Privacy Policy

Effective date: August 21, 2026

1. Introduction

This Privacy Policy describes how Osyr ("we," "us," "our") collects, uses, and protects your personal information when you use our website, platform, and services (collectively, the "Service"). We are committed to protecting your privacy and being transparent about our data practices.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials (managed through Supabase Auth). If you sign up via Google OAuth, we receive your name, email, and avatar from Google.

Organization Data

We store the data your organization creates through the Service: clients, projects, tasks, documents, invoices, calendar events, knowledge base uploads, and AI agent interactions. This data belongs to you and your organization.

Payment Information

Payment processing is handled by Paddle (for subscriptions) and Stripe (for client invoice payments, configured per tenant). We do not store credit card numbers, bank details, or cryptocurrency wallet keys on our servers. Payment information is processed and stored by these third-party payment processors in accordance with PCI DSS standards.

Usage and Technical Data

We collect session identifiers, page views, click patterns, web vitals (TTFB, LCP, CLS, INP), error logs, and IP addresses. This data is used for product analytics, debugging, and improving the Service. Analytics tracking requires your explicit consent via our cookie consent banner.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Send administrative notifications (account confirmations, security alerts, billing communications)
  • Detect and prevent fraud, abuse, and security incidents
  • Analyze usage patterns to improve functionality and user experience (with your consent)
  • Comply with legal obligations

4. AI Processing

Our AI Features process your data to generate responses, drafts, and analyses. AI processing is performed by third-party AI providers (Google Gemini). Your data is sent to these providers solely for the purpose of generating responses for your organization.

We do not use your data to train AI models. Your organization's data is not shared with other users or used to improve models for other customers. AI outputs may be logged for quality assurance and debugging purposes.

5. Data Sharing

We do not sell your personal information. We share your data only in the following circumstances:

  • Service providers: We share data with third-party providers who help us operate the Service (Supabase for database and auth, Vercel for hosting, Resend for email, Paddle/Stripe for payments, Google Gemini for AI, PostHog for analytics). These providers are contractually bound to protect your data.
  • Legal requirements: We may disclose your data if required by law, regulation, or legal process.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred, subject to the same privacy protections.
  • With your consent: We may share data when you explicitly authorize us to do so.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Row-level security (RLS) at the database level — each organization's data is isolated
  • Role-based access control (RBAC) with five permission levels
  • Append-only audit logging of all data modifications
  • Edge rate limiting to prevent abuse
  • Hashed API keys (SHA-256) — never stored in plaintext
  • Regular security monitoring via Sentry error tracking

While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7. Data Retention

We retain your account information for as long as your account is active. Organization data is retained while your subscription is active and for up to 30 days after termination to allow for data export.

Webhook delivery logs are pruned after 30 days. Analytics event data is retained for 12 months. Audit logs are retained for 24 months.

8. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under data protection law:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate personal data
  • Erasure:Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request restriction of processing of your personal data
  • Portability: Request a copy of your data in a structured, machine-readable format
  • Objection: Object to processing of your personal data
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at hello@osyr.tech. We will respond within 30 days.

9. International Data Transfers

Your data may be processed in countries outside your own. Our infrastructure providers (Supabase, Vercel) operate globally. We ensure that international transfers are protected by appropriate safeguards, including standard contractual clauses where required by applicable law.

10. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication, security, and core functionality. These cannot be disabled.
  • Analytics cookies: Used to understand how you use the Service. These are optional and require your explicit consent via our cookie consent banner.

You can manage your cookie preferences at any time through the cookie consent banner displayed on first visit.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service at least 30 days before they take effect. The "Effective date" at the top indicates when this policy was last updated.

13. Contact

For questions about this Privacy Policy or to exercise your data rights, contact us at hello@osyr.tech.