Trust & Security

Privacy overview

A plain-language summary of what Oconee Runtime collects and why. The Privacy Policy remains the governing document, and this page links to it throughout.

This overview is written for evaluation. It does not replace the Oconee Runtime Privacy Policy, which is the legally governing document and takes precedence where the two differ.

What we collect

Information categories

Grouped by why it exists, because that is the question a reviewer is actually asking.

Account information

Name, work email address, organization, and the role a user holds within it.

Why: To create and authenticate accounts, and to apply the right permissions.

Operational metadata

Which extensions and integrations are installed, their versions, and whether they are reporting.

Why: To keep the service working and to show an organization where coverage is missing.

Product and security event data

Records of AI activity that policy was evaluated against: what kind of action was attempted, against what kind of resource, in what context, and what decision was returned.

Why: This is the product. It is what makes AI activity reviewable and what an audit trail is built from.

Analytics data

Pseudonymous usage of the public marketing website, with IP anonymization enabled.

Why: To understand which pages help people evaluate the product.

Billing data

Subscription plan, billing contact, and payment status.

Why: To operate subscriptions. Card details are handled by our payment processor and are not stored by Oconee.

Support communications

Messages sent through the contact and support forms, and the email address they came from.

Why: To answer them.

Separation

These do not mix

The distinction that matters most in a vendor review is which of these ever meets the others. They do not.

Marketing analytics

Collected only on the public website. It is pseudonymous, IP-anonymized, and never joined to customer event data. The authenticated product does not send data to a third-party marketing analytics service.

Product and security telemetry

Collected inside the product to make governance decisions reviewable. It is scoped to the organization it belongs to and is not used for advertising or shared with marketing tools.

Customer data

Belongs to the customer's organization. It is not used to train AI models, is not sold, and is not made available to other organizations.

Billing data

Handled through our payment processor. Card numbers are transmitted to the processor directly and are not stored on Oconee systems.

No AI model training

Customer prompts, responses, repositories and organizational data are not used to train public or proprietary AI models.

Read the full Privacy Policy

Last updated: September 7, 2026