Back to Product Home Data Protection & Trust

Privacy Policy

Last updated: July 2026

At Olib AI, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your data when using the steffi.ai platform. Because Steffi is designed to run autonomous AI agents in high-compliance environments, we prioritize local processing, credential encryption, and zero telemetry.

1. Information We Collect

1.1 Account & Licensing Data

  • Name and business email provided during beta registration and purchase.
  • Organization workspace parameters.
  • License key activation data, hardware tokens (CPU type, MAC hash), and seat counts.

1.2 Execution Log Telemetry (SaaS only)

For SaaS-hosted workspaces, we record execution statistics such as agent active runtimes, token consumption budgets, and API success rates to facilitate billing. However, for self-hosted instances, this telemetry is completely disabled and remains 100% on-premises.

1.3 Data We Do NOT Collect

  • Your customers' database contents or raw file attachments processed by agents.
  • Plaintext passwords or API keys stored in the AES-256-GCM Credential Vault.
  • Agent-generated conversation histories, memory stores, and vector records.
  • Web traffic, cookies, and raw DOM payloads automated by the Specter browser.

2. How We Use Your Information

We use your collected business contact and billing information solely to:

  • Provide, validate, and manage license keys across your authorized worker nodes.
  • Deliver customer service, software patch notifications, and technical support.
  • Enforce resource budgets and hourly rates starting at $5/hour per Lite agent.
  • Prevent security violations, reverse-engineering attempts, and prompt injection abuses.

3. Data Storage & Security Controls

3.1 Encryption Standards

All sensitive information, including API keys and passwords saved in the credential vault, is encrypted using AES-256-GCM. We secure data in transit via TLS 1.3 encryption protocols.

3.2 Local Sandbox Execution

To secure workflow isolation, local custom scripts (Python, Node) run within capability-gated containers that talk to the core engine over Unix Domain Socket (UDS) gRPC gateways. This limits context exposure and protects your host server infrastructure from leaks.

3.3 Zero Third-Party Selling

We do not sell, trade, or monetize any personal or business data collected on our platform. All processing metrics remain strictly confidential.

4. Compliance & Privacy Rights (GDPR / CCPA)

Depending on your jurisdiction (such as the EU under GDPR, or California under CCPA), you hold legal rights regarding your business information:

  • The right to access and copy your account registration data.
  • The right to request data correction or complete deletion from our activation databases.
  • The right to request deactivation and transfer of licenses to new machines.

To exercise these rights, please email us at support@olib.ai.

5. Contact Information

If you have any questions, compliance reviews, or audit requests regarding this Privacy Policy, please contact our legal counsel:

Olib AI Legal DeptStone Mountain, Georgia, United Statessupport@olib.ai