Privacy Policy
Who controls your data
Justas Raudonius, operating Okapi as an individual business activity in Lithuania, is the controller for personal data described in this policy. Customers control the event, log, and user data they choose to send to Okapi Cloud; Okapi processes that customer content to provide the service.
Information we collect
For website requests, we may receive technical data such as IP address, user agent, requested URL, and timestamp in short-lived operational and security logs. We do not use advertising trackers at launch.
For an Okapi account, we process identifiers and settings such as your name, email address, authentication and session records, organization membership, plan, usage, support messages, and administrative audit events.
Okapi Cloud processes the error events, logs, releases, source maps, project details, and related content that customers submit. Self-hosted product data stays in the operator’s infrastructure; limited license and update-check data is described in our Telemetry disclosure.
Launch waitlist
When you join the Okapi launch waitlist, we collect your email address, the source page where you joined, and a keyed hash of your IP address. We do not store the raw IP address.
We use the email address for one launch notification. Joining the waitlist is not a general marketing subscription.
How we use information
We use personal data to provide and secure Okapi, authenticate users, process customer instructions, measure plan usage, support customers, prevent abuse, maintain records, communicate service changes, and meet legal obligations.
Depending on the context, processing is necessary to perform a contract, comply with law, pursue legitimate interests such as service security and improvement, or act on consent that you may withdraw.
Payments
Paddle is the merchant of record and collects billing and payment details at checkout. Okapi receives transaction, customer, product, subscription, amount, tax, and payment-status information needed to provision and support purchases, but does not receive full card details. Paddle processes personal data under its own privacy policy.
Service providers
We use providers for hosting, content delivery and security, source and deployment infrastructure, payment processing, and customer communication. They may process personal data only for their contracted purpose and subject to applicable safeguards.
When data is transferred outside the European Economic Area, we rely on an applicable legal transfer mechanism provided by the recipient or otherwise required by law.
Retention and deletion
The waitlist IP hash is cleared after 30 days. Local waitlist entries are deleted 90 days after general availability unless you request deletion sooner.
Account and service records are kept while needed to provide Okapi and for a reasonable period afterward for security, disputes, and legal obligations. Cloud customer content follows the configured retention period and customer deletion actions; backup copies age out through the backup-retention cycle. Payment and tax records are retained as legally required.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent without affecting earlier lawful processing and may complain to your local data-protection authority.
For customer content, contact the organization that controls the Okapi project first. We will assist that customer with valid requests where required.
Contact
To exercise a privacy right or ask a question, email useokapi@gmail.com. We may ask for enough information to verify your identity and locate the relevant data.