Privacy policy
This policy explains what personal data OkTrack processes, why it is needed, and the choices available to you.
Who is responsible
OKTRACK
Postal address available on request.
Privacy contact: support@oktrack.app
Information we process
We process account and profile details, workspace membership, preferences, selected work activity, daily-update drafts and revisions, selected delivery destinations, delivery status, subscription state, support requests, and limited technical records needed to operate and secure the service. When you connect another service, we process only the information needed for the feature you chose and show the requested access before you authorize it.
When you approve delivery, OkTrack sends the content permitted by that destination's settings to the Slack conversation, Microsoft Teams channel, or email address you chose. A private-link mode sends a short notice and secure link instead of the update body. We retain delivery status, attempt timing, and the provider's remote message identifier for reliability and duplicate prevention; application telemetry does not contain update text.
We do not sell personal information, use work activity for advertising, or store complete payment-card details. Private calendar titles are minimized, credentials are protected, and raw responses from connected services are not kept as general application records.
For Google Docs and Sheets, Notion, and Figma connections, we process selected-scope activity metadata such as a provider and resource identifier, a minimized title, action type, connected-member identifier, occurrence time, and source link. This activity can help explain a proposed review block but does not establish an exact duration. We do not retain document or page bodies, spreadsheet cells or formulas, design canvas or node content, previews, revision diffs, or comment text from these connections.
Why we use it
- to provide accounts, workspaces, daily updates, approved delivery, and paid subscriptions;
- to secure the service, prevent abuse, diagnose failures, and recover interrupted work;
- to respond to plan inquiries, feedback, feature requests, and bug reports;
- to send optional communications or measure product usage when you consent; and
- to meet legal, accounting, and regulatory obligations.
These activities rely on contract performance, steps you request before entering a contract, legitimate interests in running a safe and reliable service, consent where requested, and legal obligations where applicable. You may withdraw consent at any time without affecting earlier lawful processing.
Company workspaces
An organization generally controls the work data placed in its workspace, while OkTrack processes that data to provide the service. Workspace owners and authorized administrators can manage membership, delivery policy, and access approved updates according to their role. Draft content remains available only within its authorized workspace scope. Contact your organization first about organization-controlled records.
Service providers and international processing
We use a limited number of service providers for functions such as hosting, storage, account security, communications, payments, product operations, and consented usage measurement. They may process only the information needed to provide their contracted service and are subject to appropriate confidentiality, security, and data-protection terms. Some processing may occur outside your country; where required, we use recognized transfer safeguards. Services you choose to connect also operate under your relationship with them. Those optional connected services currently include GitHub, Google, Microsoft, Atlassian, Linear, Productive, Harvest, Timely, Notion, Figma, Slack, Microsoft Teams, and the configured email delivery service when their corresponding integration is enabled and you authorize or select it. Slack, Microsoft, and email providers receive approved update content only when used as a delivery destination.
Retention and deletion
We keep personal data only while it is needed for the service, security, legitimate business records, or law. Short-lived authorization, rate-limit, and job records expire automatically. Delivery attempts and remote message identifiers are retained only as long as needed for reliability, audit, and duplicate prevention. Workspace records remain while the relevant workspace exists so approved updates stay reviewable. Account and workspace deletion remove associated destinations and delivery records subject to limited legal, security, backup, and organization-controlled retention needs.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. OkTrack also provides controls for preferences, connected services, portable account downloads, and deletion. We may need to verify your identity before fulfilling a request. You may complain to the competent data-protection authority, including the authority for your location.
Cookies, security, and changes
Necessary browser storage keeps accounts secure. Optional usage measurement remains off until you choose it and can be changed from the cookie notice. We use access controls, encryption, verification, minimization, and audit records appropriate to the service. Material changes to this policy will be dated here and communicated when required.