Privacy policy
What we collect, why, how long we keep it and who else sees it, for every Olee product, in one document.
Last updated 11 September 2026 · Applies to every Olee product · Olee AI (Pvt) Ltd
Contents
01
Who this is about
Olee AI (Pvt) Ltd operates the Olee products. This policy covers all four of them, each of which keeps its own accounts, and this site. There are two very different relationships in it:
You, our customer. We are the controller of your account: your name, your email, your organisation, what you bought and what you used.
The people your content is about, a candidate who applied, a customer who chatted to your bot, a person named on a document you uploaded. For them you are the controller and we are your processor, acting on your instructions.
If you are a candidate, a client or a customer of an Olee user and want your data removed, the organisation that uploaded it decides. Write to them first. If you cannot reach them, use our removal page and we will pass it on.
02
What we collect
Because you have an account
Your name, email address and password hash. We never see your password.
Your organisation, your role in it, and which products it holds.
Billing details: what you bought, what you were charged, and the invoice. Card numbers go to Stripe and never reach us.
Security events: sign-ins, failed attempts, and changes an administrator made.
Because you use a product
What you upload or send, documents, CVs, website content, questions, drafts.
What the product produced from it, extracted fields, scores, answers, transcripts, generated documents.
Usage counts, so we can meter a plan and show you what you have used.
Technical logs: request times, errors and IP addresses, kept short and used to keep the service up and to investigate abuse.
What we do not collect
We do not sell personal data, ever, to anybody.
We do not run advertising trackers or third-party analytics that profile you across the web.
We do not use your content to train AI models, ours or anybody else's.
03
Why we are allowed to
To perform our contract with you, running the product you bought, and billing you for it.
Legitimate interests, keeping the service secure, preventing abuse, and understanding which features are used so we can improve them.
Legal obligation, keeping tax and accounting records.
Consent, where we ask for it, for example a candidate agreeing to be kept in a talent pool. You may withdraw it at any time.
04
How long we keep it
Where a product lets an administrator set a retention window, they set it within the limits below. When a window ends the record is deleted automatically, not archived.
DataRuleDefault
CVs and applicationsDeleted automatically at the end of the period12 months
Interview recordingsAudio and transcript, deleted together6 months
Talent pool recordsKept only with the candidate agreeing24 months
Uploaded documents and what was read from themDeleted together, on your instruction or at the end of the periodUntil you delete
Chat conversationsKept while the workspace is live, then with the accountUntil you delete
Audit eventsCannot be shortened below the legal minimum7 years
Accounts and organisationsDeleted after the account is closed30 days
Invoices and payment recordsKept for tax and accountingAs the law requires
Backups roll off on their own schedule and are fully replaced within 35 days of a deletion.
05
Who else sees it
We use a small number of providers to run the service. Each is bound to process data only on our instructions.
ProviderWhat forWhere
SupabaseDatabase, authentication and file storageSingapore / India
VercelHosting and content deliveryEdge, primary India
Google (Gemini)AI models that read, answer and scoreRegional
StripeCard payments and subscriptionsUnited States
ZeptoMailTransactional emailRegional
CloudflareBot protection on sign-in and public formsGlobal
Meta (WhatsApp)Only if you connect a WhatsApp numberGlobal
We will give 14 days' notice, by email and in the product, before adding a provider that would process your content.
06
What the AI providers get
The products send the model only what it needs to answer the request in front of it: the passage, the CV, the image, the question. The provider processes it and returns a result.
Your content is not used to train the model. We use the providers' paid API tiers, where training on customer content is off by contract, not by a setting.
07
How it is protected
Every client's rows are separated by row-level security policies in the database. An application bug alone is not enough to reach another client's data.
Data is encrypted in transit, and at rest by the storage provider.
Access to production is limited to the people who need it, and administrative actions are written to an audit log.
Creating an account needs an invitation code, on every product.
Product-to-product calls use per-product secrets that are compared inside the database, so the stored hash never leaves it.
08
Your rights
You may ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, or to have it sent somewhere else. Write to hi@olee.ai and we will answer within 30 days.
If the data is inside a customer's workspace, we will pass the request to that customer, because it is theirs to decide.
09
Where the products differ
OleeHire only
An interview is recorded, transcribed and scored. Candidates are told before it starts, and the audio and the transcript are deleted together at the end of the retention window. The employer, not us, decides who inside their organisation may listen to it.
OleeVision only
Identity documents are read and the extracted fields returned. Delete a document and every field read from it is deleted with it, in one action.
Oleon only
A conversation with your bot, on your site or on WhatsApp, is your record of your customer. WhatsApp messages also pass through Meta under their own policy, which we do not control.
OleeLaw only
Judgments and statutes in the library are published public documents. Your searches and drafts are yours, are private to your account, and are never used to improve the library.
10
Children
The products are not for children. We do not knowingly collect personal data from anyone under 16. If you believe we have, write to hi@olee.ai and we will delete it.
11
Changes to this policy
We will email account holders and show a notice in the product at least 14 days before a material change takes effect. The date at the top of this page is when it was last changed.
Questions about this document go to hi@olee.ai. Anything about your account or a charge is faster at the same address.