Privacy Policy
Last updated: 18 August 2026.
1. Data we process
- Account data: your name, work email, company, password hash, and team/permission settings.
- Campaign data: lead lists you upload (contact name, email, company, and any custom columns you provide), templates, message content, and sending configuration.
- Operational data: message send, delivery, bounce, complaint, unsubscribe and reply events; mailbox, domain and placement health; support records; and security/audit logs.
- Public-site data: standard request logs needed to serve and protect the site. If you allow optional marketing analytics, the additional public-page data described in section 6 is also processed.
2. How we use it
We use data to operate and secure 1OAKS: authenticate users, render and send campaigns, manage replies and deliverability, enforce suppression and unsubscribe choices, provide support, prevent abuse, monitor errors, administer billing, and provide optional features you choose to use. We do not offer your uploaded lead lists for sale.
3. Service providers
Depending on the feature and production configuration, 1OAKS uses these provider categories and services:
- Hosting and backups: Microsoft Azure.
- Mailbox connection and email operations: Microsoft 365 and Microsoft Graph for connected mailboxes, and Twilio SendGrid for email delivery and delivery/reply events.
- DNS and bot protection: Cloudflare, including DNS setup and Turnstile on protected public forms.
- Deliverability and address checks: Google Postmaster Tools when connected, plus the configured verification provider (Kickbox, ZeroBounce, MailerCheck, or Bouncer) when real address verification is enabled.
- Error monitoring: Sentry when configured, for technical error and diagnostic context.
- Payments: Stripe when paid billing is enabled; Stripe handles payment details used for checkout and billing management.
- Optional AI and marketing analytics: OpenAI, Ahrefs Web Analytics, and Impact.com as described below.
4. Your leads
You are the controller of the lead data you upload. You are responsible for having a lawful basis to process and contact those individuals. We process it as your processor to deliver your campaigns and honor unsubscribe and suppression signals.
5. Optional AI assistance
AI assistance is optional. When a signed-in user asks 1OAKS to create a campaign plan, generate campaign copy, or draft a reply, we send the instructions and relevant context needed for that request to the OpenAI API. Depending on the feature, that context may include campaign and lead fields, message text, or text from a public website the user supplied. Manually written campaigns do not require this generation step. Avoid placing unnecessary sensitive information in AI prompts or source fields, and review generated output before using it.
6. Optional public-page analytics and your choice
Optional marketing analytics are off by default. Even when 1OAKS enables the feature in production, Ahrefs and Impact.com scripts do not load until you choose Allow optional analytics. Choosing Continue without analytics keeps those scripts off. Your browser stores only that choice—allow or decline—in local storage; it does not store your name, email, or a choice timestamp.
- Ahrefs Web Analytics: aggregate public-page usage, such as page URL, referrer, browser/device and language information, general location derived from the request IP, and page, link or form interactions.
- Impact.com: partner/referral attribution and link/impression measurement. Impact.com may process referral and interaction data, IP/browser/device information, and cookies or similar identifiers used for attribution.
These provider scripts are limited to the home, resources, Brief, checklist, and public tools pages. They do not load on sign-in, sign-up, password reset, setup, account, unsubscribe, or authenticated application pages. Use the Privacy choices button on an eligible public page to change your choice. Changing from allowed to off reloads the page so already-loaded provider code stops. Clearing this site's browser data also clears the saved choice. This choice does not turn off essential session, security, or service operations.
7. Retention & deletion
We retain account and campaign data for the life of your account, subject to operational, security and legal retention needs. Email [email protected] to request export or deletion of your tenant's data.
8. Security
Passwords are hashed, sessions are signed, state-changing requests are CSRF-protected, and admin access requires MFA. No system is perfectly secure; report concerns to [email protected].
9. Contact
Privacy questions: [email protected].