Ohtani
Get in touch

Privacy Policy

Last Updated: January 2025

This Privacy Policy describes how Ohtani Technologies Limited ("we", "us", or "our") collects, uses, and shares information when you use our platform and services.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Identity information: First name, last name, username
  • Contact information: Email address(es)
  • Authentication data: Password (encrypted), two-factor authentication status
  • Profile information: Profile image URL
  • Organization data: Organization membership, role, and permissions

This information is collected and managed through our authentication provider, Clerk.

1.2 User-Generated Content

When you use our services, you are sending the following to our services:

  • Chat conversations: Messages you send and AI-generated responses
  • Documents and files: Files you upload to the platform
  • Custom preferences: AI response detail level, custom instructions
  • Projects: Project names and organization of your content

1.3 Usage Information

We automatically collect information about how you use our services:

  • Interaction data: Features used, pages visited, actions taken
  • Company views: Which companies you view and when
  • Session information: Session duration, timestamps
  • Technical data: Browser type, device information, IP address

1.4 Cookies and Local Storage

We use cookies and local storage for:

Cookie/StoragePurposeDuration
Theme preferenceRemembers your light/dark mode setting1 year
Sidebar stateRemembers sidebar expanded/collapsed stateSession
Cookie consentStores your tracking preferencesPersistent
AuthenticationMaintains your logged-in sessionSession

2. How We Use Your Information

We use collected information to:

  • Provide our services: Process your requests, generate AI responses, store your documents
  • Personalize your experience: Apply your preferences and custom instructions
  • Improve our platform: Analyze usage patterns, fix bugs, develop new features
  • Ensure security: Detect fraud, prevent abuse, maintain platform integrity
  • Communicate with you: Send service-related notifications

3. Third-Party Services

3.1 Clerk (Authentication)

We use Clerk for user authentication and account management. Clerk processes:

  • Account credentials and login information
  • Session management and security tokens
  • Organization membership data
  • Two-factor authentication

For more information, see Clerk's Privacy Policy.

3.2 Datadog (Monitoring & Analytics)

We use Datadog for application monitoring and analytics:

What we collect:

  • Session recordings (with privacy masking enabled)
  • Performance metrics and error tracking
  • User interactions and navigation patterns
  • API request/response times

Privacy protections:

  • All text, images, and sensitive content are automatically masked in session recordings
  • On our marketing site, tracking requires explicit consent
  • We do not track authentication flows on third-party domains

User identification sent to Datadog:

  • User ID (anonymized identifier)
  • Session ID
  • Organization ID and role

For more information, see Datadog's Privacy Policy.

3.3 Amazon Web Services

AWS hosts our web and server-side services, as well as our databases and AI tooling.

Uploaded files are stored primarily in AWS S3:

  • Files are stored in private buckets with access controls
  • Files are organized by organization to ensure data isolation
  • Metadata stored includes: original filename, upload date, uploader ID

For more information, see AWS Privacy Policy.

3.4 FactSet (Financial Data)

We use FactSet to retrieve financial data for analysis. No personal information is shared with FactSet by our service.

4. Data Sharing

We do not sell your personal information. We share data only:

  • With service providers: Third-party services listed above that help operate our platform
  • For legal compliance: When required by law, legal process, or government request
  • For safety: To protect rights, safety, and property of users and the public
  • With your consent: When you explicitly authorize sharing

5. Data Security

We implement security measures including:

  • Encryption: Data encrypted in transit (TLS) and at rest
  • Authentication: Secure login with mandatory two-factor authentication
  • Access controls: Role-based permissions and organization isolation
  • Content Security Policy: Strict browser security headers to prevent attacks
  • Secure file handling: Pre-signed URLs with short expiration times

6. Data Retention

  • Account data: Retained while your account is active
  • Chat conversations: Stored indefinitely unless you delete them
  • Uploaded files: Retained until you delete them
  • Usage analytics: Retained according to Datadog's retention policies
  • Cookies: Expire according to the durations listed in Section 1.4

7. Your Rights and Choices

7.1 Access and Portability

You can:

  • View your profile information in your account settings
  • Access your chat history and uploaded files through the platform
  • Request a copy of your personal data by contacting us

7.2 Correction and Deletion

You can:

  • Update your profile information through Clerk's account management
  • Delete individual chats and files through the platform
  • Request account deletion by contacting us

7.3 Cookie Preferences

  • On our marketing site, you can accept or decline analytics cookies via the cookie banner
  • You can clear cookies through your browser settings

8. International Data Transfers

Your data is primarily stored in the United Kingdom. It may also be transferred to and processed in the European Union, where our cloud providers operate specific tools.

We ensure appropriate safeguards are in place for international transfers, such as private VPC peering, which prevents data from being transferred over the open internet.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy with a new "Last Updated" date
  • Sending notification through the platform (for significant changes)

10. Contact Us

If you have questions about this Privacy Policy or your personal data, contact us at postmaster@ohtani.io.

Summary Table

Data TypeCollected ByPurposeRetention
Account infoClerkAuthenticationWhile account active
Chat messagesOhtaniAI service deliveryUntil deleted
FilesAWS S3Document storageUntil deleted
Usage dataDatadogAnalytics & monitoringPer Datadog policy
PreferencesOhtaniPersonalizationWhile account active
CookiesBrowserFunctionality1 year max