We use essential cookies for authentication and site functionality. Privacy Policy

O
OIDO STUDIO
PrivacyTermsSecurityStatusContact
OIDO SYSTEMS · LEGAL

PRIVACY POLICY

Last updated: August 2026 · Effective immediately

Oido Systems (“Oido”, “we”, “our”) operates Oido Studio, a cloud-based AI agent platform. This Privacy Policy explains what data we collect, how we use it, and the controls you have over your information.

1. Who This Applies To

This policy applies to all users of the Oido Studio cloud platform, including members of organisations that access Oido through a team subscription. If your employer has provided you access, their organisation agreement governs data handling at the workspace level.

1a. Our Two Roles: Controller and Processor

Oido handles two different kinds of personal data, under two different roles. The distinction matters, because it decides who is responsible for what.

We are the controller of the data we hold about you as our customer: your name, email, password hash, organisation details, billing tier, and the request logs we keep to run the service. We decide why and how that data is processed, and this policy governs it.

We are a processor for everything your agents handle on your behalf, the content of the emails, orders, tickets, records and documents they read and write in your systems, including personal data about your own customers, staff and suppliers. You are the controller of that data. You decide what your agents may access, what they do with it, and how long it is kept. We process it only to provide the service, on your instructions, and never for our own purposes.

Where we act as processor, our processing terms and, for Enterprise customers, a Data Processing Agreement, govern that relationship alongside this policy. Contact us for a copy.

1b. Your Responsibilities as Controller

Because you decide what your agents process, you are responsible for:

  • Having a lawful basis for the personal data you connect to Oido, and telling the people concerned as your own privacy notice requires
  • Not putting special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation) or criminal offence data into Oido without agreeing that use with us in writing first
  • Not using Oido to process data about children
  • Configuring which actions require human approval, and keeping your organisation's access, roles and credentials current
  • Choosing your AI provider and any tools you connect, and accepting their terms for data you route to them

Oido is a business tool. It is not intended for personal use, and you must be at least 18 years old to hold an account.

2. Data We Collect

Account data, collected at registration:

  • Name and email address
  • Hashed password (we never store plaintext passwords)
  • Organisation name, slug, and billing tier

Platform data, generated while using Oido:

  • Agent configurations, names, and instructions you create
  • Conversation history between users and agents
  • Session identifiers and tab/agent routing data
  • Channel connection settings (Telegram, Discord, etc.)
  • Extension and MCP server configurations
  • Skill definitions created within your organisation

Credentials, stored with encryption:

  • AI provider API keys (AES-256-GCM encrypted at rest)
  • Integration credentials (encrypted, scoped per organisation)
  • Channel tokens (encrypted, never exposed in plaintext in responses)

Usage data, for reliability and improvement:

  • Request logs (method, path, status, latency, no request bodies)
  • Error traces for debugging (no user content)
  • Feature usage aggregates for product decisions

3. Data We Do Not Collect

  • We do not sell or rent your data to any third party
  • We do not use your conversation data, or the content your agents process, to train AI models
  • We do not store billing card details (handled by Stripe)
  • We do not read your agent conversations for advertising purposes, and no product data is passed to our website analytics
  • We do not build advertising profiles about you. Advertising storage and ad personalisation are disabled at all times (see section 9)

3a. Why We Are Allowed to Process It (Legal Basis)

Where we act as controller, we rely on:

  • Performance of a contract, to create and run your account, provide the platform, and handle billing and support
  • Legitimate interests, to keep the service secure and reliable, prevent abuse, debug faults, and understand which parts of our website are useful. We balance this against your rights, and you can object at any time
  • Consent, for website analytics cookies and for marketing email. You can withdraw consent at any time, without affecting processing that already happened
  • Legal obligation, to keep accounting records and to respond to lawful requests

4. How Data Flows to Third Parties

Oido connects your agents to AI providers and tools that you configure. Data flows only to services you explicitly connect:

  • AI providers (OpenAI, Gemini, DeepSeek, OpenRouter, etc.), your conversation data is sent to whichever provider you configure. Each provider's privacy policy applies to data they receive.
  • Channel integrations (Telegram, Discord, WeChat, DingTalk), messages are routed through the channel platform's API. Their terms of service apply.
  • MCP tool servers and n8n workflows, data passed through your configured integrations is subject to those services' policies. You configure these; we route them.
  • Stripe, billing information is handled by Stripe. We store only the subscription status, not card details.

No data is shared with Oido partners, advertisers, or data brokers.

4a. Sub-processors and International Transfers

To run the platform we use a small number of sub-processors, including our hosting and database provider, our email delivery provider, Stripe for payments, and Google for website analytics. Where you connect an AI provider or a third-party tool yourself, that provider processes data on your instruction; some act as independent controllers under their own terms, which is why you connect your own accounts.

A current list of sub-processors is available on request. We will give notice before adding a new sub-processor that processes customer content, and Enterprise customers may object under their Data Processing Agreement.

Transfers outside the EEA and UK. Some providers, in particular AI providers, operate outside the EEA and the UK. Where personal data is transferred, we rely on European Commission adequacy decisions where one exists, and otherwise on Standard Contractual Clauses, with the UK Addendum for UK transfers. If your rules require that data never leaves your own environment, Oido can be self-hosted on Enterprise, and your choice of AI provider and region remains yours.

