Legal

Privacy Policy

OODAC Technologies LLC builds and operates software products and provides AI consulting services. This policy explains what we collect, why, and what you can do about it — across oodac.com and every product we run on an oodac.com subdomain.

Last updated 1 September 2026

The short version

We collect the minimum needed to run the product you are using. We do not sell personal information. We do not use your documents, files or content to train AI models. You can ask us to delete your data at any time and we will.

Who we are

OODAC Technologies LLC, a Virginia limited liability company, 8401 Mayland Drive, Suite A, Richmond, VA 23294, USA. For any privacy question or request, write to [email protected]. We are the data controller for the services described here.

What we collect

CategoryWhat it isWhy we have it
Account dataEmail address, display name, and — where you sign in with Google — the basic profile Google returns.To identify you, secure your account, and let you back into it.
Content you createDocuments, files, records and settings you make inside a product.To provide the product. This is yours; we store it so you can use it.
Contact enquiriesName, email, company and message from the form on oodac.com.To answer you. Nothing more.
Billing dataSubscription status, plan and invoice history.To bill you correctly and show your invoices.
Usage analyticsPage views and aggregate events.To see what works. Collected with self-hosted Umami — no cookies, no cross-site tracking, no advertising identifiers.
Technical logsIP address, timestamps, user agent, error traces.Security, abuse prevention, and debugging. Kept short.

What we deliberately do not collect

We do not run advertising trackers, we do not build behavioural profiles, and we do not buy personal data about you from third parties. We never take payment card numbers. Card details go directly to Stripe and never touch our servers.

How we use it

We send marketing email only to people who asked for it, and every marketing message carries a working one-click unsubscribe that we honour immediately. Unsubscribing from marketing never stops the transactional messages you need to use the product.

AI processing

Some products use AI models to review, explain or draft content at your request. Where that happens, the content you submit is sent to the model provider solely to return your result. We do not permit your content to be used to train those models, and we do not train our own models on it.

Who we share it with

We share data only with the service providers that make our products run, and only what they need. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

ProviderRole
Amazon Web ServicesHosting, databases and file storage (US regions)
Amazon SESSending transactional and opted-in email
VercelApplication hosting and delivery for some products
CloudflareDNS, CDN and bot protection
StripePayment processing and billing. Stripe is the controller of your card data.
GoogleSign-in with Google, where you choose it
AI model providersProcessing content you explicitly submit to an AI feature

We will also disclose data if the law genuinely requires it, or to protect our rights, users or the security of the service. If a business transfer ever happened, we would tell you before your data moved.

Where your data lives

Our infrastructure runs in the United States. If you access our products from outside the US, your data is transferred to and processed in the US. Where transfers from the EEA or UK require a legal mechanism, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum.

How long we keep it

When you delete your account we remove your content and personal data from live systems promptly. Encrypted backups age out on their normal cycle, generally within 35 days.

Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use. Write to [email protected] and we will respond within 30 days.

If you are in the EEA or UK

You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your local supervisory authority. Our legal bases are contract (to provide the service), legitimate interests (security, abuse prevention, product improvement), consent (marketing email), and legal obligation (tax and accounting records).

If you are in California

You have the rights to know, delete, correct and opt out under the CCPA/CPRA, and we will not discriminate against you for exercising them. In the previous twelve months we have not sold personal information and have not shared it for cross-context behavioural advertising.

Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production systems is limited and authenticated. Databases have point-in-time recovery enabled. No system is perfectly secure, but we treat losing or exposing your data as the most serious failure we could have, and we build accordingly.

Children

Our products are not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, write to us and we will delete it.

Changes

If we change this policy materially we will update the date above and, where the change matters to you, tell you by email or in the product before it takes effect.

Contact

OODAC Technologies LLC
8401 Mayland Drive, Suite A, Richmond, VA 23294, USA
Privacy: [email protected] · Support: [email protected] · +1 571 307 4650