This Privacy Policy explains how OctoReport ("we", "our", or "the platform") collects, uses, and protects your personal data when you use our services.
By using OctoReport, you agree to the practices described in this policy. If you do not agree, please stop using the service.
1. Information we collect
1.1 Account information
- Email address – used for registration, login verification codes, and service notifications.
- Login session – after a successful login we set a session cookie in your browser and keep the corresponding session record in our own database (revocable server-side).
OctoReport uses passwordless email-code login: we never collect or store account passwords, and we do not offer Google, GitHub, or any other third-party sign-in.
1.2 Usage data
- Source configurations (search, RSS, email, crawlers, etc.).
- Content collected via those sources.
- Libraries, reports, and Ask conversations you create.
- Task logs and credit transactions related to your usage.
1.3 Technical data
- Access logs (IP address, browser, OS, timestamps, visited pages).
- Performance metrics (load times, API latency) for optimization.
- Error logs with sensitive fields redacted.
1.4 Cookies and analytics
We use cookies to keep you logged in and remember your preferences.
Our marketing site uses self-hosted Umami analytics: it is cookie-free, does not track you across sites, and the data stays on our own infrastructure.
2. How we use your data
- To provide core features such as collection, cleaning, reporting, and Ask.
- To maintain your account and verify your identity.
- To monitor system health, improve reliability, and debug issues.
- To send important notifications such as task status or low-balance alerts.
- To send onboarding and product-marketing emails on the basis of your consent when registering. Every marketing email includes an unsubscribe link, and transactional emails (verification codes, task alerts) are unaffected by unsubscribing.
3. Third-party services
We rely on third-party providers for LLM inference, crawling, email delivery (SMTP/IMAP), and payments (Stripe on the global site; payment processors never share your card details with us and we do not store them). Authentication is handled by our own email verification-code system — no third-party identity provider is involved. We only share the minimum data needed to provide the service and require providers to follow strict security and privacy standards.
4. Data storage and security
- PostgreSQL for structured data such as accounts, content, and reports.
- Cloudflare R2 for files you upload; local storage and Redis for caching and queues.
- Transport-level encryption (HTTPS/TLS) for all external traffic and AES-256-GCM encryption for sensitive API keys.
- Login codes are single-use and short-lived (15 minutes, temporary lockout after repeated failures); sessions are stored server-side and can be revoked at any time.
5. Your rights
- Access and update your account information at any time.
- Delete content, sources, and libraries in-product; request full account deletion via [email protected] (we verify your identity, then remove the account and associated data — irreversible).
- Export data manually today; automated export options are planned.
- Contact us if you believe your data has been mishandled.
6. Contact
If you have questions about this Privacy Policy, reach us at:
- Email: [email protected]
- Website: www.octoreport.com
© 2026 OctoReport. All rights reserved.