Legal

Privacy Policy

What we collect, why we hold it, who else sees it, and how long it stays. Analytics runs on the marketing site alone and only with your permission, we run no advertising trackers anywhere, and we do not train models on your content.

Last updated

1Who we are, and which hat we wear

Octri, LLC, [Registered address to be confirmed before launch], operates Octri. This policy explains what we do with personal data across the marketing site, the dashboard, the documentation sites we host, and our API.

Two different relationships run through the product, and the difference matters:

  • We are the controller for data about our own customers: the people who hold Octri accounts, their organisations, and how they use the dashboard. This policy covers that data.
  • We are a processor for the content you put into Octri: your specs, your documentation, the questions your readers ask your docs, and everything your application sends to monitoring. You decide what goes in and why. We act on your instructions. If you are a reader of a documentation site hosted on Octri, the company whose docs you are reading is the controller, and their privacy policy governs, not this one. See section 9.

For questions about either role, write to support@octri.dev.

2What we collect

When you create an account

  • Your name, email address and profile picture URL.
  • A hash of your password, if you signed up with one. We never store the password itself.
  • Your Google or GitHub user id, if you signed in with one of those. We do not receive your password from them.
  • Whether you have verified your email address.
  • If you turn on two-factor authentication: an encrypted authenticator secret and hashes of your recovery codes. The secret is encrypted with AES-256-GCM and is never returned by the API.
  • How you found us: the UTM parameters, referring site and landing page recorded once at signup. We use it to understand which channels work.

About your organisation

  • Organisation name, plan, limits, and the SDK languages you have active.
  • Member list with roles, permissions and per-project access, plus pending invitations.
  • Credit balances, usage counters and AI token totals used for metering and billing.
  • Your subscription and customer references from Paddle. Card numbers never reach our servers.
  • If you configure SAML single sign-on: your identity provider’s entity ID, sign-on URL, signing certificate, allowed email domains and attribute mapping.

Content you put into the product

  • OpenAPI specs, generated and hand-written documentation, guides, custom components, custom code, logos and branding.
  • Vector embeddings of your documentation pages, used to answer Ask-the-docs questions.
  • Connection details for the services you link: GitHub installations and repositories, package registry accounts, and custom domain configuration. Webhook URLs are encrypted at rest.

When you use the service

  • A security audit log: what happened, who did it, their email address, the IP address and browser user agent, and whether it succeeded.
  • Server logs and rate-limit counters, which include IP addresses, for security and debugging.
  • Records of transactional emails we sent you, so we can tell whether a password reset or an invite actually arrived.

From your documentation sites

  • Page views: which page, and when. We do not store an IP address, a user agent or a visitor identifier against a page view.
  • Feedback votes: whether a page was marked helpful.
  • Ask-the-docs conversations:the question, our answer, the pages cited, and a random visitor id kept in the reader’s browser so a conversation holds together. The id is not linked to a name or an email. These are deleted after 7 days.

From your application, through monitoring

Monitoring stores what your application chooses to send: errors and stack traces, logs, traces and spans, performance data, release markers and uptime check results. That payload is under your control and can contain personal data about your own users if you put it there. Configure your instrumentation to strip what you do not need.

On the marketing site

If you subscribe to the newsletter we keep your email address until you unsubscribe. This site can also run Google Analytics 4, loaded through Google Tag Manager, and only for visitors who allow the analytics category — for everyone else it is absent from the page, and it is absent from the dashboard and from hosted documentation sites for everyone. We run no advertising or cross-site tracking scripts on any Octri surface. See the Cookie Policy.

3Why we use it

  • To run the service: authenticate you, enforce permissions, generate docs and SDKs, host your documentation, and meter what you use. Legal basis: performance of our contract with you.
  • To bill you: apply plan limits, charge subscriptions and credit packs through Paddle, and issue receipts. Legal basis: contract, and legal obligation for tax records.
  • To keep the platform secure: audit logging, rate limiting, fraud and abuse detection. Legal basis: our legitimate interest in protecting the service and our customers.
  • To support you: answer tickets, investigate faults, and tell you about incidents, expiring credits or failed payments. Legal basis: contract, and legitimate interest.
  • To improve the product: aggregate usage figures showing which features get used. Legal basis: legitimate interest. We use aggregates, not individual behaviour profiles.
  • To market to you: product news and the newsletter, only where you opted in or where a soft opt-in applies to existing customers. Legal basis: consent or legitimate interest. Every message has an unsubscribe link.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not make automated decisions with a legal or similarly significant effect on you.

4What we send to AI providers

Three features send data outside our infrastructure:

  • Documentation generation. The relevant portion of your OpenAPI spec goes to our language-model provider, which returns the prose.
  • Ask the docs.The reader’s question and the matching passages from your documentation go to the model provider, which returns the answer.
  • Search indexing. Your documentation text goes to an embedding provider, which returns the vectors we store and search against.

