Privacy Policy
Last updated: March 30, 2026 · Effective: March 30, 2026
This Privacy Policy explains how Owla (“Owla”, “we”, “us”, or “our”) collects, uses, and protects information when you use our platform. We are committed to transparency — if you have questions, contact us at privacy@owla.ai.
1. Who We Are
Owla is an AI Search OS for B2B brands. We help companies monitor and improve their visibility across AI-powered search engines including ChatGPT, Gemini, Perplexity, Claude, and Grok. Our platform is provided by Owla (“Company”), accessible at owla.ai.
2. Information We Collect
2.1 Account Information
When you sign up or log in, we collect:
- Name and email address
- Company name and website
- Password (stored hashed — we never see it in plaintext)
- Authentication tokens when using Google Sign-In
2.2 Brand & Configuration Data
To run AI visibility monitoring, you provide:
- Your brand name, product description, and target keywords
- Competitor names and domains you want tracked
- Brand facts (pricing, features, claims) used to evaluate AI responses
2.3 Usage Data
We automatically collect technical data when you use the platform:
- Pages viewed, features used, and actions taken
- Browser type, operating system, and IP address
- Session duration and navigation patterns
- Error logs and performance metrics
2.4 AI Engine Data
Our background engine (Owla Engine) sends queries to third-party AI search engines on your behalf to monitor how those engines respond when asked about your brand. We store:
- Queries sent to AI engines
- Raw AI responses received
- Computed visibility scores and analysis results
- Historical snapshots to enable trend tracking
3. How We Use Your Information
- Deliver the service — run AI visibility scans, generate reports, and populate your dashboard
- Authenticate you — manage sessions and access control
- Improve the platform — analyze usage patterns to fix bugs and build features
- Communicate with you — send product updates, alerts, and support responses
- Billing & operations — process payments, enforce plan limits, prevent abuse
- Legal compliance — respond to lawful requests and enforce our Terms
We do not sell your personal data to third parties. We do not use your brand data to train AI models.
4. Data Sharing
We share data only in limited circumstances:
- Infrastructure providers — Supabase (database hosting), Vercel (application hosting). These providers act as data processors under our instruction.
- AI search engines — queries are sent to ChatGPT, Gemini, Perplexity, Claude, and Grok APIs. These are anonymized brand monitoring queries, not linked to individual user identities.
- Analytics tools — aggregated, anonymized usage data may be shared with analytics providers.
- Legal requirements — if required by law, court order, or to protect rights and safety.
- Business transfers — in the event of a merger or acquisition, data may transfer to the successor entity. We will notify you before this occurs.
5. Data Retention
We retain your data for as long as your account is active. Specifically:
- Account data — kept until you delete your account
- AI scan history — retained for up to 24 months to enable trend analysis
- Billing records — retained for 7 years as required by applicable law
- Deleted accounts — personal data is purged within 30 days of account deletion, except where legal retention obligations apply
6. Security
We implement industry-standard safeguards including:
- Encryption in transit (TLS 1.2+) and at rest
- Hashed password storage (bcrypt)
- Row-level security policies in our database
- Access controls limiting who on our team can access production data
No system is 100% secure. If you discover a vulnerability, please disclose it responsibly at security@owla.ai.
7. Your Rights
Depending on your location, you may have the right to:
- Access — request a copy of data we hold about you
- Correction — correct inaccurate personal data
- Deletion — request deletion of your account and associated data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request we limit processing in certain circumstances
To exercise any right, email privacy@owla.ai. We will respond within 30 days.
8. Cookies
We use cookies and similar technologies to:
- Keep you logged in (session cookies)
- Remember your preferences (locale, theme)
- Measure platform usage (analytics cookies)
You can control cookies via your browser settings. Disabling essential cookies will prevent login and core features from working.
9. Children's Privacy
Owla is a B2B platform not directed at individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it promptly.
10. International Transfers
Our infrastructure is primarily hosted in the United States via Supabase and Vercel. If you access Owla from the European Economic Area (EEA) or other regions with data transfer restrictions, your data may be transferred internationally. We rely on standard contractual clauses and other legal mechanisms to ensure compliant transfers.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we do, we will update the “Last updated” date at the top. For material changes, we will notify you by email or in-app notification at least 14 days before they take effect.
12. Contact
For privacy-related questions or requests:
- Email: privacy@owla.ai
- Website: owla.ai