Privacy Policy
Last updated: July 24, 2026 · The English version is the binding one.
1. Controller
OkOvia is operated by Intelectouch (“we”), the data controller for the personal data described here. Contact: hello@okovia.com.
2. What we collect
- Account data — name, email address, and optional profile photo, received from Google/Firebase Authentication when you sign in.
- Product telemetry — usage metadata that OkOvia customers send from their own applications: token counts, model and provider names, feature labels, durations, statuses and error codes, and salted one-way hashes. This data describes AI usage; it is associated with the customer’s workspace.
- Waitlist — the email address you submit to the release waitlist, with your language preference.
- Cookies — a session cookie (sign-in), a language cookie, and a theme preference. No advertising or cross-site tracking cookies.
- Logs — standard technical logs (IP address, timestamps, endpoints) kept for security and reliability.
3. What we do not collect — by construction
The SDKs, tag, and connectors are designed so that content never leaves your application: no prompts, no model responses, no DOM content, no form data, no end-user documents. Where correlation is needed, the SDKs compute salted hashes on-device and send only the hash. Customers must not use custom fields to send end-user personal data (see the Terms of Service).
4. Why we process it
- To provide the service: authentication, cost calculation, dashboards, recommendations (contract).
- To keep the service secure and reliable: logs, rate limiting (legitimate interest).
- To contact you about the release, if you joined the waitlist (consent — withdraw anytime).
We do not sell personal data and we do not use it for advertising.
5. Where it is processed
Infrastructure is hosted on Hostinger (cloud servers); authentication is provided by Google Firebase. These providers process data on our behalf under their own compliance programs. Data may be processed outside your country; we apply appropriate safeguards.
6. Retention
- Account data: while your account exists.
- Telemetry: while the owning workspace exists.
- Waitlist: until the release announcement or your withdrawal, whichever comes first.
- Technical logs: for a short rolling window.
7. Your rights
Under the LGPD (Brazil) and, where applicable, the GDPR, you may request access, correction, deletion, or portability of your personal data, and withdraw consent. Write to hello@okovia.com and we will respond within the legal time frame.
8. Security
Traffic is encrypted with TLS; API keys are stored hashed and scoped by least privilege (public, ingest-only, and secret key types); correlation hashes are salted per installation.
9. Changes
We may update this policy. Material changes will be announced on the site or in the console.