1Information We Collect
We adhere to the principle of “Data Minimization”:
- Account & Identity Information: Email address, encrypted password, and basic profile data.
- AI Interaction Data: Prompts you input, uploaded files, Auto-Task context, conversation history, and generated outputs.
- Integration & Authorization Data (Sensitive): When you authorize Octer.ai to connect with third-party applications (e.g., GitHub, Notion), we collect and securely store API Access Tokens or authorization credentials.
- Technical & Log Data: IP address, device identifiers, browser type, and interaction logs.
2How We Use Your Information
- Core Service Operation: To parse instructions, coordinate multi-agent workflows, and execute long-running Auto-Tasks.
- AI Model Training & Optimization (Regional Strategy):
- EEA, UK, and Switzerland Users: By default, your data is NOT used for training. We will only use your data for model improvement with your explicit opt-in consent. Contact [email protected] to withdraw that consent.
- Other Regions: We may use de-identified data to improve our models where permitted by applicable law and your choices. You may opt out by contacting [email protected]. Any consent required by applicable law must be obtained separately.
- Personalization: Saved preferences, conversation context, and relevant task experience can help tailor responses and recommendations for your account. This service functionality is distinct from training a general-purpose model. Connecting a mailbox or enabling a device permission is not blanket consent to unrelated model training.
- Security & Anti-Fraud: To monitor for anomalous API activity and protect against Prompt Injection attacks.
3Data Sharing & Sub-processors
We do not sell your personal data. We only share information with trusted parties under strict confidentiality:
- AI Service Providers: Cloud AI features send the prompts, relevant context, and media needed for the requested feature to the model or image-processing providers used by that feature. Provider identity, processing location, retention, and training restrictions depend on the service and applicable agreements; this policy does not promise universal zero data retention. See Section 8 for iOS data flows and contact [email protected] for the providers applicable to your feature.
- Infrastructure Providers: Hosting, storage, content delivery, and app-update services process the data needed to deliver the Services, including uploaded files and technical request information.
4Data Security & Technical Safeguards
We use access controls and protected communications to safeguard personal information. In the iOS App, locally stored sign-in tokens and device-only mailbox credentials use iOS secure storage. No method of storage or transmission is completely secure.
- Retention: Account information, conversations, uploaded media, email task records, and saved preferences are retained for the purposes described in this policy, including providing your account history and requested services. The period depends on the data type, your deletion requests, and applicable legal, security, or dispute-resolution needs.
- Deletion: When data is no longer needed for those purposes, we delete or anonymize it. Backup copies may remain until the applicable backup rotation completes and are subject to restricted access. Records that must be retained for legal obligations or resolving disputes are limited to those purposes.
- Your Requests: See Account and data deletion to request deletion of an account or specified data and information about applicable retention periods. Disconnecting an integration alone does not delete previously processed content.
5Your Global Privacy Rights
Regardless of your location, we respect your rights to Access, Rectify, Delete, Restrict Processing, and Data Portability.
6Regional Addenda
6.1 Mainland China (Applicable under PIPL)
- Separate Consent: For the processing of sensitive personal information (e.g., API Tokens) and cross-border data transfers, we will obtain your Separate Consent via distinct interface pop-ups.
- Next-of-Kin Rights: In the event of a user’s death, their next-of-kin may exercise the rights to access, copy, rectify, or delete the deceased user’s data for their own legitimate interests by contacting [email protected], unless otherwise arranged by the user before death.
6.2 European Economic Area (EEA) and UK (Applicable under GDPR)
- Legal Basis: We process data based on “Performance of a Contract” and “Legitimate Interests.” Training is based strictly on “Consent.”
6.3 South Korea (Applicable under PIPA)
- Immediate Destruction: Personal data is destroyed without undue delay when its retention period expires or its processing purpose is fulfilled, subject to retention required by applicable law.
6.4 Japan (Applicable under APPI)
- Cross-border Transfer Disclosure: We ensure that any overseas third party receiving personal data maintains a system for personal information protection that meets APPI standards.
7Third-Party Platform SDKs
To power Auto-Task automations across social platforms, Octer.ai integrates with official SDKs and APIs provided by Instagram, Facebook, TikTok, and X (formerly Twitter). These integrations are activated only when you explicitly authorize a given platform via OAuth, and you may revoke access at any time from the platform’s connected-apps settings or from your Octer.ai Integrations panel.
7.1 Instagram (Instagram Graph API / Meta Business SDK)
- Purpose: Publishing posts, Reels, and Stories; reading insights and comments for connected Instagram Business or Creator accounts.
- Data Exchanged: OAuth access tokens, account ID and handle, media assets you instruct Octer.ai to publish, and aggregated engagement metrics returned by Meta.
- Retention: Access tokens are used to maintain the connection you authorize and refreshed according to the provider’s token lifecycle. You can revoke authorization through the platform’s settings.
- Reference: Instagram Privacy Policy.
7.2 Facebook (Facebook Graph API / Meta Business SDK)
- Purpose: Managing Pages you administer — scheduling posts, reading comments and messages, and retrieving Page-level analytics.
- Data Exchanged: OAuth tokens scoped to the permissions you grant (e.g.,
pages_manage_posts,pages_read_engagement), Page IDs, post content you author, and insight data returned by Meta. - Use Limitations: We comply with the Meta Platform Terms and Developer Data Use Policy. We do not sell Meta Platform Data, nor use it for advertising or profiling outside of the features you activate.
- Reference: Meta Privacy Policy.
