New: Trust & Privacy Manifesto
Read our founder's personal commitment to privacy and why OSQR is built on architectural trust, not promises.
Privacy is Capability
If you can't trust your AI, you can't use it to its full potential. OSQR is built on privacy from the ground up.
"Your data belongs to you."
OSQR exists to make you more capable — not to extract anything from you. Everything you upload, write, think, or store in OSQR belongs solely to you. Your data is never sold, and never used to train AI. The only thing it's ever shared with is the AI provider that answers your request — and only the text that request needs. OSQR uses your data to think for you, not for anyone else.
OSQR is a private intelligence engine — not a data farm.
1Our Privacy Commitments
Your Vault is Yours Alone
Your files, chats, uploads, and memories are encrypted at rest and isolated to your account. OSQR's systems use them only to work for you, and your content is never sold. We don't read your content as a matter of course — the rare exception is a named engineer investigating a specific fault on your account, which we keep to what the problem requires.
Never Used for Training
OSQR does not train any AI model on your data — ours or anyone else's — and the AI providers we send requests to don't train on it either. Not now. Not ever.
Encrypted & Secure
Your vault is encrypted at rest (AES-256-GCM) under a key unique to your account, and protected in transit (TLS 1.2+, TLS 1.3 on modern clients). Embeddings are stored as numeric vectors, not as readable text. OSQR can decrypt your content to do the work you're asking for — that's what makes an assistant that knows your world possible — so this is not zero-knowledge, and we won't claim it is.
The "Burn It" Button
Delete your data instantly. One click. Irreversible. Documents, embeddings, chats, memories, vault, profile, cached outputs and logs — gone for good. It deletes your whole workspace, which takes your business's records inside it with it: website and text conversations, voicemails and call transcripts. What it does not reach: the phone number rented for you, which has to be released separately; voicemail audio held by the telephony company; the do-not-contact list, which we keep on purpose so nobody who asked you to stop texting them is ever resurrected; and contact records, which are stored without a link to the workspace and so are left behind rather than removed with it.
2Privacy Tiers
You control how your data is used. Choose the level that fits your comfort.
Maximum Privacy
- Nothing leaves your vault except what's sent to AI models to answer your questions
- None of your data improves OSQR globally
- No anonymization, no analytics on your content
- Fully private — the strictest setting
Improve My OSQR
- No raw content is ever shared
- Optionally allow OSQR to learn from patterns only
- Example: "User sets fitness goals but doesn't follow through"
- Improves your personal model — not anyone else's
Global Patterns
- Opt-in only, off by default, extra warnings
- Anonymously contribute patterns (never content)
- Zero identifiable data — aggregated trends only
- Help improve OSQR for everyone (the "Waze" model)
3Where Your Data Lives
| Data Type | Storage |
|---|---|
| Your Documents | Encrypted database (PostgreSQL + Neon) |
| Your Embeddings | Numeric vectors — not stored as readable text |
| Your Profile | Encrypted rows tied only to your account |
| Your Chats | Encrypted at rest; only the text needed for a request is sent to AI providers |
| AI Requests | Only the text needed to answer your question is sent to AI providers |
4How Your Content Is Accessed
Being honest: OSQR is not “zero-knowledge.” Running the AI means our servers have to decrypt and read your content to answer you. So the promise isn't “we can't see it” — it's that we tightly limit who and what touches it, and never use it against you.
