Skip to main content
Early pricing is live. Access is by request — ask with an email address.Early pricing is live. Access is by request.

Version 4.4 — effective 2026-08-26

Privacy Policy

How Oabo collects, uses, shares, and protects data in its B2B System of Record for AI.

Oabo Scorecard is a product of AgentX, LLC (“Oabo”, “we”, “us”). It is a business-to-business System of Record for AI: software that records an organization’s AI agents, measures their spend and their return, and produces auditable value, governance, and performance reporting. This policy explains what we collect, why, who else sees it, and what you can ask us to do about it.

Oabo is sold to organizations. The organization (our “customer”) is the controller of the business data it brings to the service; Oabo acts as its processor for that data. Oabo has no consumer data product — there is no personal mailbox, calendar, inbox-cleaning, or end-user record. Three public-site activities are the exception, and we say so where they come up: our enquiry forms, support chat, and website analytics.

Summary

The short version

  • Most of what we hold is business data your organization brings us — an inventory of AI systems, what they cost, what they returned, and an audit trail of who changed what.
  • We run one analytics tool, Google Analytics. It does not load until you accept it. Decline, and no analytics cookie is set.
  • We do not sell personal data, do not share it for advertising, and run no advertising tags.
  • Oabo does not use workspace data to train AI models. Core product workflows do not need a model. Support is the narrow exception: an authorized person may ask OpenAI to draft a reply from the support conversation, and a person reviews every draft before anything is sent.
  • Oabo is work software for adults. It is not built to hold health, payment-card, or government-ID data, and our Terms prohibit submitting it.
  • You can ask for a copy of your data, a correction, or deletion at adam@oaboscorecard.com. We answer within 45 days.

