1. Who we are
OneLamp is operated by Saho Labs, Inc. (“OneLamp”, “we”, “us”). OneLamp is a shared context layer for AI tools: you connect your apps, services, and knowledge once, and any AI tool you authorize can read and write that context through our MCP server. This policy describes how we handle personal data as the data controller.
2. Information we collect
We collect the following categories of data:
- Account data. Email address, display name, and authentication metadata. You can sign in with GitHub, Google, or an email one-time code.
- Your context. The repos, docs, APIs, tools, and notes you choose to connect, and the context we build from them, including structure, embeddings, and metadata used to retrieve it. This is your data; we process it to provide the service.
- Connection credentials. Tokens and keys you authorize so we can read the sources you link (for example, an OAuth token for a repository). Credentials are stored encrypted and used only to build and refresh your context.
- Connected clients & queries. The AI clients you authorize (and the access tokens issued to them through the standard OAuth flow) and the queries your AI tools make against your context.
- Usage & device data. Log data, IP address, approximate location, and product-analytics events used to operate and improve the service.
3. How we use your data
- To create and secure accounts and authenticate sign-ins.
- To capture, structure, index, and serve your context to the AI tools you connect.
- To provide the MCP server and enforce rate limits.
- To maintain security, prevent abuse, and debug the service.
- To communicate with you about security and service updates.
- To comply with legal obligations and enforce our Terms of Service.
Your data is not used to train AI models. We do not train models on your context, and we do not permit our service providers to use it for training. OneLamp is a retrieval layer, not a generation layer. The default query path returns a ranked context pack, with no LLM on the path.
4. Legal bases
Where the GDPR or similar laws apply, we rely on: performance of a contract (operating the context layer), legitimate interests (security, abuse prevention, product improvement), consent (optional analytics), and compliance with legal obligations.
5. How we share data
We share personal data only as needed to run the service:
- With the AI tools you connect. When you link an AI client, your context is served to it at your direction. You control which clients are connected.
- Service providers. Cloudflare (hosting, storage, edge compute, and email delivery) and product-analytics providers, each under contractual data-protection terms.
- Legal & safety. When required by law, or to protect the rights, safety, and property of users and the public.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not sell your personal data.
6. Data retention
We keep your context and account data for as long as your account is active. You can export your context or delete your account at any time; on deletion we remove your context and revoke stored connection credentials, retaining only limited records required for legal and security purposes. Access tokens for connected clients are retained until you revoke them.
7. Security
We use industry-standard safeguards including encryption in transit, encrypted connection credentials, per-user isolation, scoped access, and rate limiting. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.
8. International transfers
OneLamp runs on a global edge network, so your data may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. OneLamp is portable by default: you can export your entire context at any time. To exercise these rights, email legal@onelamp.ai. You may also lodge a complaint with your local data-protection authority.
10. Children
OneLamp is not directed to children under 18, and we do not knowingly collect their data. If you believe a minor has provided us data, contact us and we will delete it.
11. Browser extension (OneLamp for Chrome)
The OneLamp browser extension lets you save context from, and pull context into, the pages where you work. Because it can act on any site, it requests broad host access — but it is built to touch a page’s content only when you ask it to:
- On demand by default. The extension reads a page’s content (or an AI chat transcript) only when you click Save or Recall memory, or insert context into a field. What you save goes to your private OneLamp store through the same MCP server described above — nothing is sent in the background.
- No background browsing capture. The extension never records the pages you visit on its own — every save is an explicit action you take. There is no passive or automatic page-visit logging.
- Your sign-in token stays local. The extension’s access token is held only by its background service worker; the on-page helper and side panel never receive it.
- No selling, no ads, no training. Data handled by the extension is used only to provide your context layer, consistent with this policy. We do not sell it, use it for advertising, or train models on it.
The extension requests these browser permissions: host access (to read a page you save and write context into a field), activeTab/scripting/tabs (to act on the current tab), storage (your settings and the sign-in token), identity (the OAuth sign-in popup), and sidePanel (the OneLamp panel).
12. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice.
13. Contact
Email us at legal@onelamp.ai.