Privacy notice
What Oat collects when you use it, why, who else handles it, where it is stored, how long it stays, and what you can ask us to do.
Last updated 30 September 2026
In short
- Airmeet Inc. provides Oat and is responsible for your personal data.
- We use what you give Oat, and what you connect, to prepare, review and publish your work. We do not sell it or use it for ads.
- Your content goes to AI model providers only for the task in hand, and we do not train models on it.
- Data is stored in Singapore; some of our providers are in the United States.
- You can see, correct, delete or export your data and withdraw consent. India and US residents have the extra rights in sections 11 and 12.
- Grievances go to CGO@airmeet.com.
Oat is a product of Airmeet Inc. AI Labs. It is provided by Airmeet Inc., a Delaware corporation.
1. Who we are
Oat is a product of Airmeet Inc. AI Labs. It is provided by Airmeet Inc., a Delaware corporation, at 440 N Barranca Ave #5787, Covina, CA 91723, United States (“Airmeet”, “we”, “us”). Our group company in India is Airmeet Networks Private Limited, WeWork Salarpuria Magnificia, Tin Factory, 78, Old Madras Road, Doorvani Nagar, Bengaluru 560016, Karnataka, India.
For the personal data described here, Airmeet Inc. is the Data Fiduciary under India's Digital Personal Data Protection Act, 2023, the business under the California Consumer Privacy Act, and the controller under other laws that use that word.
2. What this notice covers
This notice covers withoat.com, the Oat app (the Desk, Studio and a workspace's settings), sign-in and chat with Oat on WhatsApp, the emails Oat sends, and the forms on this site. It does not cover websites or apps of other companies, including the social networks and tools you connect; their own policies apply.
Two kinds of people use Oat through a creator rather than directly: readers who subscribe to a creator's newsletter, and visitors to a website a creator hosts on Oat. For their data, the creator decides what is collected and why, and we process it on the creator's behalf. Readers and visitors can write to the creator, or to us and we will pass the request on.
3. What we collect and why
This is the itemised list of the personal data Oat handles, where it comes from, and the purpose for each item.
| Data | Where it comes from | What it is for |
|---|---|---|
| Account: your WhatsApp number, name, email address if you add one, sign-in records and sessions | You, WhatsApp (through Zernio) when you send the sign-in code, and Clerk, our sign-in provider | Signing you in, proving the number is yours, and knowing which workspaces you belong to |
| Workspace membership: your role, invitations, when you were last active | You and the Owner of the workspace | Deciding what you can see and approve |
| What you write and make: posts, drafts, briefs, comments, revision requests, approvals, voice rules, memory and lessons Oat learns from your edits, brand kits, uploads and files | You and your team, in the Desk, Studio or WhatsApp | Preparing, reviewing and publishing your work, and keeping a record of who approved which revision |
| Websites you import, including a full copy of a site you ask Oat to clone (pages, text, images, styles, screenshots) | The public website you name, fetched after you confirm you own it or are authorised to use it | Rebuilding and hosting your site on Oat, and learning your voice from your own writing |
| Wispr Flow meetings and dictations | Wispr Flow, only after you connect it and choose what to import | Using what you said as source material and voice evidence |
| WhatsApp messages and voice notes you send to Oat, their transcripts, and the replies | You, through Oat's WhatsApp Business number (Meta WhatsApp via Zernio) | Chatting with Oat, making and approving work in chat, daily updates you opted into |
| Spoken input in Studio and voice forms (audio, then its transcript) | You, from your microphone, only while you are talking to Oat | Turning speech into text and answers |
| Connected accounts: account names and IDs, granted permissions, encrypted access tokens, your posts and their metrics | Instagram, LinkedIn, X, Threads, TikTok, YouTube, Bluesky and other networks through Zernio; Google Analytics, Search Console and YouTube through Google; your website host | Reading your history and performance, and publishing only what you approve |
| Public web data: search results, news and pages about your topics, and your own public LinkedIn posts | Exa, Parallel, Firecrawl and Tavily search the public web for Oat; Context.dev returns public brand details (logos, colours) for a domain | Research, sources for drafts, and your voice corpus where LinkedIn does not share your past posts with apps |
| Newsletter subscribers: email addresses, confirmation and unsubscribe status, deliveries, opens, clicks, bounces, complaints | Readers who subscribe to a creator's newsletter; Resend delivery reports | Sending the creator's newsletter and honouring unsubscribes (we act for the creator) |
| Visits to websites hosted on Oat: page, referrer, device type and a daily visitor hash | The visitor's browser. No cookies; the IP address is used to make the hash and is not stored | Showing the creator how their site is read (we act for the creator) |
| Product analytics: pages viewed, clicks, errors, performance, session recordings with typed text masked, server logs with secrets and contact details removed, and a record of each AI call (model, cost, and the prompt and answer with secrets removed) | Your browser and our servers, sent to PostHog through withoat.com/ox | Finding bugs, understanding which features help, and keeping AI quality and cost in check |
| Access and contact requests: name, email, what you make, site address, role, message | The forms on this site | Replying to you and deciding whether Oat fits |
| Usage, audit and technical records: who did what and when, job states, model usage and cost, IP address, browser, request path, errors | Generated by the service, Vercel and Clerk | Security, fraud prevention, debugging, staying within budget, and meeting legal duties |
We do not collect payment details: Oat is free during its beta. We do not buy personal data, and we do not run advertising pixels or advertising cookies.
