Last Updated: March 24, 2026
oakallow is built by Islemonics Studios LLC. We are committed to protecting your privacy and being transparent about how we handle your data. We collect only what is necessary to provide our API service and never sell your personal information.
oakallow provides a hosted API for governing AI agent tool execution: permissions, approvals, tokens, and audit trails. This Privacy Policy describes how we collect, use, and protect information when you use our services, visit our website, or interact with our API.
By creating an account or using our API, you agree to the collection and use of information as described in this policy.
When you create an account, we collect your name and email address. We use Supabase Authentication to manage your login credentials securely. Passwords are hashed and never stored in plain text.
Payment processing is handled entirely by Stripe. We store your Stripe customer ID for linking purchases but never store credit card numbers, CVVs, or full card details on our servers.
We log API requests for billing, debugging, and security purposes. This includes: API key prefix (not the full key), endpoint called, permission check results, execution logs, timestamps, and IP addresses. Tool parameters submitted during permission checks are processed but not permanently stored beyond the execution log retention period.
When you contact support or submit feedback, we collect the content of your message, your email, and any screenshots you attach. This data is used to resolve your inquiry and improve our service.
We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising purposes.
oakallow processes permission check requests, tool definitions, approval workflows, and execution logs on your behalf. This data belongs to you. We act as a data processor, not a data controller, for the tool and permission data you submit through the API.
Permission resolution happens at the edge (Cloudflare Workers) for speed. Permission rules are stored in Cloudflare D1 and Supabase. Tool definitions, approval requests, and execution logs are stored in Supabase.
We use the following third-party services to operate oakallow:
Each provider has their own privacy policy. We select providers with strong security practices and data handling commitments.
Account data is retained as long as your account is active. If you delete your account, we will remove your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records).
API execution logs and permission check logs are retained according to your plan. You can request deletion of your data at any time by contacting us.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us at privacy@oakallow.io. We will respond within 30 days.
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. Continued use of the service after changes constitutes acceptance of the updated policy.
Business Address
Islemonics Studios LLC
3020 Bernal Ave Ste 1103014
Pleasanton, CA 94566
Privacy Inquiries
privacy@oakallow.ioGeneral Inquiries
hello@oakallow.io