OSQR never:
- ✕Sells or rents your data
- ✕Trains AI models on your content
- ✕Shows you ads or builds ad profiles
- ✕Lets staff open your vault documents — no support tool can reach them
- ✕Reads your conversations without your say-so, or without leaving a record
- ✕Keeps a hidden copy after you delete
What OSQR actually accesses:
- ✓Decrypts your content on our servers, only to run the AI and features you ask for
- ✓Sends only the text needed for a request to AI providers (who don't train on it)
- ✓Lets staff see account metadata by default — email, plan, billing, error logs
- ✓Reads your conversations only when you approve a specific request, for a set number of hours, with a record you can read
- ✓Stores everything encrypted at rest, isolated to your account
5The "Burn It" Button
Instant, Complete Deletion
When you click "Burn It," OSQR permanently deletes:
- • All your documents
- • All embeddings
- • All chat history
- • All memories
- • Your entire vault
- • All profile data
- • Cached model outputs
- • All system logs
- • Your workspace and everything filed in it
- • Website and text conversations
- • Voicemails and call transcripts
- • Your encryption keys, destroyed first
Once deleted, OSQR cannot recover your data.
There is no undo. No internal archive. No ghost copy for analytics. Our database provider keeps short-term encrypted backups of its own, on its own clock, and deleted rows age out of those with time.
What Burn It does not reach. If you rent a phone number through us, that number is not handed back to the telephone company by this button — write to us and we will release it. Voicemail audio sits on the telephony company's systems rather than ours, and is not deleted by this button either. We keep the do-not-contact list: if somebody replied STOP to your business, that stays, because erasing it would let them be texted all over again. And contact records — the people list your conversations built up — are stored without a link back to the workspace, so those rows are left behind rather than removed with it; ask us and we will clear them by hand.
Legal exception: In rare cases where OSQR is required by law, regulation, valid legal process (such as a subpoena or court order), or governmental request to preserve data, the "Burn It" function may be temporarily suspended for the affected account until the legal obligation is resolved. We will notify you if this occurs, unless prohibited by law from doing so.
6How AI Requests Work
When OSQR sends something to AI providers (OpenAI, Anthropic, etc.), the rule is simple:
Only the exact text necessary to answer your question goes to the model.
Example:
If you ask: "Summarize page 4 of my document"
→ OSQR only sends page 4's text to the AI
Example:
If you ask: "What were my goals last month?"
→ OSQR fetches goals from your vault internally, sends only your question and the relevant text
You control what is sent because it is always tied to your explicit action.
7Encryption & Security
At Rest
AES-256 encryption via Neon/PostgreSQL
In Transit
TLS 1.2+ / HTTPS for all connections
Passwords
Hashed with bcrypt/argon2 (never stored in plain text)
Embeddings
Stored as numeric vectors, not as readable text
8Data Minimization
OSQR collects the minimum necessary:
- Email address
- Password (hashed)
- Subscription status
- Usage metrics (not content)
- Optional profile info you provide
That's it. No tracking. No surveillance. No creepy behavior. No "shadow profiles."
9When OSQR Runs on a Business's Website or Phone Line
Some businesses use OSQR to power the chat on their own websites, the text lines on their own phone numbers, and — where they have switched it on — to answer those numbers when somebody calls. If you chat, text or speak with one of those assistants, you are talking to that business, not to OSQR: the business is the controller of your data. Its privacy policy governs the conversation, and OSQR processes it on their behalf under our Data Processing Agreement.
The first time you call one of those numbers and an assistant answers: it opens the call by telling you that the call is transcribed and that you are speaking with an AI assistant. If you have called that business before and already heard that: it opens with a short reminder that the call is transcribed. Nothing else changes on a later call — you are still speaking with an AI assistant, and whenever you ask whether you are talking to a person, on that call or any other, it will say plainly that you are not. Your voice reaches that assistant live, as you speak, through one of the two AI providers we have approved for that job — one is in use at a time, and every provider we use is on our subprocessor list. The words of the conversation are written down and kept with the business's record of you. The audio of that conversation is not recorded.
A voicemail is different. If nobody answers and you leave a message, that message is an audio recording. It is held by the telephony company that carries the call, transcribed so the business can read it, and today nothing deletes that audio on a schedule — we keep the transcript, they keep the recording.
