Legal

Privacy Policy

Effective
October 1, 2026
Last updated
October 1, 2026
This policy is published in full and describes what we actually do today, including in section 7 where our cookie practice is not yet where it should be. It has not been through outside counsel review. For a data processing addendum, a sub-processor list or a security questionnaire, email legal@oaura.ai.

Oaura is a platform for building AI agents, so personal data moves through it in two very different ways: the data you give us to be our customer, and the data you put into Oaura to build with. Section 2 separates the two, and it is worth reading before anything else.

Section 6 covers what happens to a prompt once an agent sends it to a model provider, and section 7 lists what runs on this website — plainly, including the part we have not finished fixing.

1Scope and who we are

1.1

This policy explains what MB Tilfortis, a small partnership registered in Kaunas, Lithuania (“Oaura”, “we”, “us”) does with personal data. It covers this website, oaura.ai, the Oaura dashboard at oaura.app, our API, and the embeddable chat widget our customers install on their own sites.

1.2

Who this is for

Four groups of people show up in this policy, and the rules differ for each:

  • Visitors — anyone browsing oaura.ai.
  • Prospects — people who contact us, book a demo or email sales.
  • Customers — people with an Oaura account, and the colleagues they invite into a workspace.
  • End Users — people who talk to an agent one of our customers built. We handle their data on that customer’s instructions, not our own; section 2 explains why that matters.
1.3

Related documents

Our terms of service govern the commercial relationship, the security page describes our technical measures and current compliance status, and our data processing addendum covers clause 2.2 processing in contractual form. Ask for the addendum at legal@oaura.ai.

2When we decide, and when you decide

Oaura wears two hats, and nearly every question about your data has a different answer depending on which one applies.

2.1

We are the controller for our own business

For our website, our marketing, our sales conversations, our billing and our customers’ account administration, we decide why and how personal data is used. We are the controller, this policy is the notice we owe you, and sections 3, 4, 7 and 12 apply directly.

2.2

We are a processor for what you put in Oaura

For the content a customer ingests into a knowledge base, the conversations their agents hold with End Users, and the records in their agent databases, the customer decides. They are the controller; we process on their documented instructions under our data processing addendum. Section 5 covers this.

2.3

If you are an End User

If you spoke to an agent on somebody else’s website and want your data corrected or deleted, ask that organization — they control it and they can act on it directly in their dashboard. If you cannot reach them, write to privacy@oaura.ai and we will pass the request on; we are not permitted to act on their data without their instruction.

3Personal data we collect

3.1

From visitors to this site

Pages viewed, referring site, approximate location derived from IP, browser and device type. Section 7 names the specific tools and is honest about which of them set cookies.

3.2

When you contact us

Our contact form asks for your name, work email, company, which plan interests you, and your message. Booking a demo sends you to Calendly, which collects what it needs to put the meeting in a calendar. Emailing hello@oaura.ai gives us whatever is in the email.

3.3

When you have an account

  • Account and identity: name, email address, company, workspace role, and authentication records handled by Clerk.
  • Billing: plan, billing period, invoice history, VAT identification number, and the country we charge tax in. Card details go to Stripe and we never see or store them.
  • Operational telemetry: API request metadata, conversation counts, error and latency records, feature usage, and audit events on plans that include them.
  • Support: the correspondence you send us and the notes we take on it.
3.4

What we do not want

Do not send us special category data under Article 9 of the GDPR — health, biometrics, political or religious views, trade union membership, sexual orientation — or data subject to HIPAA, unless we have agreed to it in writing. We do not yet offer a HIPAA business associate agreement. Clause 5.3 of our terms says the same.

3.5

Where it comes from

Almost all of it comes from you — a form you filled in, an account you created, an email you sent. The rest the Service produces as you use it: request logs, usage counters, error and latency records. Two things reach us second-hand: Clerk passes on what your identity provider asserts when you sign in through SSO, and Stripe tells us the billing country and tax status it worked out for your payment. We do not buy contact lists, we do not pay an enrichment or data-broker service to fill in your job title, headcount or revenue, and we do not scrape social profiles. If we hold a prospect record about you, it is because you or a colleague contacted us.

4Why we use it, and our legal basis

Under the GDPR we need a lawful basis for every use. These are ours, in plain terms.

