1. Introduction
This Privacy Policy explains how okr.io ("we", "us", "our") collects, uses, shares, and protects your personal information when you use our service. We are committed to protecting your privacy and being transparent about our data practices.
By using okr.io, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
We collect information you directly provide to us:
- Account Information: Email address, name, and profile information when you create an account
- Workspace Data: Objectives, key results, tasks, and strategic context you enter during Office Hours
- Communications: Messages you send to support or feedback you provide
- Payment Information: Billing details processed securely through Stripe (we don't store full card numbers)
- Integration Credentials: API keys or OAuth tokens for third-party services you connect
2.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Usage Data: Pages visited, features used, actions taken, and time spent
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, referring URLs, and error logs
- Cookies: Session cookies for authentication and analytics cookies (with your consent)
2.3 AI-Generated Data
When our AI agents execute tasks, we collect:
- Task instructions and context provided by you
- Generated deliverables and outputs
- Agent performance metrics and logs
- Founder signals detected during Office Hours
3. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and maintain the Service | Account data, workspace data, usage data | Contract performance |
| Process payments | Billing information | Contract performance |
| Send transactional emails | Email address, workspace data | Contract performance |
| Send marketing communications | Email address, name | Consent (opt-in) |
| Improve the Service | Usage data, anonymized content | Legitimate interest |
| Provide customer support | Account data, communications | Contract performance |
| Detect and prevent fraud | Usage data, device information | Legitimate interest |
| Comply with legal obligations | As required by law | Legal obligation |
4. AI and Machine Learning
4.1 How We Use AI
okr.io uses AI to:
- Generate OKRs based on your Office Hours responses
- Execute tasks through AI agents
- Detect founder signals and strategic drift
- Provide recommendations and insights
4.2 AI Training
We may use anonymized and aggregated data to improve our AI models. We do NOT use your specific workspace content, deliverables, or strategic context to train general-purpose AI models. Your data remains yours.
4.3 Third-Party AI Providers
We use third-party AI providers (such as OpenAI and Anthropic) to power some features. When we send data to these providers:
- We send only the minimum data necessary for the task
- We have data processing agreements in place
- These providers are prohibited from using your data for training
5. Information Sharing
5.1 We Never Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.2 When We Share Data
We may share your information in these limited circumstances:
- Service Providers: With vendors who help us operate the Service (hosting, payment processing, email delivery, analytics) under strict confidentiality agreements
- Workspace Members: With other members of your workspace, as determined by your workspace settings and roles
- Integrations: With third-party services you explicitly connect (e.g., Linear, GitHub)
- Legal Requirements: When required by law, subpoena, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to you)
- With Your Consent: When you explicitly authorize sharing
5.3 Service Providers
We use the following categories of service providers:
- Hosting: Cloudflare (infrastructure, CDN, Workers)
- Payment Processing: Stripe
- Email Delivery: Resend
- AI Processing: OpenAI, Anthropic
- Analytics: Privacy-respecting analytics only
6. Data Security
6.1 Security Measures
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest
- Secure password hashing using bcrypt
- Regular security audits and penetration testing
- Access controls and authentication requirements
- Monitoring and logging of system access
- Incident response procedures
6.2 Data Location
Your data is stored on servers located in the United States and may be processed in other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for international transfers.
6.3 Breach Notification
In the event of a data breach affecting your personal information, we will notify you within 72 hours via email and provide information about what data was affected and what steps you should take.
7. Data Retention
7.1 Active Accounts
We retain your data for as long as your account is active and as needed to provide the Service.
7.2 After Account Deletion
When you delete your account:
- Your data is retained for 30 days to allow recovery
- After 30 days, personal data is permanently deleted
- Anonymized analytics data may be retained
- Data required for legal compliance may be retained longer
7.3 Backups
Backups are retained for up to 90 days for disaster recovery purposes.
8. Your Rights
Depending on your location, you may have the following rights:
8.1 Access and Portability
You can access your data through the Service settings or request a full export by contacting us. We provide data in standard, machine-readable formats.
8.2 Correction
You can update your account information through the Service settings or by contacting us.
8.3 Deletion
You can delete your account through settings or by contacting us. Upon request, we will delete your personal data, subject to legal retention requirements.
8.4 Objection and Restriction
You can object to certain processing activities or request that we restrict processing of your data.
8.5 Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time (e.g., unsubscribe from marketing emails).
8.6 Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.
9. Cookies and Tracking
9.1 Essential Cookies
We use essential cookies for authentication and security. These cannot be disabled.
9.2 Analytics Cookies
We use privacy-respecting analytics to understand how the Service is used. You can opt out through your browser settings.
9.3 Do Not Track
We respect Do Not Track browser signals and will not track you when DNT is enabled.
10. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
11. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt out of sale of personal information (we don't sell data)
- Right to deletion
- Right to non-discrimination for exercising these rights
To exercise these rights, contact us at privacy@okr.io.
12. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, you have rights under GDPR including:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
Our legal bases for processing are contract performance, legitimate interests, and consent as described above.
13. International Transfers
If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses and other appropriate safeguards for international transfers.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Your continued use after changes constitutes acceptance.
15. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights:
- Email: privacy@okr.io
- Support: support@okr.io
For GDPR-related inquiries, you may also contact our Data Protection Officer at dpo@okr.io.