Legal

Privacy Policy

Last updated 9 October 2026

1. Who we are and what this policy covers

Oralink ("Oralink", "we", "us") provides an AI assistant for businesses. It helps a business watch its customer conversations, appointments and online store, answers questions about them, prepares replies and follow-ups, and carries out actions the business has allowed. This policy explains what personal data we handle when you visit oralink.ee or use the Oralink application, why, who else sees it, and what rights you have.

Contact: contact@oralink.ee, +372 5687 8188. Questions about your data, and requests to use your rights, go to this address.

2. Two roles: your data and your customers' data

For information about you and your team (your account, your business profile, how you use Oralink), we decide why and how it is used. We are the controller.

When you connect a channel or a store, Oralink also handles information about your customers and contacts (for example people who message your Instagram or WhatsApp account, or the buyers in your online store). For that information we act on your behalf and on your instructions, as your processor. You are responsible for having a lawful basis to use it, for telling your customers that you use tools like Oralink, and for the messages and actions you allow Oralink to perform. A data processing agreement is available on request.

3. What we collect

Account and business details: your name, email address, sign-in credentials (passwords are stored only as secure hashes by our authentication provider), the business name, type, services, prices, languages, opening hours and tone you enter, your team members and their roles, and settings such as notification preferences.

Instagram (if you connect it): the connected professional account's identifier, username and access token (stored encrypted), and the conversations sent to and from that account: message content, timestamps, and the identifiers and public profile details Instagram provides for the people who write to you. We use this to show your inbox, produce replies and record what was sent.

WhatsApp (if you connect it): the connected WhatsApp Business account's and phone number's identifiers and display name, and an access token (stored encrypted), and the conversations sent to and from that number: message text, timestamps, and the phone number and profile name WhatsApp provides for the people who write to you. For a photo, voice note, file, location or contact card we keep only a short label (for example "[Photo]") and any caption, not the file itself. WhatsApp messages travel through Meta's WhatsApp Business Platform, which handles them under its own terms. We use this to show your conversations, produce replies you allow and record what was sent.

Appointments (if you use booking): the contact name and details the person gives, the service, date and time, and status.

Google Calendar (if you connect it): the e-mail address of the connected Google account, an access token and a refresh token (stored encrypted), and, when you open the calendar or ask for it, the events Google returns for the period shown: title, time, notes, guests, reminder settings and who created them. We read them live from Google; we do not keep a copy of your calendar. See section 12 for the rules that apply to Google user data.

Online store (if you connect Shopify): orders (order number, status, payment and fulfillment status, dates, currency, totals and the items ordered), products (title, description, vendor, variants, prices and stock) and, only if you allow it and your store's app has been granted it by Shopify, customers' names, account status, tags and the total each has spent. We do not request customers' email addresses, phone numbers or postal addresses from your store, and we do not receive payment card details. Access tokens are stored encrypted.

Ask Oralink and voice: the questions and commands you write or speak, Oralink's answers, drafts and lists it prepares, and the chats you keep. When you use voice, your recording is sent to our AI provider to be turned into text, and Oralink's spoken answer is generated from the answer text. We do not store the audio recordings or the generated audio.

Research you ask for: when you ask Oralink to look something up, your request and the public information found are processed, and the results you keep are saved in your workspace.

Support and billing: messages you send to support, and your plan and subscription status. Payments are handled by our payment provider; we do not see or store your full card number.

Reminders and notifications (if you use them): the text and time of the reminders you create are kept in your browser. If you turn on notifications on a device, a copy of your reminders and a push address for that device are also stored on our servers. If you enable message notifications, we also keep a short preview, sender name, channel and conversation identifier for each incoming message for up to 7 days, to show it to your workspace members and deliver their alerts. See section 13.