4.1

To run the Service — contract

Creating your account, authenticating you, operating your agents, applying your plan limits and providing support. Without this data there is no service to give you.

4.2

To bill you — contract and legal obligation

Taking payment, issuing invoices, and keeping the accounting and tax records Lithuanian law requires us to keep.

4.3

To keep the Service working and safe — legitimate interests

Monitoring availability, investigating errors, preventing abuse and fraud, enforcing clause 5 of our terms, and improving the product from aggregate usage patterns. Our interest is running a reliable platform; we have weighed it against your interests and use the least data that achieves it.

4.4

To talk to you about Oaura — legitimate interests or consent

Replying when you contact us, and sending product and service announcements to customers. Marketing email to people who are not customers goes out only with consent, and every message carries an unsubscribe link that works.

4.5

To defend ourselves — legitimate interests and legal obligation

Establishing, exercising or defending legal claims, and responding to lawful requests from authorities.

4.6

What we never do

We do not sell personal data. We do not share it for cross-context behavioral advertising. We do not use Customer Data to train, fine-tune or evaluate any model, ours or anyone else’s — see section 6.

5Data you put into Oaura

5.1

What it includes

Documents and content ingested into knowledge bases, conversation history between your agents and your End Users, records your agents read or write in connected systems, and the configuration of the agents themselves.

5.2

How we treat it

As your data, processed on your instructions, for as long as you keep it. We do not mine it, sell it, or look at it except where you ask us to for support, where we must to investigate abuse or a security incident, or where the law compels us.

5.3

You choose what goes in

We do not review ingested content before an agent uses it. Having a lawful basis for the personal data you ingest, and giving your own End Users the notices they are owed, is your responsibility as the controller.

5.4

Aggregate statistics

We compile de-identified, aggregated figures — request volumes, error rates, feature adoption — to operate and improve the Service. They never identify you, your End Users or any individual, and we do not publish anything that could.

6AI models, prompts and your keys

This is the section most privacy policies for AI products are vague about. Ours tries not to be.

6.1

Where your prompts go

When an agent answers, it sends its instructions, the retrieved knowledge and the conversation so far to a language model provider. That provider receives whatever is in that payload, including any personal data it contains.

6.2

Voice messages are transcribed

The widget accepts voice input, so audio an End User speaks is sent to a speech-to-text model and comes back as text. The transcript then joins the conversation history and is Customer Data under section 5, with the same treatment as anything else typed into a conversation. Recorded speech is personal data in its own right and some markets attach their own notice requirements to it, so if you switch voice input on, say so in the notice you give your End Users.

6.3

Your keys, your provider, their terms

On every plan you can bring your own provider key. Calls made with your key run under your agreement with that provider, and their privacy terms govern what they do with the prompt — including whether they retain it and for how long. We are not a party to that agreement. Read it before routing personal data through a provider, and choose one whose retention and region match your obligations.

6.4

We do not train on your data

We do not use Customer Data, prompts or model output to train, fine-tune or evaluate any model. We do not supply your data to a provider for that purpose either. We cannot promise what a provider does under your own agreement with them — only what we do.

6.5

Keys are stored, not read

Keys you supply are encrypted at rest with envelope encryption, scoped to a single agent, and kept out of logs. See the security page.

6.6

Automated decisions

We do not make decisions about you with legal or similarly significant effects by automated means. If you build an agent that does, Article 22 of the GDPR applies to you as the controller, and clause 5.3 of our terms tells you not to.

7Cookies, analytics and the widget on this site

7.1

What runs on oaura.ai today

  • Google Tag Manager — container GTM-NR4PVLZM, which loads on every page and can load further tags. Depending on the tags configured in it, this may set cookies and may send your IP address and page views to Google.
  • Plausible Analytics — page views and referrers, measured without cookies and without tracking you across sites. Data is held in the EU.
  • The Oaura widget — the real product, embedded on our own site. If you open it and type, your messages are processed by our platform exactly as described in section 5, with Oaura as the controller for that conversation.
  • Strictly necessary storage — local storage for your theme choice and similar interface preferences. It stays in your browser.
7.2

Consent, stated plainly

We do not currently show a cookie consent banner, which means tags loaded through Google Tag Manager run before you have had a chance to refuse them. That is a gap we are closing, and we would rather write it down here than describe a consent flow that does not exist yet. In the meantime you can block these scripts with any content blocker, or with your browser’s own controls, and the site will work normally. If you want your analytics records removed, write to privacy@oaura.ai.

