Privacy Policy

Effective date: August 7, 2026

This Privacy Policy explains how OctoLead, operated by Hanmin Wang in China ("OctoLead," "we," "us," or "our"), collects, uses, stores, and shares information when you use the OctoLead website, cloud agent, connectors, and related services (the "Service").

Please read this Policy before using the Service. The features you choose and the permissions you grant determine what information we process.

1. Information We Process

We may process the following categories of information:

  • Account and contact information, such as your email address, authentication identifiers, profile information, and communications with us.
  • Task and content information, such as prompts, chat messages, instructions, uploaded files, generated files, artifacts, tool results, and feedback.
  • Connector credentials and authorization information, such as OAuth access tokens, refresh tokens, granted scopes, account identifiers, and connection status. We do not receive your Google password.
  • Connected-service data that you ask OctoLead to retrieve or act on, including data from Google services described below and other third-party connectors you enable.
  • Technical and usage information, such as IP address, browser and device information, timestamps, request and error metadata, feature usage, and security events.
  • Transaction information, if you purchase a paid offering. Payment processors may process full payment credentials; OctoLead may receive transaction status and related billing records rather than full card details.

2. Google User Data

OctoLead accesses Google user data only after you initiate a connection and complete Google's OAuth consent flow. The exact permissions are shown on Google's consent screen and depend on the connector or Google Workspace suite you select.

Google Workspace

Depending on the suites you enable, OctoLead may request identity permissions and permissions for Google Docs, Sheets, Slides, Drive, or Gmail. These permissions may allow OctoLead to read, create, edit, organize, send, or otherwise act on content when needed to carry out your explicit task. For example, the Gmail integration may require gmail.modify, and the Docs, Sheets, Slides, and Drive integrations may request the corresponding Google Workspace scopes. Do not connect a Google account or enable a suite unless you are authorized to let OctoLead perform the requested actions on that account.

Google Analytics

The Google Analytics connector requests analytics.readonly. It may list Analytics accounts and GA4 properties you can access and retrieve reporting data so OctoLead can produce the analysis or summary you request. It does not use this connector to modify Analytics configuration or data.

Google Ads

The Google Ads connector requests the https://www.googleapis.com/auth/adwords scope. Google defines that scope broadly, but OctoLead's current product implementation uses it only for account discovery and bounded, read-only reporting. Current operations can list accessible customer accounts, retrieve supported reporting metadata, and query allowlisted customer, campaign, ad-group, and ad performance fields. OctoLead's current Google Ads integration does not create, edit, pause, or delete campaigns, ads, keywords, budgets, billing settings, or users.

Limited Use commitments

Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. In particular:

  • we use Google user data only to provide or improve user-facing features that you explicitly request;
  • we do not sell Google user data;
  • we do not use Google user data for targeted advertising, credit assessment, or eligibility decisions;
  • we do not use, or permit others to use, Google user data to train generalized or non-personalized artificial intelligence or machine-learning models; and
  • human access is limited to cases you affirmatively request or consent to, security or abuse investigation, legal obligations, or internal operations where the data has been aggregated or de-identified, as permitted by the Google policy.

3. How We Use Information

We use information to:

  • authenticate users and operate, maintain, and secure the Service;
  • execute the tasks and connector actions you request;
  • provide task history, chats, artifacts, exports, support, and account administration;
  • refresh authorized connections and show their connection state;
  • diagnose errors, prevent abuse, enforce usage limits, and protect users and infrastructure;
  • communicate service, security, support, and administrative information; and
  • comply with applicable law and resolve disputes.

We do not claim that every processing activity relies on the same legal basis. Depending on the context and applicable law, processing may be based on your consent, performance of a service you request, our legitimate operational and security needs, or a legal obligation.

4. AI and External Processing

OctoLead is a cloud agent. To complete a task, relevant portions of your prompt, connected-service data, files, and tool results may be processed by AI model services. OctoLead may route model requests through OpenRouter, which may in turn route them to an upstream model provider selected for the task. Only submit information that you are authorized to process through these services.

