Privacy Policy

Last updated

The short version

Olokas runs AI-search visibility scans for paying customers and free audit users. To do that we store an account record (email, plan), the domains and queries you ask us to track, and the answers we get back from each AI engine. We share the minimum with the sub-processors listed below to make the product work. We do not sell your data, run ad targeting, or train models on it. You can delete your account and underlying data at any time.

What we collect

We collect three kinds of data:

Account data.
Your email address (used for sign-in via magic link), the plan you're on, and timestamps for sign-up and last activity. If you subscribe, your Stripe customer and subscription IDs.
Workspace data.
The domains you ask us to monitor, the queries you assign to each domain, and the scan results we collect from ChatGPT, Perplexity, Google AI Overviews, and Claude on your behalf. Reports we generate from that data are stored so you can re-open them.
Operational data.
Server-side logs that record request metadata (route, status, timing) for debugging and abuse prevention. We do not run third-party browser analytics, ad pixels, or fingerprinting scripts.

How we use it

We use the data above to:

  • Run the scans you've configured.
  • Produce reports and email them to you on schedule.
  • Process payments, send receipts, and handle subscription lifecycle events.
  • Respond when you write in, and detect abuse (rate limits, spam, scraping).

We do not use your queries, scan results, or reports to train machine-learning models. We do not sell or rent your data to third parties.

Sub-processors

Olokas is built on top of the following services. Each one receives the minimum data needed for its job:

Supabase (auth + database).
Stores your account, queries, domains, scan results, and reports. Hosted in the EU.
Stripe (payments).
Handles checkout, recurring billing, and the customer portal. We never see your card number — Stripe holds it.
Vercel (hosting).
Serves the marketing site and the signed-in app. Edge logs are retained for a short window for debugging.
Resend (transactional email).
Sends magic-link emails, weekly reports, and account notifications.
Anthropic, OpenAI, Perplexity, SerpAPI (scan engines).
Receive the queries you've configured at scan time. We send the query text, not your account email. Each provider's own retention policy applies to the request on their side.

Data retention

While your account is active, we keep your workspace data indefinitely so historical reports stay meaningful. If you cancel, we keep the data for 30 days in case you reactivate, then delete it. If you delete your account, we remove your data within 30 days, except where we're required to keep certain records (for example, invoice records for tax compliance).

Your rights

Depending on where you live, you may have the right to access the data we hold about you, ask us to correct or delete it, export it in a portable format, or object to particular processing. Concretely, the things we'll do on request:

  • Send you a copy of your account, queries, and scan history in JSON.
  • Delete your account and all linked data (see retention above).
  • Stop sending marketing emails (you can also use the unsubscribe link on any email).

Email hello@olokas.com from the address on your account and we'll handle it within 30 days. EU/UK users have the right to lodge a complaint with their local data-protection authority.

Cookies and tracking

We use a small number of strictly-necessary cookies to keep you signed in (Supabase session cookies). We don't run third-party analytics, advertising, or cross-site tracking pixels. No banner is shown because nothing requires consent beyond what makes the product work.

International transfers

Olokas serves users globally. Some sub-processors host data outside the EU/UK. Where required, transfers rely on the relevant Standard Contractual Clauses or equivalent mechanism between us and the sub-processor.

Children

Olokas is a B2B product not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, please email us and we'll delete it.

Changes to this policy

We'll update the “Last updated” date at the top whenever we change anything substantive. For material changes that affect how we use existing data, we'll email account holders before the change takes effect.

Contact

Privacy questions, deletion requests, or anything else covered here: hello@olokas.com. See also our Terms of Service.