Privacy Policy
This policy explains what Autonomous processes when you create an account, connect a computer or let an AI assistant use tools on that computer.
Last updated September 26, 20261. Who controls the data
Autonomous is published by Kevin Funchal under the Octamundi product brand. For data processed to operate Autonomous, the Autonomous publisher acts as the controller under applicable privacy law. Requests about access, correction, deletion or other privacy rights can be initiated through our support page or by email at autonomousmcp@gmail.com.
2. What we process
| Account | Email address and account status. Passwords are stored only as salted scrypt hashes. Account API keys are stored only as cryptographic hashes and are shown in plaintext only when issued. |
|---|---|
| Paired computers | Device id, device name, tool catalog, online state, last-seen time and a hashed device credential. |
| Tool calls | Tool name, arguments, result, selected device, status and timestamps. Arguments and results can contain paths, file contents, command output or other information you asked the tool to process. |
| Usage | Timestamped usage events used to enforce rolling call limits, quotas and credits. |
| Connected AI assistants | Which assistant was authorized, what it was allowed to do, connection details and a scrambled copy of the access it holds. |
| Billing | When you buy a paid plan, Stripe sends us the identifier of your Stripe customer and subscription, the plan purchased and its status. We store the customer identifier to match future subscription events to your account. |
| Sessions and security | A hashed website session token and limited request or diagnostic metadata needed to authenticate, protect and troubleshoot the service. |
The public Octamundi pages use essential browser storage for security and basic preferences. Optional analytics remain disabled unless you allow them through Cookie settings. We do not use advertising cookies or behavioral advertising trackers. Card numbers are entered on a checkout page hosted by Stripe and are never processed or stored by Autonomous.
3. Why we process it
- Provide the account, the computer connection and the forwarding and running of the tools you ask for.
- Authenticate users, devices and connected applications.
- Apply quotas, prevent replay or abuse, investigate failures and protect service integrity.
- Maintain a short retry and audit window for tool calls.
- Process a paid plan and keep your plan in sync with the subscription you bought.
- Comply with legal obligations and respond to valid legal requests when required.
Under the LGPD, these purposes may rely on performance of a contract or requested service, legitimate interests in security and service integrity, compliance with legal obligations, and consent where the law specifically requires it.
4. How long we keep it
| Tool calls, arguments and results | 7 days by default. |
|---|---|
| Usage events | At least 35 days, or the longest configured quota window plus 1 day, whichever is longer. |
| Website sessions | 7 days, or until the session is revoked or expires. |
| OAuth access tokens | 1 hour. |
| OAuth refresh tokens | 30 days, or earlier when revoked. |
| OAuth authorization codes | 1 minute and single-use; expired or used codes are pruned shortly afterward for replay detection. |
| Pairing codes | 10 minutes and single-use. |
| Billing identifiers | While the account exists, so a later subscription change can still be matched to it. |
| Account, device and active connection metadata | Until you remove the device or connection, close the account, or the data is no longer required for the service. |
| Infrastructure diagnostics | Kept only for operational security and troubleshooting, with rotation intended to remain short. Records may be preserved longer when reasonably necessary to investigate abuse, security incidents or comply with law. |
5. Who receives data
The AI assistant you connect receives the results of the calls it makes because that is necessary to perform the requested workflow. That provider processes data under its own terms and privacy policy.
Stripe processes payment and subscription data as an independent payment provider when you buy a paid plan. Infrastructure providers that host or secure Autonomous may process data on our behalf as service providers. We may also disclose information when legally required or when reasonably necessary to protect users, the service or others. We do not sell personal data, rent it to advertisers, or use tool-call content to train our own AI models.
6. International processing
Infrastructure, payment or connected AI providers may process data outside Brazil. Where the LGPD requires safeguards for an international transfer, we use the applicable legal mechanisms and require providers to protect the data according to their role.
7. Security and your controls
- Traffic to Autonomous is protected in transit using HTTPS/TLS.
- Passwords use scrypt. API keys, device credentials, session tokens and OAuth tokens are stored as hashes.
- Accounts cannot intentionally address devices owned by another account.
- You can revoke a connected application and unpair a computer.
- You can restrict local filesystem access with the agent’s allowed-directories configuration.
Autonomous is a remote execution bridge, not an isolation sandbox. Only pair computers you are authorized to operate and do not expose folders containing data that should not be processed through the service.
8. Your LGPD rights
Subject to the LGPD and applicable exceptions, you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability where applicable, information about sharing, information about consent, revocation of consent, and review of certain automated decisions.
To exercise a right, start through Support. We may need to verify your identity before fulfilling a request. We can retain information when the law permits or requires it, including for security, fraud prevention, legal claims or compliance.
9. Sensitive information and minors
Autonomous is not designed as a repository for sensitive personal data. Tool output can nevertheless contain whatever is present on a computer you choose to expose. Use local access controls to avoid processing secrets or sensitive categories that are not necessary for your task. The service is not directed to children.
10. Changes
We may update this policy when the product, law or our data practices change. The current version and update date will remain available at this URL.