How your data is protected.
Before you connect anything, here's exactly what we do with it — in plain language. Every line maps to how oka actually works.
We never read your inbox
Connecting Google lets oka find your warm paths to investors. To do that, we read only the To, From, and Cc headers of your messages — who you've been in touch with. We never request or receive the content of your emails. The only Gmail permission we ask for is metadata, so there's no path in oka that can read an email body.
Your workspace is yours
Your pipeline, notes, matches, and the warm-path map we build for you belong to your workspace and are never shown to other customers. Every database read is scoped to your workspace before it runs, and our data access is written to fail closed: a query that lacks its workspace scope fails rather than returning someone else's data.
One thing is shared by design: the professional profile of an investor — their name, the fund they work at, their role, and their public LinkedIn — becomes part of oka's collaborative investor graph, so every founder benefits from an accurate map. Direct contact details you import — an investor's email address and phone number — are the exception: they stay private to your workspace and are never shared with other customers. See our privacy policy for the legal basis and how to object or request erasure.
Your tokens are encrypted
The access tokens that let oka talk to Google on your behalf are encrypted at rest with AES-256-GCM before they touch our database, and decrypted only in memory to make the calls you authorized.
You can leave in one click
From Settings → Your data you can disconnect Google (we revoke it at Google and delete the token), export everything we hold, or delete your account with a 7-day grace window. No support ticket, no waiting.
Want the full detail?
See our security page for how each guarantee is enforced, and our privacy policy for the legal bases and your rights. Questions go to privacy@getoka.ai.