7.3

Do Not Track

Browsers send a Do Not Track signal inconsistently and there is no agreed standard for honoring it, so we do not claim to. Plausible does not track you across sites regardless.

8Who we share data with

We use a deliberately small number of sub-processors. Each one gets only what its job requires, under a contract that holds it to terms at least as strict as ours. The authoritative current list is on the security page and in our data processing addendum.

Stripe
Payments, invoicing and tax calculation. Receives billing identity and transaction data; holds your card details so that we do not.
Clerk
Authentication and workspace identity, including SAML SSO and SCIM provisioning on Enterprise.
Supabase
Database and file storage for workspace and agent data.
Your LLM provider
The model vendor you choose. Receives agent prompts as described in section 6.
Google (Tag Manager)
Tag delivery on this marketing site. See section 7.
Plausible
Cookieless website analytics, EU-hosted.
Calendly
Demo scheduling, if you book a meeting with us.
8.1

Others we may share with

Professional advisers under confidentiality; authorities where the law requires it, and then only what is required; and a buyer or successor if the business is sold, in which case we will tell you before your data moves and this policy continues to apply until it is replaced.

8.2

Sub-processor changes

Customers can ask to be notified before we add or replace a sub-processor, and to object, under our data processing addendum.

9International transfers

9.1

Where your workspace lives

On Business and Enterprise you choose a hosting region, US or EU. On Enterprise, agent data can be isolated to a dedicated database in the region you pick, or to your own infrastructure.

9.2

When data leaves the EEA

Some of our sub-processors are established outside the European Economic Area, and a model provider you choose may be too. Where we transfer personal data out of the EEA we rely on the European Commission’s standard contractual clauses, or on an adequacy decision where one covers the recipient, together with the additional measures the transfer requires. Ask at privacy@oaura.ai for the mechanism applying to a specific recipient.

10How long we keep data

10.1

Customer Data

For as long as you keep it. Conversation history is held for the window your plan provides and then ages out. After your account closes, clause 11.5 of our terms applies: 30 days to export, then deletion from live systems, after which it ages out of encrypted backups on our normal backup cycle.

10.2

Account and billing records

Billing and accounting records are kept for the period Lithuanian tax and accounting law requires, which outlasts your account. Account identity data is deleted with the account, except what those records need.

10.3

Everything else

Support correspondence is kept while it is useful for support history and then deleted. Security and audit logs are kept for as long as they are useful for investigating incidents. Prospect data where nothing came of it is deleted when it is clearly stale. Aggregate statistics under clause 5.4 are not personal data and are kept indefinitely.

11How we protect it

11.1

Measures

Encryption in transit and at rest, row-level scoping between tenants, envelope-encrypted credential storage, least-privilege access for our own staff, and per-agent budget caps, rate limits and prompt-injection guards. The current detail lives on the security page, including which certifications we hold and which we are still working toward — we do not claim ones we have not earned.

11.2

Breach notification

If a personal data breach occurs we will notify the Lithuanian supervisory authority within 72 hours where the GDPR requires it, notify affected customers without undue delay so that they can meet their own obligations, and tell affected individuals directly where the risk to them is high.

11.3

Reporting a vulnerability

Send it to security@oaura.ai. We will not pursue researchers who report in good faith and give us reasonable time to fix the issue.

12Your rights

If the GDPR or UK GDPR applies to you, you have the rights below. They apply to data we hold as controller; for data we hold as processor, clause 2.3 explains who to ask.

12.1

What you can ask for

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion, where we have no overriding reason to keep it.
  • Restriction — a pause on processing while a dispute is resolved.
  • Portability — the data you gave us, in a machine-readable format.
  • Objection — to processing based on legitimate interests, including profiling, and to direct marketing at any time with no reason needed.
  • Withdrawal of consent — at any time, without affecting what was lawful before you withdrew it.
12.2

How to exercise them

Account holders can export, correct and delete most data directly from the dashboard — that is the fastest route. For anything else, email privacy@oaura.ai. We respond within one business week and complete within one month, extendable by two further months for a complex request, in which case we will tell you why. Exercising these rights is free unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.