Our providers are named on the subprocessors page. They process this traffic under commercial API terms that prohibit training on it. Neither they nor we train models on your content.

Account data, billing data and monitoring payloads are not sent to model providers.

5Who we share it with

We share personal data with four groups, and no others:

  • Our subprocessors, who process data on our behalf under contract. The full list, what each one does and where it operates, is on the subprocessors page. We keep that page current and will give notice before adding a subprocessor that handles customer data.
  • Services you connect yourself, such as GitHub or a package registry. Data goes there because you asked for it, on your credentials.
  • Professional advisers, such as auditors and lawyers, bound by confidentiality.
  • Authorities, where the law requires it. We check that a request is valid and narrow, and we tell you unless we are legally prohibited from doing so.

If Octri is ever acquired or merged, account data transfers with the business. You will be told before that happens and before any change to this policy takes effect.

6How long we keep it

Most of these limits are enforced by the database itself, so the data expires whether or not anyone remembers to clear it.

DataKept forNotes
Account and organisation recordsWhile the account existsErased within 30 days of closing the organisation or asking us to.
Projects, specs, docs, componentsWhile the project existsDeleting the project removes all of it immediately.
Security audit log365 daysSign-ins, permission changes, billing events. Deleted automatically.
Documentation page views365 daysPage and timestamp only. No IP address, no user agent, no visitor id.
Documentation feedback votes365 daysHelpful / not helpful, per page.
Ask-the-docs chat sessions7 daysQuestions, answers and the anonymous visitor id, then deleted.
Webhook delivery log3 daysRequest and response metadata for the webhooks you configured.
Sign-in sessions30 days from issueRefresh tokens expire and are removed. Revoking a session ends it sooner.
Monitoring events7 to 365 days by planErrors, logs, traces and checks sent by your application. Aggregate rollups outlive them.
Billing recordsAs required by tax lawHeld by Paddle as merchant of record; we keep subscription references.

Deleting a project removes its specs, documentation, analytics, chat sessions, changelog, components, webhooks and generated SDK artifacts straight away. Closing an organisation, or asking us to erase everything we hold for you, is completed within 30 days, and monitoring data is removed on the same request. Backups roll off on their own cycle inside that window. We keep the minimum needed for tax, accounting and dispute records afterwards, which is billing data rather than your content. The commitment is set out in section 12 of the DPA.

7How we protect it

Traffic is encrypted in transit with TLS. Passwords are hashed. Authenticator secrets and stored webhook URLs are encrypted at rest with AES-256-GCM. API keys are stored hashed, can carry an expiry, and can be revoked. Access inside an organisation is governed by roles and per-project permissions, and privileged actions land in an audit log you can read.

Full detail, plus how to report a vulnerability, is on the security page.

8Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent. If you are in the EEA or the UK these come from the GDPR. If you are in California they come from the CCPA as amended, which also gives you a right not to be discriminated against for exercising them.

Much of this you can do yourself:

  • Update your name, email and profile picture in account settings.
  • See and revoke active sessions, and manage two-factor authentication, under security.
  • Read your organisation’s audit log.
  • Export your specs and generated SDKs from the dashboard.
  • Delete a project, or delete the whole organisation, from its settings.

For anything else, email support@octri.dev. We respond within 30 days and will tell you if we need longer. We may ask you to confirm your identity before acting on a request.

If you are unhappy with our response you can complain to your local data protection authority. In the UK that is the Information Commissioner’s Office.

If your data is in Octri because a customer of ours put it there, send your request to them. We will pass on any request that reaches us and support them in answering it.

9If you are reading someone’s docs

Documentation sites hosted on Octri belong to our customers. When you read one, here is everything that happens:

  • A page view is recorded: the page and the time. No IP address, no user agent and no identifier are stored with it.
  • If you vote on whether a page helped, that vote is recorded against the page.
  • If you use the chat, your question and the answer are stored for 7 days along with a random id held in your browser, then deleted.
  • If the site is password-protected or behind SSO, a session cookie is set so you do not have to unlock it on every page.
  • Layout preferences, such as sidebar width, are kept in your browser and never sent to us.

The site owner decides what is published and can see the analytics above. For anything else, contact them. Their privacy policy governs their site.

10International transfers

Octri is operated from the United States and our subprocessors operate in the United States and the European Economic Area. Where personal data moves out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described above. The location of each subprocessor is listed on the subprocessors page.

11Children

Octri is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email support@octri.dev and we will delete it.

12Changes to this policy

We will post any update here and change the date at the top. For material changes we email account owners at least 30 days before the new version takes effect, and we will ask for consent again where the law requires it.

13Contact

Octri, LLC
[Registered address to be confirmed before launch]

Privacy: support@octri.dev
Security: founders@octri.dev
Everything else: support@octri.dev

Our processor terms are published in full as the Data Processing Agreement. It is pre-signed and already in force for every customer, so there is nothing to countersign. If your procurement process needs a countersigned copy naming your entity, write to founders@octri.dev.