4. How AI processing works
Oat uses large language models to research, draft, check, transcribe and make images. Calls go through the Vercel AI Gateway to the model provider configured for that task: today Anthropic (Claude) for writing and site building, OpenAI (GPT) for Studio, WhatsApp conversations, realtime voice and transcription, Google (Gemini) for voice forms, and TypeSafe AI for checking drafts. The model in use can change; the Desk shows which model prepared each draft.
What is sent: the material the task in hand needs, such as your brief, the relevant parts of your archive and voice rules, the draft, research found for it, your message or transcript, and for site work the pages being rebuilt. Access tokens and passwords are never sent to a model.
Retention by model providers: for the checking and routing calls, Oat asks the Gateway for zero data retention. Other calls run under each provider's standard API terms, under which a provider may keep inputs and outputs for a limited period, for example for abuse monitoring. We do not claim zero retention for those calls.
No training on your content: we do not use your content to train AI models. The voice rules and lessons Oat learns from your edits are stored in your workspace, shown to you, and can be changed or removed.
Model output is software output. A voice score says how close a draft is to your voice rules; it does not prove who wrote something, and a cited source does not prove a fact. You review and approve before anything is published.
5. Product analytics and session recordings
On withoat.com and in the app, PostHog records pageviews, clicks, performance, errors and a replay of each session. It runs for analytics and recordings whenever you use Oat; there is no separate consent prompt for it. Its traffic goes through Oat's own address (withoat.com/ox), and it is never loaded on websites or newsletter pages creators host on Oat.
What recordings hide: everything you type is masked, except checkboxes, radio buttons and sliders. Password and one-time-code fields, token and key fields, Clerk's code boxes, the account-connection credentials dialog and the WhatsApp QR code are not recorded at all, and the WhatsApp sign-in code is masked. Request and response headers and bodies are not recorded, and sign-in codes and tokens in page addresses are removed. When you are signed in, events are linked to your account ID and, if you added them, your name and email address.
From our servers, PostHog also receives errors and server log lines with secrets, email addresses and phone numbers removed, and a record of each AI call: the model, tokens, cost, timing, and the prompt and answer with secrets removed and long text cut at 12,000 characters. That lets us find and fix bad answers and see what each feature costs.
PostHog is our service provider, hosted in the United States, and does not use this data for advertising. Recordings are kept for 30 days and events for 12 months.
6. Who receives your data
- Service providers that run parts of Oat for us, bound by contract to use the data only for that. Each is listed, with what it receives and where, on the subprocessors page.
- Platforms you connect or publish to, which receive what you approve and what the connection needs, under their own terms.
- Other members of your workspace, who see the workspace's content according to their roles.
- Our group companies, including Airmeet Networks Private Limited, where needed to run and support Oat, under this notice.
- Authorities and advisers, where the law requires it, to protect rights and safety, or to our lawyers and auditors.
- A buyer or successor, if Airmeet or Oat is merged, sold or restructured; we will tell you before your data becomes subject to a different privacy notice.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We may publish aggregated figures that cannot identify anyone.
7. Where your data is stored and international transfers
Oat's database and private file storage (Neon) and its web functions (Vercel) run in Singapore. Some services we use run in the United States, including sign-in (Clerk), email (Resend), product analytics (PostHog), the queue behind background jobs (Vercel Workflows) and the AI model providers; the full list with regions is on the subprocessors page. So your data may be processed outside the country you live in.
From India: the DPDP Act allows transfers outside India except to countries the Government of India restricts by notification. We do not transfer personal data to any restricted country.
From the EEA or the UK: where a transfer goes to a country without an adequacy decision, we rely on Standard Contractual Clauses or an equivalent safeguard. Questions about this go to our Data Protection Officer at dpo@airmeet.com.
