Privacy Policy
- Effective
- October 1, 2026
- Last updated
- October 1, 2026
Oaura is a platform for building AI agents, so personal data moves through it in two very different ways: the data you give us to be our customer, and the data you put into Oaura to build with. Section 2 separates the two, and it is worth reading before anything else.
Section 6 covers what happens to a prompt once an agent sends it to a model provider, and section 7 lists what runs on this website — plainly, including the part we have not finished fixing.
1Scope and who we are
Who this is for
Four groups of people show up in this policy, and the rules differ for each:
- Visitors — anyone browsing oaura.ai.
- Prospects — people who contact us, book a demo or email sales.
- Customers — people with an Oaura account, and the colleagues they invite into a workspace.
- End Users — people who talk to an agent one of our customers built. We handle their data on that customer’s instructions, not our own; section 2 explains why that matters.
Related documents
Our terms of service govern the commercial relationship, the security page describes our technical measures and current compliance status, and our data processing addendum covers clause 2.2 processing in contractual form. Ask for the addendum at legal@oaura.ai.
2When we decide, and when you decide
Oaura wears two hats, and nearly every question about your data has a different answer depending on which one applies.
We are the controller for our own business
For our website, our marketing, our sales conversations, our billing and our customers’ account administration, we decide why and how personal data is used. We are the controller, this policy is the notice we owe you, and sections 3, 4, 7 and 12 apply directly.
We are a processor for what you put in Oaura
For the content a customer ingests into a knowledge base, the conversations their agents hold with End Users, and the records in their agent databases, the customer decides. They are the controller; we process on their documented instructions under our data processing addendum. Section 5 covers this.
If you are an End User
If you spoke to an agent on somebody else’s website and want your data corrected or deleted, ask that organization — they control it and they can act on it directly in their dashboard. If you cannot reach them, write to privacy@oaura.ai and we will pass the request on; we are not permitted to act on their data without their instruction.
3Personal data we collect
From visitors to this site
Pages viewed, referring site, approximate location derived from IP, browser and device type. Section 7 names the specific tools and is honest about which of them set cookies.
When you contact us
Our contact form asks for your name, work email, company, which plan interests you, and your message. Booking a demo sends you to Calendly, which collects what it needs to put the meeting in a calendar. Emailing hello@oaura.ai gives us whatever is in the email.
When you have an account
- Account and identity: name, email address, company, workspace role, and authentication records handled by Clerk.
- Billing: plan, billing period, invoice history, VAT identification number, and the country we charge tax in. Card details go to Stripe and we never see or store them.
- Operational telemetry: API request metadata, conversation counts, error and latency records, feature usage, and audit events on plans that include them.
- Support: the correspondence you send us and the notes we take on it.
What we do not want
Do not send us special category data under Article 9 of the GDPR — health, biometrics, political or religious views, trade union membership, sexual orientation — or data subject to HIPAA, unless we have agreed to it in writing. We do not yet offer a HIPAA business associate agreement. Clause 5.3 of our terms says the same.
Where it comes from
Almost all of it comes from you — a form you filled in, an account you created, an email you sent. The rest the Service produces as you use it: request logs, usage counters, error and latency records. Two things reach us second-hand: Clerk passes on what your identity provider asserts when you sign in through SSO, and Stripe tells us the billing country and tax status it worked out for your payment. We do not buy contact lists, we do not pay an enrichment or data-broker service to fill in your job title, headcount or revenue, and we do not scrape social profiles. If we hold a prospect record about you, it is because you or a colleague contacted us.
4Why we use it, and our legal basis
Under the GDPR we need a lawful basis for every use. These are ours, in plain terms.
To run the Service — contract
Creating your account, authenticating you, operating your agents, applying your plan limits and providing support. Without this data there is no service to give you.
To bill you — contract and legal obligation
Taking payment, issuing invoices, and keeping the accounting and tax records Lithuanian law requires us to keep.
To keep the Service working and safe — legitimate interests
Monitoring availability, investigating errors, preventing abuse and fraud, enforcing clause 5 of our terms, and improving the product from aggregate usage patterns. Our interest is running a reliable platform; we have weighed it against your interests and use the least data that achieves it.
To talk to you about Oaura — legitimate interests or consent
Replying when you contact us, and sending product and service announcements to customers. Marketing email to people who are not customers goes out only with consent, and every message carries an unsubscribe link that works.
To defend ourselves — legitimate interests and legal obligation
Establishing, exercising or defending legal claims, and responding to lawful requests from authorities.
