Privacy Policy
Olo exists because sensitive data should never leave your device. This policy is written to reflect that architecture. We collect less than almost any product you use, and we explain exactly what we do collect, why, and what never leaves your machine.
If anything here is unclear, email us at olosecurity+legal@gmail.com.
- Who we are
- The core commitment: your content never leaves your device
- What we do collect
- What we do not collect
- What team admins can and cannot see
- How we use the information we collect
- Service providers and subprocessors
- Cookies and website analytics
- Legal bases
- Data retention
- Security
- Data breach notification
- Your rights
- Children
- International transfers
- Changes to this policy
- Contact
1. Who we are
Olo Security, Inc., a Delaware corporation (“Olo,” “we,” “us”), provides a macOS application and related services that detect and redact sensitive data on your device before it reaches AI tools. This policy covers the Olo desktop application, the Olo browser extension, our website at olosecurity.com, and our account and team services (together, the “Services”).
2. The core commitment: your content never leaves your device
The text you type, paste, or upload into AI tools, and the text Olo reads in order to protect you, is processed entirely on your device. Specifically:
- We never transmit your content.The contents of your prompts, text fields, messages, or documents are never sent to Olo’s servers or to any third party by Olo. Classification and redaction happen locally on your Mac.
- We never transmit detected spans. The specific words or values Olo flags as sensitive (a name, a patient record, an API key) stay on your device. They are not logged remotely, not sent for analysis, and not used to train models.
- We never transmit derivatives of your content. We do not send hashes, embeddings, or any other representation from which your content could be reconstructed.
- The process that reads your screen has no network access. Olo is built as two separate processes. The process that reads and classifies text cannot make network connections. A separate sync process handles networking and is only capable of transmitting the metadata described in Section 3.
This is verifiable. You can run a network monitor while using Olo and confirm that no content leaves your machine.
3. What we do collect
Account information
When you create an account, we collect your email address, your name if you provide one, and a password or authentication credential. If you join or create a team, we collect your team membership and role (admin, manager, or member).
Redaction metadata
To provide coverage statistics, team policy features, and audit reporting, the Olo sync process transmits event metadata consisting of:
- a timestamp
- the policy category that fired (for example, “PHI” or “credentials”)
- a redaction count
- the name of the application in which the detection occurred
- the associated account or team identifier
That is the complete list. Metadata never includes the content that triggered a detection.
Payment information
If you purchase a paid plan, payment is processed by a third-party payment processor. We receive confirmation of payment and plan status, not your full card details.
Website and support data
If you visit olosecurity.com, contact support, or email us, we collect the information you provide (such as your email and the contents of your message) and standard technical data such as browser type and pages visited.
Crash and diagnostic reports
If the app crashes, macOS may offer to send a crash report. Crash reports contain technical stack information, not the contents of text fields you were working in. Diagnostic reporting is optional.
4. What we do not collect
- The contents of your prompts, messages, documents, or text fields
- The specific values Olo detects or redacts
- Your browsing history
- Keystroke logs
- Screenshots or screen recordings
- Any data used to train AI models
5. What team admins can and cannot see
If you are part of a team, your team’s admins and managers can see aggregate metadata: for example, how many redactions occurred this week, in which policy categories, across which applications, and by which team members.
Admins and managers can never see your prompts, your text, or the specific values that were detected or redacted. That information does not exist on our servers, so it cannot be shown to anyone.
6. How we use the information we collect
We use account information to operate your account, authenticate you, and provide team features. We use redaction metadata to display coverage statistics, power team policy and audit reporting, and understand aggregate product usage. We use payment information to bill you. We use support communications to help you.
We do not sell your personal information. We do not share your personal information with third parties for their own advertising or marketing purposes.
7. Service providers and subprocessors
We use a small number of service providers to operate the Services, such as our database and authentication provider (Supabase) and a payment processor. These providers process data on our behalf, under contract, and only for the purposes described in this policy. Because content never leaves your device, our service providers never receive your content either.
A current list of our subprocessors is available on request. For team and business customers, a data processing addendum is available on request.
9. Legal bases
Where data protection law (such as the GDPR or UK data protection law) requires a legal basis, we rely on: performance of a contract (operating your account and the Services), legitimate interests (securing the Services, understanding aggregate usage, preventing abuse), consent (where required, for example optional diagnostics), and legal obligations (such as tax and accounting requirements).
Olo’s local-only architecture is a deliberate application of data minimization. We designed the product so that the most sensitive category of data, the content itself, is never processed by us at all.
10. Data retention
Account information is retained while your account is active. Redaction metadata is retained to provide historical reporting for you or your team; you or your team admin may request deletion. If you delete your account, we delete or de-identify your personal information within a reasonable period, except where retention is required by law.
11. Security
We protect the data we do hold using industry-standard measures, including encryption in transit and at rest, access controls, and the architectural separation described in Section 2. The strongest security measure in Olo is structural: the data most attackers would want does not exist on our servers.
12. Data breach notification
If we become aware of a breach affecting the security of your personal information, we will investigate, take appropriate remedial measures, and notify affected users and relevant authorities where required by law, without undue delay. Because content never reaches our servers, the scope of any potential breach is limited to the account information and event metadata described in Section 3.
13. Your rights
We extend the following controls to every user, regardless of where you live: the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise these rights by emailing olosecurity+legal@gmail.com. We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising your rights.
If you are in the EEA or UK, you also have the right to lodge a complaint with your data protection authority. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and correct; we do not sell or share personal information as those terms are defined under California law. If you live in another jurisdiction with its own data protection law, we will honor the rights that law provides.
14. Children
The Services are not directed to children under 13 (or the higher age required in your jurisdiction), and we do not knowingly collect personal information from them.
15. International transfers
Our servers may be located in the United States. Where we transfer personal information from other jurisdictions, we use appropriate safeguards such as standard contractual clauses.
16. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you through the app or by email. The date at the end of this policy reflects the current version.
17. Contact
Questions, requests, or concerns: olosecurity+legal@gmail.com. Privacy inquiries are handled directly by our founding team.
This policy was last updated on July 30, 2026.