Technical and security data: sign-in and session information, device and browser type, IP address and logs needed to keep the service secure, reliable and free of abuse. The website and app store a few items in your browser (such as your session, language and theme choices, which guides you have seen, and your reminders). We do not use advertising cookies or third-party analytics trackers. So that you can see and end your sessions, we also keep a list of the devices signed in to your account (Settings → Account): the browser and operating system, the approximate place and the IP address of your last sign-in activity, and when each device was first and last used. A device stays in that list for 90 days after it was last used, and the list is deleted when you delete your account.

4. Why we use it, and our legal bases

To provide the service you asked for: to run your account, show your conversations, appointments and store, answer your questions, prepare and send the replies and actions you allow, keep a record of what Oralink did, and provide support (performance of a contract).

To keep the service safe and working: security, fraud and abuse prevention, fixing errors and improving reliability (our legitimate interests).

To bill you and meet legal duties: subscriptions, taxes and accounting (contract and legal obligation).

To contact you about the service: account, security and product notices you need, and messages you have chosen to receive (contract, legitimate interests or your consent, as applicable). You can change notification settings in the app.

We do not sell personal data, we do not use your or your customers' data for advertising, and we do not use it to train our own models.

5. AI features

Oralink uses artificial intelligence to understand your requests, write answers and drafts, look up public information, and transcribe and speak in voice mode. To do this, the relevant text (and, in voice mode, the recording) is sent to our AI provider, which processes it on our behalf. We send only what is needed for the request.

AI can be wrong or incomplete. Oralink is built to act only within the permissions and limits you set and to ask for your approval where you require it, but you remain responsible for reviewing what it prepares and for the actions you allow. Nothing Oralink says is legal, financial or professional advice.

6. Who we share data with

We share data only with the service providers that help us run Oralink, and with the platforms you choose to connect:

  • Database, authentication and back-end hosting (Supabase).
  • Website and application hosting and delivery (our hosting provider and its network).
  • AI processing: text, and voice recordings, for answers, drafts, research, transcription and speech (OpenAI).
  • Payments and subscriptions (Stripe).
  • The platforms you connect: Instagram and WhatsApp (Meta) to read and send messages for your account, Shopify to read your store data, and Google Calendar to read and change the events you ask us to. Their own terms and privacy policies apply to their handling of data.
  • Notification delivery, only if you turn on notifications: the push service of your browser's maker (Apple, Google, Mozilla or Microsoft) carries the notification to your device. The content is encrypted for your device (see section 13).
  • Email delivery for account messages such as verification and password reset.

Team members in your workspace can see the data their role allows. Oralink staff access customer data only when needed to run, secure or support the service. We may disclose data if the law requires it, or to protect our rights, users or the public, and in a business transfer such as a merger, in which case this policy continues to apply to your data.

7. Where data is processed

Our providers may process data outside the European Economic Area. When they do, we rely on safeguards recognised by European law, such as the European Commission's standard contractual clauses or an adequacy decision, where they apply.

8. How long we keep it

Account and workspace data is kept while your account is active. Chats you delete in Ask are permanently erased; chats you archive are kept until you delete them. Integration event records from connected channels and stores are deleted automatically after a limited period (by default 30 days). When you disconnect a channel or store, the stored access is removed; when a store is uninstalled, or Shopify asks us to erase a shop or a customer, we delete the corresponding stored records. Reminders and the push addresses of your devices are kept for a shorter time (see section 13).

When you delete your account, or ask us to, we delete or anonymise your data within a reasonable time, except what we must keep by law (for example billing records) or need to establish, exercise or defend legal claims, and backups, which expire on their normal cycle.

9. Security

We protect data with access controls that separate workspaces from each other, encryption of connection credentials, encrypted connections and logging of what Oralink does. No system is completely secure. If a breach affecting your personal data occurs, we will notify you and the authorities where the law requires.

10. Your rights

If the GDPR or similar laws apply to you, you have the right to access your data, correct it, have it erased, restrict or object to its use, receive it in a portable format, and withdraw consent you gave, at any time. You can do much of this yourself in the app (settings, deleting chats, disconnecting integrations). For anything else, write to contact@oralink.ee. We will answer within one month.

