Oliver
  • OliverDB Engine
  • Swarm
  • Agent Flight Control
  • Solutions
  • Resources
  • Contact us
Request access

Oliver AI — Privacy Policy

Effective date: August 28, 2026

This Privacy Policy explains how Oliver AI, Inc. ("Oliver AI," "we," "us," or "our") handles personal information in connection with our websites, OliverDB Cloud, OliverDB deployed in a customer's own Kubernetes environment ("BYOC"), and OliverDB deployed in a customer's Snowflake environment using Snowpark Container Services ("OliverDB for Snowflake"). Together, these are referred to as the "Services."

The information Oliver AI handles depends on the deployment model. OliverDB Cloud is operated on infrastructure controlled by Oliver AI and its service providers. BYOC and OliverDB for Snowflake run inside the customer's own environment, and the data-handling commitments for those deployments are described separately below.

1. Scope and Our Roles

  • Account Data. Information associated with a user or customer relationship, such as name, business email address, organization, authentication details, billing records, support communications, and Cloud usage information. Oliver AI generally acts as a controller of Account Data.
  • Website Data. Information collected when someone visits our websites or interacts with our marketing, including device and browser information, IP address, approximate location, referral information, pages viewed, site interactions, and information submitted through a form. Oliver AI generally acts as a controller of Website Data.
  • Customer Content. Data, table contents, SQL queries and results, prompts, inputs, outputs, logs, or other content that a customer provides to, makes available to, or processes using an OliverDB service. As between Oliver AI and the customer, the customer controls Customer Content. Where Oliver AI processes personal information in Customer Content on the customer's behalf, the applicable Terms of Service, ordering document, and Data Processing Addendum ("DPA") govern that processing.

We do not sell Customer Content or use Customer Content to train shared or general-purpose artificial-intelligence or machine-learning models.

2. Deployment-Specific Data Practices

OliverDB Cloud

OliverDB Cloud is a managed service operated by Oliver AI using infrastructure hosted by service providers, including Amazon Web Services in the United States. To provide OliverDB Cloud, Oliver AI and its service providers may host, store, process, transmit, and secure Customer Content as directed by the customer and as described in the applicable agreement and DPA.

OliverDB Cloud may also generate operational information needed to run, secure, meter, support, and bill the service, including request counts and latency, storage and ingest volumes, instance lifecycle events, IP addresses, error information, and logs of console or administrative actions. We do not use Customer Content for advertising or to train shared or general-purpose AI or ML models.

OliverDB in your own Kubernetes environment (BYOC)

When a customer runs OliverDB in its own Kubernetes environment using the Oliver operator, Customer Content is processed inside the customer's cluster. For this deployment:

  • Customer Content stays in the customer's environment. Oliver AI does not receive, store, or process table contents, queries, query results, or application logs from a BYOC environment.
  • What the environment reports to us. The Oliver agent installed with the operator sends Oliver AI the usage metadata needed to administer and bill the environment: the environment's identity, the number and size (CPU and memory) of OliverDB instances and their pods, node capacity, and agent health. The agent's access is read-only, and it does not send Customer Content.
  • Software delivery. BYOC environments pull OliverDB software from a container registry operated by Oliver AI using per-environment credentials. The registry records pull activity (credential, image, time, and IP address) to secure and support the service.
  • The customer controls the cluster, its network, its storage, and who can access it.

OliverDB for Snowflake (Snowpark Container Services)

When OliverDB is deployed using Snowpark Container Services, OliverDB executes within the customer's Snowflake environment and processes Customer Content there. For this deployment:

  • No Customer Content leaves Snowflake. Oliver AI does not receive, collect, transmit, or store Customer Content from the SPCS deployment on Oliver AI-controlled infrastructure. This includes customer table or data contents, SQL queries and query results, prompts, and other workload content.
  • No deployment data is sent to Oliver AI. Application logs, telemetry, metrics, and usage or performance data from the SPCS deployment are not transmitted outside the customer's Snowflake environment to Oliver AI.
  • No outbound connections are configured by Oliver AI. Oliver AI configures no External Access Integrations or other outbound connections from the OliverDB SPCS containers.
  • The customer controls access. The customer controls its Snowflake account, region, permissions, and the Snowflake objects made available to OliverDB. OliverDB processes Customer Content only within that environment and under the permissions the customer grants.
  • No shared-model training. Customer Content processed in the SPCS deployment is not used to train shared or general-purpose AI or ML models.