7.3 TikTok (TikTok for Developers / Content Posting API)
- Purpose: Uploading videos to your connected TikTok account, reading basic profile data, and retrieving post-level analytics where authorized.
- Data Exchanged: OAuth tokens,
open_idandunion_id, display name and avatar, video files and captions you submit, and returned performance metrics. - Regional Handling: TikTok processes content subject to its own regional data residency (e.g., Project Clover for EEA users, Project Texas for US users). Octer.ai does not control TikTok’s downstream storage.
- Reference: TikTok Privacy Policy.
7.4 X (X API v2, formerly Twitter)
- Purpose: Posting Tweets, reading your timeline and mentions, and pulling engagement data for accounts you connect.
- Data Exchanged: OAuth 2.0 tokens with PKCE, user ID and handle, Tweet content you publish, and response payloads from the X API.
- Use Limitations: We adhere to the X Developer Agreement and Policy, including restrictions on off-X matching and redistribution of X Content.
- Reference: X Privacy Policy.
Your Control: At any time you may disconnect a platform from your Octer.ai Integrations panel. Disconnection stops future use of that connection for new tasks. You can also revoke authorization directly with the provider. Previously completed actions and records are not automatically undone or deleted; request deletion as described in Section 8.6.
8iOS App
This section explains the mobile App offered for iOS. It supplements the policy above; a feature uses the information relevant to that feature when you use or enable it.
8.1 Account, sign-in, and connected services
You can sign in using the available account methods, including Apple or Google. We receive the account identifier and the profile information provided by your chosen sign-in service, such as your email address and name. Sign-in does not by itself grant access to your mailbox or social accounts. Connecting those services requires a separate authorization or setup.
8.2 Connected email and reply assistance
When you connect a mailbox, the App uses its address, connection settings, and authorization credentials to retrieve messages and prepare or send replies. New mailbox connections in the current iOS App use device-only credential storage: mailbox passwords or app-specific authorization codes are stored in iOS secure storage. The mailbox address, label, and connection status are also sent to Octer.
Device-only credentials do not mean device-only email processing. Messages analyzed by the App, including sender and recipient addresses, subject, message body, timestamps, message identifiers, and analysis results, can be sent to Octer for task synchronization, email assistance, and task logs. Relevant email context may be processed by cloud AI when that feature is used. Existing cloud-connected mailboxes may use server-side credentials according to their connection setup.
The reply flow lets you review and confirm a message before sending. Confirmed replies are delivered through your configured mailbox provider, either from the device or through the connected service. Only connect mailboxes and submit correspondence you are authorized to use.
8.3 Cloud AI and on-device processing
Octer Cloud processes submitted prompts, conversation context, selected images, and relevant task data on remote services, including the AI providers used for the requested feature. Where available on a supported device, the Apple on-device model option processes that model request locally. Choosing it does not make separate features such as account synchronization, media uploads, email task synchronization, or cloud image generation local.
Cloud image features, including avatar generation, transmit the selected image and instructions to the processing service. Review the feature-specific disclosure before choosing to proceed. An iOS microphone or photo permission is not consent to every form of cloud processing. We must obtain any additional consent required for sharing personal data with third-party AI services before that sharing occurs.
8.4 Voice, photos, and device permissions
- Voice input: Microphone and speech-recognition permissions let you dictate text. Recognition uses Apple’s speech services and may involve remote processing depending on device and service availability; it is not guaranteed to remain on-device. Transcribed text becomes part of the conversation or task you submit. The current App does not implement a separate audio-recording upload or archive feature.
- Selected images: Images you select can be uploaded for chat, profile, or image-generation features. Permission to save photos allows the App to save an image or an exported Idea screenshot to your photo library. Exporting an Idea screenshot does not record other apps or your entire screen.
- Device motion: Motion input is used locally for interface effects; it is not submitted as task content.
- Your choices: You can decline or revoke permissions in iOS Settings. The corresponding optional feature may then be unavailable. Revoking a permission does not delete content already submitted.
8.5 Providers and cross-border processing
Depending on the feature you use, recipients include Apple for sign-in or speech services, Google for Google sign-in, your mailbox provider for email retrieval and delivery, social platforms you authorize, cloud AI and image-processing providers, and infrastructure providers such as Expo for app updates. Sign-in providers process authentication information; they do not receive mailbox access solely because you sign in.
Remote services may process data outside your country of residence. Applicable transfer safeguards and any required consent depend on your region and the recipient. Contact [email protected] for information about the providers, locations, and safeguards applicable to your use. The regional protections in Section 6 continue to apply.
8.6 Account and data deletion
To request deletion of your Octer account and associated personal data, email [email protected] with the subject “Octer account deletion” and the email address associated with your account. You can also request deletion of specified conversations, email task records, uploaded media, or saved preferences. Do not include passwords, mailbox authorization codes, or access tokens.
We may ask for information needed to verify account ownership, explain any data that must be retained and why, and respond within the time required by applicable law. Deleting the Octer account affects the same account used on the website and iOS App; it does not delete your Apple, Google, mailbox, or social-platform account.
Signing out, uninstalling the App, and disconnecting a mailbox or social account are different from deleting your Octer account or previously synchronized data. Revoke third-party access in the provider’s settings if you also want to end that authorization. Copies of messages already delivered to recipients remain under those recipients’ control.
9Policy Changes
For material changes affecting your rights or data sharing practices, we will provide at least 30 days’ notice via email or prominent in-app notification. The last-updated date identifies this revision; material changes take effect after the applicable notice period. Where consent is required for new processing, continued use alone does not replace that consent.
10Contact Us
For questions regarding this policy, your rights, or AI data boundaries: