New: Trust & Privacy Manifesto
Read our founder's personal commitment to privacy and why OSQR is built on architectural trust, not promises.
Privacy is Capability
If you can't trust your AI, you can't use it to its full potential. OSQR is built on privacy from the ground up.
"Your data belongs to you."
OSQR exists to make you more capable — not to extract anything from you. Everything you upload, write, think, or store in OSQR belongs solely to you. Your data is never sold, and never used to train AI. The only thing it's ever shared with is the AI provider that answers your request — and only the text that request needs. OSQR uses your data to think for you, not for anyone else.
OSQR is a private intelligence engine — not a data farm.
1Our Privacy Commitments
Your Vault is Yours Alone
Your files, chats, uploads, and memories are encrypted at rest and isolated to your account. OSQR's systems use them only to work for you, and your content is never sold. We don't read your content as a matter of course — the rare exception is a named engineer investigating a specific fault on your account, which we keep to what the problem requires, and which you approve and can read a record of.
Never Used for Training
OSQR does not train any AI model on your data — ours or anyone else's — and the AI providers we send requests to don't train on it either. Not now. Not ever.
Encrypted & Secure
Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+) — unreadable in a raw database leak. Embeddings are stored as numeric vectors, not as readable text.
The "Burn It" Button
Delete your data instantly. One click. Irreversible. Documents, embeddings, chats, memories, vault, profile, cached outputs and logs — gone for good. It deletes your whole workspace, which takes your business's records inside it with it: website and text conversations, voicemails and call transcripts. What it does not reach: the phone number rented for you, which has to be released separately; voicemail audio held by the telephony company; the do-not-contact list, which we keep on purpose so nobody who asked you to stop texting them is ever resurrected; and contact records, which are stored without a link to the workspace and so are left behind rather than removed with it.
2Privacy Tiers
You control how your data is used. Choose the level that fits your comfort.
Maximum Privacy
- Nothing leaves your vault except what's sent to AI models to answer your questions
- None of your data improves OSQR globally
- No anonymization, no analytics on your content
- Fully private — the strictest setting
Improve My OSQR
- No raw content is ever shared
- Optionally allow OSQR to learn from patterns only
- Example: "User sets fitness goals but doesn't follow through"
- Improves your personal model — not anyone else's
Global Patterns
- Opt-in only, off by default, extra warnings
- Anonymously contribute patterns (never content)
- Zero identifiable data — aggregated trends only
- Help improve OSQR for everyone (the "Waze" model)
3Where Your Data Lives
| Data Type | Storage |
|---|---|
| Your Documents | Encrypted database (PostgreSQL + Neon) |
| Your Embeddings | Numeric vectors — not stored as readable text |
| Your Profile | Encrypted rows tied only to your account |
| Your Chats | Encrypted at rest; only the text needed for a request is sent to AI providers |
| AI Requests | Only the text needed to answer your question is sent to AI providers |
4How Your Content Is Accessed
Being honest: OSQR is not “zero-knowledge.” Running the AI means our servers have to decrypt and read your content to answer you. So the promise isn't “we can't see it” — it's that we tightly limit who and what touches it, and never use it against you.
OSQR never:
- ✕Sells or rents your data
- ✕Trains AI models on your content
- ✕Shows you ads or builds ad profiles
- ✕Lets staff open your vault documents — no support tool can reach them
- ✕Reads your conversations without your say-so, or without leaving a record
- ✕Keeps a hidden copy after you delete
What OSQR actually accesses:
- ✓Decrypts your content on our servers, only to run the AI and features you ask for
- ✓Sends only the text needed for a request to AI providers (who don't train on it)
- ✓Lets staff see account metadata by default — email, plan, billing, error logs
- ✓Reads your conversations only when you approve a specific request, for a set number of hours, with a record you can read
- ✓Stores everything encrypted at rest, isolated to your account
5The "Burn It" Button
Instant, Complete Deletion
When you click "Burn It," OSQR permanently deletes:
- • All your documents
- • All embeddings
- • All chat history
- • All memories
- • Your entire vault
- • All profile data
- • Cached model outputs
- • All system logs
- • Your workspace and everything filed in it
- • Website and text conversations
- • Voicemails and call transcripts
- • Your encryption keys, destroyed first
Once deleted, OSQR cannot recover your data.
There is no undo. No internal archive. No ghost copy for analytics. Our database provider keeps short-term encrypted backups of its own, on its own clock, and deleted rows age out of those with time.
What Burn It does not reach. If you rent a phone number through us, that number is not handed back to the telephone company by this button — write to us and we will release it. Voicemail audio sits on the telephony company's systems rather than ours, and is not deleted by this button either. And we keep the do-not-contact list: if somebody replied STOP to your business, that stays, because erasing it would let them be texted all over again. Contact records — the people list your conversations built up — are stored without a link back to the workspace, so those rows are left behind rather than removed with it; ask us and we will clear them by hand.
