Short version: Your conversations and personal data live mostly on your device. We don't sell your data. We don't train AI models on it. AI providers (OpenAI, Replicate) process your inputs but don't keep them. Generated images return to your device — we don't store copies.
1. Data Controller
The data controller responsible for your personal data is:
Reg. No.: J13/3604/2023
Tax ID (CUI): 49038091
EUID: ROONRC.J13/3604/2023
Address: Iosif Ivanovici 12, Constanța, Romania
Contact: hello@osyren.app
2. What we collect
2.1 Information you provide directly
- Account information: email address (via Firebase Authentication), display name, password (hashed).
- Chat content: messages you write or speak to Osyren are sent to AI providers to generate responses.
- Plans, reminders, and personal facts: information you ask Osyren to remember (e.g. "I work in marketing", "my daughter's name is Maria") is stored to personalize your experience.
- Voice recordings: when you use voice input, audio is sent to OpenAI Whisper for transcription, then discarded.
- Photos you send: photos uploaded to Osyren are processed by AI providers (OpenAI for analysis, Replicate for generation), then discarded from our servers. Generated images return to your device.
- Documents: PDFs and other documents you upload for parsing are processed and discarded after the AI returns its response.
- Subscription status: handled by Apple App Store / Google Play. We receive only confirmation that you have an active subscription.
2.2 Information collected automatically
- Device timezone: to schedule reminders correctly.
- Crash and error logs: anonymous diagnostic information to fix bugs.
- Anonymous analytics: aggregated, anonymized data about feature usage (no personal content).
2.3 What we do NOT collect
- We do not access your contacts unless you explicitly invite them to a shared chat.
- We do not access your location unless you grant explicit permission for a specific feature.
- We do not access your photo library — only photos you actively share with Osyren.
- We do not collect health or financial data.
- We do not track you across other apps or websites.
- We do not use third-party advertising trackers or pixels.
3. AI image processing
Photos and prompts you upload for AI image generation are processed as follows:
- Sent to Replicate's servers (US-based) for processing through Google's "Nano Banana" model — a state-of-the-art image generation and editing model that preserves your identity in generated photos.
- Replicate does not use your photos to train AI models.
- Generated images are returned to your device and stored locally only.
- We don't keep copies of input photos or generated outputs on our servers.
- For users in the EU, transfers to Replicate are governed by Standard Contractual Clauses (SCCs).
4. How we use your information
- To provide the service: process your messages, generate AI responses, schedule reminders, sync your data across your devices.
- To improve Osyren: identify and fix bugs through anonymous crash reports.
- To communicate with you: respond to support requests sent to hello@osyren.app.
- To process subscriptions: through Apple App Store and Google Play (we don't see your payment details).
- To comply with legal obligations: respond to lawful requests from authorities.
5. Third-party processors
The following providers process your data on our behalf:
| Provider | Purpose | Region |
|---|---|---|
| OpenAI | Chat, voice transcription, photo analysis | USA |
| Replicate | AI image generation | USA |
| Firebase (Google) | Authentication, data sync | EU / USA |
| Railway | Backend infrastructure | USA |
| Apple / Google | Subscription billing & payment processing | USA / EU |
| Vercel | Website hosting & anonymous analytics | USA / EU |
For transfers outside the EU, we rely on Standard Contractual Clauses (SCCs) and other safeguards required by GDPR.
6. Data storage and security
Your data is stored in the following locations:
- Conversations and chat history: primarily on your device (AsyncStorage, encrypted by your operating system) and synced through Firestore for cross-device access.
- Sync data: Firebase Firestore (Google Cloud, EU/US regions), encrypted in transit and at rest.
- Backend logic: Railway servers (USA).
- Image processing: Replicate servers (USA), discarded after processing.
- Subscription data: Apple/Google (we don't store payment details).
We use HTTPS for all data in transit, hashed passwords, and standard cloud security practices. However, no online service can guarantee absolute security.
7. Data sharing
We do not sell your personal information. We do not share your data with advertisers. We do not train AI models on your data.
We share data only in these limited cases:
- With AI providers (OpenAI, Replicate) strictly to generate responses to your queries.
- With infrastructure providers (Firebase, Railway, Vercel) strictly to operate the service.
- With Apple/Google for subscription billing.
- With affiliate partners (GetYourGuide, Yesim, etc.) only when you explicitly click an affiliate link.
- If required by law or valid legal process.
- If you explicitly share data via shared chats or shared reminders with another user.
8. Your rights (GDPR + CCPA)
Under GDPR (for EU users) and CCPA (for California users), you have the right to:
- Access your data — view what Osyren stores about you in the app's Memory section.
- Correction — edit or delete any fact, plan, reminder, or chat directly from the app.
