Trust & Security
Privacy overview
A plain-language summary of what Oconee Runtime collects and why. The Privacy Policy remains the governing document, and this page links to it throughout.
This overview is written for evaluation. It does not replace the Oconee Runtime Privacy Policy, which is the legally governing document and takes precedence where the two differ.
What we collect
Information categories
Grouped by why it exists, because that is the question a reviewer is actually asking.
Account information
Name, work email address, organization, and the role a user holds within it.
Why: To create and authenticate accounts, and to apply the right permissions.
Operational metadata
Which extensions and integrations are installed, their versions, and whether they are reporting.
Why: To keep the service working and to show an organization where coverage is missing.
Product and security event data
Records of AI activity that policy was evaluated against: what kind of action was attempted, against what kind of resource, in what context, and what decision was returned.
Why: This is the product. It is what makes AI activity reviewable and what an audit trail is built from.
Analytics data
Pseudonymous usage of the public marketing website, with IP anonymization enabled.
Why: To understand which pages help people evaluate the product.
Billing data
Subscription plan, billing contact, and payment status.
Why: To operate subscriptions. Card details are handled by our payment processor and are not stored by Oconee.
Support communications
Messages sent through the contact and support forms, and the email address they came from.
Why: To answer them.
Separation
These do not mix
The distinction that matters most in a vendor review is which of these ever meets the others. They do not.
Marketing analytics
Collected only on the public website. It is pseudonymous, IP-anonymized, and never joined to customer event data. The authenticated product does not send data to a third-party marketing analytics service.
Product and security telemetry
Collected inside the product to make governance decisions reviewable. It is scoped to the organization it belongs to and is not used for advertising or shared with marketing tools.
Customer data
Belongs to the customer's organization. It is not used to train AI models, is not sold, and is not made available to other organizations.
Billing data
Handled through our payment processor. Card numbers are transmitted to the processor directly and are not stored on Oconee systems.
No AI model training
Customer prompts, responses, repositories and organizational data are not used to train public or proprietary AI models.
Last updated: September 7, 2026