[00] legal ยท privacy

Privacy Policy

Last updated: July 23, 2026

Oakspace Inc. ("Oak", "we", "us", or "our") operates the Oak version control service including the hosted platform at oak.space and the Oak CLI. This Privacy Policy (this "Policy") describes what data we collect, how we use it, and your rights regarding that data.

For personal data contained in repositories or other content that Oak processes on behalf of an account holder or organization, Oak generally acts as a processor or service provider, and the relevant account holder or organization determines the purposes and means of processing. Requests concerning that personal data should generally be directed to the relevant account holder or organization.

[01] data we collect

What we collect.

Account information

To create an account we collect a username, an email address, and a password (kept only as a salted hash). You may optionally add a display name and avatar. If you sign in with GitHub instead, we receive your GitHub username, user ID, and associated email to identify you — we request identity scopes only (read:user user:email), never repository access.

Your code and content

When you push repositories to Oak, we store your code, commit history, branch metadata, and associated content (blobs, manifests). This data is stored on our servers to provide the version control service. If you make a repository public, its code, content, and associated repository metadata will be publicly accessible.

Usage data

We collect basic usage information including:

  • IP addresses and request metadata (timestamps, endpoints accessed)
  • CLI version and platform information sent with API requests
  • Repository names, branch names, and operation types (push, pull, etc.)
  • Error logs and crash reports

Server logs

Our servers automatically log HTTP requests, including IP addresses, user agents, request paths, and response codes. These logs are used for debugging, security monitoring, and service improvement.

Payment information

Paid plans are billed through Stripe, our payment processor. When you subscribe, Stripe collects and processes your payment-card details directly — we never see or store full card numbers. We retain a Stripe customer and subscription identifier, your billing email, and your plan and seat count so we can operate your subscription.

Importing from GitHub

If you connect GitHub to import a repository, we use a short-lived, read-only installation token scoped to the repositories you select, solely to copy the code you choose to import into Oak. We do not request write access, and you can revoke the connection from your GitHub settings at any time.

We collect personal data directly from you, automatically when you use Oak, and from services you choose to connect, such as GitHub and Stripe.

[02] how we use it

How we use your data.

We use collected data to:

  • Provide and operate the Oak service (storing and syncing your code)
  • Administer accounts, subscriptions, and billing
  • Maintain and improve service reliability and performance
  • Debug issues and respond to support requests
  • Detect and prevent abuse, fraud, and security threats
  • Communicate with you about the service, security, billing, and, where permitted by law, product updates
  • Comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy
  • Generate aggregate, anonymized usage statistics

Where applicable law requires a legal basis, we process personal data as necessary to perform our contract with you, comply with legal obligations, pursue our legitimate interests in operating, securing, improving, and protecting Oak, and with your consent where required.

We do not sell your personal data or code to third parties or share personal data for cross-context behavioral advertising or targeted advertising. Oak itself does not train machine learning models on your code. We do not share your code with third parties except as required to operate the service (e.g., cloud infrastructure providers), at your direction, to comply with law or protect rights, safety, and security, or in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to appropriate protections.

No AI calls on your behalf. Oak does not send your code, branch names, diffs, or any other repository content to AI providers, and makes no AI calls on your behalf.

Email. We send account, security, and billing notices through Resend, our email provider — these are required to operate your account. We may also send occasional product updates where permitted by applicable law; every such message includes an unsubscribe link, and opting out does not affect required account email.

Any other coding agent you run alongside Oak (Claude Code, Cursor, GitHub Copilot, etc.) is a separate integration with its own privacy posture; treat what you put into those tools accordingly. Oak receives the code, repository data, and usage information transmitted to Oak through those agents' use of the service.

[03] storage & retention

Where it lives, how long it stays.

Data storage & security

Your data is stored on servers hosted by third-party cloud infrastructure providers. We use reasonable administrative, technical, and organizational safeguards designed to protect personal data, including encrypted connections (TLS) for data in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Important: Because Oak is experimental, we strongly recommend maintaining independent backups of any code you store with us. We are not responsible for data loss.

