DRAFT — legal publication BLOCKED: required factual inputs or review are missing.

Privacy Policy

Oqera

Effective date: [[EFFECTIVE_DATE]]

1. Who is responsible

[[LEGAL_ENTITY_NAME]], registration number [[ENTITY_REGISTRATION_NUMBER]], [[REGISTERED_ADDRESS]], operates the Closed Beta at https://oqera.org and https://app.oqera.org. Operator country context: Kazakhstan. The approved data-processing roles and actual service relationships must be recorded before publication: [[AI_PROVIDER_DATA_ROLE]]

Privacy contact: [[PRIVACY_EMAIL]]

2. What we collect

2.1 Application and account data

The application collects your name, email, company/product name, optional URL, role, team size, what you are building, current manual AI coordination, AI tools and desired delegation. The founder uses it to review requests for a limited cohort and contact selected participants. Submission does not create an account or access.

Invited account authentication is handled by Supabase. Oqera does not store your password. Admission applications, decisions and beta grants are persisted by Oqera.

2.2 Content you create ("Your Content")

2.3 Credentials you connect

The Apps catalog and connection configuration are part of the beta. An actual connection or OAuth flow requires its own setup and consent; the catalog alone does not authorize external actions or establish connected-service readiness.

We do not display these values back to you in full after saving, and they are not included in API responses.

2.4 Technical data

IP address, browser and device information, timestamps, and request logs, collected for security, abuse prevention and debugging. Error diagnostics if you have consented to error reporting.

2.5 Payment data

Oqera paid billing and subscriptions are off for this Closed Beta. Oqera does not offer checkout or collect payment instruments through a billing service. Your AI provider bills you directly; its handling of payment data is governed by its terms.

3. Why we process it, and on what legal basis

PurposeDataBasis
Provide the ServiceAccount data, Your Content, credentialsPerformance of a contract
Execute agent runsTask context, canon, memory, filesPerformance of a contract
Review Closed Beta applicationsApplication details and review decisionsBasis subject to approved publication review
Security, abuse prevention, fault diagnosisTechnical data, logsLegitimate interests
Service communications (outages, changes to terms)Email addressPerformance of a contract; legitimate interests
Marketing emailEmail addressConsent — opt-in, withdrawable at any time

We do not sell personal data. We do not use Your Content to train AI models.

4. Sending your data to AI providers

To run an agent, we send the relevant task context — which may include canon entries, task board content, workspace file contents and conversation history — to the AI provider whose credentials you supplied.

This is the core function of the Service and cannot be disabled while using agents.

That provider processes the data under its own terms and privacy policy, not ours. Different providers make different commitments about retention and training. Some free tiers explicitly reserve the right to train on submitted data.

You choose the provider, so you choose those terms. We recommend reviewing your provider's data policy before putting sensitive business information into the Service. Compatibility of any provider/model must be confirmed for your beta setup. The beta does not promise support for every provider or local runtime.

5. Service providers and data-processing roles

Approved actual Closed Beta service list, purposes, roles and locations: [[SUBPROCESSORS]]

Hosting provider: [[HOSTING_PROVIDER]]; hosting region: [[HOSTING_REGION]]. Supabase project region: [[SUPABASE_REGION]].

AI-provider data flow and role: [[AI_PROVIDER_DATA_ROLE]]. Model context is sent using the participant's own key. A BYO key alone does not settle the legal role of Oqera or the chosen provider; the approved description must reflect the actual flow.

Paddle and connected app services are excluded from this initial beta. Optional research services belong in the approved list only if they actually process data in the enabled Closed Beta workflows.

6. Where your data is stored

Primary infrastructure: [[HOSTING_PROVIDER]], [[HOSTING_REGION]]. Backup storage location: [[BACKUP_LOCATION]]. Offsite backup status: [[OFFSITE_BACKUP_STATUS]].

Cohort geography and applicable transfer arrangements: [[COHORT_GEOGRAPHY]]. No geographically separate backup or specific hosting jurisdiction is promised until these actual publication facts are confirmed.

7. How long we keep it

DataRetention
Account dataWhile your account is active
Your ContentWhile your account is active
After account closure[[RETENTION_DAYS]] days, then deleted
Request and security logs[[LOG_RETENTION_DAYS]] days
Source records and workflow history[[SOURCE_RETENTION_POLICY]]
BackupsDeleted content persists in backups until they rotate out, up to [[BACKUP_RETENTION_DAYS]] days

Deletion process and timing: [[DATA_DELETION_PROCESS]]. Backup expiry follows the confirmed backup policy above. No immediate or automated deletion is promised.

8. Security

The application stores AI-provider credentials encrypted and scopes stored records to authenticated users. Server admission checks additionally require an active beta grant. Workflow review checkpoints require the user's decision where specified.

Deployment safeguards and legal disclosures must be reviewed for the actual external cohort host: [[LEGAL_REVIEW_CONFIRMATION]]. This draft does not assert verified production isolation, nightly backups or a completed target-host acceptance.

No system is perfectly secure. Applicable breach notification obligations must be covered by the approved publication review.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent.

To exercise a right, use the confirmed contact [[PRIVACY_EMAIL]] and the approved request process. Response timing must be covered by that process. We may ask you to verify your identity first.

Data export process: [[DATA_EXPORT_PROCESS]].

Data deletion/closure process: [[DATA_DELETION_PROCESS]].

If you are in the EEA or UK and believe we have mishandled your data, you may complain to your local supervisory authority.

10. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe a minor has provided us data, contact [[PRIVACY_EMAIL]] and we will delete it.

11. Browser storage and analytics

Browser storage supports authentication, interface preferences and a submission receipt. The application receipt contains no email, application details or access decision and does not authorize access.

The app also keeps drafts of chat messages and selected business forms in this tab's session storage so they survive a reload or navigation. Drafts are separated by account, team and form, cleared at sign-out, and not shared with other tabs. Credentials, binary attachments and saved human approvals are excluded from this draft mechanism. Closing the tab ends that browser session; sensitive business notes may still be present while the tab remains open.

First-party product telemetry records allowlisted event categories with the account identity resolved by the server, build and time. Interface error observations contain a category and build, rather than exception text, stacks, URLs or task content. Diagnostic delivery is best effort. Authorized beta operators can inspect these observations and answer a participant's submitted report in the app. Reports and optional screenshots contain what the participant chooses to send; participants should remove passwords and keys before submitting them. Log retention remains subject to [[LOG_RETENTION_DAYS]].

Any external analytics used by the actual beta deployment must be identified in the approved service list with its purpose and applicable notice. Disabled scripts or hosting options in repository examples do not prove a deployed analytics mode.

12. Changes

We may update this policy. For material changes we will give notice by email or in-product notice before they take effect, and update the effective date above. Previous versions are available on request.

13. Contact

[[PRIVACY_EMAIL]] — [[LEGAL_ENTITY_NAME]], [[REGISTERED_ADDRESS]]