---
title: "Privacy Policy"
description: "How 2men AI collects, uses, retains, and protects information across Ocho and related services."
canonical: https://ocho.bot/privacy
last_updated: 2026-08-25
---

# Privacy Policy

> How 2men AI collects, uses, retains, and protects information across Ocho and related services.

Effective · August 15, 2026

2men AI (“2men AI,” “we,” “us,” or “our”) operates Ocho — our branded platform available at ocho.bot — together with 2men.ai and related applications, APIs, and services that provide internet-based access to data (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you access or use the Service, and describes our commitments regarding data minimization and the non-sale, non-sharing, and non-dissemination of your personal information. By using the Service, you agree to the collection and use of information as described here. If you access the Service under a signed agreement with us, that agreement’s confidentiality and data-processing terms govern in the event of any conflict with this Policy.

## 1. Information We Collect

- Account information: name, email address, username, password, company name, billing details, and job title.
- Identity verification information, where required for regulated data access (e.g., government ID, business license).
- Communications you send to us, including support requests and feedback.
- Payment information, processed by our third-party payment processor (we do not store full payment card numbers).
- Usage data: API calls, query logs, data access frequency, endpoints accessed, timestamps, and error logs.
- Device and connection data: IP address, browser type, operating system, device identifiers.
- Cookies and similar tracking technologies (see Section 7).
- Data from identity verification providers, credit reference agencies, or partner platforms integrated with the Service.
- Information from data sources or upstream providers that the Service aggregates, indexes, or makes accessible, where such data may include information about individuals who are not our direct customers.

We collect only the categories of information reasonably necessary for the purposes described in this Policy, and we do not collect additional categories of personal information without updating this Policy and, where required, obtaining your consent.

## 2. How We Use Information

- Provide, operate, maintain, and improve the Service, including authenticating access and enforcing usage limits.
- Process transactions, send billing notices, and manage accounts.
- Monitor for security threats, fraud, unauthorized access, and violations of our contractual terms.
- Respond to inquiries, provide customer support, and send administrative communications.
- Comply with legal obligations, including tax and regulatory reporting requirements.
- Analyze usage trends, and, on an aggregated and de-identified basis, develop or improve machine learning and analytics features, consistent with the terms of our customer agreements.
- With your consent, send marketing communications, which you may opt out of at any time.

We do not use personal information for purposes materially different from those disclosed in this Policy without providing notice and, where required by law, obtaining your consent.

## 3. Legal Bases for Processing (where applicable, e.g., GDPR/UK GDPR)

- Performance of a contract with you.
- Compliance with a legal obligation.
- Our legitimate interests, such as securing the Service and preventing fraud, provided these interests are not overridden by your rights.
- Your consent, where required (e.g., certain marketing communications or non-essential cookies).

## 4. How We Share Information — and What We Do Not Do With It

**No Sale or Sharing of Personal Information.** We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA or similar law — regardless of whether money or other valuable consideration is exchanged. We do not disclose personal information to any third party for that third party’s own independent marketing purposes. Any narrower or contrary statement elsewhere in a prior version of this Policy is superseded by this Section.

**Data Minimization in Sharing.** Where disclosure is necessary for one of the purposes below, we disclose only the categories of information reasonably necessary to accomplish that purpose — not our full data holdings about you.

We may share information only in the following limited circumstances:

- Service providers and subprocessors: hosting, cloud infrastructure, payment processing, analytics, and customer support vendors. Each such vendor is bound by a written agreement that (i) limits their use of the information strictly to providing the contracted service to us, (ii) prohibits them from retaining, using, selling, or disclosing the information for any other purpose, including their own or a third party’s marketing, (iii) requires confidentiality and industry-standard security safeguards, and (iv) requires deletion or return of the information upon termination of the engagement, except as required by law.
- Data sources/partners: where the Service provides access to third-party datasets, we share only the minimum query metadata necessary to fulfill the request and enforce licensing terms; we do not share your account, contact, or billing information with a data source beyond what is necessary for that purpose, and data sources may not use shared metadata for independent marketing to you.
- Legal and safety: to comply with valid legal process or applicable law, respond to lawful requests from public authorities, or protect the rights, property, or safety of 2men AI, our users, or others. We disclose only the information specifically required to respond to the request, and, unless prohibited by law or court order, we will make reasonable efforts to notify the affected user before disclosure.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections. Any successor entity must honor the commitments in this Policy with respect to personal information collected before the transfer, and we will provide notice of any change in ownership or control.
- Aggregated or de-identified data: we may share information that has been aggregated or de-identified such that it cannot reasonably be used to identify you, and we contractually and technically commit not to attempt to re-identify such data or permit others to do so.
- With your consent or at your direction.

We do not disclose sensitive personal information (e.g., government identification, precise geolocation, where collected) except as strictly necessary to provide the Service, comply with law, or as permitted with your consent.

## 5. Data Retention

**Governing principle.** We retain personal information only for as long as reasonably necessary to fulfill the purpose for which it was collected, satisfy a legal or contractual obligation, resolve disputes, and enforce our agreements — and no longer. Where a shorter retention period is operationally practical, we apply the shorter period.