- Deletion — delete your account in-app via Settings → Profile → Delete Account, or contact us. Permanent deletion within 30 days.
- Data portability — request a copy of your data in JSON format by emailing us.
- Object to processing or restrict it under applicable laws.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your data protection authority. In Romania: ANSPDCP.
9. Data retention
- Active accounts: data retained while you use the service.
- Deleted accounts: full deletion within 30 days.
- Backups: maximum 90 days.
- Anonymous analytics: maximum 24 months.
- Crash logs: maximum 90 days.
- Subscription records: retained as required by tax and accounting law (typically 5-10 years in Romania).
10. Children's privacy
Osyren is intended for users 17 and older. We do not knowingly collect personal information from children under 13 (or 16 in some EU countries). If you believe a child has provided us information, please contact us at hello@osyren.app and we will delete it immediately.
11. International data transfers
Your data may be processed in countries outside your own, including the United States (where OpenAI, Replicate, and Google operate servers). We rely on Standard Contractual Clauses (SCCs) and other legal mechanisms required by GDPR to protect your data during such transfers.
12. Cookies and tracking
The Osyren app does not use cookies. Our website (osyren.app) uses anonymous analytics only with your consent. See our Cookie Policy for details.
13. Changes to this policy
We may update this privacy policy from time to time. When we do, we'll update the "Last updated" date at the top of this page and, for significant changes, notify you in the app or by email.
14. Contact
Questions about this policy or your data?
- Email: hello@osyren.app
- Telegram: @OsyrenAI
- Postal: KDN Estate SRL, Iosif Ivanovici 12, Constanța, Romania
Affiliate Links and Tracking Linkuri afiliate și tracking Link di affiliazione e tracciamento Enlaces de afiliados y seguimiento
Our website and mobile app contain affiliate links to third-party services (Aviasales, ZenHotels, Carla, GetYourGuide, Yesim, NordVPN, SafetyWing, Mondly). When you click an affiliate link, the third-party service may set cookies on your device to track the referral. We may earn a commission if you make a purchase through these links, at no additional cost to you. Site-ul și aplicația noastră conțin linkuri afiliate către servicii terțe (Aviasales, ZenHotels, Carla, GetYourGuide, Yesim, NordVPN, SafetyWing, Mondly). Când dai click pe un link afiliat, serviciul terț poate seta cookies pe dispozitivul tău pentru a urmări referința. Putem primi un comision dacă faci o achiziție prin aceste linkuri, fără cost suplimentar pentru tine. Il nostro sito web e l'app mobile contengono link di affiliazione a servizi di terze parti (Aviasales, ZenHotels, Carla, GetYourGuide, Yesim, NordVPN, SafetyWing, Mondly). Quando clicchi su un link di affiliazione, il servizio terzo può impostare cookie sul tuo dispositivo per tracciare il riferimento. Possiamo guadagnare una commissione se effettui un acquisto tramite questi link, senza costi aggiuntivi per te. Nuestro sitio web y aplicación móvil contienen enlaces de afiliados a servicios de terceros (Aviasales, ZenHotels, Carla, GetYourGuide, Yesim, NordVPN, SafetyWing, Mondly). Cuando haces clic en un enlace de afiliado, el servicio de terceros puede establecer cookies en tu dispositivo para rastrear la referencia. Podemos ganar una comisión si realizas una compra a través de estos enlaces, sin costo adicional para ti.
These third parties have their own privacy policies governing data collection and use. To opt out of affiliate tracking, you can: (1) dismiss the affiliate bar on our homepage using the × button, (2) configure your browser to block third-party cookies, or (3) decline cookies when you first visit our site. Aceste terțe părți au propriile politici de confidențialitate care reglementează colectarea și utilizarea datelor. Pentru a renunța la tracking-ul afiliat, poți: (1) închide bara cu parteneri de pe pagina principală cu butonul ×, (2) configura browserul să blocheze cookies de la terți, sau (3) refuza cookies când vizitezi site-ul prima dată. Queste terze parti hanno le proprie politiche sulla privacy che regolano la raccolta e l'uso dei dati. Per disattivare il tracciamento di affiliazione, puoi: (1) chiudere la barra dei partner sulla home page con il pulsante ×, (2) configurare il browser per bloccare i cookie di terze parti, o (3) rifiutare i cookie alla prima visita del sito. Estos terceros tienen sus propias políticas de privacidad que rigen la recopilación y el uso de datos. Para excluirte del seguimiento de afiliados, puedes: (1) cerrar la barra de socios en nuestra página principal con el botón ×, (2) configurar tu navegador para bloquear cookies de terceros, o (3) rechazar las cookies cuando visitas el sitio por primera vez.