Data

What we collect

  • Account & identity data — the work email, display name, role assignment, and business-unit scope of each authorized user, plus a password hash. Sign-in is by email and password over standard OAuth2 token auth, and we check that the sign-up address works by emailing you a verification link. Oabo does not offer Sign in with Google or enterprise SSO; if we add them, we will describe here what the provider tells us about you before the feature is available.
  • Organization & configuration data — your organization profile, role and segregation-of-duties configuration, tenant preferences, connected-provider settings, and the attribution rules that decide which team a measured agent belongs to.
  • Connected-provider credentials — if an administrator connects a source, Oabo receives the key, token, OAuth grant, or connection configuration submitted by the administrator or issued by that provider. Oabo encrypts the stored credential before storage and never returns it to the browser. The codebase contains a QuickBooks Online connection that, when enabled, uses Intuit OAuth and a rotating refresh token; transient access tokens are not stored. QuickBooks is not enabled in this deployment. See “Connected providers” below.
  • Usage telemetry — per-day counts of what your AI tools consumed: token counts, model and provider names, the tool or harness reporting them, session counts, and a project fingerprint. This arrives from the sources described under “How usage is measured”, and from vendor accounts you connect. It contains no prompt or response text.
  • Connected accounting data — QuickBooks is not enabled in this deployment. If Oabo enables it later and an administrator connects it, Oabo reads Bills and Purchases in the configured lookback window, including transaction dates, amounts, currency, vendor or payee, account name, and line description, to identify known AI vendors. Oabo computes provider-and-month billed totals and variance for the authorized response, but retains only reconciliation status and line counts by provider and month plus sync diagnostics. It does not persist billed totals, variance amounts, raw bill lines, vendor or payee names, account names, or descriptions.
  • Per-seat identifiers, stored as pseudonyms — some feeds identify the person who used a tool (a work email or a vendor account id) so that spend can be shown per seat. Oabo replaces that identifier with a one-way hash unique to your organization before storing it, and does not retain the original. The hash still relates to a person, so we treat it as personal data.
  • AI inventory & value data — the agents, models, owners, cost and capacity records, value claims, baselines, rate cards, evaluation results, risk findings, and attestations you and your team record in the service.
  • Audit & evidence data — an application-maintained, per-organization hash chain of mutating actions: who did what, and when. The production chain is unsigned and is not an immutable database ledger; a database owner could recompute it, and deleting entries from the end is not independently detectable from the chain alone. Where the action arrives with a web request, we also record the IP address it came from. More than half of the code paths that write an audit entry do not have the request in hand and record a local placeholder instead, so treat a recorded address as an operational signal rather than proof. Where a workspace was created through a free-trial signup, we also keep the email address and IP address it was created from, to investigate abuse of the free trial.
  • Operational logs — security, performance, and diagnostic logs, including records of the calls Oabo makes to vendor APIs on your behalf when you connect an account.
  • Training records — where your organization uses Oabo Practice, the training environment, we record each person’s progress through it: attempts, rank and progress, preferences, and any certificate issued to them. Practice runs against a separate database from your live workspace, and its records stay there. Practice also loads no analytics tag at all.
  • People your team asks for cost information — an administrator can run a cost campaign, which emails colleagues they name and asks which AI tools their team pays for. We store the address, whether the message was sent, and the tools and seat counts each person reports back. The recipient needs no Oabo account. Your organization chooses those addresses; we send on its behalf, within sending limits we enforce.
  • Enquiries from our public forms — the name, email, company, phone number, message, and IP address of anyone who writes to us. When you request access, we store the email address and IP address plus one coarse path naming the first public page opened in that browser tab; the path carries no query string, fragment, referrer, cookie, or cross-session identifier. We keep these to answer you and to run our business. This and website analytics are the two places Oabo is the controller of a non-customer’s personal data rather than a processor for a customer.
  • Support conversations — the message, any email address you choose to give us, the source IP address used for abuse controls, our reply, and a secret conversation key stored in your browser. We send a private Telegram notification containing the sender address, organization name, subject, thread number, and up to 500 characters of the new message so the founder can answer. That notification is an ordinary Telegram cloud-chat copy outside Oabo’s deletion workflow; deleting the Oabo thread does not automatically delete the Telegram copy. Do not put PHI, patient information, credentials, payment-card data, or other sensitive personal data in a support message. When an authorized person asks for a suggested reply, OpenAI receives the subject and up to the latest 20 text messages, each capped at 4,000 characters. The suggestion is shown to that person for review and is never sent to you automatically.
  • Website analytics — how people use oaboscorecard.com, but only if you accept it. See “Cookies and similar storage”.

Cookies

Cookies and similar storage

An earlier version of this page said Oabo set no cookies. That was wrong, and we are stating it plainly rather than quietly editing it: the site loads Google Analytics through Google Tag Manager, and Google Analytics sets cookies that last about two years. The notice and the behaviour are both fixed in this release — analytics now loads only if you accept it.

What Oabo stores in your browser.
NameWhat it doesWhere it livesSet byHow long
Essential, always onThese make signing in work. There is no version of the product without them.
oabo_token, oabo_user, oabo_orgKeeps you signed in and remembers which workspace you are in.Browser local storage for the Oabo site only — not a cookie.OaboUntil you sign out or clear your browser.
Session refresh tokenRenews your session so you are not asked to sign in again every hour.A first-party cookie marked HttpOnly, so page scripts cannot read it.OaboUntil it expires or you sign out.
Analytics choiceRemembers whether you accepted or declined analytics, so we stop asking.Stored on your device for the Oabo site only.OaboUntil you change it or clear your browser.
Interface preferencesRemembers things like light or dark mode.Browser local storage for the Oabo site only.OaboUntil you clear your browser.
oabo.support.visitorOnly if you start a chat with us from this site. It is how your browser finds its way back to that conversation to read the reply. It is not an account, it identifies nobody, and it is set only once you send a message.Browser local storage for the Oabo site only — not a cookie.OaboUntil you clear your browser.
oabo.access.landing_pathKeeps one coarse path naming the first public page opened in this browser tab.Browser session storage for the Oabo site only — not a cookie.OaboUntil you close this browser tab.
Analytics, only after you acceptNone of these exist unless you choose Accept. Decline and nothing below is ever set.
_gaTells one browser apart from another so visits can be counted.Cookie on oaboscorecard.com.Google Analytics (Google LLC)About 2 years.
_ga_DYVHBS335JHolds the state of your analytics session. The suffix is our analytics property id.Cookie on oaboscorecard.com.Google Analytics (Google LLC)About 2 years.

