Skip to main content

New: Trust & Privacy Manifesto

Read our founder's personal commitment to privacy and why OSQR is built on architectural trust, not promises.

Privacy is Capability

If you can't trust your AI, you can't use it to its full potential. OSQR is built on privacy from the ground up.

"Your data belongs to you."

OSQR exists to make you more capable — not to extract anything from you. Everything you upload, write, think, or store in OSQR belongs solely to you. Your data is never sold, and never used to train AI. The only thing it's ever shared with is the AI provider that answers your request — and only the text that request needs. OSQR uses your data to think for you, not for anyone else.

OSQR is a private intelligence engine — not a data farm.

1Our Privacy Commitments

Your Vault is Yours Alone

Your files, chats, uploads, and memories are encrypted at rest and isolated to your account. OSQR's systems use them only to work for you, and your content is never sold. We don't read your content as a matter of course — the rare exception is a named engineer investigating a specific fault on your account, which we keep to what the problem requires.

Never Used for Training

OSQR does not train any AI model on your data — ours or anyone else's — and the AI providers we send requests to don't train on it either. Not now. Not ever.

Encrypted & Secure

Your vault is encrypted at rest (AES-256-GCM) under a key unique to your account, and protected in transit (TLS 1.2+, TLS 1.3 on modern clients). Embeddings are stored as numeric vectors, not as readable text. OSQR can decrypt your content to do the work you're asking for — that's what makes an assistant that knows your world possible — so this is not zero-knowledge, and we won't claim it is.

The "Burn It" Button

Delete your data instantly. One click. Irreversible. Documents, embeddings, chats, memories, vault, profile, cached outputs and logs — gone for good. It deletes your whole workspace, which takes your business's records inside it with it: website and text conversations, voicemails and call transcripts. What it does not reach: the phone number rented for you, which has to be released separately; voicemail audio held by the telephony company; the do-not-contact list, which we keep on purpose so nobody who asked you to stop texting them is ever resurrected; and contact records, which are stored without a link to the workspace and so are left behind rather than removed with it.

2Privacy Tiers

You control how your data is used. Choose the level that fits your comfort.

A

Maximum Privacy

Default
  • Nothing leaves your vault except what's sent to AI models to answer your questions
  • None of your data improves OSQR globally
  • No anonymization, no analytics on your content
  • Fully private — the strictest setting
B

Improve My OSQR

  • No raw content is ever shared
  • Optionally allow OSQR to learn from patterns only
  • Example: "User sets fitness goals but doesn't follow through"
  • Improves your personal model — not anyone else's
C

Global Patterns

  • Opt-in only, off by default, extra warnings
  • Anonymously contribute patterns (never content)
  • Zero identifiable data — aggregated trends only
  • Help improve OSQR for everyone (the "Waze" model)

3Where Your Data Lives

Data TypeStorage
Your DocumentsEncrypted database (PostgreSQL + Neon)
Your EmbeddingsNumeric vectors — not stored as readable text
Your ProfileEncrypted rows tied only to your account
Your ChatsEncrypted at rest; only the text needed for a request is sent to AI providers
AI RequestsOnly the text needed to answer your question is sent to AI providers

4How Your Content Is Accessed

Being honest: OSQR is not “zero-knowledge.” Running the AI means our servers have to decrypt and read your content to answer you. So the promise isn't “we can't see it” — it's that we tightly limit who and what touches it, and never use it against you.

