Privacy Policy · U.S. & International · Windows
OKEight Privacy Policy (Windows)
1. Information we collect
1.1 You provide
- Account: email address, third-party account identifier, and auth tokens used at sign-in.
- Connector authorization: OAuth tokens and connection status when you connect Gmail, Slack, and similar channels.
- Payment: transaction information handled by our payment processor when you buy or subscribe (we do not store full card numbers).
- Feedback you submit: your optional note, a bounded structured diagnostic timeline, and any generated reply, conversation excerpt, transcript, counterpart information, or screenshot that you separately preview and choose to include.
1.2 Processed transiently to draft a reply
- Conversation context: conversation text visible in the current window on your trigger, your instruction, and the local tone/profile memory needed for the reply.
- Screenshots (fallback): an in-memory, cropped image of the current conversation area when Accessibility can't read it (discarded after local OCR).
- Voice: audio while you hold to talk, streamed for cloud speech recognition (see Section 4; the raw recording is not kept by OKEight).
1.3 Collected automatically
Anonymous product metrics: event names, enums, counts, app version, OS version, an anonymous install id, and an optional signed-in user id. Excludes message bodies, drafts, recipient names, screenshots, and raw audio.
2. What stays on your device
OKEight's live read starts locally: Windows accessibility interfaces (UI Automation) read the current window's visible text; screenshots are handled in memory; OCR runs first on-device via a bundled local OCR model. Your tone profile, personal profile, person cards, reply events, learned corrections, and usage counts are stored locally in the app's data folder. You can view them, open the data folder, or clear them any time in Settings. Diagnostic traces also stay on your device unless you actively submit a feedback report; the submission screen shows the exact structured diagnostics and optional content you selected to send.
3. How we use information
- Provide and operate OKEight — read the current conversation on your trigger and draft replies in your voice.
- Authenticate you, meter usage, and enforce quotas.
- Maintain security, prevent abuse and fraud, and debug technical issues.
- Improve the product using anonymous metrics.
- Investigate a problem you deliberately report and track its resolution in our internal issue system.
We do not train foundation models on your conversations, and OKEight's product metrics never include message content. When you use a model (managed or your own key), the model provider processes the content under its own policy.
4. Screenshots, OCR & voice
Screenshots are only for apps accessibility interfaces can't read; OKEight crops to the conversation area, runs OCR on-device first, and discards the image. Only if OCR is insufficient may a vision-capable model receive it for transcription. Raw hold-to-talk audio is not stored by OKEight; on Windows, dictation uses cloud speech recognition — audio is streamed through our relay to the speech provider selected in Settings (Volcengine “Doubao” or Alibaba Cloud), which returns the transcript and processes the audio under its own policy.
5. Service providers we share with
We share only what is necessary, with providers acting as our processors or as independent controllers you direct data to:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk, Inc. | Sign-in & authentication | Email, login identifier, auth tokens |
| Cloudflare / Vercel | Hosting & the model proxy (stateless forwarding) | Conversation context & instruction (not logged by design) |
| Anthropic, Google (Gemini), OpenRouter, and any provider you choose | Draft / rewrite replies, distill memory, vision transcription | Conversation context & instruction needed for the task |
| Composio, Inc. | Managed connectors (Gmail / Slack / Google Chat) auth, status & read/write | Connector OAuth tokens, message payload you asked to process |
| Volcengine (Doubao) / Alibaba Cloud | Cloud speech recognition for hold-to-talk dictation | Voice audio (not retained by OKEight) |
| Analytics backend | Anonymous product metrics | Event names, enums, counts, versions, anonymous install id |
| Meta Platforms, Inc. | Ad measurement on the okeight.ai marketing site only (Meta Pixel; never inside the app) | Page views, download clicks, ad click id, cookie identifiers set by Meta |
| Linear | Internal triage of feedback you actively submit | Issue category, your note, app/system metadata, bounded diagnostic timeline, and a protected report link |
| Supabase | Access-controlled, short-term feedback delivery and private review storage | Your feedback note, bounded structured diagnostics, selected generated reply or conversation/transcript excerpt, counterpart information, and screenshot |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may disclose information if required by law or to protect rights and safety.
Google user data (Limited Use). OKEight's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Chat data you authorize (spaces, messages, and memberships) is used only to provide the features you enabled — surfacing conversations awaiting your reply and learning your own writing tone to draft replies for you. We do not sell it, use it for advertising, or transfer it to others except as needed to provide the feature (e.g. the managed connector above), to comply with law, or in a merger. No human reads your Google data except with your consent, for security, to comply with law, or in aggregated or anonymized form.
6. Your choices & controls
- Use your own model key so requests never pass through our servers.
- Turn off learning from your sent messages; opt out of anonymous product metrics.
- Open your local data folder; clear reply history and learned memory in Settings.
- Before sending feedback, review and remove every optional content attachment. Feedback is never submitted automatically.
7. U.S. state privacy rights (incl. California)
Depending on your state (e.g. California/CCPA, and similar laws in Virginia, Colorado, Connecticut, Utah, and others), you may have the right to: know/access the personal information we hold; delete it; correct it; obtain a portable copy; and opt out of sale/sharing or targeted advertising. As noted above, we do not sell or share personal information for cross-context behavioral advertising.
We honor opt-out preference signals such as Global Privacy Control (GPC) where applicable. You will not be discriminated against for exercising your rights. To make a request, contact support@amplift.ai; we may need to verify your identity.
8. International users & transfers
OKEight is operated from the United States, and our providers are largely U.S.-based; using OKEight involves transferring your information to the United States and other countries. Where required (e.g. for EEA/UK users), we rely on appropriate safeguards such as Standard Contractual Clauses. Payment for some regions may be processed by an affiliated entity; where that applies, the payment page will identify the processing entity.
9. Retention & security
Local data stays on your device until you delete it or uninstall. A submitted feedback report may remain in an encrypted local outbox for up to seven days while delivery is retried. The complete live Supabase feedback record, including its copy of your note, bounded structured diagnostics, and any selected private content, becomes inaccessible after 14 days and is scrubbed from live storage within 24 hours; encrypted provider backups may remain recoverable for up to seven additional days. The full delivery row is removed by 30 days. A minimal, long-lived anti-duplicate record retains only the random report ID, account-bound owner, terminal result or error, and any Linear receipt; it contains no note, diagnostics, environment data, or attachment reference and exists only to prevent report-ID takeover and duplicate Linear issues. The safe Linear issue summary is retained for support, security, and product-quality records until it is no longer needed or you request deletion where applicable. Account and connection status are kept while you use OKEight and deleted or anonymized within a reasonable period after account closure, unless the law requires otherwise. We use transport encryption, access controls, encryption at rest, and encrypted token storage (Windows DPAPI). No assistant that must send context to an external AI model can claim 100% local privacy.
10. Children
OKEight is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child provided us information, contact us and we will delete it.
11. Changes & contact
We may update this policy periodically; material changes will be notified in-app or on the website. This policy is part of, and subject to, the OKEight Terms of Service for Windows (U.S. & International); if they conflict, the Terms control.
Controller: Ampliftai Inc.
Privacy requests: support@amplift.ai · Support: support@amplift.ai
© 2026 Ampliftai Inc. · Last updated July 27, 2026.