Privacy Policy
Last updated: September 27, 2026
This Privacy Policy describes how DIGITAL WARRIORS LLC ("Operator Base," "we," "us," or "our") collects, uses, and shares information when you use the Operator Base operator app and our hosted AI agent platform, Delta Agents (including the Delta Agents web dashboard and the Delta Agents iOS and Android apps), together with our related services (collectively, the "Service").
It sits alongside our Terms of Service, our Data Processing Addendum, our Sub-processor list, and our Security page. Where this policy refers to the providers we use or to a security control, those pages are the current source of truth. We link to them rather than restate them here, so there is one place that stays up to date.
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Two roles, and which one covers your data
Operator Base holds two different roles depending on whose data is involved. The distinction decides which document governs.
- Data about you, our customer. We are the controller for three categories: your account data, your billing data, and the User Content you and your team create inside the operator app, which is what the Terms of Service defines as User Content in its section 4. Section 2 of our Data Processing Addendum sets out all three and explains why they sit outside that agreement. This Privacy Policy is the document that governs them.
- Data about your end contacts. These are the leads, prospects, and customers your AI agents talk to, together with their conversations and the records your agents build. You decide who enters the platform and why, so you are the controller and we are the processor. That processing is governed by the Data Processing Addendum rather than by this policy, and this policy describes it only so that the picture is complete.
If you are an end contact who has spoken with an AI agent built on Operator Base, the business that operates that agent decides what happens to your data. Contact them first. Section 8 explains what we do if you write to us instead.
2. Information we collect
Account data
When you create an account, we collect your email address, name, and password. Your password is cryptographically hashed by our authentication provider and is never stored in plain text.
Content you create in the operator app
We collect content you create within the operator app, including posts, messages, comments, files you upload, and other community contributions.
Device and usage data
We automatically collect:
- device type, operating system, and app version;
- push notification tokens, held so that we can deliver the notifications you have turned on;
- usage and diagnostic events, such as which features are used and when an error occurs, which we use to operate and improve the Service.
Payment data
Payments are processed by Stripe. We do not store your card number, bank account details, or other financial instruments, and card numbers never reach our systems. We retain your subscription status and transaction history for billing purposes.
Data you place in the AI agent platform
When you build and run agents, the platform holds the data those agents work with: contact records, conversation history across chat, SMS, email, and messaging channels, voice call recordings and transcripts, agent memory, conversation summaries, text embeddings, appointment and opportunity records, and anything else you choose to put into custom fields, uploaded files, or agent instructions. Section 4 of the Data Processing Addendum sets out these categories in full. We hold this data on your behalf and on your instructions.
The Service is not designed for special categories of personal data, for data relating to criminal convictions, or for protected health information. Do not put that data into the Service.
3. How we use information
- Provide the Service. Authentication, data synchronization, the operator app and its community features, and the building, deployment, and running of your AI agents across the channels you connect.
- Send notifications. Notifications you have turned on, such as mission reminders, messages, and community updates.
- Operate and improve the product. Usage and diagnostic events help us understand how features are used and where something is failing.
- Billing and fraud prevention. Process subscriptions and detect unauthorized transactions.
- Communicate with you. Respond to support requests and send service-related announcements.
- Keep the Service secure. Rate limiting, abuse controls, audit logging, and investigating incidents.
We do not sell personal information. We do not use it to train generalized artificial intelligence or machine learning models of our own.
4. How we share information
We share data with third-party providers that process it on our instructions in order to deliver the Service. Rather than duplicate that roster here, where it would drift out of date, we publish and maintain it on our Sub-processor page. That page names every provider we engage across the whole of Operator Base, covering the operator app, the AI agent platform, and this website. For each one it states what it does, which category of data it can reach, and where it processes that data. It is kept current there rather than here.
The categories of provider we engage are:
- cloud hosting and application infrastructure;
- database, file storage, and caching;
- AI model providers, for the platform features that classify, summarize, index, and search content, and for in-product help;
- content safety classification, where you have enabled the safety guard on an agent;
- email sending and receiving, both for the email your agents handle and for transactional email to operators;
- messaging channels;
- real-time audio and video transport, and recording, for the live calls and hangouts in the operator app;
- speech to text, for the voice notes you record and for our course and help videos;
- contact data services used by the prospecting and outreach tools: web search, contact enrichment, and email address verification;
- payment processing, and the customer relationship management system that holds our own record of you as a customer;
- error monitoring, infrastructure alerting, product analytics, advertising and affiliate attribution on this website, and retrieval of the public web pages you add as a knowledge base source;
- video hosting, delivery and compression, over-the-air app updates, and GIF search.
Push notifications for the operator app are delivered through the platform push services: the Apple Push Notification service on iOS, Firebase Cloud Messaging on Android, and your browser's push service if you enable web notifications. These receive the device token and the notification itself, which can name the person who sent you a message and quote the first 100 characters of it.
Analytics, session recording, and advertising. When you use the operator app in a web browser, a session recording provider records the screen so we can see where the interface is failing people. It is tied to your Operator Base user identifier, not to your email address, and it does not run in the iOS or Android app. On this website we run product analytics and advertising, affiliate, and click attribution tags. Each of these providers is named on the Sub-processor page with what it can reach. We do not run any of them against the conversations or contact records held in the AI agent platform.