Data retention

We retain your code and repository data for as long as your repositories exist on the service. Server logs and usage data are retained for up to 90 days for operational purposes. We retain other personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the service, comply with legal obligations, resolve disputes, and protect security. Residual copies may remain in backups until overwritten in the ordinary course.

If you stop using the service, we may delete inactive repositories and associated data after a reasonable period of inactivity. We will make reasonable efforts to notify users before deleting data, but cannot guarantee advance notice during the experimental phase, except where notice is required by applicable law.

[04] the CLI

What the CLI does on your machine.

The Oak CLI runs locally on your machine. It:

  • Reads and writes files only within Oak-initialized repository directories
  • Stores local repository data in a .oak directory within your project, or in a local mount cache under ~/.oak/mounts/ when you use oak mount
  • Sends your code to Oak servers only when you explicitly publish it (for example oak push, oak commit --push, or finishing a mount)
  • Sends your CLI version and platform with API requests for compatibility purposes
  • Does not collect telemetry or analytics beyond what is described above
[05] the rest

Cookies, third parties, your rights.

Cookies and tracking

When you sign in, Oak sets a single, strictly-necessary, first-party cookie to keep you logged in (plus a short-lived cookie during the GitHub sign-in handshake). These are essential to operate the service, are not used for advertising, and are used without consent only where permitted by applicable law.

For website analytics we use Plausible Analytics, which we configure without cookies or persistent identifiers to provide aggregated usage statistics. We do not use analytics to serve targeted advertising or build profiles of individual visitors. We use no other third-party tracking scripts.

Because Oak does not collect personal data about your online activities over time and across third-party websites for targeted advertising, Oak does not respond differently to browser "Do Not Track" signals. We honor legally recognized opt-out preference signals where applicable.

Service providers (subprocessors)

We rely on a small set of third-party providers to operate Oak. They process data only as needed to deliver the service, subject to contractual obligations to protect the data and use it only for specified purposes:

  • Amazon Web Services — cloud compute hosting (United States)
  • PlanetScale — managed database for account and repository metadata
  • Cloudflare — object storage (R2) for your code, plus CDN/edge delivery
  • Stripe — payment processing for paid plans
  • Resend — transactional and product-update email
  • GitHub — optional sign-in and repository import, only if you connect it
  • Plausible — privacy-friendly, cookieless website analytics

Our infrastructure is currently hosted in the United States. If you access Oak from outside the U.S., your data is transferred there to provide the service. Where required by applicable law, we use recognized transfer mechanisms, such as the European Commission's Standard Contractual Clauses, and other appropriate safeguards for international transfers.

Your rights

You can generally manage your repository data as follows:

  • Access your data — while your account and repositories remain active, you can access your code via oak pull
  • Delete your data — contact us to request deletion of your repositories and account data
  • Export your data — pull your repositories locally at any time, or use oak export to replay history into a fresh git repo

Depending on where you live, you may also have legal rights to request access to, correction or deletion of, or a portable copy of your personal data; to object to or restrict certain processing; to withdraw consent; to opt out of the sale or sharing of personal data or its use for targeted advertising; and to appeal a denial of a privacy request. Oak does not sell or share personal data for cross-context behavioral advertising or process personal data for targeted advertising. You may also have the right to complain to your local data-protection authority.

To exercise these rights or ask questions, email [email protected]. We may need to verify your identity and may deny or limit a request where permitted by law. You may use an authorized agent where applicable, and we will not discriminate against you for exercising a privacy right.

Children's privacy

Oak is not directed at children under 13, and users must satisfy the eligibility requirements in our Terms of Service. We do not knowingly collect personal information from children under 13 or from anyone who does not satisfy those eligibility requirements without legally valid parental consent. If you believe a child has provided us with personal data, please contact us so we can delete it.

Changes to this Policy

We may update this Policy from time to time. We will update the "Last updated" date at the top of this page. If a change materially affects your privacy rights, we will provide additional notice, such as by email or through the service, before the change takes effect where required by applicable law.

Contact

Questions about this Policy? Email [email protected] or write to Oakspace Inc. at 1100 Boylston Ave., Suite 506, Seattle, WA 98101.