Privacy notice
Last updated: August 28, 2026
Oakley stores the phone number and profile details needed to provide the service, message content and delivery records, saved memories and open loops, approved or pending actions, and limited operational history. Google access and refresh tokens are encrypted at rest. Completed onboarding task text is removed 7 days after completion. Oakley does not sell personal data.
Service providers and data use
- Spectrum carries iMessage and other supported messaging traffic. Oakley receives message content and provider delivery metadata through Spectrum.
- Anthropic receives the conversation context and relevant saved information needed to generate replies, extract durable memories and commitments, and create morning briefs.
- Voyage AI receives text selected for semantic embeddings so Oakley can retrieve relevant memories.
- Google receives OAuth and Gmail or Calendar requests when a user connects Google. Oakley reads only the authorized data needed for requested features and stores encrypted OAuth credentials. Deleting an account revokes the Google grant before removing the local credentials.
- Duffel receives flight-search criteria when a user asks for flight options. Oakley uses Duffel test mode and does not complete purchases.
Provider message payloads are minimized after 7 days. LLM and tool request/response logs are deleted after 30 days. Job and early-access delivery history and resolved approvals are deleted after 90 days. Message text and completed privacy requests are deleted after 365 days. Closed open loops are deleted after 365 days. Memories not used for 730 days are deleted. Waitlist records are deleted after 30 days and rate-limit counters after 2 days. Active memories, open loops, and pending privacy requests remain until no longer needed or the user requests deletion. Expired Google authorization states are removed automatically.
Oakley minimizes stored data by persisting only text needed for conversation and product features, stripping executable approval capabilities from model logs, excluding embedding vectors and OAuth tokens from exports, limiting Gmail bodies passed into the service, and using hashed, expiring Google authorization state.
Access, export, and deletion
Users may message Oakley with “export my data” or “delete my data.” Oakley creates a durable request for the operator. The operator tools require that matching request from the user’s existing messaging identity before they can create a complete JSON export or permanently delete the account and all user-linked records. Deletion also revokes and removes connected Google credentials. A minimal, non-profile deletion receipt is retained temporarily so a lost response can be retried safely.
Backups maintained by infrastructure providers may retain encrypted copies temporarily until their normal rotation completes. Legal or security obligations may require limited information to be retained where applicable.