This table lists what the site sets today. If that set changes, this table changes with it. Oabo Practice (practice.oaboscorecard.com) carries no analytics tag at all — the tag is absent from that build, not merely switched off.

Choices

Analytics and your choices

Nothing runs until you say yes. Nothing that is not essential runs before you choose. On your first visit we ask, with Accept and Decline offered as equal choices. Until you accept, no analytics script loads and no analytics cookie is written. If you decline, we do not ask again on that browser, and we do not treat declining as a reason to give you a worse site — everything works the same. If you close the question without answering, that counts as a decline for that visit.

This is the complete list of outside services this website can load, and each loads only after you accept. It is generated from the same declaration the site’s Content-Security-Policy is checked against, so it cannot quietly fall out of date:

  • Google Tag ManagerLoads the analytics tag once you have said yes. Reached at www.googletagmanager.com.
  • Google AnalyticsCounts page visits so we can see which pages people find useful. Reached at www.google-analytics.com, analytics.google.com.

If your browser or an extension sends a Global Privacy Control signal, we treat it as a decline and never load analytics, without asking you anything. You can still turn analytics on yourself afterwards if you want to.

You can change your mind at any time using Privacy choices at the bottom of any page. Withdrawing consent stops the analytics script from loading again and clears the analytics cookies from your browser. Two honest limits: cookies saved in a different browser or on a different device have to be cleared there, and measurements already recorded stay in Google’s reports for the retention period set on the property. You can also delete the cookies yourself in your browser at any time.

What analytics collects if you accept: the pages you view and how you got here, your approximate location derived from your IP address, and your device and browser type. Google LLC processes this for us as our analytics provider and handles the data under its own terms. We use it to understand which pages are useful and where people get stuck. We have not turned on Google’s advertising features, we do not use analytics data to target advertising, and we do not combine it with data from your Oabo workspace. The signed-in product itself is not the point of this: analytics exists for the public marketing site.

Sources

Connected providers

An administrator or governance lead can connect a source so value and cost reporting traces to real usage, billing, or accounting data rather than figures typed into a spreadsheet. The enabled connection methods currently include Anthropic Enterprise Analytics, OpenAI Enterprise Cost, OpenRouter, LiteLLM, and Azure OpenAI Cost Management. The codebase also contains a QuickBooks Online connection, but it is not enabled in this deployment and the Connections page does not offer it unless Oabo configures its Intuit application credentials. You can also upload a provider’s cost export as a file, and disconnect a source at any time. The Connections page names the exact source and access method before an administrator connects it.

These connections are read-only with respect to source business data: Oabo does not create, modify, or delete vendor usage records, cloud resources, or QuickBooks books. Authentication can issue or rotate a credential; Intuit rotates the QuickBooks refresh token when Oabo refreshes access. Oabo never asks an AI vendor for compliance or conversation-export APIs, because those return the content of your people’s conversations and Oabo does not want it.

A connector credential is encrypted before storage using AES-256-GCM with a key held in our hosting provider’s secret manager. The encryption is bound to your organization, so a copied row cannot be decrypted for anyone else. A stored credential is never returned to the browser or written to a log. QuickBooks reads Bills and Purchases to identify known AI vendors and computes reconciliation amounts on demand. Oabo retains only provider-and-month status, line counts, and sync diagnostics rather than the amounts or raw accounting lines.

Measurement

How usage is measured

Counting what your AI tools cost means reading something on the machines where they run. Oabo does this in the narrowest way we could design, and it is worth being precise about it.

