Legal

Privacy Policy

Last updated: March 30, 2026  ·  Effective: March 30, 2026

This Privacy Policy explains how Owla (“Owla”, “we”, “us”, or “our”) collects, uses, and protects information when you use our platform. We are committed to transparency — if you have questions, contact us at privacy@owla.ai.

1. Who We Are

Owla is an AI Search OS for B2B brands. We help companies monitor and improve their visibility across AI-powered search engines including ChatGPT, Gemini, Perplexity, Claude, and Grok. Our platform is provided by Owla (“Company”), accessible at owla.ai.

2. Information We Collect

2.1 Account Information

When you sign up or log in, we collect:

  • Name and email address
  • Company name and website
  • Password (stored hashed — we never see it in plaintext)
  • Authentication tokens when using Google Sign-In

2.2 Brand & Configuration Data

To run AI visibility monitoring, you provide:

  • Your brand name, product description, and target keywords
  • Competitor names and domains you want tracked
  • Brand facts (pricing, features, claims) used to evaluate AI responses

2.3 Usage Data

We automatically collect technical data when you use the platform:

  • Pages viewed, features used, and actions taken
  • Browser type, operating system, and IP address
  • Session duration and navigation patterns
  • Error logs and performance metrics

2.4 AI Engine Data

Our background engine (Owla Engine) sends queries to third-party AI search engines on your behalf to monitor how those engines respond when asked about your brand. We store:

  • Queries sent to AI engines
  • Raw AI responses received
  • Computed visibility scores and analysis results
  • Historical snapshots to enable trend tracking

3. How We Use Your Information

  • Deliver the service — run AI visibility scans, generate reports, and populate your dashboard
  • Authenticate you — manage sessions and access control
  • Improve the platform — analyze usage patterns to fix bugs and build features
  • Communicate with you — send product updates, alerts, and support responses
  • Billing & operations — process payments, enforce plan limits, prevent abuse
  • Legal compliance — respond to lawful requests and enforce our Terms

We do not sell your personal data to third parties. We do not use your brand data to train AI models.

4. Data Sharing

We share data only in limited circumstances:

  • Infrastructure providers — Supabase (database hosting), Vercel (application hosting). These providers act as data processors under our instruction.
  • AI search engines — queries are sent to ChatGPT, Gemini, Perplexity, Claude, and Grok APIs. These are anonymized brand monitoring queries, not linked to individual user identities.
  • Analytics tools — aggregated, anonymized usage data may be shared with analytics providers.
  • Legal requirements — if required by law, court order, or to protect rights and safety.
  • Business transfers — in the event of a merger or acquisition, data may transfer to the successor entity. We will notify you before this occurs.

5. Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account data — kept until you delete your account
  • AI scan history — retained for up to 24 months to enable trend analysis
  • Billing records — retained for 7 years as required by applicable law
  • Deleted accounts — personal data is purged within 30 days of account deletion, except where legal retention obligations apply

6. Security

We implement industry-standard safeguards including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Hashed password storage (bcrypt)
  • Row-level security policies in our database
  • Access controls limiting who on our team can access production data

No system is 100% secure. If you discover a vulnerability, please disclose it responsibly at security@owla.ai.

7. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of data we hold about you
  • Correction — correct inaccurate personal data
  • Deletion — request deletion of your account and associated data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Restriction — request we limit processing in certain circumstances

To exercise any right, email privacy@owla.ai. We will respond within 30 days.

8. Cookies

We use cookies and similar technologies to:

  • Keep you logged in (session cookies)
  • Remember your preferences (locale, theme)
  • Measure platform usage (analytics cookies)

You can control cookies via your browser settings. Disabling essential cookies will prevent login and core features from working.

9. Children's Privacy

Owla is a B2B platform not directed at individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it promptly.

10. International Transfers

Our infrastructure is primarily hosted in the United States via Supabase and Vercel. If you access Owla from the European Economic Area (EEA) or other regions with data transfer restrictions, your data may be transferred internationally. We rely on standard contractual clauses and other legal mechanisms to ensure compliant transfers.

11. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will update the “Last updated” date at the top. For material changes, we will notify you by email or in-app notification at least 14 days before they take effect.

12. Contact

For privacy-related questions or requests: