OktoLabs

Privacy Policy

Last updated: February 2026

1. Introduction

OktoLabs ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use the Okto platform and our website at oktolabs.dev.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and organization name.

Usage Data

We collect anonymized usage data including workflow execution counts, feature usage patterns, and performance metrics. This data is used to improve the Service and is never sold to third parties.

Website Analytics

We use Cloudflare Web Analytics, which is privacy-focused and does not use cookies or track individual users across sites.

3. Self-Hosted Deployments

If you self-host Okto, we do not collect any data from your deployment. The self-hosted version operates entirely on your infrastructure with no telemetry or phone-home functionality.

4. How We Use Your Data

  • Provide and maintain the managed cloud service
  • Send service-related communications (outages, updates, security alerts)
  • Improve the platform based on aggregated usage patterns
  • Respond to support requests
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data to train AI models. We do not share your data with advertisers.

5. Data Storage and Security

Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Managed cloud data is stored in your selected region (US, EU, or APAC). We perform regular security audits and penetration testing. Access to production systems is restricted and logged.

6. Your Workflow Data

Your workflows, configurations, and execution outputs remain your property. We do not access, read, or analyze the content of your workflows except when required for technical support (with your explicit consent) or to comply with legal obligations.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and data
  • Export your data in standard formats
  • Object to processing of your data
  • Withdraw consent at any time

8. Cookies

Our website uses only essential cookies required for authentication and session management on the managed cloud service. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Third-Party Services

The managed cloud service may integrate with third-party LLM providers (OpenAI, Anthropic, Google, etc.) as configured by you. When you use these integrations, your prompts and data are sent to those providers under their respective privacy policies. We do not control how third-party providers handle your data.

10. Data Retention

We retain your account data for as long as your account is active. Execution logs are retained for 90 days by default (configurable on Team and Enterprise plans). Upon account deletion, your data is permanently removed within 30 days.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes via email or through the Service.

12. Contact

For privacy-related questions, please contact us at privacy@oktolabs.dev.