Beta draft·This policy is a starting-point draft for the invite-only beta. It has not been reviewed by counsel. We expect to replace it with a finalized version before public launch.

Legal · Last updated April 30, 2026

Privacy Policy

This policy explains what information Ondek (“we”, “us”) collects when you use the Service, how we use it, who we share it with, and the choices you have. Capitalized terms not defined here have the meanings given to them in our Terms of Service.

1. Information we collect

We collect information you give us, information generated by your use of the Service, and information from third-party integrations you connect.

  • Account information. Name, email, password hash, role, optional company and phone, billing address.
  • Customer Data. Artists you add, songs and releases, contacts, deals, tasks, documents you upload, notes, and similar workspace content.
  • Email content (optional). If you connect Gmail, we read and store the messages you authorize so the Service can triage and summarize them. You can disconnect at any time.
  • OAuth tokens. When you connect Google or Spotify, we store the access and refresh tokens needed to make API calls on your behalf, encrypted at rest.
  • Usage data. Pages visited, actions taken, feature usage, IP address, device, browser, and approximate location derived from IP. Used for security, debugging, and product improvement.
  • Payment information. Handled directly by Stripe. We never store your card number; we receive a Stripe customer ID, the last four digits of your card, and billing metadata.

2. How we use information

  • To operate, maintain, and improve the Service.
  • To process transactions, send invoices and receipts, and prevent fraud or abuse.
  • To provide AI features — processing the relevant subset of your data through our AI provider (Anthropic) to generate summaries, drafts, and analytics. We do not allow the AI provider to train on your data.
  • To communicate with you about your account, security, product updates, and (if you opt in) tips and announcements.
  • To comply with legal obligations and enforce our agreements.

3. How we share information

We do not sell your personal information. We share it only with service providers acting on our behalf and under contractual obligations to protect your data:

  • Stripe— payments and subscription billing.
  • Anthropic— AI inference for Manager Brain, briefings, and email triage. Anthropic is contractually prohibited from training on your data.
  • Soundcharts— receives the artist identifiers needed to fetch streaming and chart data on your behalf.
  • Google and Spotify— only when you explicitly connect those accounts; we send each provider only the requests needed to power the integrations you enabled.
  • Cloudflare R2— document and file storage.
  • Railway and Vercel— hosting infrastructure.
  • Sentry— error tracking. We disable PII capture by default.
  • Resend / SMTP provider— transactional email delivery.

We may also disclose information when required by law, in response to valid legal process, or to protect the rights, property, or safety of Ondek, our users, or others. If we are ever involved in a merger, acquisition, or asset sale, your information may transfer to the successor entity, subject to this policy or one materially similar to it.

4. Soundcharts data attribution

Streaming counts, chart positions, social-platform metrics, and related data displayed inside the Service are powered by Soundcharts. Soundcharts data is provided under their license terms and may be cached on our infrastructure to reduce cost and latency. We display a “Last synced” indicator on every Soundcharts-derived surface so you can see how fresh the underlying data is.

5. Security

We use industry-standard practices: TLS in transit, encryption at rest for sensitive fields (OAuth tokens, password reset tokens), hashed passwords (bcrypt), single-use refresh-token rotation, rate-limited authentication endpoints, and 2FA-style account lockout after repeated failed logins. No system is perfectly secure; if you suspect a vulnerability or compromise, please contact hello@ondek.ai.

6. Data retention

We retain your account and Customer Data for as long as your account is active. After termination we retain Customer Data for up to 30 days to allow export, then delete it from active systems. Backup snapshots may persist for up to 90 days. Logs and aggregated, de-identified usage statistics may be retained longer for security, fraud prevention, and analytics.

7. Your choices and rights

  • Access and update. You can review and edit your account profile and most workspace data directly in the Service.
  • Export. Email us to request an export of your Customer Data in a common machine-readable format.
  • Deletion.Email us to request deletion of your account. We'll confirm by reply and complete the deletion within 30 days, subject to legal retention requirements.
  • Marketing opt-out. Every marketing email includes an unsubscribe link. Transactional emails (security, billing, account) cannot be opted out of while your account is active.
  • Disconnect integrations.Settings → Integrations lets you disconnect Google or Spotify at any time; we revoke and delete the related tokens.

8. International users

Ondek is operated from the United States. By using the Service you understand that your information will be processed in the U.S. and other countries where our service providers operate. We do not currently target users in jurisdictions that require additional disclosures (EU/UK GDPR, Brazil LGPD, etc.); we will update this policy before expanding to those markets.

9. Children

Ondek is not intended for anyone under the age of 18. We do not knowingly collect information from children under 18. If we learn we have, we will delete it.

10. Changes to this policy

We may update this policy from time to time. If we make material changes we'll notify you (typically by email or a banner in the Service). The “Last updated” date at the top of this page reflects the latest revision.

11. Contact

Questions about this policy or about how we handle your data? hello@ondek.ai.

Last updated · April 30, 2026