  • The Oabo collector — an optional agent you install on a workstation or server where AI coding tools are used. It opens the local session records those tools keep and extracts only the numbers: how many tokens were used, by which model, on which day, and how many sessions there were. Prompt and response text is never extracted, never stored, and never leaves the machine — the record the collector sends has no field that could carry it.
  • A project fingerprint — so usage can be grouped by project, the collector sends a short label derived from the project’s directory: usually just its name, but where the tool did not record one, the whole directory path. Either can contain the operating-system username. You can set the fingerprint explicitly if you would rather it did not.
  • An inline AI gateway or managed policy — where your organization routes AI traffic through a gateway, or applies a managed telemetry policy to a coding tool, those systems can send Oabo metrics. The policy Oabo generates explicitly turns prompt logging, response logging, and tool-detail logging off.
  • What Oabo refuses — the endpoint that receives managed-policy telemetry accepts metrics only, and rejects log and trace data outright, because those signals can carry prompt and response text. The gateway endpoint does accept traces, because that is the only shape a gateway sends; where such a trace carries the text of a request or a response, Oabo does not read those fields and has nowhere to put them — the records these feeds write have no field capable of holding free text.

Managed-machine usage can include the sanitized machine name and signed-in operating-system account. Oabo stores those reported identifiers with the usage so your authorized administrators can identify the source. Oabo does not retain prompt or response content from the collector.

Use

How we use data

  • To provide the service — recording AI inventory, computing the value ledger, running governance and performance views, and generating the audit pack.
  • To authenticate users and enforce role-based access, segregation of duties, and business-unit scoping.
  • To maintain an application-level history of mutations and the evidence your reviewers use.
  • To secure, monitor, debug, and improve the service, and to keep our email sending from being abused.
  • To communicate with authorized users about the service, including security and operational notices.
  • To answer support messages, notify the founder through Telegram, and — only when an authorized person requests it — ask OpenAI for a reply suggestion that a person reviews.
  • To understand how the public website is used — only with your consent, and only in aggregate.

We do not sell customer data, and we do not use the business data you bring to Oabo to train AI models. Core workspace processing does not require a language model. The support-drafting exception is limited to the support conversation and happens only when an authorized person requests a suggestion.

Email

Email we send

Oabo sends a small, fixed set of messages related to an account or a task someone started: a trial welcome, two account-status notices before trial access changes, notifications from our contact form, and cost-campaign invitations an administrator sends to colleagues. The automatic trial notices state the relevant date and the read-only or access change. They do not invite a purchase or paid continuation. Every message says who it is from. We do not add anyone to a mailing list.

Before Oabo adds any trial-conversion email whose primary purpose is promotional, it must complete a primary-purpose review. A commercial message must have accurate sender and subject information, clear commercial identification, a valid physical postal address, a clear opt-out, and a working suppression process before approval. No promotional trial-conversion email is approved today. If you would rather not receive an operational message, reply or write to adam@oaboscorecard.com and we will stop. We also apply sending limits — per recipient, per organization, and per day — so that a free-trial workspace cannot be used to send mail to strangers.

Tenancy

Multi-tenant isolation

Oabo is multi-tenant and org-scoped. Every customer record is bound to a single organization, and access is filtered by organization on every request — a user who attempts to reach another organization’s data is treated as if it does not exist. Within an organization, the nine roles, segregation-of-duties rules, and business-unit scoping determine which slice of data each user can see and which actions they can take.

Sharing

Who we share data with

We use a small number of providers to run the service. Each one is used for the purpose named here and nothing else, under the terms it publishes for business customers.