8. How long we keep it
We keep personal data only as long as the purpose needs it, then delete or anonymise it.
| Data | Kept for |
|---|---|
| Account and membership | While your account is open. After you ask us to delete it, removed from active systems within 30 days |
| Workspace content, imports, clones, uploads, WhatsApp messages and transcripts | Until you delete them or ask us to delete the workspace; then removed from active systems within 30 days |
| Backups | Up to 30 days; deleted data leaves backups as they expire |
| WhatsApp sign-in codes | 10 minutes; the one-time sign-in ticket lasts 5 minutes |
| Connection tokens | Until you disconnect the account |
| On-demand web research results | About one day, as a cache |
| Newsletter subscribers | Until the creator deletes them or the newsletter. An unsubscribe is kept so it is honoured |
| Product analytics events (PostHog) | 12 months |
| Session recordings (PostHog) | 30 days |
| Security, access and server logs | 1 year, as the DPDP Rules, 2025 (rule 8(3)) require |
| Access and contact requests | Until the matter is closed, and at most 12 months after our last reply |
| Records of your privacy choices (opt-outs, unsubscribes, STOP) | As long as needed to honour them |
We may keep some data longer where the law requires it or to establish or defend legal claims, and only for that.
9. How we protect it
- Connections to Oat and between Oat's services are encrypted in transit (HTTPS/TLS).
- Each workspace's data is kept apart by row-level security in the database, and every read and write checks membership.
- Access tokens and other connection secrets are encrypted with AES-256-GCM before they are stored.
- AI models never receive credentials, and nothing is published without an approval tied to one exact revision.
The security page describes these controls. No system is perfectly secure; section 15 says what we do if something goes wrong.
10. Your rights and choices
Wherever you live, you can ask us to:
- tell you what personal data we hold about you and how we use it, and give you a copy;
- correct, complete or update it;
- delete it;
- withdraw a consent you gave, as easily as you gave it;
- stop sending you marketing or updates.
Approved pieces can be exported as Markdown or HTML from the Desk. For everything else, email support@airmeet.com with “Oat privacy” in the subject, from the email or WhatsApp number on your account if you can. We may ask you to confirm you control the account before acting, and we answer within 30 days. Sections 11 and 12 add the rights and timelines that Indian and US law give.
11. If you are in India (DPDP Act, 2023)
Notice and consent. Section 3 is the itemised notice of the personal data we process and the purpose for each. Where we rely on your consent (for example, WhatsApp daily updates, importing Wispr Flow data, or connecting an account), it covers that purpose only. The daily-update box on the sign-in page is ticked by default; you can untick it before you continue. You can withdraw it at any time from settings, by disconnecting the account, by sending STOP on WhatsApp, or by writing to us. Withdrawal stops future processing for that purpose; it does not undo processing already done. Some data we process for legitimate uses the Act allows, such as keeping your account working and meeting legal duties.
Your rights as a Data Principal. You can ask for a summary of your personal data and the processing, and the identities of other Data Fiduciaries and processors we shared it with; ask for correction, completion, updating or erasure; have your grievance redressed; and nominate another person to exercise your rights if you die or become incapable. To nominate someone, write to us with their name and contact details.
Grievance Officer. Grievance Officer, Airmeet Inc., email CGO@airmeet.com; postal address in India: Airmeet Networks Private Limited, WeWork Salarpuria Magnificia, Tin Factory, 78, Old Madras Road, Doorvani Nagar, Bengaluru 560016, Karnataka, India. The Data Protection Officer can be reached at dpo@airmeet.com. We acknowledge a grievance within 72 hours and resolve it within 30 days, and in any case within the 90 days the DPDP Rules, 2025 allow.
Consent Managers. Oat does not currently accept consent through a Consent Manager registered with the Data Protection Board. You can give, manage and withdraw consent directly with us as above.
Children. Oat is for people aged 18 or over. We do not knowingly process the personal data of anyone under 18, and we do not track, profile or target advertising at children. If we learn we have, we delete it. A parent or guardian can write to the Grievance Officer.
Breaches. If a personal data breach affects you, we will tell you without delay, in plain words: what happened, when, the likely consequences, what we are doing, what you can do, and whom to contact. We will report it to the Data Protection Board of India as the DPDP Rules require, with a full report within 72 hours of becoming aware of it.
Complaints to the Board. Please use our grievance process first. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
Information Technology Act, 2000. We follow reasonable security practices for sensitive personal data under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent they still apply. Complaints about content hosted on Oat (such as a site or newsletter a creator publishes) can be sent to the Grievance Officer under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; we acknowledge them within 24 hours and act within 15 days, or faster where those Rules require.
12. If you are in the United States
California (CCPA, as amended by the CPRA)
In the last 12 months we collected these categories of personal information, from the sources and for the purposes in section 3:
- Identifiers: name, phone number, email address, account and device identifiers, IP address.
- Customer records: account and contact details.
- Internet or other electronic network activity: use of the app and site, session recordings, logs.
- Approximate location derived from IP address (not precise geolocation).
- Audio and electronic information: voice notes and spoken input.
- Professional information you choose to share, such as your role and what you make.
- Inferences: the voice rules and preferences Oat learns from your edits.
