Privacy Policy
LAST UPDATED: SEPTEMBER 27, 2026
Overview
OCore, Inc. ("OCore," "we," "our," or "us") builds the living O&M layer for water and wastewater utilities. This policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices you have. It covers our website (ocore.io), the OCore platform, and our iOS app.
When your utility uses OCore, its agreement with us also governs its data. If that agreement and this policy conflict, the agreement controls.
Information we collect
On our website.
- Analytics. We use PostHog to see how people find and use the site: pages viewed, links clicked, the referring site, and campaign tags. PostHog runs in cookieless mode, so it doesn't store cookies or identifiers on your device.
- Company identification. We use RB2B to match the IP addresses of visitors in the United States to companies and, in some cases, to individual business profiles. RB2B sets its own cookies and local storage on your device to do this. We use the results to learn which organizations are interested in OCore.
- Server logs. Our host keeps standard request logs, such as IP address, browser type, time, and the page requested, to run and secure the site.
When you contact us. When you email us or request a demo, we collect your name, email address, organization, and whatever else you choose to include.
On the OCore platform and in the iOS app.
- Account information. Your name, email address, phone number if provided, role, and the utility you work for. Your utility's administrator creates your account. We don't store your password in readable form.
- Operational data. SCADA readings and alarm events, equipment and asset records, procedures and O&M manual content, rounds, tasks, and notes.
- Content you add. Documents, photos, signatures, voice-note audio files, and recordings and transcripts from knowledge-capture interviews.
- Co-agent conversations. The questions you ask the AI co-agent and the answers it gives.
- Location. If you allow it, the app uses your device's location to place an asset or site on the map. We save only the position you place. You can decline, and the rest of the app still works.
- Camera and photos. The app opens your camera or photo library only when you choose to attach a photo.
- Usage and diagnostics. Sign-in events, a log of the actions taken in the platform, the IP address of each request (used for security), and basic error reports that record the type of error and the screen it happened on.
We don't use the app to track you across other companies' apps or websites, and we don't show ads.
How we use information
- Provide, run, secure, and support OCore
- Respond to questions and demo requests
- Understand how our website and platform are used, and improve them
- Send product updates when you've asked to hear from us
- Meet legal obligations and enforce our agreements
Improving OCore. We may use data about how the platform is used, and data that's aggregated or de-identified so it doesn't identify your utility or any person, to improve OCore, including to train our models. We don't train models on your utility's identifiable data unless your utility opts in in writing.
AI and the co-agent
OCore's AI co-agent teaches, grounds, and recommends. The operator stays in command. Its answers are AI-generated and can be wrong, so check them before you act. OCore doesn't act on your operational systems.
To answer a question, we send it, along with the plant records the co-agent needs, to our AI model provider, Anthropic. We also send the text of documents your utility uploads to Anthropic to sort them, and to Voyage AI to index them for search. These providers process the data to return a result to us. Anthropic doesn't use it to train its models, and it may keep it for a limited time for safety and abuse monitoring under its commercial terms. If your utility supplies its own Anthropic account, requests go through that account under your utility's terms with Anthropic.
Who we share information with
We don't sell personal information, and we don't share it for advertising. We share it only:
- With the service providers listed below, to run OCore for us
- With your utility: its administrators can see account and activity information for their staff
- When the law requires it, or to protect the safety of people, public health, or our systems
- As part of a merger, acquisition, or sale of assets, subject to this policy
- With your consent
Providers that process platform and app data. Each may use the data only to provide its service to us, and must protect it at least as well as this policy does.
- Vercel: application and website hosting
- Supabase: database and sign-in
- TigerData: storage for SCADA time-series data
- Anthropic: AI model provider for the co-agent and document sorting
- Voyage AI: search indexing for documents
- Esri and OpenStreetMap: maps
- Google Fonts: typefaces the platform loads from Google
Website and business tools. PostHog and RB2B (website analytics, described above), HubSpot (our contact records), and Microsoft 365 (email). These services handle information under their own privacy policies.
Our providers may change as OCore grows. We'll keep this list current.
How long we keep information
- Platform data. We keep your utility's data while its agreement is active. When the agreement ends, your utility can ask for an export for 30 days. After that, we delete it from our active systems, and copies in backups are removed as the backups expire. Aggregated or de-identified data doesn't identify anyone and isn't covered by this deletion.
- Account information, co-agent conversations, and activity logs. We keep them while your account and your utility's agreement are active.
- Contact information. We keep it while we have a business relationship with you, or until you ask us to delete it.
Deleting your account
To delete your account, email info@ocore.io from the address on your account, or use the account deletion option in the app where it's available. Your utility manages your account, so we confirm the request with your utility and then delete your account information. Records you created as part of your utility's work, such as rounds, notes, and asset records, belong to your utility and stay with its records.
Your choices and rights
If you're a website visitor or a contact, OCore holds your information. You can ask us to access, correct, or delete it, or to stop sending you updates. We won't treat you differently for asking. You can also block cookies in your browser, which stops RB2B from using them.
If the data is your utility's platform data, OCore processes it for your utility, on its instructions, as a service provider. Send requests about that data to your utility, and we'll help your utility respond.
Device permissions. You can turn off location, camera, or photo access for the app at any time in your iPhone's Settings.
Security
We protect data with safeguards suited to the systems it supports, including encryption in transit, role-based access controls, and database-level separation between utilities. No system is perfectly secure. For details, see our Security page.
Where information is processed
OCore is based in the United States. We and our providers process information in the United States and may process it in other countries.
Children
OCore is built for utility professionals. It isn't directed to children under 13, and we don't knowingly collect their information.
Changes to this policy
When our practices change, we'll update this page and the date at the top.
Contact
For privacy questions or requests, email info@ocore.io.
OCore, Inc.
710 South Redwood Rd
North Salt Lake City, UT