Back to home

Privacy Policy

Last updated: August 2026

1. Overview

Osyr ("we", "us", "our") provides an AI business operating system for service businesses. This Privacy Policy explains what personal data we collect, why we collect it, how it is used and protected, and the choices you have — including your rights under the GDPR, CCPA/CPRA and other applicable privacy laws.

This policy applies to our website, our application, our public client portal, and any related services (together, the "Service"). By using the Service, you agree to the collection and use of information as described here.

2. Data we collect

We collect the following categories of data:

  • Account data— name, email address, password (stored as a salted hash by our identity provider), and your organization's profile details (business name, address, logo).
  • Workspace data — the clients, projects, tasks, documents, proposals, contracts, invoices, calendar events and other records you create in the Service. This is your data; it is processed solely to provide the Service to you.
  • AI processing data — content you submit to our AI agents (for example, a brief used to draft a proposal). This content is sent to our AI providers to generate the requested output and is not used to train third-party models.
  • Payment data — we do not store raw card numbers. Card payments are processed by our payment providers (e.g. Stripe). We store only provider references, the payment amount, status, and (for crypto) the asset, network and transaction hash needed to verify and reconcile payments.
  • Technical & usage data — IP address, browser type, device information, pages visited, and feature usage. We use this to operate, secure and improve the Service and to diagnose errors.

3. How we use your data

  • To provide, maintain and secure the Service (contractual necessity).
  • To process transactions and reconcile payments (contractual necessity).
  • To send service communications — e.g. payment confirmations, security alerts, and transactional emails (contractual necessity).
  • To send product updates and marketing emails, only with your consent or where permitted by law — you can opt out at any time.
  • To improve the Service through aggregated, de-identified usage analytics.
  • To comply with legal obligations, resolve disputes and enforce our agreements.

4. AI and your data

Osyr's AI agents generate drafts and analysis from the content you provide. Before using AI features, you are shown a consent explainer describing exactly how AI uses your data, and you can decline. Your workspace data is used only to serve your own requests — it is never shared with other customers and is never used to train models that would expose your business information.

5. When we share data

We do not sell your personal data. We share data only with sub-processors who help us operate the Service, under written agreements that require them to protect your data:

  • Hosting & database providers (e.g. Vercel, Supabase) — to store and serve the Service.
  • AI model providers — to generate outputs you request.
  • Payment providers (e.g. Stripe, crypto payment rails) — to process card and crypto payments.
  • Email providers — to deliver transactional and (where consented) marketing email.
  • Analytics & monitoring (e.g. PostHog, Sentry) — to understand usage and diagnose errors.

We may also disclose data where required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where practicable).

6. How we protect data

Security is built into the Service: data is encrypted in transit (TLS) and at rest, tenant data is isolated at the database level with row-level security, all writes are audit-logged with actor and timestamp, and API keys are stored hashed. While no system is perfectly secure, we apply industry-standard safeguards and continuously monitor for issues.

7. Data retention & deletion

We retain your workspace data for as long as your account is active. When you delete data (records, documents, invoices) it is removed from the Service; backups are purged on a rolling schedule. Owners may delete their entire workspace at any time from Settings — this permanently removes the workspace and its data after a short grace period.

Audit logs are retained for security and compliance purposes for the period required by applicable law.

8. Your rights

Depending on your location, you may have the right to access, correct, export (portability), restrict or delete your personal data, and to object to or withdraw consent for processing. To exercise any of these rights, contact us at hello@osyr.ai or use the export/delete tools in Settings. We respond to verified requests within the timeframe required by law (typically 30 days).

California residents may also exercise their rights under the CCPA/ CPRA, including the right to know what personal information we collect and the right to request deletion.

9. Cookies & tracking

We use essential cookies (e.g. authentication and security) required for the Service to function, and — only with your consent — analytics cookies that help us understand usage. You can accept or decline non-essential cookies via the consent banner shown on your first visit, and you can change your choice at any time. For details on analytics, see our providers' documentation (PostHog, Sentry).

10. Children's privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email or an in-product notice before they take effect. Continued use of the Service after changes means you accept the updated policy.

12. Contact us

Questions about this policy or your data? Email us at hello@osyr.ai.