- To secure the product: authentication, rate limits, audit trails and abuse investigation.
- To support you: diagnosing a problem you report, with the minimum access needed.
- To bill fairly: aggregate AI usage counts per business.
Your business data is never used to train AI models.
Where it is stored
In Canada. The database, authentication service and file storage run in the Supabase ca-central-1 region (Montreal). Application servers run on Vercel. Backups stay in the same region.
Who else processes it
- Supabase Inc: managed Postgres, authentication and edge functions (Canada).
- Vercel Inc: application hosting, scheduled jobs and the AI Gateway.
- Anthropic PBC: large language models, reached through the Vercel AI Gateway. Prompts contain only the data needed to answer the question at hand and are not retained for training.
We update this list before adding a subprocessor that handles customer data.
How long we keep it
Business data is kept until you delete it. An admin can set a retention window per business, after which a weekly job deletes transactions, payroll entries and raw uploaded rows older than the window. Audit entries are kept for 400 days. When an owner deletes a business, its records are removed and only a tombstone remains: the business name, who deleted it, when, and how many rows were removed.
Your choices
- Export: admins can download the entire workspace as JSON, and the audit log as CSV, at any time.
- Correction: business data can be edited or re-imported from the Data page.
- Deletion: owners can delete a business from Settings; individual datasets can be deleted from the Data page.
- Access and complaints: write to privacy@forecight.com. You may also complain to the Office of the Privacy Commissioner of Canada.
Security
Encryption in transit and at rest, row level isolation between businesses, least privilege database roles, two step verification and audit logging. The details are on our security and trust page.
Changes
If this policy changes in a way that affects you, we will say so in the product before the change takes effect.