Privacy Policy.
This policy explains what personal data we process, why, and the rights you have. We aim to keep it plain — not lawyerly for its own sake.
Last updated · 5 August 2026
1. Who we are
oka is a product of NCG Invest UG (“oka”, “we”, “us”). NCG Invest UG is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).
For any privacy question or request, contact us at privacy@getoka.ai.
2. Data we collect
Account data: your name, email address, and authentication details when you sign up.
Company and raise data: information you provide about your company and round, including your website, and the funds, notes, and pipeline you create in your workspace.
Connected-account data: with your explicit consent, email metadata from Gmail — the To, From, Cc, and Date headers of your messages; your LinkedIn connections (name, company, and role) when you connect your LinkedIn account; and contacts you import. We use these to map your network to relevant funds and surface warm intro paths. We never process or store the content of your emails; we hold professional metadata about who you've been in contact with, not the contents of your inbox. When you connect LinkedIn, we read only your own connections and basic professional profile fields — never your LinkedIn messages or other members' private data, and we never post, message, or act on your behalf. If you connect Google Calendar, we read your calendar events (attendees and times, never titles or descriptions) solely to map who you've met.
Contacts derived from your email: where a message header identifies a person at an investor you correspond with, we create a contact record for them in your workspace — their name and email address — so you can see who at a fund you already have a relationship with. These records are private to your workspace: other Oka customers never see them, and their email addresses are never shown to anyone outside your workspace. We do not create records for shared mailboxes (such as info@ addresses), and we never derive a person's name from an email address — where the header carries no name, the relationship stays attached to the fund rather than to a person. You can remove any of these people from your network at any time, and they are deleted when your workspace is deleted.
Drafts we place in your Gmail: if you ask oka to write an outreach email and choose to export it, we create a DRAFT in your own Gmail account and nothing more. oka never sends email from your account — not automatically, not on a schedule, and not through any agent. You review the draft in Gmail and press send yourself. We ask for the permission that allows this only at the moment you export a draft, so if you never use the feature, you never grant it.
Account connections run through our processor Unipile SAS (France, EU) under a data processing agreement. Technically, the authorization you grant when connecting covers broader account access than we use; our systems are built so that only the metadata described above can be retrieved and stored — there is deliberately no code path that reads message content. You can disconnect at any time in Settings, which deletes the connection at Unipile as well.
Investor data: professional information about investors and the funds they work at — names, roles, firms, and public profile links. This is collected from public and third-party professional sources (such as fund websites and professional networking profiles), not from your inbox content.
Usage data: technical logs such as device, browser, and interaction events, used to operate and improve the product. This includes product analytics and session recordings, described in section 7.
3. How we use your data
To provide the service: matching you with relevant investors, mapping intro paths, and powering your fundraising workspace.
To improve the product: understanding how features are used and where they can be better.
To communicate with you: service messages, support, and — where permitted — product updates you can opt out of.
4. Legal bases (GDPR Art. 6)
We process your personal data on the basis of contract (to deliver the service you signed up for), consent (for connecting Gmail and LinkedIn and importing contacts, and for optional communications), and legitimate interests (to secure and improve the product), balanced against your rights.
Investor data — professional information about investors who are not oka users — is processed on the basis of legitimate interests (Art. 6(1)(f)): helping founders identify and reach relevant investors, using professional information from public and third-party professional sources. We balance this against the investor's interests and rights, and we honour objections (see section 9).
Shared professional profiles: when you import an investor or a professional contact, the professional profile fields — name, the fund or firm they work at, their role or title, and their public LinkedIn profile — become part of oka's shared investor graph, so that other founders can also find and reach that investor. This is processed on the basis of legitimate interests (Art. 6(1)(f)) in maintaining an accurate, collaboratively-built map of the investor community, balanced against the individual's interests and rights, and subject to the same objection and erasure route (see sections 9 and 10). Direct contact details you import — a person's email address and phone number — are NOT added to the shared graph: they remain private to your own workspace and are never shown to other customers.
5. Sharing and processors
We do not sell your personal data. We share data only with service providers (processors) who help us run oka — for example cloud hosting and database providers, and Unipile SAS (EU) for account connections (section 2) — under data processing agreements and only to the extent necessary.
The one exception, described in section 4, is the shared professional profile fields of investors and professional contacts (name, fund, role, LinkedIn), which are visible to other oka customers so the investor graph stays accurate for everyone. Imported email addresses and phone numbers are never shared this way — they stay in the workspace that imported them.
Where data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
6. Google user data and Limited Use
oka's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, that means four commitments about anything we receive from your Google account — email metadata, calendar events, and the contacts you import. We use it only to provide and improve the user-facing features described in this policy: mapping who you already know to the funds in your pipeline, and helping you draft outreach. We never use it for advertising, and we never sell it. We do not transfer it to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition — and never for their own purposes. And no human at oka reads it, except with your explicit permission (for example when you ask support to look at a problem), where security or the law requires it, or in aggregated and anonymised form for internal operations.
We do not use Google user data to train, develop, or improve generalised artificial intelligence or machine-learning models — neither our own nor anyone else's.
Where a feature you invoke uses AI, the relevant details are sent to our AI providers (Anthropic and OpenAI) purely to produce your result — for example, when you ask oka to draft an email, the recipient's first name and the professional context of that fund go into the request so the draft reads properly. The content of your emails is never included, because we never hold it. These providers act as our processors under agreements that prohibit training on our data, and they return the result and retain nothing for their own purposes.
7. Product analytics and session recordings
We use PostHog to understand how oka is used and where it falls short. PostHog is hosted in the European Union (Frankfurt) and acts as our processor under a data processing agreement; your usage data is not transferred outside the EEA for this purpose.
No cookies, no tracking across sites. PostHog is configured to store nothing on your device — no cookies and no browser storage — and we do not use it to track you across other websites. Because nothing is stored on your device, no cookie banner is required. This processing rests on our legitimate interests (Art. 6(1)(f)) in operating, securing, and improving the product, balanced against your rights.
What we record: pages viewed, clicks and similar interactions, approximate location derived from your IP address at country level, and technical details such as browser and device. For signed-in users these are linked to your user account so we can understand how real workflows unfold. We also record a small number of named product events — for example that a search was run or an intro was requested — deliberately without the content: we record that a search happened and how many results it returned, never the words you typed.
Session recordings: inside the signed-in product only, we record a replay of the pages you interact with, so we can see where the product is confusing. We do not record our public website — browsing our marketing pages is never captured this way. Everything you type is masked before it leaves your browser — the recording never contains the content of any input field — and areas showing private notes and contact details are blanked out. We use these recordings only to diagnose and improve the product.
You can object to this processing at any time under Art. 21 GDPR by emailing privacy@getoka.ai, and we will exclude your account from analytics and session recording. Setting your browser's “Do Not Track” signal also disables it.
8. Retention
We keep personal data for as long as your account is active and as needed to provide the service. You can request deletion at any time; we will delete or anonymise data unless we are required to retain it by law.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on legitimate interests. You may also withdraw consent at any time and lodge a complaint with a supervisory authority.
If you're an oka user, you can export everything we hold and delete your account directly from Settings → Your data, and disconnect Google in one click. To exercise any other right, email privacy@getoka.ai.
10. Investors: objection and erasure
If you are an investor in our dataset and not an oka user, you have the right to object to our processing and to request erasure. Use our remove-my-data page — once we verify the request, we delete your information and add a suppression record so it cannot be re-ingested. You can also reach us at privacy@getoka.ai.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and adjust the “last updated” date above. Material changes will be communicated where appropriate.