If you are a customer of a business that uses Oralink (for example you wrote to its Instagram account), please contact that business first; it decides how your data is used. We will help it respond to you.

You may also complain to your data protection authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).

11. Children

Oralink is a business service and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

12. Google user data (Google Calendar)

If you connect Google Calendar, Oralink asks Google for permission to see and edit events on the calendar of the account you choose (the scope https://www.googleapis.com/auth/calendar.events), and for your e-mail address (and the standard sign-in identifier, openid) so we can show which account is connected. You can say no on Google's consent screen and keep using the rest of Oralink.

What we do with it: show your events in the Oralink calendar, avoid double bookings, suggest free times, and create, move, change and delete events when you or, within the permissions you set, your assistant do. When you ask Ask Oralink about your calendar (for example "what do I have tomorrow?"), the events needed to answer are sent to our AI provider, which processes them only to produce the answer. We do not use Google user data for anything else.

Oralink's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not sell Google user data; we do not use it for advertising, including personalised or retargeted ads; we do not use it to develop, improve or train generalised AI or machine-learning models; and we do not allow people at Oralink to read it, except with your consent, to investigate abuse or a security problem, or when the law requires it.

How you stop it: disconnect Google Calendar in Connections (we delete the stored tokens at once), and you can also remove Oralink's access at https://myaccount.google.com/permissions. Events already in your Google Calendar stay there, because they belong to you. To ask us to erase anything else we hold about you, write to contact@oralink.ee.

13. Reminders and notifications

Reminders you create in Oralink, by hand or by asking Ask Oralink, are kept in your browser on the device where you created them, and ring there while Oralink is open. Asking Oralink to set one is handled like any other request (see section 5).

Only if you turn on notifications on a device (in Reminders or Settings, after which your browser asks for permission), Oralink can notify you when the app is closed. We then store on our servers (Supabase): the text and due time of your reminders, and the push address of that device with technical details: the keys your browser created for it, the browser and device type, the website address it was created on, whether it is an installed app, and when it was created and last worked. At the due time our server sends the reminder to that push address. When a reminder belongs to a calendar event, only its short text, its time and the event's identifier are kept, not the event itself. If you do not turn on notifications, your reminders are not copied to our servers.

Incoming customer messages may also create a short-lived notification record for each current workspace member: the channel, sender name, short text preview, conversation identifier and time. These records let the app show a new-message banner and unread count. Message push is off by default; if you switch it on and enable notifications on a device, our server sends a new-message alert to that device. In Settings you can hide the sender and text in both in-app and system alerts, or turn either delivery method off. Your device's lock-screen settings still control who can see its notifications.

The notification is carried by the push service of your browser's maker: Apple (Safari), Google (Chrome), Mozilla (Firefox) or Microsoft (Edge). We encrypt the content with the keys your browser created, so the push service cannot read it. It does see that a notification was sent to your device, when, and how large it was.

How long we keep it: your reminders are deleted from our servers when you turn notifications off on your last device, when you delete the reminder, or 7 days after they are due. Message notification records are deleted after 7 days, and only current workspace members can view them. The push address of a device is deleted when you turn notifications off on it, when you sign out on it, when you remove it in Reminders, when its push service tells us it no longer works, or when you delete your account. When you sign out, the reminders kept in that browser are also cleared, so the next person who signs in there does not see them. Turning notifications off in your browser or system settings also stops them; we delete the address once the push service reports that it is no longer valid.

Why we do this: to deliver the reminders and message alerts you choose to receive as part of Oralink, after you have enabled the relevant settings and allowed notifications in your browser where applicable. You can switch message push off without affecting reminders. We use this data only for delivery, not for advertising or analytics.

14. Changes to this policy

We will update this policy when the service or the law changes, for example when we add a feature that handles personal data in a new way. The "Last updated" date above shows the current version, and we will tell you about important changes in the app or by email.