Our providers, and what each can see.
ProviderWhat it does for usWhat it can see
Google Cloud (Google LLC)Runs the application (Cloud Run) and holds our encryption keys (Secret Manager).Customer data in the running application.
NeonThe managed PostgreSQL database.Customer data at rest.
CloudflareProvides DNS, content delivery, and edge routing for normal oaboscorecard.com traffic. The native Cloud Run origin is also internet-reachable.Requests sent through oaboscorecard.com, including IP addresses. Direct-origin requests do not pass through Cloudflare.
ResendSends Oabo and customer-directed email.The recipient address and the content of that message.
Google Analytics (Google LLC)Website analytics for the public site — only if you accept.How you use oaboscorecard.com; not your workspace data.
Telegram Messenger Inc.Sends a private support notification to the founder and carries the founder's reply back to Oabo.The sender address, organization name, subject, thread number, up to 500 characters of each new message, and the founder's reply.
OpenAI OpCo, LLCDrafts a suggested support reply only when an authorized person asks.The support subject and up to the latest 20 text messages, each capped at 4,000 characters. No attachment is sent.

Telegram stores each support notification and founder reply in ordinary cloud-chat history. Oabo has not verified a separate retention period for that history. Oabo’s deletion workflow does not remove it automatically; deletion must happen separately in Telegram, so Oabo cannot promise that both copies disappear at the same time.

We will keep this list current, and tell customers through the service or by email when it changes. If your organization needs a signed data-protection agreement with us or with one of these providers, ask and we will tell you where that stands.

  • Support drafting is the only model-processing path. An authorized person may ask OpenAI to draft a reply from the support conversation. The suggestion stays private until a person reviews, edits, and sends it. Core workspace data is not sent into that draft. Where you connect a vendor account, traffic goes the other way — Oabo reads your usage and cost data out of that vendor.
  • Your connected providers — we read usage, cost, or accounting data from the sources you connect; we do not send your Oabo workspace records back to them. Current enabled sources are Anthropic Enterprise Analytics, OpenAI Enterprise Cost, OpenRouter, LiteLLM, and Azure OpenAI Cost Management. Intuit QuickBooks Online is described above but is not enabled in this deployment.
  • Legal & safety — where required by law, or to protect the rights, safety, and security of Oabo, our customers, or the public.
  • Corporate transactions — in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell personal data, and we do not share it for targeted or cross-context behavioural advertising. There are no advertising trackers on this site. We do not use your data to profile people or make automated decisions about them.

Location

Where data is processed

Oabo runs in the United States. The application runs on Google Cloud Run in Google’s us-east1 region, and the database is managed by Neon. Normal requests to oaboscorecard.com pass through Cloudflare’s network, so a request from outside the United States reaches a Cloudflare location near you before it reaches us. The native Cloud Run origin is also internet-reachable, and a request sent directly there does not pass through Cloudflare. If we begin processing customer data outside the United States, we will say so here first.

Security

How we protect data

Data is encrypted in transit with TLS. Connected-provider keys get a second layer: Oabo encrypts them with AES-256-GCM before storage, bound to your organization, with a key held in our hosting provider’s secret manager and never stored in the database — so a copy of the database on its own is inert. Those keys are never returned to the browser and never written to a log. Our hosting providers encrypt stored data at rest.

Access is governed by authentication, role-based authorization, segregation of duties, and tenant isolation. Application mutations are recorded in a per-organization hash chain. The production chain is unsigned and is not a database-enforced immutable ledger.

Three limits worth stating plainly. The backend has authenticated self-service endpoints for multi-factor enrollment, confirmation, recovery codes, disabling, and an organization policy, but Oabo does not yet expose a customer-facing enrollment screen. A customer would need direct API use; our own administrative account can also enroll through operator tooling. Treat MFA as an incomplete product rollout, not a generally available customer-facing control. The audit trail’s IP field is only as good as its source: more than half the code paths that write an entry do not have the web request in hand and record a local placeholder. And we hold no security certification. Oabo has not completed a SOC 2 audit or any equivalent, and we will not describe our practices as certified or compliant until one is done.

Your access token, account summary, and workspace identifier are held in your browser’s local storage for the Oabo origin only. Workspace records remain on Oabo’s servers. The one first-party cookie we write carries only an HttpOnly session refresh token. Beyond it,Oabo’s own product code introduces no cookie of any kind, and an automated test fails the build if a third writer appears. Every other cookie described on this page belongs to website analytics and exists only where you asked for it — see “Cookies and similar storage” above.