Because Oliver AI does not receive Customer Content or deployment telemetry from OliverDB for Snowflake, provisions elsewhere in this Policy concerning Oliver AI's storage, retention, deletion, disclosure, or international transfer of Customer Content do not apply to data that remains in the customer's Snowflake environment. The customer's agreement with Snowflake and the customer's own Snowflake configuration govern Snowflake's handling of that data.

3. Information We Collect

  • Registration and authentication. Name, business email address, organization identifiers, and authentication information received through our authentication provider, WorkOS, when users sign in through email, an OAuth provider, or organization single sign-on.
  • Billing and commercial information. Transaction records, orders, subscription details, and credit-ledger history. Stripe processes payments for direct purchases; we do not store full payment-card numbers and receive only limited payment tokens and metadata, such as card brand and last four digits.
  • Cloud and BYOC usage and security information. Operational metadata described in Section 2 for OliverDB Cloud and BYOC environments, including instance and API activity, request counts and latency, storage and ingest volumes, instance and pod sizes and lifecycle events, IP addresses, registry pull activity, and console-action logs.
  • Support and communications. Messages, attachments, and related records when users contact us, request support, participate in a sales process, or otherwise communicate with Oliver AI.
  • Website and cookie information. Device, browser, IP address, approximate location, referral source, pages viewed, session information, and site interactions collected through cookies and similar technologies, including Google Analytics. If a visitor submits a website form, we collect the information the visitor provides; form submissions are relayed to our email by FormSubmit.
  • Marketplace information. If a customer obtains OliverDB through Snowflake Marketplace, Snowflake may process account, subscription, commercial, and usage information under the customer's agreement with Snowflake and Snowflake's privacy disclosures. If Snowflake provides information to Oliver AI to administer, support, or fulfill the Marketplace relationship, we handle that information as Account Data under this Policy.

Oliver AI does not collect Customer Content, queries, results, logs, telemetry, metrics, or usage or performance data from OliverDB for Snowflake, and does not collect Customer Content from BYOC environments, as described in Section 2.

4. How We Use Personal Information

We use Account Data and Website Data to:

  • provide, operate, administer, and support the Services;
  • authenticate users and manage accounts and permissions;
  • process transactions, administer subscriptions, meter usage, and bill customers;
  • maintain security, prevent abuse and fraud, troubleshoot, and protect the Services and our users;
  • respond to support requests and other communications;
  • analyze website and Cloud-service performance and improve our products using aggregated or de-identified information where appropriate;
  • send operational, legal, security, and billing notices;
  • send marketing communications only with your consent, with an unsubscribe option in every message; and
  • comply with law, enforce agreements, and establish or defend legal claims.

Where the GDPR or UK GDPR applies, our legal bases may include performance of a contract, our legitimate interests in operating and securing our business and Services, compliance with legal obligations, and consent where required. A person may withdraw consent at any time, without affecting processing that occurred before withdrawal.

5. How We Disclose Information

We may disclose Account Data, Website Data, and — for OliverDB Cloud only — Customer Content as follows:

  • Service providers and subprocessors. To vendors that provide hosting, authentication, payments, analytics, communications, security, and support services under contractual obligations appropriate to their role. Current providers include Amazon Web Services for Oliver-operated infrastructure, WorkOS for authentication, Stripe for payments, Google Analytics for website analytics, and FormSubmit for relaying website contact-form submissions. Our current Subprocessor List for OliverDB Cloud is available at https://aws.olivercloud.ai/legal/subprocessors.
  • Legal and safety disclosures. To comply with applicable law, regulation, legal process, or governmental request; to protect rights, safety, and security; or to investigate fraud, abuse, or violations of our agreements. Where legally permitted, we may notify the affected customer before disclosure.
  • Corporate transactions. In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and use restrictions.
  • At a customer's direction. To other parties when a customer requests, authorizes, or directs us to do so.

We do not sell personal information for money. We do not sell Customer Content or use Customer Content for cross-context behavioral advertising. Oliver AI does not disclose Customer Content from OliverDB for Snowflake or from BYOC environments, because Oliver AI does not receive it.

6. Cookies and Similar Technologies

The OliverDB Cloud console uses cookies that are necessary for functions such as sign-in, session management, and security protections; it does not use advertising or cross-site tracking cookies. Our marketing website uses Google Analytics, which may set cookies or use similar technologies to distinguish users and sessions, understand website traffic and interactions, and measure performance.