OSQR never:

  • Sells or rents your data
  • Trains AI models on your content
  • Shows you ads or builds ad profiles
  • Lets staff open your vault documents — no support tool can reach them
  • Reads your conversations without your say-so, or without leaving a record
  • Keeps a hidden copy after you delete

What OSQR actually accesses:

  • Decrypts your content on our servers, only to run the AI and features you ask for
  • Sends only the text needed for a request to AI providers (who don't train on it)
  • Lets staff see account metadata by default — email, plan, billing, error logs
  • Reads your conversations only when you approve a specific request, for a set number of hours, with a record you can read
  • Stores everything encrypted at rest, isolated to your account

5The "Burn It" Button

Instant, Complete Deletion

When you click "Burn It," OSQR permanently deletes:

  • • All your documents
  • • All embeddings
  • • All chat history
  • • All memories
  • • Your entire vault
  • • All profile data
  • • Cached model outputs
  • • All system logs
  • • Your workspace and everything filed in it
  • • Website and text conversations
  • • Voicemails and call transcripts
  • • Your encryption keys, destroyed first

Once deleted, OSQR cannot recover your data.

There is no undo. No internal archive. No ghost copy for analytics. Our database provider keeps short-term encrypted backups of its own, on its own clock, and deleted rows age out of those with time.

What Burn It does not reach. If you rent a phone number through us, that number is not handed back to the telephone company by this button — write to us and we will release it. Voicemail audio sits on the telephony company's systems rather than ours, and is not deleted by this button either. We keep the do-not-contact list: if somebody replied STOP to your business, that stays, because erasing it would let them be texted all over again. And contact records — the people list your conversations built up — are stored without a link back to the workspace, so those rows are left behind rather than removed with it; ask us and we will clear them by hand.

Legal exception: In rare cases where OSQR is required by law, regulation, valid legal process (such as a subpoena or court order), or governmental request to preserve data, the "Burn It" function may be temporarily suspended for the affected account until the legal obligation is resolved. We will notify you if this occurs, unless prohibited by law from doing so.

6How AI Requests Work

When OSQR sends something to AI providers (OpenAI, Anthropic, etc.), the rule is simple:

Only the exact text necessary to answer your question goes to the model.

Example:

If you ask: "Summarize page 4 of my document"

→ OSQR only sends page 4's text to the AI

Example:

If you ask: "What were my goals last month?"

→ OSQR fetches goals from your vault internally, sends only your question and the relevant text

You control what is sent because it is always tied to your explicit action.

7Encryption & Security

At Rest

AES-256 encryption via Neon/PostgreSQL

In Transit

TLS 1.2+ / HTTPS for all connections

Passwords

Hashed with bcrypt/argon2 (never stored in plain text)

Embeddings

Stored as numeric vectors, not as readable text

8Data Minimization

OSQR collects the minimum necessary:

  • Email address
  • Password (hashed)
  • Subscription status
  • Usage metrics (not content)
  • Optional profile info you provide

That's it. No tracking. No surveillance. No creepy behavior. No "shadow profiles."

9When OSQR Runs on a Business's Website or Phone Line

Some businesses use OSQR to power the chat on their own websites, the text lines on their own phone numbers, and — where they have switched it on — to answer those numbers when somebody calls. If you chat, text or speak with one of those assistants, you are talking to that business, not to OSQR: the business is the controller of your data. Its privacy policy governs the conversation, and OSQR processes it on their behalf under our Data Processing Agreement.

The first time you call one of those numbers and an assistant answers: it opens the call by telling you that the call is transcribed and that you are speaking with an AI assistant. If you have called that business before and already heard that: it opens with a short reminder that the call is transcribed. Nothing else changes on a later call — you are still speaking with an AI assistant, and whenever you ask whether you are talking to a person, on that call or any other, it will say plainly that you are not. Your voice reaches that assistant live, as you speak, through one of the two AI providers we have approved for that job — one is in use at a time, and every provider we use is on our subprocessor list. The words of the conversation are written down and kept with the business's record of you. The audio of that conversation is not recorded.

A voicemail is different. If nobody answers and you leave a message, that message is an audio recording. It is held by the telephony company that carries the call, transcribed so the business can read it, and today nothing deletes that audio on a schedule — we keep the transcript, they keep the recording.

