Privacy Policy
The bot only sees the groups you add it to. Reading a conversation is how a recommendation happens at all, so this page is specific about what is read, what is kept, and what is thrown away.
Last updated 25 September 2026
1.Who is responsible for what
For your account and billing details, Oak Network is the data controller. For the message content in your community, you are the controller and we act as your processor — you decided to add the bot, and you are the one who must tell your members it is there.
2.What we collect
- Account — your email address, a hashed password or a Google sign-in identifier, and the workspace and members you create.
- Billing — plan, subscription status and usage counts. Card details go directly to Stripe and never reach our servers.
- Community messages — the content of messages in the channels you add the bot to, processed as described in section 3.
- Click events — when a member follows a recommendation link, we record that the click happened so your dashboard can show it. We cannot see what they went on to buy.
We never collect phone numbers. The bot cannot read direct messages, and it cannot see any group or server it has not been added to.
3.What we keep, and for how long
4.Who else processes it
We use a small number of providers to run the service. Each receives only what it needs, and none of them is permitted to use your data for their own purposes:
- Anthropic and Google — the models that read a message and decide whether to answer, and the embeddings used to match products. Message excerpts are sent for inference and are not used to train models.
- Stripe — subscriptions, cards and invoices.
- Amazon Web Services — hosting, and the transactional email we send you.
- Rainforest API — public Amazon product data. No message content is sent to it, only search terms.
- Telegram and Discord — the platforms your community is already on, governed by their own policies.
Some of these process data outside your country, including in the United States. We do not sell your data or your members’ data, and we never have.
5.Your rights
You may ask us for a copy of your data, ask us to correct it, or ask us to delete it. Deleting a workspace removes its intents, excerpts, member hashes and click events; we keep the invoice records that tax law requires us to keep.
If you are in the UK or EU you also have the right to object to processing and to complain to your data protection authority. To exercise any of this, email goodsbridge@oaknetwork.org and we will respond within 30 days.
6.Cookies
Three cookies are always on and need no consent: the one that keeps you signed in, the one that protects sign-in forms against cross-site request forgery, and gb_consent, which only remembers what you answered in the cookie banner so we do not ask again. It holds the word “granted” or “denied”, nothing about you, and expires after six months.
One thing is optional: the Meta Pixel, which tells us when an ad on Meta’s platforms brought you here and which pages you then visited, so we can see which ads work. It is off until you choose Accept in the banner. If you accept, Meta Platforms sets its own cookie in your browser and receives the pages you view here and the events described above; Meta’s use of that data is governed by Meta’s privacy policy. There is no other analytics or advertising tracking on this site.
You can change your answer at any time from “Cookie preferences” in the footer of every page. Declining later stops any further events; clearing your browser’s cookies for this site removes what Meta set.
7.Changes
If we change what we collect or how long we keep it, we will update this page and, for a material change, email you before it takes effect. Questions: goodsbridge@oaknetwork.org.