What we never do
We do not sell personal data. We do not share it for cross-context behavioral advertising. We do not use Customer Data to train, fine-tune or evaluate any model, ours or anyone else’s — see section 6.
5Data you put into Oaura
What it includes
Documents and content ingested into knowledge bases, conversation history between your agents and your End Users, records your agents read or write in connected systems, and the configuration of the agents themselves.
How we treat it
As your data, processed on your instructions, for as long as you keep it. We do not mine it, sell it, or look at it except where you ask us to for support, where we must to investigate abuse or a security incident, or where the law compels us.
You choose what goes in
We do not review ingested content before an agent uses it. Having a lawful basis for the personal data you ingest, and giving your own End Users the notices they are owed, is your responsibility as the controller.
Aggregate statistics
We compile de-identified, aggregated figures — request volumes, error rates, feature adoption — to operate and improve the Service. They never identify you, your End Users or any individual, and we do not publish anything that could.
6AI models, prompts and your keys
This is the section most privacy policies for AI products are vague about. Ours tries not to be.
Where your prompts go
When an agent answers, it sends its instructions, the retrieved knowledge and the conversation so far to a language model provider. That provider receives whatever is in that payload, including any personal data it contains.
Voice messages are transcribed
The widget accepts voice input, so audio an End User speaks is sent to a speech-to-text model and comes back as text. The transcript then joins the conversation history and is Customer Data under section 5, with the same treatment as anything else typed into a conversation. Recorded speech is personal data in its own right and some markets attach their own notice requirements to it, so if you switch voice input on, say so in the notice you give your End Users.
Your keys, your provider, their terms
On every plan you can bring your own provider key. Calls made with your key run under your agreement with that provider, and their privacy terms govern what they do with the prompt — including whether they retain it and for how long. We are not a party to that agreement. Read it before routing personal data through a provider, and choose one whose retention and region match your obligations.
We do not train on your data
We do not use Customer Data, prompts or model output to train, fine-tune or evaluate any model. We do not supply your data to a provider for that purpose either. We cannot promise what a provider does under your own agreement with them — only what we do.
Keys are stored, not read
Keys you supply are encrypted at rest with envelope encryption, scoped to a single agent, and kept out of logs. See the security page.
Automated decisions
We do not make decisions about you with legal or similarly significant effects by automated means. If you build an agent that does, Article 22 of the GDPR applies to you as the controller, and clause 5.3 of our terms tells you not to.
9International transfers
Where your workspace lives
On Business and Enterprise you choose a hosting region, US or EU. On Enterprise, agent data can be isolated to a dedicated database in the region you pick, or to your own infrastructure.
When data leaves the EEA
Some of our sub-processors are established outside the European Economic Area, and a model provider you choose may be too. Where we transfer personal data out of the EEA we rely on the European Commission’s standard contractual clauses, or on an adequacy decision where one covers the recipient, together with the additional measures the transfer requires. Ask at privacy@oaura.ai for the mechanism applying to a specific recipient.
10How long we keep data
Customer Data
For as long as you keep it. Conversation history is held for the window your plan provides and then ages out. After your account closes, clause 11.5 of our terms applies: 30 days to export, then deletion from live systems, after which it ages out of encrypted backups on our normal backup cycle.
Account and billing records
Billing and accounting records are kept for the period Lithuanian tax and accounting law requires, which outlasts your account. Account identity data is deleted with the account, except what those records need.
Everything else
Support correspondence is kept while it is useful for support history and then deleted. Security and audit logs are kept for as long as they are useful for investigating incidents. Prospect data where nothing came of it is deleted when it is clearly stale. Aggregate statistics under clause 5.4 are not personal data and are kept indefinitely.
11How we protect it
Measures
Encryption in transit and at rest, row-level scoping between tenants, envelope-encrypted credential storage, least-privilege access for our own staff, and per-agent budget caps, rate limits and prompt-injection guards. The current detail lives on the security page, including which certifications we hold and which we are still working toward — we do not claim ones we have not earned.
Breach notification
If a personal data breach occurs we will notify the Lithuanian supervisory authority within 72 hours where the GDPR requires it, notify affected customers without undue delay so that they can meet their own obligations, and tell affected individuals directly where the risk to them is high.
Reporting a vulnerability
Send it to security@oaura.ai. We will not pursue researchers who report in good faith and give us reasonable time to fix the issue.
12Your rights
If the GDPR or UK GDPR applies to you, you have the rights below. They apply to data we hold as controller; for data we hold as processor, clause 2.3 explains who to ask.
What you can ask for
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding reason to keep it.