4b. Automated Decisions

We do not use your data to make automated decisions with legal or similarly significant effects about anyone. Agents you build can take actions automatically, but you decide what those actions are and which of them must stop and wait for a named person to approve. Where a decision affects an individual meaningfully, we strongly recommend keeping a human approval step, and the platform supports this on any action.

5. Organisation Data Isolation

All data, agents, sessions, credentials, conversations, extensions, is stored isolated per organisation. One organisation cannot access another's data. We enforce this at the database layer with organisation-scoped queries and at the execution layer with per-org sandboxed environments.

6. The Oido Browser Connector (Chrome Extension)

The Oido Browser Connector is an optional Chrome extension that lets an agent operate a browser tab on your machine, using sessions you are already logged in to. It does nothing unless you install it and paste in a connector token. This section describes its data handling specifically.

Stored only in your browser, never transmitted to us except as described below:

  • Your Oido base URL and connector token (the token is sent to Oido only as an authentication header, exactly as your browser sends a session cookie)
  • Your origin allowlist and its settings
  • The current task’s tab reference and pinned origin, held for the duration of a task

What the extension can and cannot see:

  • The agent operates a tab that the extension itself opens. It does not read your other tabs, your browsing history, or your bookmarks.
  • Content read from that tab, page text, links, and form controls, is sent to Oido and then to whichever AI provider you have configured, in the same way as any other agent input (see section 4).
  • The tab uses the sessions already present in your Chrome profile, which is what allows an agent to act on a site you are logged in to. The extension does not read, extract, or transmit your cookies, saved passwords, or credentials.
  • Chrome displays its “being debugged” banner on the tab for as long as the agent is driving it.

Limits you control: the agent can only reach origins on your allowlist, and each task is pinned to the first site it opens, so a single task cannot move between sites. The connector token is scoped to the Connected Browser channel and cannot be used anywhere else in your Oido account.

Removal: uninstalling the extension deletes everything it stored, including the connector token. Tokens can also be left to expire; they are valid for 30 days.

7. Data Retention

  • Active accounts: data retained for the life of the account
  • Deleted accounts: data purged within 30 days of deletion request
  • Conversation history: retained until deleted by user or account closure
  • Logs: system logs retained for 90 days for debugging, then deleted
  • Backups: encrypted backups retained for 30 days, then rotated

8. Your Rights

Depending on your jurisdiction, you have rights including:

  • Access, request a copy of all data we hold about you
  • Correction, update inaccurate information
  • Deletion, request full erasure of your account and data
  • Portability, export your agent configurations and conversation data
  • Restriction, ask us to limit how we use your data while a question is resolved
  • Objection, object to processing we carry out on the basis of legitimate interests, including website analytics
  • Withdraw consent, at any time, where we relied on consent

To exercise any of these rights, email contact@oidostudio.com. We respond within one month, and may extend by a further two months for complex requests, in which case we will tell you within the first month.

If you are an employee, customer or supplier of a business that uses Oido, and your data was processed by that business's agents, please contact that business directly. They are the controller of that data. If you contact us instead, we will pass the request to them and support them in answering it.

You also have the right to complain to a data protection supervisory authority in the country where you live or work, or where you believe the issue arose. We would ask you to raise it with us first so we can try to put it right.

8a. Data Breaches

If a breach affects personal data we hold as controller, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, and we will tell affected users where the law requires it. Where we act as processor for your agents' data, we will notify you without undue delay after becoming aware, with the information you need to meet your own obligations as controller.

9. Cookies and Analytics

This section previously stated that we used no analytics or advertising cookies. That was inaccurate: our public website uses Google Analytics 4 and Google Ads conversion measurement. The description below is what actually runs.

Inside the product (app.oidostudio.com and your workspace): only functional cookies required for authentication and session handling. No analytics or advertising cookies are set in the product.

On our public website:

  • Google Analytics 4, used to understand which pages people find useful. Analytics storage is set to denied by default and is only enabled if you accept in the cookie banner.
  • Google Ads conversion measurement, used to count sign-ups that came from an advertisement. Advertising storage, advertising user data and ad personalisation are set to denied at all times, so no personalised advertising profile is built from your visit.

Until you accept, these tools are loaded in a consent-denied state and set no analytics or advertising cookies. You can change your choice at any time by clearing site data in your browser, which resets the banner. Clearing cookies inside the product will log you out.

We do not use pixel tracking from social networks, and we do not sell or share your data with advertisers or data brokers.

10. Security Practices

See our Security page for a full description of the technical and organisational measures we use to protect your data, including encryption standards, access controls, and incident response procedures.

11. Changes to This Policy

We will notify you of material changes via email and in-app notice at least 14 days before changes take effect. Continued use after the effective date constitutes acceptance. We maintain a changelog of this policy on request.

12. Who We Are, and How to Reach Us

Oido Systems operates Oido Studio and is the controller for the data described in section 1a. For privacy questions, data requests, a copy of our sub-processor list, or a Data Processing Agreement: contact@oidostudio.com.

For general enquiries: contact@oidostudio.com.

© 2024 OIDO SYSTEMS
PrivacyTermsSecurityStatusContact