No method of transmission or storage is perfectly secure, but we maintain administrative, technical, and organizational safeguards appropriate to the data we hold.

Retention

Retention & deletion

We retain customer data for as long as the organization’s account is active, and thereafter as needed to meet legal, audit, and contractual obligations. Historical audit and evidence records are intentionally retained for the duration governed by the customer agreement; this is a retention practice, not a claim of database-enforced immutability.

Being straight about where the product is today: a free-trial workspace becomes read-only when the trial ends, and about a week later access to it is switched off entirely — signing in no longer reaches the workspace, reading included. The data itself is not erased. Oabo does not yet delete data on a schedule, and there is no button in the product that erases an organization. We are building both. Until they exist, both retrieval and deletion are done by hand when you ask us — which, after access is switched off, is the only way to get your data back.

Public-form enquiries and website analytics follow the same rule: we keep them until they are no longer useful for the purpose we collected them for, or until you ask us to delete them.

Rights

Your privacy rights

Wherever you live, you can ask us for any of the following. We do not charge for it, and we will not treat you differently for asking.

  • A copy of your data — what personal data we hold about you, why we have it, and who we share it with.
  • A portable copy — in a common machine-readable format, where we hold it that way.
  • A correction — if something we hold about you is wrong.
  • Deletion — of your personal data, subject to records we are required to keep.
  • To opt out of analytics — use Privacy choices at the bottom of any page. You do not need to write to us for that one.

We do not sell personal data or share it for cross-context behavioural advertising, so there is nothing to opt out of there. We do not use personal data for profiling that produces legal or similarly significant effects.

How to ask. Email adam@oaboscorecard.com with “Privacy request” in the subject and tell us what you want. We may need to ask you for enough information to be confident of who you are, and we use anything you send for that check and nothing else. Someone authorized to act for you can make a request on your behalf if they can show you asked them to.

When you will hear back. Within 45 days. If a request is genuinely complicated we may need up to 45 more, and we will tell you inside the first 45 that we need them, and why.

If we say no. We will tell you why. You can ask us to reconsider by replying with “appeal” in the subject. The founder, Oabo’s only privacy decision-maker today, reviews the recorded reason and the request again and answers in writing within 45 days. This is a reconsideration, not an independent review. Where applicable law gives you a regulator complaint path, we will identify it in the answer.

If you work for an Oabo customer. Your employer controls the data in its workspace, so send your request to them first — they can access, correct, and export within the product. If you write to us instead, we will pass the request to them, help them answer it, and tell you we have done so.

Eligibility

Who may use Oabo

Oabo is business software, sold to organizations and used at work. You must be 18 or older to use it. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and if we learn that we have, we delete it. If you believe a child’s data has reached us, write to adam@oaboscorecard.com and we will remove it.

Changes

Changes, and what changed in this one

Each version of this policy carries a version number and an effective date at the top. A change in substance moves the first number (2.0 to 3.0); a correction or a wording change moves the second (2.0 to 2.1). Material changes are communicated to customers through the service or by email before they take effect where we can. Earlier versions are available on request.

Version 4.42026-08-26. What changed:

  • Added the Telegram cloud-copy retention and deletion boundary and the sensitive-data warning shown before a support message is sent.
  • Described a refused request’s appeal as founder reconsideration, not independent review.
  • Rewrote automatic trial messages as account-status notices and recorded the gate for any future promotional trial-conversion email.
  • Added the contact form’s just-in-time Privacy Policy link.
  • Corrected the Cloudflare description: normal domain traffic uses the edge, but the native Cloud Run origin remains internet-reachable.

Contact

Contact us

Privacy questions and requests go to adam@oaboscorecard.com, and we are the right people to ask: Oabo Scorecard is a product of AgentX, LLC. Existing customers may also use the contact channel provided in their Oabo account or customer agreement. Our Terms of Service cover the rest of the relationship, including what must not be put into the service.