### 5.1 Retention Schedule by Category

- Account information (name, email, billing details, job title): retained for the duration of your active account, plus 12 months following account closure for legal, audit, and dispute-resolution purposes, unless you request earlier deletion and no legal basis requires retention.
- Payment and billing records: retained for 7 years, consistent with applicable tax and accounting recordkeeping requirements. We do not retain full payment card numbers; these are held only by our third-party payment processor.
- Identity verification information: retained only for as long as necessary to complete verification and satisfy any applicable regulatory requirement, and in any event no longer than 90 days after verification is complete, unless a longer period is required by law.
- Usage, API, and access/query logs: retained for 12 months for security and audit purposes, after which they are deleted or aggregated into a form that does not identify you, unless a longer period is required by law or a contractual obligation to a data source.
- Support communications and feedback: retained for 24 months after the request is resolved, to support quality review and recurring-issue diagnosis.
- Marketing preferences and opt-outs: retained for as long as necessary to honor your preference, including a minimal record confirming the opt-out itself.
- Cookies and tracking identifiers: retained per the durations described in our Cookie Policy / Section 7.

### 5.2 Deletion, Anonymization, and Backups

Upon account termination, or upon a valid deletion request under Section 9, we will delete or irreversibly anonymize personal information within 30 days from our production systems, except where retention is required by law, is subject to a legal hold, or is necessary to complete a transaction, resolve a dispute, or enforce our agreements. Copies of information retained in encrypted backups are purged or overwritten in the ordinary course of our backup rotation cycle, and in no event later than 90 days after deletion from production systems; such backup copies are not accessed for any purpose other than disaster recovery in the interim.

Where we anonymize rather than delete information, “anonymize” means processing the data so that it can no longer reasonably be used to identify you, whether alone or in combination with other reasonably available information, and we commit not to attempt to reverse that process.

### 5.3 Legal Holds and Extended Retention

We may retain specific information beyond the periods above where necessary to comply with a legal hold, subpoena, court order, active litigation, or a bona fide regulatory investigation. Any information retained under this subsection is limited to what is responsive to the specific hold or obligation and is deleted promptly once that obligation ends.

## 6. Data Security

We implement administrative, technical, and physical safeguards designed to protect information from unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and audit logging. Access to personal information is limited to personnel and vendors who need it to perform their function, consistent with Section 4. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected individuals and any applicable regulators as required by applicable law and without undue delay.

## 7. Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies to authenticate sessions, remember preferences, and analyze usage. You can control cookies through your browser settings; disabling certain cookies may limit functionality of the Service. Where required by law, we will request your consent before placing non-essential cookies. We do not permit third-party advertising cookies to be used to build cross-site profiles of you through the Service.

## 8. International Data Transfers

If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where we or our service providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers, and any recipient remains bound by the sharing and retention limitations described in Sections 4 and 5.

## 9. Your Privacy Rights

Depending on your location, you may have rights to:

- Access, correct, or delete personal information we hold about you.
- Object to or restrict certain processing, including profiling.
- Request data portability.
- Withdraw consent at any time, where processing is based on consent.
- Confirm that we do not sell or share personal information, and limit use of sensitive personal information (California residents, under CCPA/CPRA).
- Lodge a complaint with a supervisory or data protection authority.

To exercise these rights, contact us at hello@ocho.bot. We will verify your identity before fulfilling requests and respond within the timeframe required by applicable law. We will not retaliate against you for exercising these rights.

## 10. Children’s Privacy

The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction), and we do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information promptly and in accordance with Section 5.

## 11. Third-Party Data Accessed Through the Service

Where the Service provides access to datasets containing information about third parties (individuals who are not our direct users), we act in the capacity described in our data source agreements, and we apply the same non-sale, non-sharing, and retention-limitation commitments described in Sections 4 and 5 to that data — we do not independently use, retain beyond the period necessary to provide the Service, or disclose such third-party data outside the scope authorized by the applicable data source agreement. Business customers accessing such data are independently responsible for ensuring their own use complies with applicable data protection laws, including any purpose limitations or onward disclosure restrictions attached to that data, and remain subject to the data-use terms in their Order Form and our Cloud and Data Access Service Agreement.

## 12. Relationship to Business Contracts

If you access the Service as an employee or representative of a business Customer under a signed Cloud and Data Access Service Agreement (or equivalent contract) with us, that contract’s confidentiality, data restriction, and data processing terms govern your organization’s use of Output Data and Confidential Information. This Policy addresses our handling of personal information as a business generally and does not expand or limit the contractual rights and obligations set out in that agreement or an executed Data Processing Addendum.

## 13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes — including any change that would broaden our sharing of personal information or shorten your rights under this Policy — by posting the updated policy on ocho.bot and 2men.ai and updating the “Effective Date” above, and, where required by law, by additional notice (e.g., email).

## 14. Contact Us

If you have questions about this Privacy Policy, contact us at:

2men AI · Ocho
Email: hello@ocho.bot

---

Ocho — AI knowledge orchestration · [Home](https://ocho.bot/) · [Docs](https://ocho.bot/docs) · [Blog](https://ocho.bot/blog) · [About](https://ocho.bot/about) · [Developers](https://ocho.bot/developers) · [Contact](https://ocho.bot/contact) · [llms.txt](https://ocho.bot/llms.txt)