Integrations you connect. Some vendors receive data only because you connected an account and supplied your own credentials, such as your CRM, your telephony provider, your calendar, and the model provider key your agents run on. You choose those vendors and hold the contract with them, so they are not our sub-processors. They are listed separately on the Sub-processor page. Disconnecting an integration stops any further transmission to it, and data already delivered is held under your agreement with that vendor.
We may also disclose information if required by law, regulation, legal process, or governmental request.
5. Google Calendar integration
If you connect a Google account, Operator Base requests access to your Google Calendar to provide scheduling features. Specifically, we use the calendar.events and free/busy scopes to:
- read your availability (free/busy) to determine open times;
- list, create, reschedule, and cancel calendar events at your direction.
What we store. We store an encrypted OAuth refresh token so the connection persists until you disconnect it. Short-lived access tokens are held only in memory and are never written to disk. We access your calendar data in real time to perform the actions above and do not retain the contents of your calendar events.
What we do not do. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized artificial-intelligence or machine-learning models. We do not transfer it to third parties except as needed to provide these scheduling features or as required by law.
Deletion. You can revoke access at any time by disconnecting the calendar in Operator Base or via your Google Account permissions. On disconnect or account deletion, we delete the stored refresh token.
Operator Base's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data retention
Your account data. We retain it for as long as your account is active or as needed to provide the Service.
What happens when you delete your account. Deletion runs immediately, not on a delay. Your sign-in account is deleted and the private records attached to it are removed with it, in the same request. Two exceptions are worth knowing before you press the button, because they are deliberate rather than accidental:
- Community content stays, under a deleted author. Your community posts, comments, lounge messages, and the direct messages you sent are reassigned to an anonymous placeholder author and your name and profile photo are stripped from them. Deleting them outright would remove the other side of conversations other members are still part of. The content remains; the attribution to you does not. Files you uploaded, including the images and video attached to that content, stay with it.
- Some records are kept where the law requires it, for example transaction records needed for tax and accounting, or records needed to resolve a dispute.
If you want the anonymized content removed as well, email support@operatorbase.app and our team will action it.
Data in the AI agent platform. This stays in the Service while your subscription is active, so that your export tools keep working, and we delete or return it on your instruction. Section 12 of the Data Processing Addendum governs deletion and return, and it is the controlling document if the two ever read differently. Residual copies in routine backups are removed on the ordinary backup rotation of our infrastructure provider.
Two limits are worth stating plainly. Erasure of an individual contact pseudonymizes that contact record rather than deleting the underlying row. Deletion by us does not reach copies held in the third-party systems you connected, such as your CRM or your telephony provider, which have to be erased in those systems as well.
7. Security
Our technical and organizational measures are described in full on our Security page, including tenant isolation enforced in the database, encryption in transit and at rest, application-level encryption of the credentials you connect, redaction of logs and error reports, an append-only audit trail, and access controls. That page also states the known limits of those controls, and lists the certifications and controls we do not hold, including SOC 2, ISO 27001, HIPAA, and independent penetration testing. We do not claim any certification or audit that we have not obtained.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability, the reporting process is on the Security page.
8. Your rights and choices
If you hold an Operator Base account:
- Access and correction. You can view and update your profile information at any time within the app.
- Account deletion.You can delete your account from Settings > Account > Delete Account. You may also request deletion by emailing support@operatorbase.app.
- Notifications.You can disable push notifications at any time through your device's system settings or your browser settings.
- Account export.A tenant administrator can request an export of the account's data from the dashboard, delivered through a short-lived signed link.
Data subject requests. Depending on where you live, you may have rights to access, correct, delete, port, or object to the processing of your personal data. Send the request to support@operatorbase.app and the Operator Base team will action it and confirm back to you. Where we are assisting one of our customers with a request about their end contacts, we do that within 10 business days, as set out in section 9 of the Data Processing Addendum.
One operation is still performed by our team rather than through a self-service control: an export narrowed to a single data subject. There is no button for that one today, and we would rather say so than imply one that does not exist. Erasure of an individual contact used to be on that list and no longer is: since August 19, 2026 a tenant administrator can erase a contact from the AI agent platform dashboard, with a preview of the affected records and a cancellation window before anything is destroyed.
If a request reaches us about a customer's end contact. Where the data belongs to one of our customers rather than to us, we will confirm receipt, direct the request to that customer, and notify them. Section 9 of the Data Processing Addendum sets out how we assist our customers with these requests.
9. Children's privacy
Operator Base is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information promptly.
10. Where we process data, and international transfers
We process data in the United States. The AI agent platform's application services and primary database run in the AWS us-east-1region. The operator app's backend, which also holds the sign-in accounts used across the Service, runs in a separate project in the us-west-2 region. We have not configured a European or other non-US region for any part of the Service. Delivery is not the same as storage: our hosting and content delivery providers serve files and run edge code from whichever network location is nearest your device, which can be outside the United States, while the systems that store your data stay in the regions named here. Processing locations for our sub-processors are listed on the Sub-processor page.
If you are outside the United States, using the Service means your information is transferred to and processed in the United States. Where a transfer involves personal data protected by the GDPR or the UK GDPR, the transfer mechanism, including the standard contractual clauses, is set out in section 14 of our Data Processing Addendum.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through an in-app notification. Changes to the list of providers we use are notified through the process described on the Sub-processor page. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
DIGITAL WARRIORS LLC
180 NE 29th St, Apt 330
Miami, FL 33137
support@operatorbase.app