Ocur Start free

Legal

Privacy Policy

Ocur works inside the tools your company already runs on. That only makes sense if it is completely clear what Ocur touches, why it touches it, where it goes and how you take it away again. This page is that, in plain language — no lawyer required.

Last updated 6 August 2026 Effective 6 August 2026 Applies to ocur.ai · app.ocur.ai · the Ocur desktop companion

The short version

  • We never sell your data, and we never use it for advertising.
  • We do not use your content — or anything Ocur reads from Google Workspace — to train generalized AI or machine-learning models. Not ours, not anyone's.
  • Ocur only reaches an account after you connect it, and only does what you asked for. Anything you haven't cleared for autopilot waits for your sign-off.
  • Your workspace is isolated from every other customer's. Credentials are encrypted at rest.
  • Disconnect a service, or delete everything, whenever you like — it takes one click.
  • Your data is hosted in the European Union.
Contents

01Who we are

Ocur is the AI operating system for companies. It plugs into the platforms a company already runs on — email, calendar, files, chat, the web — and does the work inside them, on demand or on autopilot.

Ocur is operated by OcurAI, Inc., a Delaware C corporation, registered office 131 Continental Dr, Suite 305, Newark, DE 19713, United States, principal place of business Luisenstraße 8, 38448 Wolfsburg, Germany (“Ocur”, “we”, “us”). For everything described here, we are the data controller in the sense of the EU General Data Protection Regulation (GDPR) — except where we process data on your behalf as a processor, which is the normal case for the content your company puts into the product (see section 5).

Privacy questions, requests and complaints: privacy@ocur.ai. We answer every one of them.

App identity

These are the details our application is registered under — including with Google, for the OAuth consent screen you see when you connect a Google account:

Application name Ocur
Publisher OcurAI, Inc.
Home page https://ocur.ai
Application https://app.ocur.ai
Privacy policy https://ocur.ai/privacy
Terms of service https://ocur.ai/terms
Contact privacy@ocur.ai

02What this policy covers

This policy covers:

  • the Ocur website at ocur.ai, including the game at ocur.ai/be-ai;
  • the Ocur application at app.ocur.ai and its API;
  • the Ocur desktop companion app that connects your own computer to Ocur;
  • the messaging channels you can reach Ocur through (WhatsApp, Telegram, Slack, Discord).

It does not cover the third-party services you connect Ocur to. When Ocur reads your Gmail or edits a Google Sheet on your instruction, Google's own privacy policy still governs what Google does with that data.

03The data we process

Account data

Your name, email address, profile picture, the organisation you belong to and your role in it. Sign-in is handled for us by Clerk; we hold the resulting profile so we know whose workspace is whose.

The content you give Ocur

Everything you send it and everything it produces: chat messages and voice input, the files and documents you upload, the knowledge you add, the automations and tasks you set up, the memories you (or your admins) explicitly save, and the record of every run.

Data from the accounts you connect

Ocur can connect to Google (Gmail, Calendar, Drive, Contacts), Microsoft 365, Slack, GitHub, Notion, Trello, Telegram, WhatsApp, Discord, and to any tool you add yourself through a custom connector or an MCP server. Once you connect a service, Ocur reads and writes there strictly to carry out the work you asked for. Section 4 sets out the Google case in full.

Usage and technical data

Server logs (IP address, browser and device type, timestamps, the endpoint called), error diagnostics, the number of tokens a run consumed, and an audit trail of the actions Ocur took on your behalf — which is what makes the "every step on the record" promise real.

Billing data

Plan, invoices, billing country, VAT status. Card payments run through Stripe — we never see or store full card numbers.

Website data

Aggregate, cookie-free product analytics on ocur.ai. See section 13.

04Google user data

Ocur is a Google API Services client. Because Gmail, Calendar and Drive are among the most sensitive things a company can hand over, this section spells out exactly what we ask for, what we do with it, and what we will never do with it.

Nothing is connected until you connect it

Google access is per-service and opt-in. Connecting Gmail does not connect Drive; connecting Calendar does not connect Gmail. You grant each one from Ocur's connector settings, you see Google's own consent screen listing the permissions, and you can take any of them back at any time (section 11).

The permissions we request, and why

Scope What it allows Why Ocur needs it
openid userinfo.email userinfo.profile Read the connected Google account's email address, name and profile picture. To show you which account is connected and to use the right one when several are.
gmail.readonly Read messages, threads, labels and attachments in the connected mailbox. Triage and summarise the inbox, find the thread you're asking about, pull the invoice out of an attachment, answer "what did the supplier actually say?".
gmail.modify Apply and remove labels, mark as read, archive, and manage drafts. Keep the inbox in the state you asked for — label, file, archive, tidy up after a run.
gmail.compose Create and edit drafts in the connected mailbox. Prepare a reply for you to read and approve before anything is sent.
gmail.send Send a message from the connected mailbox. Actually send the reply or the payment reminder once you approve it — or automatically, if you put that job on autopilot yourself.
contacts.readonly profile.emails.read Read your Google contacts and their email addresses. So "email Anna about the invoice" reaches the right Anna, without you looking the address up.
calendar.events Read, create, change and delete events on the connected calendar. Answer "when am I free?", book the meeting, move it when the other side reschedules.
drive Open, create, edit and organise files in the connected Drive. Do the work inside the actual document — reconcile the invoice sheet, update the deck, file the export where it belongs.

