Last updated: August 2026 · Effective immediately
Oido Systems (“Oido”, “we”, “our”) operates Oido Studio, a cloud-based AI agent platform. This Privacy Policy explains what data we collect, how we use it, and the controls you have over your information.
This policy applies to all users of the Oido Studio cloud platform, including members of organisations that access Oido through a team subscription. If your employer has provided you access, their organisation agreement governs data handling at the workspace level.
Oido handles two different kinds of personal data, under two different roles. The distinction matters, because it decides who is responsible for what.
We are the controller of the data we hold about you as our customer: your name, email, password hash, organisation details, billing tier, and the request logs we keep to run the service. We decide why and how that data is processed, and this policy governs it.
We are a processor for everything your agents handle on your behalf, the content of the emails, orders, tickets, records and documents they read and write in your systems, including personal data about your own customers, staff and suppliers. You are the controller of that data. You decide what your agents may access, what they do with it, and how long it is kept. We process it only to provide the service, on your instructions, and never for our own purposes.
Where we act as processor, our processing terms and, for Enterprise customers, a Data Processing Agreement, govern that relationship alongside this policy. Contact us for a copy.
Because you decide what your agents process, you are responsible for:
Oido is a business tool. It is not intended for personal use, and you must be at least 18 years old to hold an account.
Account data, collected at registration:
Platform data, generated while using Oido:
Credentials, stored with encryption:
Usage data, for reliability and improvement:
Where we act as controller, we rely on:
Oido connects your agents to AI providers and tools that you configure. Data flows only to services you explicitly connect:
No data is shared with Oido partners, advertisers, or data brokers.
To run the platform we use a small number of sub-processors, including our hosting and database provider, our email delivery provider, Stripe for payments, and Google for website analytics. Where you connect an AI provider or a third-party tool yourself, that provider processes data on your instruction; some act as independent controllers under their own terms, which is why you connect your own accounts.
A current list of sub-processors is available on request. We will give notice before adding a new sub-processor that processes customer content, and Enterprise customers may object under their Data Processing Agreement.
Transfers outside the EEA and UK. Some providers, in particular AI providers, operate outside the EEA and the UK. Where personal data is transferred, we rely on European Commission adequacy decisions where one exists, and otherwise on Standard Contractual Clauses, with the UK Addendum for UK transfers. If your rules require that data never leaves your own environment, Oido can be self-hosted on Enterprise, and your choice of AI provider and region remains yours.
We do not use your data to make automated decisions with legal or similarly significant effects about anyone. Agents you build can take actions automatically, but you decide what those actions are and which of them must stop and wait for a named person to approve. Where a decision affects an individual meaningfully, we strongly recommend keeping a human approval step, and the platform supports this on any action.
All data, agents, sessions, credentials, conversations, extensions, is stored isolated per organisation. One organisation cannot access another's data. We enforce this at the database layer with organisation-scoped queries and at the execution layer with per-org sandboxed environments.
The Oido Browser Connector is an optional Chrome extension that lets an agent operate a browser tab on your machine, using sessions you are already logged in to. It does nothing unless you install it and paste in a connector token. This section describes its data handling specifically.
Stored only in your browser, never transmitted to us except as described below:
What the extension can and cannot see:
Limits you control: the agent can only reach origins on your allowlist, and each task is pinned to the first site it opens, so a single task cannot move between sites. The connector token is scoped to the Connected Browser channel and cannot be used anywhere else in your Oido account.
Removal: uninstalling the extension deletes everything it stored, including the connector token. Tokens can also be left to expire; they are valid for 30 days.
Depending on your jurisdiction, you have rights including:
To exercise any of these rights, email contact@oidostudio.com. We respond within one month, and may extend by a further two months for complex requests, in which case we will tell you within the first month.
If you are an employee, customer or supplier of a business that uses Oido, and your data was processed by that business's agents, please contact that business directly. They are the controller of that data. If you contact us instead, we will pass the request to them and support them in answering it.
You also have the right to complain to a data protection supervisory authority in the country where you live or work, or where you believe the issue arose. We would ask you to raise it with us first so we can try to put it right.
If a breach affects personal data we hold as controller, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, and we will tell affected users where the law requires it. Where we act as processor for your agents' data, we will notify you without undue delay after becoming aware, with the information you need to meet your own obligations as controller.
This section previously stated that we used no analytics or advertising cookies. That was inaccurate: our public website uses Google Analytics 4 and Google Ads conversion measurement. The description below is what actually runs.
Inside the product (app.oidostudio.com and your workspace): only functional cookies required for authentication and session handling. No analytics or advertising cookies are set in the product.
On our public website:
Until you accept, these tools are loaded in a consent-denied state and set no analytics or advertising cookies. You can change your choice at any time by clearing site data in your browser, which resets the banner. Clearing cookies inside the product will log you out.
We do not use pixel tracking from social networks, and we do not sell or share your data with advertisers or data brokers.
See our Security page for a full description of the technical and organisational measures we use to protect your data, including encryption standards, access controls, and incident response procedures.
We will notify you of material changes via email and in-app notice at least 14 days before changes take effect. Continued use after the effective date constitutes acceptance. We maintain a changelog of this policy on request.
Oido Systems operates Oido Studio and is the controller for the data described in section 1a. For privacy questions, data requests, a copy of our sub-processor list, or a Data Processing Agreement: contact@oidostudio.com.
For general enquiries: contact@oidostudio.com.