13If you are in California

The CCPA, as amended by the CPRA, gives California residents their own set of rights. This section is the notice the statute asks for, in the statute’s vocabulary rather than the GDPR’s.

13.1

What this section covers

The personal information we handle as a business — the data in section 3, collected for the purposes in section 4, where we are the one deciding. It does not cover what a customer puts into Oaura. There we act as a service provider on that customer’s instructions, we are contractually barred from using the information for our own purposes, and requests about it go to the customer under clause 2.3. Information the CCPA exempts, such as records governed by other federal privacy statutes, is out of scope too.

13.2

Your rights

  • Know — what we collected about you over the past 12 months, where it came from, why we collected it, and which categories of third party received it.
  • Access — a copy of that information.
  • Correct — a fix for anything inaccurate.
  • Delete — removal, except where the statute lets us keep something, for instance the tax and accounting records in clause 10.2.
  • Limit the use of sensitive personal information — see clause 13.5. We collect none, so there is nothing to limit.
  • Opt out of sale or sharing — see clause 13.4. We do neither, so there is nothing to opt out of.
  • Non-discrimination — no worse price, plan, or level of service because you exercised any of these.
13.3

Categories we collect

Sorted into the statute’s categories, for the preceding 12 months. All of it comes from the sources in clause 3.5, is used for the purposes in section 4, and is disclosed for a business purpose to the service providers named in section 8 and to the advisers and authorities in clause 8.1.

  • Identifiers — name, work email address, company name, account and workspace identifiers, IP address.
  • Commercial information — your plan, billing period, and invoice and payment history. Card numbers go to Stripe and never reach us.
  • Internet or other electronic network activity — pages viewed on oaura.ai, referring site, API request metadata, feature usage, error and latency records.
  • Geolocation data — the approximate city or country we derive from your IP address. Nothing precise.
  • Professional or employment information — your company, your role in a workspace, and whatever you chose to tell us about your team when you got in touch.
  • Inferences — none worth the name. We do not build a profile of you; the aggregate figures in clause 5.4 are not about an identified person.

We collect nothing from the remaining statutory categories: no biometric information, no education records, and no audio or visual recordings for our own purposes — the voice input in clause 6.2 is Customer Data, which clause 13.1 puts outside this section.

13.4

Sale and sharing

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as the CCPA defines those terms. We have not done so in the preceding 12 months. There is therefore nothing for a “Do Not Sell or Share My Personal Information” link to turn off, and a Global Privacy Control signal from your browser has nothing to switch off here either.

13.5

Sensitive personal information

We do not collect it, ask for it, or want it — clause 3.4 asks you not to send it. We do not use or disclose personal information to infer characteristics about you, and we do not use it for any purpose beyond the ones section 4 lists.

13.6

Making a request

Email privacy@oaura.ai. We confirm receipt within 10 business days and answer within 45 calendar days, extendable once by a further 45 where the request is genuinely complex, in which case we tell you before the first 45 are up. To verify who you are we match what you send us against the account and may ask you to confirm from the account email address, or to supply a detail only the account holder would know; we will not ask you for a government identity document. An authorized agent may act for you with your written, signed permission, and we may still ask you to confirm the authorization directly. Requests are free, and we only decline where the statute permits it.

14Children

14.1

Oaura is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to privacy@oaura.ai and we will delete it. If you deploy an agent that children will use, that is your responsibility as controller, and the law in your market may require more of you than it requires of us.

15Changes to this policy

15.1

We update this policy as the product changes. The effective date at the top always reflects the current version. For changes that materially affect how we use personal data, we will email account administrators at least 30 days before they take effect. Minor corrections take effect when posted.

16Contact and complaints

MB Tilfortis
Kaunas, Lithuania

Privacy questions, requests and erasure: privacy@oaura.ai
Data processing addendum and contracts: legal@oaura.ai
Vulnerability reports: security@oaura.ai

We have not appointed a data protection officer, because we are not required to. Privacy requests reach a named person on our team, not a queue.

If you think we have mishandled your data, tell us first — we would rather fix it. You can also complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), our lead supervisory authority, or to the authority where you live or work.