We request the narrowest set of scopes that lets these features work end to end. If a feature stops needing a permission, we drop the permission.

What we do with Google data

  • We use it only to provide the features you asked for. A run fetches what the task needs, does the task, and reports back.
  • We do not keep a copy of your mailbox or your Drive. Ocur has no background mirror of your Google account. What persists afterwards is the record of the run inside your workspace: the conversation, the result, the audit entry — plus anything you or your admin explicitly chose to save into company memory or the knowledge base.
  • Access and refresh tokens are encrypted at rest and used only to call Google on your behalf.
  • Your workspace is isolated. Google data from your account is never mixed with another customer's, and never used to answer another customer's question.
Limited Use disclosure

Ocur's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, we do not use Google Workspace APIs, or any data obtained through them, to develop, improve or train generalized artificial intelligence or machine-learning models. Content from Gmail, Google Calendar, Google Drive or Google Contacts is passed to our AI model providers only to carry out the specific task you requested, under contracts that forbid them from training their models on it (see section 6).

What we never do with Google data

  • We never sell it, and we never transfer it to data brokers or information resellers.
  • We never use it for advertising, ad targeting, or any purpose unrelated to the features you asked for.
  • We never use it to build a profile of you for anyone else's benefit.
  • No human at Ocur reads it, except in four narrow cases: with your explicit consent (for example when you ask us to look into a specific run), where it is strictly necessary for security or abuse investigations, where the law requires it, or where the data has been aggregated and anonymised so that it no longer identifies anyone.

05How we use data, and on what legal basis

Where your company is our customer, we process the content in your workspace on your instructions, as a processor — your company decides what goes in and what Ocur is allowed to do with it. Where we decide the purposes ourselves (running accounts, billing, keeping the service secure, improving the website), we are the controller. The legal bases under Article 6 GDPR:

What we do Legal basis
Provide the product: run tasks, drive connectors, keep memory, deliver results Performance of the contract, Art. 6(1)(b) — and your instruction as the customer
Connect a third-party account and act inside it Your consent, given per service at the moment you connect it, Art. 6(1)(a)
Keep the service secure, prevent abuse, debug failures Legitimate interests, Art. 6(1)(f)
Billing, invoicing, tax records Contract and legal obligation, Art. 6(1)(b) and (c)
Aggregate product analytics and service improvement Legitimate interests, Art. 6(1)(f) — aggregated, never content-level
Service emails you can't opt out of (security, billing, outages) Contract, Art. 6(1)(b)

We do not sell personal data, and we do not do behavioural advertising.

06AI models and how your content is processed

Ocur is built on large language models. To answer you or complete a task, the relevant part of your content — your message, the document in question, the email thread it needs to read — is sent to a model provider, processed, and the result comes back. Today those providers are Anthropic, OpenAI and Google (Gemini), with ElevenLabs for speech when you use voice mode.

  • They do not train on your content. We use these providers under their business/API terms, which prohibit using data submitted through the API to train their models.
  • We do not train models on your content either — not our own models, and not fine-tunes of anyone else's.
  • Only what the task needs is sent. Ocur passes the relevant context for the job at hand, not your whole workspace.
  • Model output can be wrong. That is exactly why anything consequential waits for a human sign-off unless you have deliberately put that job on autopilot.

07Who we share data with

We share data with the service providers that make Ocur work — nobody else. Each one is bound by a data processing agreement, may only act on our instructions, and gets only what it needs for its job. We never sell data, and we do not share it with advertisers.

Provider What it does for Ocur Where
Amazon Web Services Hosting, databases, file storage, logs EU (Stockholm)
Vercel Hosting for the ocur.ai website Global CDN
Clerk Sign-in, sessions and organisation membership EU / US
Anthropic, OpenAI, Google The language models that do the reasoning EU / US
ElevenLabs Speech synthesis for voice mode EU / US
Supermemory Company memory and semantic search, in a container isolated per workspace EU / US
Exa Web search when Ocur needs to look something up US
E2B Sandboxed code execution when the task needs to run something EU / US
Merge, Unified.to Connector infrastructure for some third-party business tools EU / US
Stripe Payments, subscriptions and invoicing EU / US
Sentry Error and crash diagnostics EU
PostHog Aggregate product analytics EU

This list is current as of the date at the top of this page and changes as we change providers — write to privacy@ocur.ai for the up-to-date sub-processor list or to be notified of changes.

