Your data in Oatmeal.
A clear view of what stays on your device and what leaves when you choose a connected feature.
This marketing website
This site offers a fictional interactive preview, plan information, and links to configured destinations. It does not import your notes, activate licenses, or run managed ingestion. This code includes no analytics or advertising trackers, and its fonts are served locally. The hosting provider may process normal request data, such as IP addresses and browser information; any additional hosting analytics must be assessed before enabling them.
Your local workspace
Imported notes and transcripts power local search, recurring-term themes, graph, timeline, citations, and report preparation. The macOS app reads selected local folders and saves a local parse cache. Oatmeal does not modify imported originals when exploring them.
Local analysis does not require managed ingestion. Removing a local source does not delete its original from the service it came from.
Managed ingestion
When you run managed ingestion, the selected document text, title, configured classification choices, and team names or aliases are sent over HTTPS to your configured Oatmeal service. The service forwards bounded input to TypeSafe Jev to classify category, audience, and document type. Jev is not the chat or transcription provider.
The broker is designed not to persist raw document text or log request bodies. It stores keyed fingerprints, classification results, usage records, seat and subscription identifiers, and hashed email and device bindings to enforce quotas and licensing. Hosting infrastructure and provider retention policies must be reviewed as part of deployment. This is not a zero-retention guarantee.
Failed provider requests and technical retries do not consume a second document allowance. A completed result flagged for review still counts. Existing local sources stay available when your allowance runs out.
Email and license activation
Each paid seat has a unique Oatmeal license key. Activation checks the assigned employee email using a time-limited email code, and binds the seat to one active device. The configured email delivery provider receives the destination address and verification message. Lemon Squeezy handles subscription billing; Oatmeal checks subscription status and purchased seat quantity.
In the desktop app, managed license credentials and the random installation secret use macOS Keychain. They are not saved in transcript files, shared workspace settings, or browser local storage. Paid seat activation is desktop-only. This marketing website does not store or activate a managed license.
Chat and other connections
Asking a question through a connected AI provider sends the bounded evidence packet and recent same-scope chat context to that provider. Its account, costs, and data handling are separate. Source connectors use the credentials and permissions you configure to fetch available notes or transcripts. Copying evidence to another assistant is a separate action.
Oatmeal does not join meetings, record audio, or generate speech-to-text transcripts. Review the original evidence and your selected providers’ policies before sending confidential information.
Before managed service launch
Managed billing and ingestion are not enabled until the operator configures and tests the service. Hosting location, support contact, provider policies, retention/deletion procedures, and any required agreements must be finalized before customers are invited to use it. This page describes the implemented data flow; it is not a claim of a compliance certification.