How long it is kept: for now, until the business closes its OSQR account and deletes its workspace. There is no expiry date on a conversation and no automatic clean-up that removes one: a typed chat, a text thread, a voicemail transcript and the written record of a call all stay while the account exists. We are building a proper deletion tool — a way to erase one person's records on request — and until it ships we do it by hand. Write to us at info@osqr.ai and we will carry it out and tell you when it is done.

To exercise privacy rights over one of those conversations, contact the business you were talking to — they hold the relationship, and we support them in honoring your request. For text lines, reply STOP at any time and messaging ends immediately. On a call, saying you do not want to be contacted again is enough — the assistant writes it down, and from then on that business cannot text you or dial you through OSQR on any of its lines, not just the one you were on.

10Google User Data & Third-Party Integrations

When you connect your Google account (Gmail, Calendar, Drive, Contacts, Tasks) to OSQR, OSQR receives a scoped OAuth grant from Google that lets OSQR act on your behalf inside your Google account. This section describes exactly what OSQR does with that access and what it does not do.

Scopes OSQR requests from Google

ScopeWhat OSQR uses it for
gmail.modifyRead, label, archive, send, and reply to emails when you instruct OSQR (or your OSQR VA) to do so. OSQR only acts on messages in response to your explicit commands or the automations you configure.
calendarCreate, update, and read events on your Google Calendar when you ask OSQR to schedule, reschedule, or look up meetings.
drive.fileOpen and save only the specific Drive files you ask OSQR to work with (per-file access — OSQR cannot browse your whole Drive).
contactsLook up and create contacts when you ask OSQR to email or message someone.
tasksRead and write items to your Google Tasks when you ask OSQR to capture or complete a task.
userinfo.emailIdentify which Google account the grant belongs to. Not used for marketing.

Google API Services User Data Policy & Limited Use

OSQR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • OSQR does not use Google user data (including Gmail message content) to train generalized or third-party AI / ML models.
  • OSQR does not sell, rent, or transfer Google user data for advertising, re-selling, or any purpose unrelated to the user-facing features you asked OSQR to perform.
  • OSQR does not allow humans to read Google user data except (a) with your explicit consent, (b) where necessary for security investigations or to comply with applicable law, or (c) where the data has been aggregated and anonymized for service-operations purposes (e.g., error counts).
  • OSQR only transfers Google user data to the AI providers needed to fulfill the specific request you made (e.g., summarize this thread), and only the text needed to answer that request. Sub-processors are contractually bound not to use the data for training.

Where Google data lives in OSQR

OSQR does not maintain a persistent mirror of your Gmail inbox. Messages are fetched from Google on-demand when you (or your automation) ask OSQR to act on them, and are discarded from working memory when the request completes. OSQR stores:

  • Your OAuth access and refresh tokens, encrypted at rest in our Neon (PostgreSQL) database.
  • Minimal metadata required to support your automations (e.g., the Gmail message ID you told OSQR to follow up on).
  • Logs of actions OSQR took on your behalf (who, what, when — never the message body), for audit and support.

How to revoke OSQR's access to your Google account

You can remove OSQR's access at any time:

  • 1.Inside OSQR, open Settings → Integrations and click Disconnect next to Google. OSQR immediately revokes its OAuth token and deletes the stored credentials.
  • 2.You can also revoke access directly from Google at myaccount.google.com/permissions.
  • 3.The "Burn It" button (described above) deletes every OAuth token OSQR holds for you as part of the full-account wipe.

A Note from the Founder

I built OSQR to be the AI assistant I always wanted — one that truly knows me, remembers my context, and helps me think better. But that kind of deep integration requires trust.

If you're going to index your entire life into an AI system — your documents, your thoughts, your goals, your struggles — you need to know that data is sacred.

That's why OSQR is built on privacy from day one. Not as a feature. Not as a marketing bullet point. As a foundation.

Your capability depends on your willingness to be honest with OSQR. And your willingness depends on trust. I intend to earn it.

KR

Kable Record

Founder & 100% Owner, OSQR

Questions about privacy? Concerns? Ideas?

info@osqr.ai