Beyond these providers, we disclose data only where the law requires it (a valid, binding legal request, which we review and push back on where we can), or in the event of a merger or acquisition — in which case you will be told before your data becomes subject to a different privacy policy.

08Where your data lives

Ocur runs on infrastructure in the European Union. Some of the providers above operate outside the EU, or support them from outside it. Where data reaches a country without an EU adequacy decision, the transfer is covered by the European Commission's Standard Contractual Clauses together with the technical measures in section 10.

OcurAI, Inc. is incorporated in Delaware, but that does not move your data: the systems that hold it run in the EU, and being a US company does not give anyone automatic access to it. We disclose data to authorities only against a valid, binding legal request, which we review and push back on where we can.

09How long we keep it

Data Kept for
Account and organisation data As long as the account exists; deleted when you delete it
Conversations, files, memories, automations Until you delete them, or until the account is deleted
Connector credentials and tokens Until you disconnect that service, or delete the account
Audit log of actions taken on your behalf 180 days by default
Server and security logs Up to 90 days
Invoices and tax records As long as commercial and tax law requires (up to 10 years in Germany)
Encrypted backups Rolling window, at most 35 days, then overwritten

When you delete something it is removed from the live systems immediately, and it ages out of the encrypted backups within the window above.

10How we protect it

  • Encrypted in transit (TLS) and at rest.
  • Connector credentials get a second layer: every access and refresh token is separately encrypted before it is written to the database, with a key held outside it.
  • Tenant isolation. Each workspace's data — including its memory container — is scoped to that workspace and cannot be reached from another.
  • Least privilege inside Ocur. Access to production is limited to the people who need it, and it is logged.
  • Guardrails in the product itself. Admins decide what may run unattended; everything else waits for approval, with a timeout, and every action is written to the audit trail.
  • Breach notification. If a breach affects your personal data, we notify the competent supervisory authority within 72 hours where the GDPR requires it, and we tell you without undue delay.

Found a security problem? Write to security@ocur.ai — we will work with you and we will not go after you for reporting it in good faith.

11Disconnecting and deleting

Disconnect one service

In Ocur, open the connectors settings and choose Disconnect on the service in question. The credentials we hold for it are deleted, and Ocur loses access immediately.

Revoke at Google

You can also withdraw Ocur's access from Google's side at any time, independently of us, at myaccount.google.com/permissions. The same is true of the equivalent settings at Microsoft, Slack, GitHub, Notion and every other service you have connected.

Delete everything

Deleting your account removes your profile, conversations, files, knowledge, memories, automations and stored credentials from our live systems, and they age out of the encrypted backups within the window in section 9. If you would rather we did it for you, or you want written confirmation that it is done, email privacy@ocur.ai and we will action it within 30 days. What we keep afterwards is only what the law forces us to keep, such as invoices.

12Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and get a copy.
  • Rectify anything inaccurate.
  • Erase your data (“the right to be forgotten”).
  • Restrict or object to processing based on our legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting what was lawful before.
  • Complain to a data protection supervisory authority in your country.

Write to privacy@ocur.ai and we will respond within 30 days. If you are an employee at a company that uses Ocur, your employer controls that workspace — we will point you to them and help them answer you.

If you are in California

We do not sell personal information and we do not share it for cross-context behavioural advertising — under the CCPA/CPRA or anything else. California residents can ask us to disclose, correct or delete the personal information we hold, and we will not discriminate against you for asking. Same address: privacy@ocur.ai.

Automated decisions

Ocur acts on the instructions you give it. It does not make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Consequential actions wait for a human sign-off unless your organisation has explicitly put that specific job on autopilot, and everything Ocur does is recorded and reversible by the humans who own the account.

13Cookies and analytics

The website at ocur.ai is deliberately light:

  • ocur-theme and ocur-lang — remember your dark/light and language choice. Strictly functional, set only when you make a choice.
  • PostHog product analytics, configured cookie-free: it keeps its state in memory only, writes nothing to your device, and tells us how many people read a section — not who they are. That is why you get no cookie banner here.
  • No advertising cookies, no tracking pixels, no cross-site profiling. Ever.

The application at app.ocur.ai additionally sets the session cookies it needs to keep you signed in.

14Children

Ocur is a product for companies and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to privacy@ocur.ai and we will delete it.

15Changes to this policy

We update this policy when the product changes. The date at the top always tells you which version you are reading. For material changes — a new category of data, a new purpose, a new kind of recipient — we notify account holders by email or in the product before the change takes effect. We never apply a materially different handling of previously collected data without asking you first.

16Contact us

Privacy questions, data requests, complaints, or anything on this page you find unclear:

See also our Terms of Service.

← Back to ocur.ai