Legal exception: In rare cases where OSQR is required by law, regulation, valid legal process (such as a subpoena or court order), or governmental request to preserve data, the "Burn It" function may be temporarily suspended for the affected account until the legal obligation is resolved. We will notify you if this occurs, unless prohibited by law from doing so.
6How AI Requests Work
When OSQR sends something to AI providers (OpenAI, Anthropic, etc.), the rule is simple:
Only the exact text necessary to answer your question goes to the model.
Example:
If you ask: "Summarize page 4 of my document"
→ OSQR only sends page 4's text to the AI
Example:
If you ask: "What were my goals last month?"
→ OSQR fetches goals from your vault internally, sends only your question and the relevant text
You control what is sent because it is always tied to your explicit action.
7Encryption & Security
At Rest
AES-256 encryption via Neon/PostgreSQL
In Transit
TLS 1.2+ / HTTPS for all connections
Passwords
Hashed with bcrypt/argon2 (never stored in plain text)
Embeddings
Stored as numeric vectors, not as readable text
8Data Minimization
OSQR collects the minimum necessary:
- Email address
- Password (hashed)
- Subscription status
- Usage metrics (not content)
- Optional profile info you provide
That's it. No tracking. No surveillance. No creepy behavior. No "shadow profiles."
9SMS & Text Messaging
How SMS Opt-In Works
OSQR offers an optional SMS feature that lets you text back and forth with your AI assistant. You must explicitly opt in before receiving any messages.
Opt-In Process
- 1.You log in to your OSQR account at app.osqr.ai
- 2.You navigate to Settings → Phone & SMS, or are prompted via the phone setup dialog
- 3.You enter your phone number and check the consent box agreeing to receive SMS messages
- 4.We send a one-time 6-digit verification code to confirm you own the number
- 5.After verification, you can text OSQR and receive responses via SMS
Message Details
- Message frequency varies based on your usage
- Message and data rates may apply
- Reply STOP at any time to unsubscribe from all SMS messages
- Reply HELP at any time for support information
- Reply START to re-subscribe after opting out
Your Phone Number
Your phone number is stored securely and used only for delivering SMS messages you have requested. Your mobile information and messaging consent are not shared with third parties or affiliates for marketing or promotional purposes, and are never sold. It is not used for marketing. You can disconnect your phone number at any time from Settings → Phone & SMS.
10When OSQR Runs on a Business's Website or Phone Line
Some businesses use OSQR to power the chat on their own websites, the text lines on their own phone numbers, and — where they have switched it on — to answer those numbers when you call. If you chat, text or speak with one of those assistants, you are talking to that business, not to OSQR: the business is the controller of your data. Its privacy policy governs the conversation, and OSQR processes it on their behalf under our Data Processing Agreement.
What that processing looks like: your messages, a name or contact detail only if you choose to share one in the conversation, and — for website chat — a random identifier stored in your own browser so the conversation can continue when you return. We do not sell that data, use it for advertising, or train AI models on it.
The first time you call one of those numbers and an assistant answers: it opens the call by telling you that the call is transcribed and that you are speaking with an AI assistant. If you have called that business before and already heard that: it opens with a short reminder that the call is transcribed. Nothing else changes on a later call — you are still speaking with an AI assistant, and whenever you ask whether you are talking to a person, on that call or any other, it will say plainly that you are not. Your voice reaches that assistant live, as you speak, through one of the two AI providers named on our subprocessor list. The words of the conversation are written down and kept with the business's record of you. The audio of that conversation is not recorded. If you are put through to a voicemail instead, that voicemail is an audio recording, held by the telephony provider that carries the call and transcribed so the business can read it.
How long it is kept: for now, until the business closes its OSQR account and deletes its workspace. There is no expiry date on a conversation and no automatic clean-up that removes one: a typed chat, a text thread, a voicemail transcript and the written record of a call all stay while the account exists. We are building a proper deletion tool — a way to erase one person's records on request — and until it ships we do it by hand. Write to us and we will carry it out and tell you when it is done.
Voicemail audio, said plainly: the recording itself lives with the telephony company that carries the calls, and today nothing deletes it on a schedule. We keep the transcript; they keep the audio. Ask us and we will have a specific recording removed.
To exercise privacy rights over one of those conversations, contact the business you were talking to — they hold the relationship, and we support them in honoring your request. You can also write to us at info@osqr.ai and we will route it to them and act on it ourselves. For text lines, reply STOP at any time and messaging ends immediately. On a call, saying you do not want to be contacted again is enough — the assistant writes it down, and from then on that business cannot text you or dial you through OSQR on any of its lines, not just the one you were on.