- Sensitive personal information: account log-in details, and the contents of messages where Oat is not the intended recipient (for example, Wispr Flow meetings you import). We use it only to provide the service you asked for, as the CCPA permits, and not to infer characteristics about you.
We disclose these categories to the service providers on the subprocessors page for the business purposes in section 3. We do not sell or share personal information (share meaning for cross-context behavioural advertising), and we have not done so in the last 12 months. We do not knowingly sell or share the personal information of anyone under 16.
Your rights: to know what we collect, use and disclose; to delete; to correct; to opt out of sale or sharing; to limit the use of sensitive personal information (we already use it only as the CCPA permits); and not to be discriminated against for using any of these rights. We will not deny service, charge a different price or give a different quality of service because you did.
Global Privacy Control. Because we do not sell or share personal information, there is nothing for a Global Privacy Control or Do Not Sell or Share request to switch off today. If that ever changes, we will treat a GPC signal from your browser as a valid opt-out for that browser and any account we can link to it.
How to ask. Email support@airmeet.com with “Oat privacy” in the subject. We confirm receipt within 10 business days and answer within 45 days, which we may extend once by another 45 days with notice. We verify requests by matching them to the email or WhatsApp number on the account. An authorised agent may ask for you with your signed permission; we may still ask you to confirm your identity with us directly. California's “Shine the Light” law does not apply because we do not disclose personal information to third parties for their direct marketing.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws have similar rights: to confirm whether we process their data and access it, correct it, delete it, get a portable copy, and opt out of targeted advertising, sale and profiling with legal or similarly significant effects. We do not do targeted advertising, sale or such profiling. We extend these rights to every US resident, whether or not their state's law applies to us. If we decline your request, you can appeal by replying to our answer with “Appeal” in the subject; we answer appeals within 45 days (60 days in Colorado) and tell you how to contact your state attorney general if you disagree.
Children (COPPA)
Oat is not directed at children under 13 and is for adults 18 and over. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, write to support@airmeet.com and we will delete it.
Email (CAN-SPAM)
The emails Oat sends you are about your account and your work, such as a piece being ready or a sign-in step. If we ever send marketing email, it will say who it is from, have an honest subject, include our postal address and a working unsubscribe link, and we will honour an unsubscribe within 10 business days.
WhatsApp messages (TCPA)
Oat messages you on WhatsApp only after you message Oat first (for example, to sign in or chat). Daily updates are sent only if the daily-update box is ticked when you sign in; it is ticked by default, and you can untick it before you continue. Replies to your messages are sent inside WhatsApp's 24-hour window. Send STOP at any time to stop daily updates, and START to turn them back on. Consent is never a condition of using Oat. Your carrier's data charges may apply.
13. Emails, WhatsApp and newsletters
Notification emails about your work are sent through Resend. WhatsApp sign-in, chat and daily updates go through Oat's WhatsApp Business number, run by Meta and connected through Zernio; Meta's WhatsApp terms and privacy policy apply on WhatsApp's side.
Newsletters a creator sends with Oat are the creator's. Oat requires double opt-in on its shared sending domain, adds a one-click unsubscribe link and header to every issue, and records deliveries, opens, clicks, bounces and complaints so the creator can see them and so unsubscribes and complaints are honoured.
14. Cookies and similar technologies
Oat uses cookies set by Clerk and by Oat to keep you signed in and to protect account connections, browser storage to remember small preferences and unsaved edits, and PostHog cookies and storage for product analytics and session recordings. Websites hosted on Oat set no cookies for analytics. The cookies page lists each one, what it does and how long it lasts.
15. If something goes wrong
If we become aware of a breach of personal data, we contain it, investigate it, and tell affected people and regulators as the law requires: in India as section 11 describes, and in the United States under the breach notification law of each affected person's state. Workspace Owners are told about anything that affects their workspace.
16. Changes to this notice
When this notice changes, the date at the top changes too. For material changes we email workspace Owners, or message you on WhatsApp if that is the only contact we have, before they take effect, and ask for fresh consent where the law requires it.
17. Contact
- Privacy requests and questions: support@airmeet.com (subject “Oat privacy”)
- Grievance Officer (India): Grievance Officer, Airmeet Inc., CGO@airmeet.com; Airmeet Networks Private Limited, WeWork Salarpuria Magnificia, Tin Factory, 78, Old Madras Road, Doorvani Nagar, Bengaluru 560016, Karnataka, India
- Data Protection Officer: dpo@airmeet.com
- Legal notices: legal@airmeet.com
- Post: Airmeet Inc., 440 N Barranca Ave #5787, Covina, CA 91723, United States
- Post in India: Airmeet Networks Private Limited, WeWork Salarpuria Magnificia, Tin Factory, 78, Old Madras Road, Doorvani Nagar, Bengaluru 560016, Karnataka, India
You can also reach us through the contact page.

