Trust

Built to be trusted with your network.

Oka only works if you trust it with your relationships and your inbox. Every promise below maps to something in our code — not aspiration. When we can't yet claim something, we say so.

You stay in control.

Oka's AI finds and ranks investors, maps who can introduce you, drafts outreach, and keeps your pipeline moving. But it does the work in the open: nothing leaves Oka without you.

Outreach is never sent by Oka — the product only ever drafts, by design. An email is a draft until you send it. A pipeline update proposed by the AI is a suggestion until you accept it. You review before anything goes out, and you keep the final say on anything that matters.

We never read your emails

When you connect Google, we request a metadata-only Gmail scope. We read the To, From, and Cc headers of your messages to map who you've been in touch with and surface warm paths to funds. We never request or receive the content of your emails — not one word, not a subject line we don't need, no attachments.

This is enforced at the Google permission level: the only Gmail scope we ask for is metadata. There is no path in oka that can read an email body, because we never hold the permission to.

Workspace isolation, enforced on every query

Your funds, matches, intro paths, notes, and relationship graph are scoped to your workspace and never shared across customers. Every read from our database is scoped to your workspace in the application — the customer identifier is attached to the query before it runs, so a query can only return rows that belong to you.

We treat a missing scope as a failure, not a leak: our data access is written so that an unscoped query fails closed rather than returning another customer's data. No request in oka can cross from one workspace into another.

Access within your workspace is permission-based. Team members see only what their role allows, and the workspace owner controls who is in and what they can do.

Encrypted tokens and data in transit

Your Google access and refresh tokens are encrypted at rest with AES-256-GCM envelope encryption before they touch our database. They are decrypted only in memory, only to make the calls you've authorized, and are never exposed to the client.

Google access is per-user: tokens belong to the individual who granted them and are never shared across a workspace. One teammate connecting their inbox never gives the rest of the team access to it.

All data is encrypted in transit using TLS, and encrypted at rest by our infrastructure providers.

Your grants, your controls

From Settings → Your data you can disconnect Google in one click — we revoke the grant at Google and delete the stored token. You can export everything we hold about you, or delete your account outright. Account deletion runs with a 7-day grace window, so it stays reversible until then.

Nothing here is buried in a support queue. Revoke, export, and delete are one-click actions you run yourself, whenever you want.

Connectors stay in control of their network

When someone shares their network to open warm paths for a founder, they can see exactly what's shared — and nothing more than the connections that create an intro path. There is no hidden export of their contacts.

A connector can withdraw their network at any time. Once they do, their connections stop surfacing as intro paths and are removed from what oka holds. Sharing is always theirs to take back.

We don't sell your data

We use connection metadata only to map your network to relevant funds and surface warm intro paths. We do not sell your data, we do not use it for advertising, and inbox content is never used because we never receive it.

If you're an investor in our dataset and not an oka user, you can request removal at any time. Submit your email on our remove-my-data page and, once verified, we delete it and add a suppression tombstone so it can't be re-ingested.

What we don't yet claim

We're in closed beta and we'd rather under-promise. We do not currently hold a SOC 2 report, guarantee EU-only data residency, or publish an external penetration test. When those land, we'll say so here — not before.

Our sub-processors

We rely on a small set of trusted providers to run oka. Each one processes data only to deliver the service, under a data-processing agreement: an EU-hosted database and authentication provider, cloud hosting, AI processing, payment processing, transactional email, and error monitoring.

Our database and authentication run in the EU.

The full sub-processor list is available on request — email privacy@getoka.ai.

Reporting a vulnerability

If you believe you've found a security issue, we want to hear from you. Please email security@getoka.ai with details and we'll respond promptly. We appreciate responsible disclosure and will not pursue action against good-faith research.