Before Google user data is sent through an AI provider, OctoLead must use provider settings, routing controls, or contractual terms that prohibit using that data to train generalized or non-personalized models and restrict processing to the user-requested feature. If compatible controls are unavailable, Google user data must not be sent to that provider. Provider-specific processing locations and permitted operational retention can still vary, so we do not promise that every provider offers "zero retention" or has no independent legal obligations.

5. Storage and Service Providers

OctoLead uses service providers to operate the Service. Depending on deployment and feature use, these include:

  • Supabase for authentication, databases, and application records;
  • Vercel for frontend hosting and delivery;
  • Render for backend hosting and application processing;
  • E2B for isolated cloud sandboxes used to execute agent tasks;
  • Cloudflare R2 for object and file storage; and
  • OpenRouter and upstream model providers for AI inference.

These providers may process data in countries or regions different from yours. We share only information reasonably needed for their role, subject to applicable arrangements and legal requirements.

Connector credentials stored in OctoLead's Vault are encrypted by the application before storage. Refresh credentials are intended to remain in the backend credential system. A short-lived access token may be made available to the isolated E2B sandbox assigned to your session so a tool can perform an authorized operation. Isolation and encryption reduce risk but do not make any system absolutely secure.

Task, chat, tool-result, and artifact data may be persisted in application databases or object storage so that the Service can display history, resume work, deliver outputs, investigate failures, and meet operational or legal needs.

6. Retention

OctoLead does not apply one fixed retention period to every category of data. We retain information for as long as reasonably necessary to provide the Service, maintain security and integrity, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of record, the feature used, account status, operational backup cycles, and legal requirements.

Connector credentials may remain in the Vault until you disconnect the connector, request deletion, or they are otherwise removed under our operational or legal processes. Historical chats, tasks, and artifacts may remain after a connector is disconnected because they are separate application records. Backups, security logs, and records required for fraud prevention or legal compliance may remain for a limited period after an active record is deleted.

We do not promise automatic account deletion, immediate deletion from every backup, or a universal zero-retention policy.

7. Disconnecting, Revoking, Exporting, and Deleting

Disabling a connector prevents new sessions from injecting or using that connection while preserving its stored credential. A sandbox that was already running may retain a previously issued short-lived access token until that token expires or the sandbox terminates. Disconnecting removes the stored credential from the OctoLead Vault and prevents new credential refreshes or new calls that require it. Disconnecting does not automatically revoke OctoLead in your Google Account, invalidate a token already present in a running sandbox, delete data already included in task or chat history, or delete generated artifacts.

You can separately revoke OctoLead's Google access through your Google Account connections page. Revocation at Google prevents future token use but does not automatically erase information previously incorporated into OctoLead records.

To request access to, export of, correction of, or deletion of your OctoLead account or personal information, contact humminwang@gmail.com. We may need to verify your identity and authority over the account. We will respond as required by applicable law, subject to security, legal, technical, and record-retention limitations.

8. Sharing and Disclosure

We may disclose information:

  • to the service providers described above to operate the Service;
  • when you direct an integration or task to send data to another service or recipient;
  • to protect the rights, safety, and security of users, OctoLead, or others;
  • to investigate fraud, abuse, or security incidents;
  • when required by law, regulation, legal process, or a valid government request; or
  • as part of a reorganization, financing, acquisition, or transfer of the Service, subject to appropriate notice and safeguards where required.

We do not sell personal information or Google user data.

9. Security

We use administrative, technical, and organizational measures intended to protect information, including access controls, application-layer encryption for Vault credentials, and isolated task execution environments. No internet service, transmission method, or storage system is completely secure. You are responsible for protecting your account and for promptly revoking access or contacting us if you suspect misuse.

10. International Processing

OctoLead is operated from China and uses providers that may process data internationally. By using the Service, your information may be transferred to and processed in jurisdictions with different data-protection rules. Where required, we will use appropriate legal mechanisms or obtain required consent.

11. Changes to This Policy

We may update this Policy as the Service, providers, or legal requirements change. We will publish the updated Policy with a new effective date and provide additional notice when required. Material changes apply prospectively unless applicable law permits otherwise.

12. Contact