What Obok reads, what it keeps, who else sees it, and how to make it stop.
The data controller is META Project, Al. Jerozolimskie 198N/15, 02-486 Warsaw, Poland. For anything in this policy, including requests to see or delete your data, write to kontakt@obok.ai.
To find your overdue invoices and unanswered scheduling requests, Obok reads your mailbox. Mail permissions are all-or-nothing, so the permission you grant covers your whole mailbox even though Obok only looks at the last 60 days and only keeps threads matching those two patterns. That gap between what is granted and what is used is real, and we would rather you hear it here.
With your Google account connected, and only after you connect it:
gmail.readonly) — message
subjects, bodies, participants and timestamps from the last 60 days, in order
to detect invoice and scheduling threads.calendar.readonly) —
event times, to work out which slots you are actually free for. Used for
availability; event titles and guests are not part of a draft.Obok holds no scope that permits sending, modifying or deleting anything in your mailbox or calendar. A stored connection found to carry such a scope is rejected rather than used.
| Data | Why |
|---|---|
| Threads matching an invoice or scheduling pattern — subject, body, sender, dates | To build the card you approve and to write the draft |
| The drafts Obok wrote | To show you what you are approving |
| Your decisions: approved or rejected, when, and the reason you gave | Rejection reasons become the rules that improve later drafts |
| The reply you actually sent, read from your mailbox on a later scan | To measure how far your version differed from the draft — the main signal of draft quality. The quoted chain your mail client appends is stripped before storage, so the other person's words are not kept |
| Rules — plain-language sentences about how you work | The assistant's memory. Visible, editable and deletable by you at any time |
| Your email address, and a push token if you enable notifications | Identity and notifications |
| Your Google access and refresh tokens, encrypted at rest | To read your mailbox without asking you to reconnect constantly |
| Usage events — when cards were created and decided, and the cost of the model calls | To tell whether the product works and what it costs to run |
The text of the threads Obok works on, and the drafts it writes, are sent to Anthropic's Claude API to generate those drafts. Anthropic processes this on our behalf and does not use it to train models. This is the single most significant disclosure in this policy: the content of the emails Obok handles leaves our servers.
Traffic to the service passes through Cloudflare, which terminates TLS. That means Cloudflare is technically able to see traffic — including mail content in transit — at its edge.
If you enable push notifications, a notification carries the headline of a card and its one-line reason — for example "Invoice #14 to Anna — 12 days overdue" — through Apple's push service. That is real information about your business, on a lock screen, passing through Apple. Turn notifications off if that is not acceptable; nothing else about Obok depends on them.
Your data is not sold, rented, shared with advertisers, or used to build profiles. There is no advertising in Obok, and this website carries no analytics, no cookies and no third-party scripts.
On a single server operated by us in the European Union, with no inbound network ports — it is reachable only through an outbound tunnel. The database listens on the loopback interface only. OAuth tokens are encrypted at rest.
Said plainly, because it is the honest weakness: your mail connection lives on our server rather than on your phone, and the key that protects it lives on the same machine. Someone who compromised that server could reach your mail connection. Moving credentials onto the device is planned and not done.
We process this data to perform the service you asked for (Article 6(1)(b) GDPR) and, for the small amount of usage measurement described above, on the basis of our legitimate interest in knowing whether the product works (Article 6(1)(f)). Connecting a mail account is entirely voluntary and Obok does nothing until you do.
For as long as your account exists. Because Obok is in supervised testing, no automatic retention window is enforced yet — deletion happens when you ask for it, and when the test cohort ends. If you would like your data removed sooner, write to kontakt@obok.ai and it will be deleted.
Under GDPR you may access, correct, delete, restrict or object to the processing of your data, and receive it in a portable form. Several of these are buttons rather than requests:
For anything not covered by a button, write to kontakt@obok.ai. You also have the right to complain to a supervisory authority — in Poland, Prezes Urzędu Ochrony Danych Osobowych.
Obok has no passwords. Your invitation link is itself the credential: possession of it is the whole claim to your account. There is no recovery process, and anyone you forward it to has your access. If you lose it or think someone else has it, write to us and we will issue a new one, which immediately invalidates the old.
Obok is a tool for running a business and is not directed at anyone under 16.
If this policy changes in a way that affects what we do with your data, we will tell invited testers directly rather than quietly editing this page.