- Restriction — a pause on processing while a dispute is resolved.
- Portability — the data you gave us, in a machine-readable format.
- Objection — to processing based on legitimate interests, including profiling, and to direct marketing at any time with no reason needed.
- Withdrawal of consent — at any time, without affecting what was lawful before you withdrew it.
How to exercise them
Account holders can export, correct and delete most data directly from the dashboard — that is the fastest route. For anything else, email privacy@oaura.ai. We respond within one business week and complete within one month, extendable by two further months for a complex request, in which case we will tell you why. Exercising these rights is free unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.
13If you are in California
The CCPA, as amended by the CPRA, gives California residents their own set of rights. This section is the notice the statute asks for, in the statute’s vocabulary rather than the GDPR’s.
What this section covers
The personal information we handle as a business — the data in section 3, collected for the purposes in section 4, where we are the one deciding. It does not cover what a customer puts into Oaura. There we act as a service provider on that customer’s instructions, we are contractually barred from using the information for our own purposes, and requests about it go to the customer under clause 2.3. Information the CCPA exempts, such as records governed by other federal privacy statutes, is out of scope too.
Your rights
- Know — what we collected about you over the past 12 months, where it came from, why we collected it, and which categories of third party received it.
- Access — a copy of that information.
- Correct — a fix for anything inaccurate.
- Delete — removal, except where the statute lets us keep something, for instance the tax and accounting records in clause 10.2.
- Limit the use of sensitive personal information — see clause 13.5. We collect none, so there is nothing to limit.
- Opt out of sale or sharing — see clause 13.4. We do neither, so there is nothing to opt out of.
- Non-discrimination — no worse price, plan, or level of service because you exercised any of these.
Categories we collect
Sorted into the statute’s categories, for the preceding 12 months. All of it comes from the sources in clause 3.5, is used for the purposes in section 4, and is disclosed for a business purpose to the service providers named in section 8 and to the advisers and authorities in clause 8.1.
- Identifiers — name, work email address, company name, account and workspace identifiers, IP address.
- Commercial information — your plan, billing period, and invoice and payment history. Card numbers go to Stripe and never reach us.
- Internet or other electronic network activity — pages viewed on oaura.ai, referring site, API request metadata, feature usage, error and latency records.
- Geolocation data — the approximate city or country we derive from your IP address. Nothing precise.
- Professional or employment information — your company, your role in a workspace, and whatever you chose to tell us about your team when you got in touch.
- Inferences — none worth the name. We do not build a profile of you; the aggregate figures in clause 5.4 are not about an identified person.
We collect nothing from the remaining statutory categories: no biometric information, no education records, and no audio or visual recordings for our own purposes — the voice input in clause 6.2 is Customer Data, which clause 13.1 puts outside this section.
Sale and sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as the CCPA defines those terms. We have not done so in the preceding 12 months. There is therefore nothing for a “Do Not Sell or Share My Personal Information” link to turn off, and a Global Privacy Control signal from your browser has nothing to switch off here either.
Sensitive personal information
We do not collect it, ask for it, or want it — clause 3.4 asks you not to send it. We do not use or disclose personal information to infer characteristics about you, and we do not use it for any purpose beyond the ones section 4 lists.
Making a request
Email privacy@oaura.ai. We confirm receipt within 10 business days and answer within 45 calendar days, extendable once by a further 45 where the request is genuinely complex, in which case we tell you before the first 45 are up. To verify who you are we match what you send us against the account and may ask you to confirm from the account email address, or to supply a detail only the account holder would know; we will not ask you for a government identity document. An authorized agent may act for you with your written, signed permission, and we may still ask you to confirm the authorization directly. Requests are free, and we only decline where the statute permits it.
14Children
Oaura is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to privacy@oaura.ai and we will delete it. If you deploy an agent that children will use, that is your responsibility as controller, and the law in your market may require more of you than it requires of us.
15Changes to this policy
We update this policy as the product changes. The effective date at the top always reflects the current version. For changes that materially affect how we use personal data, we will email account administrators at least 30 days before they take effect. Minor corrections take effect when posted.
16Contact and complaints
MB Tilfortis
Kaunas, Lithuania
Privacy questions, requests and erasure: privacy@oaura.ai
Data processing addendum and contracts: legal@oaura.ai
Vulnerability reports: security@oaura.ai
We have not appointed a data protection officer, because we are not required to. Privacy requests reach a named person on our team, not a queue.
If you think we have mishandled your data, tell us first — we would rather fix it. You can also complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), our lead supervisory authority, or to the authority where you live or work.