Legal · Trust

Privacy & Security Policy

Version2026.2.0Originally EffectiveApril 23, 2026Last UpdatedSeptember 14, 2026
Welcome to Octer.ai! Protecting your privacy and data security is a core principle of Octer.ai (“we,” “us,” or “our”). This Privacy & Security Policy is designed to provide transparency regarding how we collect, use, store, share, and protect your personal information when you use our website, iOS App, other applications, Agent native interface, and Auto-Task (automation) features.

1Information We Collect

We adhere to the principle of “Data Minimization”:

2How We Use Your Information

3Data Sharing & Sub-processors

We do not sell your personal data. We only share information with trusted parties under strict confidentiality:

4Data Security & Technical Safeguards

We use access controls and protected communications to safeguard personal information. In the iOS App, locally stored sign-in tokens and device-only mailbox credentials use iOS secure storage. No method of storage or transmission is completely secure.

5Your Global Privacy Rights

Regardless of your location, we respect your rights to Access, Rectify, Delete, Restrict Processing, and Data Portability.

6Regional Addenda

6.1 Mainland China (Applicable under PIPL)

6.2 European Economic Area (EEA) and UK (Applicable under GDPR)

6.3 South Korea (Applicable under PIPA)

6.4 Japan (Applicable under APPI)

7Third-Party Platform SDKs

To power Auto-Task automations across social platforms, Octer.ai integrates with official SDKs and APIs provided by Instagram, Facebook, TikTok, and X (formerly Twitter). These integrations are activated only when you explicitly authorize a given platform via OAuth, and you may revoke access at any time from the platform’s connected-apps settings or from your Octer.ai Integrations panel.

7.1 Instagram (Instagram Graph API / Meta Business SDK)

7.2 Facebook (Facebook Graph API / Meta Business SDK)

7.3 TikTok (TikTok for Developers / Content Posting API)

7.4 X (X API v2, formerly Twitter)

Your Control: At any time you may disconnect a platform from your Octer.ai Integrations panel. Disconnection stops future use of that connection for new tasks. You can also revoke authorization directly with the provider. Previously completed actions and records are not automatically undone or deleted; request deletion as described in Section 8.6.

8iOS App

This section explains the mobile App offered for iOS. It supplements the policy above; a feature uses the information relevant to that feature when you use or enable it.

8.1 Account, sign-in, and connected services

You can sign in using the available account methods, including Apple or Google. We receive the account identifier and the profile information provided by your chosen sign-in service, such as your email address and name. Sign-in does not by itself grant access to your mailbox or social accounts. Connecting those services requires a separate authorization or setup.

8.2 Connected email and reply assistance

When you connect a mailbox, the App uses its address, connection settings, and authorization credentials to retrieve messages and prepare or send replies. New mailbox connections in the current iOS App use device-only credential storage: mailbox passwords or app-specific authorization codes are stored in iOS secure storage. The mailbox address, label, and connection status are also sent to Octer.

Device-only credentials do not mean device-only email processing. Messages analyzed by the App, including sender and recipient addresses, subject, message body, timestamps, message identifiers, and analysis results, can be sent to Octer for task synchronization, email assistance, and task logs. Relevant email context may be processed by cloud AI when that feature is used. Existing cloud-connected mailboxes may use server-side credentials according to their connection setup.

The reply flow lets you review and confirm a message before sending. Confirmed replies are delivered through your configured mailbox provider, either from the device or through the connected service. Only connect mailboxes and submit correspondence you are authorized to use.

8.3 Cloud AI and on-device processing

Octer Cloud processes submitted prompts, conversation context, selected images, and relevant task data on remote services, including the AI providers used for the requested feature. Where available on a supported device, the Apple on-device model option processes that model request locally. Choosing it does not make separate features such as account synchronization, media uploads, email task synchronization, or cloud image generation local.

Cloud image features, including avatar generation, transmit the selected image and instructions to the processing service. Review the feature-specific disclosure before choosing to proceed. An iOS microphone or photo permission is not consent to every form of cloud processing. We must obtain any additional consent required for sharing personal data with third-party AI services before that sharing occurs.

8.4 Voice, photos, and device permissions

8.5 Providers and cross-border processing

Depending on the feature you use, recipients include Apple for sign-in or speech services, Google for Google sign-in, your mailbox provider for email retrieval and delivery, social platforms you authorize, cloud AI and image-processing providers, and infrastructure providers such as Expo for app updates. Sign-in providers process authentication information; they do not receive mailbox access solely because you sign in.

Remote services may process data outside your country of residence. Applicable transfer safeguards and any required consent depend on your region and the recipient. Contact [email protected] for information about the providers, locations, and safeguards applicable to your use. The regional protections in Section 6 continue to apply.

8.6 Account and data deletion

To request deletion of your Octer account and associated personal data, email [email protected] with the subject “Octer account deletion” and the email address associated with your account. You can also request deletion of specified conversations, email task records, uploaded media, or saved preferences. Do not include passwords, mailbox authorization codes, or access tokens.

We may ask for information needed to verify account ownership, explain any data that must be retained and why, and respond within the time required by applicable law. Deleting the Octer account affects the same account used on the website and iOS App; it does not delete your Apple, Google, mailbox, or social-platform account.

Signing out, uninstalling the App, and disconnecting a mailbox or social account are different from deleting your Octer account or previously synchronized data. Revoke third-party access in the provider’s settings if you also want to end that authorization. Copies of messages already delivered to recipients remain under those recipients’ control.

9Policy Changes

For material changes affecting your rights or data sharing practices, we will provide at least 30 days’ notice via email or prominent in-app notification. The last-updated date identifies this revision; material changes take effect after the applicable notice period. Where consent is required for new processing, continued use alone does not replace that consent.

10Contact Us

For questions regarding this policy, your rights, or AI data boundaries:

[email protected]

Acknowledgement: By registering, logging in, or using Octer.ai services, you acknowledge that you have read and understood this Privacy & Security Policy. For specific sensitive integrations, additional confirmation will be requested at the time of activation.