Legal

Privacy Policy

Last Updated: June 13, 2026

Introduction

Welcome to OkieDoke, a minimalist tool for social media managers to streamline client approval workflows. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our services.

Effective Date:This policy applies to all users of OkieDoke's web application and related services.

Information We Collect

Account Information (via Clerk Authentication)

When you create an account, we collect information from Clerk:

DataSourcePurpose
User IDClerkUnique account identifier
Email AddressClerkAccount authentication, notifications
Full NameOptional profile fieldDashboard display
Avatar URLOptional profile fieldBrand personalization

Profile & Brand Settings

Data stored in your OkieDoke profile:

FieldPurpose
Webhook URLIntegration with external tools (e.g., Slack, Discord)
Studio NameBrand identity in dashboard
Studio Logo URLUploaded via Vercel Blob for brand display
Brand Accent ColorUI customization (default: #22d3ee cyan-400)
Email Notification PreferenceControl for approval/change notifications
Storage UsageTracking for tier limits (FREE: 100MB, 5 links)

Deliverables & Content

Content you upload for client review:

Data TypeStored InPurpose
Media FilesUploadThingCreative work shared with clients
File MetadataNeon DatabaseStorage tracking, file type info
CaptionNeon DatabaseDeliverable identification
StatusNeon DatabaseWorkflow state (pending/approved/changes_requested)
Feedback NotesNeon DatabaseClient comments on deliverables
Personal NotesNeon DatabaseYour notes to approvers (max 200 words)
Parent IDNeon DatabaseVersion history linkage

Client & Project Data

EntityFields StoredPurpose
ClientsName, Email, CompanyContact management
ProjectsName, DescriptionOrganization structure

Precision Feedback Annotations

When clients provide feedback on deliverables:

DataPurpose
X/Y CoordinatesPinpoint feedback location on media
CommentDetailed feedback text
Resolution StatusTrack addressed feedback

Analytics & Usage Data

We collect engagement analytics for your deliverables:

Event TypeData CollectedPurpose
ViewTimestamp, User AgentTrack client engagement
ApproveTimestampMeasure approval rates
Request ChangesTimestampTrack revision cycles

Secure Review Tokens

For anonymous client access:

DataPurpose
Token Hash (SHA-256)Secure, unguessable review links
Expiry DateTime-limited access control
Usage CountPrevent duplicate approvals

Technical Data

  • IP Address: Logged for security monitoring
  • Browser/User-Agent: Stored with analytics events
  • Storage Keys: Obfuscated filenames for UploadThing

How We Use Your Information

Core Service Functionality

  • Create and manage your account via Clerk authentication
  • Generate secure review links for client approvals
  • Send email notifications via Resend (notifications@getokiedoke.com)
  • Track deliverable status and version history
  • Store and serve uploaded media files via UploadThing
  • Provide real-time analytics dashboard

Service Improvement

  • Analyze approval rates and review patterns
  • Measure average review time for workflow optimization
  • Identify top-performing deliverables for insights

Communication

  • Transactional Emails: Approval/change notifications
  • Webhook Notifications: Optional integration with external services
  • No Marketing Emails: We do not send promotional content

Security & Compliance

  • Prevent fraudulent use through token expiration
  • Monitor abnormal usage patterns
  • Enforce tier limits (storage: 100MB FREE tier, 5 active links)

Service Providers & Data Processing

ProviderServiceData SharedTerms
ClerkAuthentication & User ManagementUser ID, email, profile dataClerk Privacy
Neon DatabasePostgreSQL hostingAll application dataSOC 2 Type II certified
UploadThingMedia file storageUploaded media files, storage keysEncrypted at rest
VercelBlob storage (studio logos)Logo imagesVercel Privacy
ResendTransactional emailCreator email for notificationsResend Privacy

All processors located in the United States. GDPR-compliant data processing agreements in place.

Your Rights & Controls

Access & Portability

  • View all your data in the OkieDoke dashboard
  • Export deliverables, clients, and analytics at any time
  • Request data portability via privacy@getokiedoke.com

Correction & Updates

  • Update profile fields in Settings page
  • Modify deliverables before client approval
  • Cannot modify: Approved deliverables (immutable audit trail)

Deletion

  • Dashboard deletion: Remove deliverables, clients, projects
  • Account deletion: Complete removal via Clerk account settings
  • Retention: Analytics retained 12 months for security

Communication Control

  • Disable email notifications in Settings
  • Remove webhook URL to disable integrations

Data Retention

Data TypeRetention PeriodReason
Account InformationWhile active + 30 daysAuthentication recovery
DeliverablesWhile account activeService functionality
Media FilesWhile account activeContent delivery
Analytics Events12 monthsPerformance insights
Approval Tokens7 days after expirySecurity cleanup
Version HistoryWhile account activeAudit trail

Security Measures

Technical Safeguards

  • Token Security: SHA-256 hashed review tokens (plaintext never stored)
  • Authentication: Clerk-managed OAuth with JWT
  • Database: Neon PostgreSQL with encrypted connections
  • Storage: UploadThing with server-side encryption
  • Access Control: Row-level ownership verification on all queries

Cookies & Local Storage

TypePurposeDuration
AuthenticationClerk session managementClerk-managed
Theme PreferenceDark/light modePersistent
Analytics ConsentOpt-out tracking12 months

No third-party tracking or marketing cookies.

Children's Privacy

OkieDoke is not directed to individuals under 16. No data collected from children.

Third-Party Links

  • WhatsApp Sharing: whatsapp://send?text= links
  • Uploaded Media: External URLs you provide

We are not responsible for third-party privacy practices.

Changes to This Privacy Policy

Material changes communicated via in-app notification. Continued use constitutes acceptance.

Contact Us

For privacy-related inquiries:

Email: privacy@getokiedoke.com

Support: support@getokiedoke.com

DPO: dpo@getokiedoke.com

Response within 30 days.

OkieDoke is GDPR and CCPA compliant.