Visitors can use browser controls to block or delete cookies. Blocking necessary cookies may prevent parts of the console from working. Where applicable law requires consent for nonessential cookies, we will request it before using those cookies. Google may process information under its own privacy terms, subject to its agreement with Oliver AI.

7. Retention

We retain Account Data and Website Data for as long as reasonably necessary for the purposes described in this Policy, including while an account or customer relationship is active and afterward as needed for billing, tax, security, support, dispute resolution, legal compliance, and backup rotation. Retention periods vary based on the type of information, the purpose for which it is used, and legal requirements. When an account is closed, we delete or de-identify its Account Data within a commercially reasonable period, except where continued retention is required or permitted by law.

Retention and deletion of Customer Content in OliverDB Cloud are governed by the applicable Terms of Service, ordering document, and DPA. Customer Content and deployment data in a BYOC environment remain in the customer's cluster, and Customer Content and deployment data processed by OliverDB for Snowflake remain in the customer's Snowflake environment; Oliver AI does not retain that data and is not responsible for exporting or deleting the customer's underlying data in those environments.

8. Security

We use technical and organizational measures designed to protect information based on its nature and risk. For OliverDB Cloud, these measures include encryption in transit and at rest, tenant isolation for storage and credentials, scoped internal access, and audit logging. For BYOC, the customer operates the cluster and its access controls; the Oliver agent's access is read-only and limited to the OliverDB workloads it reports on. For OliverDB for Snowflake, Customer Content remains in the customer's Snowflake environment, and Oliver AI configures no External Access Integrations or other outbound connections from the SPCS containers. Customers remain responsible for configuring their own environments, roles, permissions, and access controls appropriately.

If we learn of a security incident affecting personal information for which Oliver AI is responsible, we will provide notice as required by applicable law and contractual commitments.

9. International Data Transfers

Oliver AI is based in the United States. Account Data, Website Data, communications, and information processed through Oliver-operated systems may be transferred to and processed in the United States and other countries where Oliver AI or its service providers operate. OliverDB Cloud and certain Oliver-operated systems use Amazon Web Services infrastructure in the United States.

When the GDPR, UK GDPR, or similar law applies to an international transfer, we use an appropriate transfer mechanism where required, such as an adequacy decision or approved contractual safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the UK transfer addendum, as reflected in our DPA.

BYOC and OliverDB for Snowflake are different: Customer Content, table and data contents, SQL queries and results, prompts, and logs processed through those deployments stay in the customer's own environment wherever it runs. For BYOC, only the usage metadata described in Section 2 is transmitted to Oliver AI in the United States; for OliverDB for Snowflake, nothing is, and the customer controls the Snowflake region in which processing occurs, subject to the customer's agreement with Snowflake.

10. Privacy Rights

Depending on location and applicable law, individuals may have rights to access, correct, delete, or obtain a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a decision regarding a privacy request. California residents may also have rights to know the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing where applicable. We do not discriminate against individuals for exercising privacy rights.

Requests may be submitted to info@oliverdb.ai. We may take reasonable steps to verify identity and authority before completing a request. Authorized agents may submit requests where permitted by law. Individuals in the EEA or UK may also lodge a complaint with their local supervisory authority.

For personal information contained in Customer Content, please contact the organization that controls the relevant data. Where Oliver AI acts as a processor for OliverDB Cloud, we will assist the customer in accordance with the applicable DPA. For BYOC and OliverDB for Snowflake, the Customer Content remains within the customer's environment and is controlled by the customer.

11. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13, and users of the Services must be at least 18 years old or the age required to enter into a binding agreement in their jurisdiction.

12. Third-Party Services

Our websites and Services may link to or interoperate with third-party services, including Snowflake. This Policy does not govern personal information processed independently by those third parties. A customer's use of Snowflake, including Snowflake Marketplace and the customer's Snowflake account, is subject to the customer's agreements with and privacy disclosures from Snowflake.

13. Changes to This Policy

We may update this Policy from time to time. We will post the revised Policy with an updated effective date. For material changes, we will notify customers through the console or by email at least 30 days before they take effect, and we will follow any applicable notice obligations in an existing contract.

14. Contact

Oliver AI, Inc. · 17632 Revello Dr, Pacific Palisades, CA 90272 · info@oliverdb.ai

Oliver.
A new kind of data platform, built for agents.
Terms Privacy AUP DPA Subprocessors