How long it is kept: for now, until the business closes its OSQR account and deletes its workspace. There is no expiry date on a conversation and no automatic clean-up that removes one: a typed chat, a text thread, a voicemail transcript and the written record of a call all stay while the account exists. We are building a proper deletion tool — a way to erase one person's records on request — and until it ships we do it by hand. Write to us at info@osqr.ai and we will carry it out and tell you when it is done.
To exercise privacy rights over one of those conversations, contact the business you were talking to — they hold the relationship, and we support them in honoring your request. For text lines, reply STOP at any time and messaging ends immediately. On a call, saying you do not want to be contacted again is enough — the assistant writes it down, and from then on that business cannot text you or dial you through OSQR on any of its lines, not just the one you were on.
10Google User Data & Third-Party Integrations
When you connect your Google account (Gmail, Calendar, Drive, Contacts, Tasks) to OSQR, OSQR receives a scoped OAuth grant from Google that lets OSQR act on your behalf inside your Google account. This section describes exactly what OSQR does with that access and what it does not do.
Scopes OSQR requests from Google
| Scope | What OSQR uses it for |
|---|---|
| gmail.modify | Read, label, archive, send, and reply to emails when you instruct OSQR (or your OSQR VA) to do so. OSQR only acts on messages in response to your explicit commands or the automations you configure. |
| calendar | Create, update, and read events on your Google Calendar when you ask OSQR to schedule, reschedule, or look up meetings. |
| drive.file | Open and save only the specific Drive files you ask OSQR to work with (per-file access — OSQR cannot browse your whole Drive). |
| contacts | Look up and create contacts when you ask OSQR to email or message someone. |
| tasks | Read and write items to your Google Tasks when you ask OSQR to capture or complete a task. |
| userinfo.email | Identify which Google account the grant belongs to. Not used for marketing. |
Google API Services User Data Policy & Limited Use
OSQR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- OSQR does not use Google user data (including Gmail message content) to train generalized or third-party AI / ML models.
- OSQR does not sell, rent, or transfer Google user data for advertising, re-selling, or any purpose unrelated to the user-facing features you asked OSQR to perform.
- OSQR does not allow humans to read Google user data except (a) with your explicit consent, (b) where necessary for security investigations or to comply with applicable law, or (c) where the data has been aggregated and anonymized for service-operations purposes (e.g., error counts).
- OSQR only transfers Google user data to the AI providers needed to fulfill the specific request you made (e.g., summarize this thread), and only the text needed to answer that request. Sub-processors are contractually bound not to use the data for training.
Where Google data lives in OSQR
OSQR does not maintain a persistent mirror of your Gmail inbox. Messages are fetched from Google on-demand when you (or your automation) ask OSQR to act on them, and are discarded from working memory when the request completes. OSQR stores:
- Your OAuth access and refresh tokens, encrypted at rest in our Neon (PostgreSQL) database.
- Minimal metadata required to support your automations (e.g., the Gmail message ID you told OSQR to follow up on).
- Logs of actions OSQR took on your behalf (who, what, when — never the message body), for audit and support.
How to revoke OSQR's access to your Google account
You can remove OSQR's access at any time:
- 1.Inside OSQR, open Settings → Integrations and click Disconnect next to Google. OSQR immediately revokes its OAuth token and deletes the stored credentials.
- 2.You can also revoke access directly from Google at myaccount.google.com/permissions.
- 3.The "Burn It" button (described above) deletes every OAuth token OSQR holds for you as part of the full-account wipe.
A Note from the Founder
I built OSQR to be the AI assistant I always wanted — one that truly knows me, remembers my context, and helps me think better. But that kind of deep integration requires trust.
If you're going to index your entire life into an AI system — your documents, your thoughts, your goals, your struggles — you need to know that data is sacred.
That's why OSQR is built on privacy from day one. Not as a feature. Not as a marketing bullet point. As a foundation.
Your capability depends on your willingness to be honest with OSQR. And your willingness depends on trust. I intend to earn it.
Kable Record
Founder & 100% Owner, OSQR
Questions about privacy? Concerns? Ideas?
info@osqr.ai