AEL Beta 0.0.1 — launching soon
Privacy policy
This policy explains what personal data OpenEng collects through the AEL websites and AEL Cloud, what it is used for, how long it is kept and what you can do about it.
Effective date: 1 October 2026.
Who we are
The AEL websites and AEL Cloud are operated by OpenEng Labs Private Limited ("OpenEng", "we", "us").
You can reach us about anything in this policy at ael@openeng.ai.
The AEL websites
This section covers the AEL websites: ael.openeng.ai, docs.ael.openeng.ai, pack.ael.openeng.ai and cloud.ael.openeng.ai.
These sites are static pages: they set no cookies, run no scripts, use no analytics or advertising tools and load nothing from other sites.
They are served by Firebase Hosting, a Google service, which receives what every browser sends with a request (your IP address, the address of the page, your browser's user agent and the page you came from) and may keep it in its standard request logs to deliver and protect the sites.
We do not use this information to identify, track or profile visitors.
AEL Cloud
AEL Cloud, the service hosted by OpenEng, is not open yet.
Until it opens, only people OpenEng invites to test it can sign in, and this policy covers that private testing.
When AEL Cloud opens, we will publish a revised privacy policy on this page.
What AEL Cloud receives from Google
People invited to test AEL Cloud sign in with their Google account.
From Google, AEL Cloud receives your Google account's unique identifier, your e-mail address and whether Google has verified it, your name and the address of your profile picture.
AEL Cloud never sees your Google password and gets no access to any other data in your Google account.
What AEL Cloud stores
- Your sign-in account: your Google account's identifier, e-mail address, name, profile picture address and sign-in times, held in Firebase Authentication, Google's sign-in service.
- Your user record: your e-mail address, name, role, account status, the invitation you joined with and the dates you joined and last signed in.
- Your invitation: the e-mail address invited, who invited it and when, when it expires and whether it was accepted or withdrawn.
- Your API tokens: each token's name, creation and expiry dates and last use, with only a keyed hash of its secret, never the token itself.
- Your workspaces: each workspace's name and members.
- Your jobs: for each build or run, its status and result, the file it started from, its timing, the compiler's messages, the built program's fingerprint and size, and the program's output, up to 64 KiB of each output stream.
- Usage counters: the builds and runs you made each month, the job time and output they used, and how many jobs you started each day.
- Audit events: a record of security-relevant actions, such as signing in, creating a token or starting a job, with ids, times and outcomes but never your e-mail address or name.
- Service logs: for each request, its time, the address requested without its query, the result and how long it took, but no IP address.
- A sign-in cookie: one cookie, set only by AEL Cloud's sign-in pages, which holds your sign-in in progress for up to 10 minutes and then keeps you signed in for a limited time, 5 days at present, or until you sign out.
The source files you send for a job are used only to run that job and are not stored.
The cookie only keeps you signed in and protects your forms; it is never used for tracking or advertising.
Your IP address is used in memory only, to limit how many requests and sign-ins one address can make, and is not written to our logs, though Google's hosting receives it with each request as it does for the websites.
While AEL Cloud is in testing, your Google address is also on the list of test users that Google's sign-in allows for AEL Cloud.
Outside the service, OpenEng keeps a private list of the people it has invited, with each one's e-mail address, the date invited and the notice they were given, and a note of each deletion request.
How we use the data
We use this data only to sign you in and identify your account, to run the programs you send, to apply limits and quotas, to keep AEL Cloud secure and prevent abuse, and to write to you about your account, your requests and security incidents.
We do not sell your data, use it for advertising, or use it, your programs or their output to train any AI model.
Google user data
AEL Cloud asks Google only for the openid, email and profile scopes, and uses what it receives only to sign you in, identify your account and write to you about your account, your requests and security incidents.
AEL Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not transfer Google user data to anyone else, use it for advertising, or let anyone read it except to run AEL Cloud, keep it secure, answer your requests or comply with the law.
Who processes the data
Google provides the infrastructure that the AEL websites and AEL Cloud run on, Google Cloud and Firebase, and processes the data for us as our provider.
No one else receives your data, and we share it with no one else unless the law requires us to.
Where the data is stored
AEL Cloud runs in Google Cloud in India, in the asia-south1 region, where its database, its logs and its backups are kept.
Some data is held outside India: your sign-in account, Google's sign-in and its list of test users are global Google services, Google's own audit logs of the service may be kept in Google's global location, and messages sent to ael@openeng.ai are kept wherever Google stores OpenEng's mail.
The pages of the websites and of AEL Cloud reach you through Google's global hosting network.
How long we keep it
- Your sign-in account and user record: until you ask us to delete them; a sign-in by someone without an invitation is deleted at once.
- Invitations: 30 days after they expire, accepted or not, so about 44 days in all, since an invitation lasts 14 days.
- API tokens: 30 days after they expire or are revoked.
- Workspaces: 30 days after you delete them.
- Job records: 30 days.
- Usage counters: 400 days after the last job they count, about 13 months.
- Audit events: 1 year.
- Service logs: 180 days.
- Google's audit logs of the service: 400 days, a period Google sets.
- Database backups: daily backups for 14 weeks, and point-in-time recovery for 7 days.
- Our list of invitees: while you may use AEL Cloud, until your data is deleted or your invitation expires unused; Google's list of test users: until we remove you, at the latest when your data is deleted.
- Our note of a deletion request: your account id for 14 weeks after the deletion, then only the dates.
- Messages you send to ael@openeng.ai, with your e-mail address, and our replies: in OpenEng's mailbox, hosted by Google, only to answer you and act on what you write; a request for a copy, correction or deletion of your data until it is done and we have told you, and any other conversation for 1 year after its last message.
Automatic deletions happen when the period ends, usually within a day.
How we protect it
- Every connection to the AEL websites and AEL Cloud is encrypted with HTTPS.
- AEL Cloud's database is reachable only by the service itself and by OpenEng as its operator, never directly from a browser or app, and Google Cloud encrypts it at rest.
- Every session and API token is checked against your account on every use, and signing out on every device revokes them all at once.
- Each program runs in an isolated sandbox with no network access and strict limits on time, memory and files.
- Security-relevant actions are recorded in the audit log, and if a security incident affects your data, we will tell you.
Your choices and rights
On your account page you can create and revoke API tokens and sign out on every device.
To get a copy of your data, correct it or delete it, write to ael@openeng.ai from the Google address you sign in with, and we will tell you when it is done.
Deletion removes your sign-in account, user record, tokens, workspaces and their job records, usage counters and invitations, and takes you off our list of invitees and Google's list of test users.
Deletion keeps the audit events, which hold only ids and no e-mail address or name, until they expire after a year, and the service logs until they expire after 180 days.
Deleted data stays in backups until they expire after 14 weeks; if we ever restore one, we delete your data from it again before it is used.
Google's own audit logs keep what they recorded about the service for their 400 days.
You can also remove AEL Cloud's access in the third-party connections of your Google account; this does not delete what we hold, so write to us for that.
Children
The AEL websites and AEL Cloud are not directed at children under 18, and we do not invite them to test AEL Cloud.
If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
The effective date at the top of this page shows when this policy last changed.
We will announce material changes on this site and in the AEL updates feed.
Contact
Questions, requests and complaints about privacy go to ael@openeng.ai.