11Google User Data & Third-Party Integrations
When you connect your Google account (Gmail, Calendar, Drive, Contacts, Tasks) to OSQR, OSQR receives a scoped OAuth grant from Google that lets OSQR act on your behalf inside your Google account. This section describes exactly what OSQR does with that access and what it does not do.
Scopes OSQR requests from Google
| Scope | What OSQR uses it for |
|---|---|
| gmail.modify | Read, label, archive, send, and reply to emails when you instruct OSQR (or your OSQR VA) to do so. OSQR only acts on messages in response to your explicit commands or the automations you configure. |
| calendar | Create, update, and read events on your Google Calendar when you ask OSQR to schedule, reschedule, or look up meetings. |
| drive.file | Open and save only the specific Drive files you ask OSQR to work with (per-file access — OSQR cannot browse your whole Drive). |
| contacts | Look up and create contacts when you ask OSQR to email or message someone. |
| tasks | Read and write items to your Google Tasks when you ask OSQR to capture or complete a task. |
| userinfo.email | Identify which Google account the grant belongs to. Not used for marketing. |
Google API Services User Data Policy & Limited Use
OSQR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- OSQR does not use Google user data (including Gmail message content) to train generalized or third-party AI / ML models.
- OSQR does not sell, rent, or transfer Google user data for advertising, re-selling, or any purpose unrelated to the user-facing features you asked OSQR to perform.
- OSQR does not allow humans to read Google user data except (a) with your explicit consent, (b) where necessary for security investigations or to comply with applicable law, or (c) where the data has been aggregated and anonymized for service-operations purposes (e.g., error counts).
- OSQR only transfers Google user data to the AI providers needed to fulfill the specific request you made (e.g., summarize this thread), and only the text needed to answer that request. Sub-processors are contractually bound not to use the data for training.
Where Google data lives in OSQR
OSQR does not maintain a persistent mirror of your Gmail inbox. Messages are fetched from Google on-demand when you (or your automation) ask OSQR to act on them, and are discarded from working memory when the request completes. OSQR stores:
- Your OAuth access and refresh tokens, encrypted at rest in our Neon (PostgreSQL) database.
- Minimal metadata required to support your automations (e.g., the Gmail message ID you told OSQR to follow up on).
- Logs of actions OSQR took on your behalf (who, what, when — never the message body), for audit and support.
How to revoke OSQR's access to your Google account
You can remove OSQR's access at any time:
- 1.Inside OSQR, open Settings → Integrations and click Disconnect next to Google. OSQR immediately revokes its OAuth token and deletes the stored credentials.
- 2.You can also revoke access directly from Google at myaccount.google.com/permissions.
- 3.The "Burn It" button (described above) deletes every OAuth token OSQR holds for you as part of the full-account wipe.
12The OSQR Companion Browser Extension
OSQR Companion is an optional browser extension that lets you send a page you are viewing to your own OSQR account — including pages that only load because you are signed in, which automated research cannot reach.
When it reads a page
Only when you click its toolbar button, and only the tab you clicked it on. The extension has no standing access to your browsing. It does not run when pages load, does not monitor tabs in the background, and does not collect your browsing history or a list of sites you visit. Your click is the capture.
What it sends, and where it goes
When you click, it reads that page's visible text, title, URL, meta description, and any text you had selected, and sends them over an encrypted connection to your OSQR workspace. Nothing else is transmitted. Captures are saved as documents in your own workspace, visible only to you, and OSQR can read them when you ask about them.
- Captured pages are stored as ordinary text in our database rather than under your personal encryption key, because the extension authenticates with an API token instead of a signed-in session. Treat a capture the way you would treat a document you uploaded to your vault.
- The extension stores one thing in your browser: an API token for your OSQR account, so captures reach the right workspace.
- A captured page is a document in your vault — deleting it there deletes it, the same as any other document.
What we do not do with it
We do not sell this data, share it with third parties, or use it for advertising. It is used to answer your questions inside your own account, and for nothing else.
A Note from the Founder
I built OSQR to be the AI assistant I always wanted — one that truly knows me, remembers my context, and helps me think better. But that kind of deep integration requires trust.
If you're going to index your entire life into an AI system — your documents, your thoughts, your goals, your struggles — you need to know that data is sacred.
That's why OSQR is built on privacy from day one. Not as a feature. Not as a marketing bullet point. As a foundation.
Your capability depends on your willingness to be honest with OSQR. And your willingness depends on trust. I intend to earn it.
Kable Record
Founder & 100% Owner, OSQR
Questions about privacy? Concerns? Ideas?
info@osqr.ai