Effective 11 August 2026
Privacy Policy
Who we are
Oda is a product of Odapyn SAS, Résidence du Val, 91120 Palaiseau, France (SIREN 948 444 468). Odapyn SAS is the data controller for the personal data described in this policy.
This policy covers the Oda product at oda.do and app.oda.do. Questions, requests, and complaints: privacy@oda.do.
What Oda does with your accounts
Oda drafts business work — social posts, outreach emails, ads, websites — and you approve every action before it happens. Nothing is published, sent, or spent on your behalf without your explicit approval in the app. This is enforced in the product: drafts are stored with a draft status and only leave it when you approve them.
Data we collect
Account data. Your email address, name, profile picture, and how you signed in (Google Sign-In or email and password). If you sign in with a password we store only a cryptographic hash, never the password.
Business context. What you tell Oda about your business, plus the work Oda produces for you: brand details, drafts, posts, emails, contacts and leads you add, websites, tasks, and your conversation history with Oda.
Connected account data. When you connect a third-party account, Oda stores an access token for it and the data needed to operate that connection. See the Instagram section below.
Payment data. Subscription and credit purchases are processed by Stripe. Oda stores your Stripe customer identifier, plan, and billing status. Oda never sees or stores your card number.
Technical data. Logs, error reports, and usage events needed to run, secure, and debug the service.
Instagram and Meta Platform data
Connecting Instagram is optional and only available for Instagram professional (Business or Creator) accounts. When you connect one, Oda requests these permissions:
instagram_business_basic— to identify the connected account (its Instagram user ID and username) and confirm the connection is working.instagram_business_content_publish— to publish a post only after you have approved that specific post in Oda, and to read back the resulting post ID and permalink so we can show you the published result.
For posts published through Oda, we also read aggregate performance metrics — reach, saves, shares, likes, and comment counts — so the app can show you how your content performed. These are counts, not the content of anyone's comments.
Oda does not read your direct messages, post without your approval, follow, like, or comment on your behalf, scrape Instagram, or use automation that simulates human interaction with the Instagram app. Oda does not sell Instagram data or use it for advertising or profiling.
Your Instagram access token is encrypted at rest and used solely to carry out actions you have approved. You can disconnect Instagram at any time from the Social section in Oda, which deletes the stored token. You can also revoke Oda from Instagram directly under Settings → Apps and Websites. Revoking through Meta triggers our data-deletion endpoint, which removes the stored token and associated platform data.
How Oda uses AI, and what that means for your data
Oda is built on large language models. To draft your content and run your tasks, the relevant parts of your business context and instructions are sent to the model providers listed below and processed under their API terms. Model providers may process this data outside the European Economic Area.
Content retrieved from the public web or received by email is treated as untrusted data by the system and is never executed as instructions.
Why we process your data (legal bases)
- Performance of a contract — to provide the service you signed up for: drafting, publishing on your approval, and managing your workspace.
- Legitimate interests — to keep the service secure, prevent abuse, debug failures, and improve the product.
- Consent — for optional integrations such as Instagram, Google, and LinkedIn. You can withdraw consent at any time by disconnecting the integration.
- Legal obligation — to meet accounting, tax, and other statutory duties.
Who we share data with
We do not sell your personal data. We share it with service providers who process it on our behalf, under contract, and only to run Oda:
- Infrastructure and storage — application hosting, databases, and object storage.
- AI model providers — to generate drafts and run your tasks.
- Content, media, and research providers — image and video generation, transcription, and web search.
- Email delivery and payments — to send and receive email on your instruction, and to process subscriptions.
- Monitoring providers — error tracking and debugging.
- Platforms you connect — Meta (Instagram and, if used, Meta Ads), Google, LinkedIn. Data flows to these only when you connect them and approve an action.
Every company in these categories is named individually, with what it does and where it processes data, on our Subprocessors page.
We may also disclose data where legally required, or to establish, exercise, or defend legal claims.
International transfers
Oda's application and primary database are hosted in the European Union. Some providers above process data outside the European Economic Area. Where that happens, we rely on the safeguards permitted under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
We keep your account and business data for as long as your account is active. When you delete your account, we delete your workspace data and revoke stored third-party tokens. Limited records may be retained where we are legally required to keep them — for example invoices for accounting purposes — and backups are purged on a rolling cycle.
Access tokens for a disconnected integration are deleted immediately on disconnection.
Security
Third-party access tokens are encrypted at rest. Access to production systems is restricted and authenticated, secrets are held in a managed secret store, and data is encrypted in transit over HTTPS. No system is perfectly secure, but we treat credentials for your connected accounts as the most sensitive data we hold.
Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. Write to privacy@oda.do and we will respond within one month.
You also have the right to lodge a complaint with your local supervisory authority. In France this is the CNIL (cnil.fr).
Deleting your data
You can delete your Oda account from the app, which removes your workspace data and revokes stored tokens. To request deletion by email, write to privacy@oda.do from the address on your account.
To remove only Meta data: remove Oda from your Instagram account under Settings → Apps and Websites. Meta then notifies Oda through our data-deletion callback and we delete the associated tokens and platform data, returning a confirmation code you can use to check the status of the request.
Children
Oda is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
Changes
We will update this policy as the product changes. Material changes will be announced in the app or by email, and the effective date at the top of this page will change.