Privacy

What Osmos stores, who else ever touches it, and how long it is kept. Written against the code rather than from a template, so you can check it on the security page and in your own account.

This is a draft, pending review. The descriptions of what the product does are accurate today; the wording has not been through a lawyer, and anything in square brackets is a detail still to be settled. Last updated 13 August 2026.

Who this is between

The service Osmos is operated by Sam Ethan Mathew — an individual, not a company. It is hosted: you do not run it, and everything below describes what happens on our side.
What it covers This website, the Osmos app, and the connector your assistants use to reach it.
How to reach us Anything on this page, including a request to see or delete what we hold: privacy@withosmos.com. Everything else is on the contact page.
The inventory

What Osmos stores

All of it lives in one Postgres database. There is no second system holding a copy for analysis.

Your account Your email address, the display name you choose, and — if you set a password — its hash, never the password. Sign in with Google or GitHub instead and Osmos keeps that provider's account identifier alongside the address it gave, which is how a returning sign-in is recognised as the same person.
What you and your assistants write Your contexts and their memory: shared knowledge, your own private notes, what replaced what, who wrote it, and which assistant published it. This is the product. It is yours, and nothing here treats it as ours.
Connected assistants One record for each assistant you have authorised, so that any one of them can be cut off without disturbing the others.
What each assistant was shown Every time an assistant picks up project knowledge: what it was working on, what it was told, and how many items were held back. The withheld ones are counted, never named. This record belongs to the person whose assistant made the call — a context's owner cannot read someone else's, because it would list their private notes.
Access history Who shared what with whom, every change to access, and every archive or restore. "When did this become visible to them" is asked months later, so the answer is kept.
Billing, only if you pay Your plan, your subscription's status, the seat count, and Stripe's identifiers for your workspace and subscription. Card numbers never reach Osmos — they go from your browser to Stripe.
Sign-in machinery Sessions, verification and invitation tokens, and the authorisations behind each connected assistant. Short-lived by design and deleted on a schedule once expired.
Rate-limit counters The one place an IP address is stored. To stop someone guessing passwords or flooding the sign-in form, Osmos counts recent attempts against a key built from the caller's address and what they typed — so a row can pair an IP address with an email address someone entered, whether or not it is an account here. It is read only to refuse the next attempt, never to build a picture of you, and the whole table is deleted after 24 hours.
What is not in the database No device or advertising identifiers, no third-party cookies, no profile of how you use the app. IP addresses appear only in the rate-limit counters above — never against your account, your contexts, or your memory. Our host keeps ordinary server logs to operate the service, as any host does; they expire automatically on our host’s schedule, which is measured in days rather than months, and we do not copy them anywhere else or use them to build a picture of you.
The part that matters

What never leaves

Your memory is not sent anywhere to make Osmos work There is no embedding model, no summarising model, and no outside service involved in finding what is relevant to a task. That matching is a full-text search inside the same database your memory already lives in. No third party receives the contents of a context, on any plan.
Nothing you write trains a model Not ours — we have none — and not anyone else's. There is no path by which it could: nothing leaves.
We do not read your contexts Access to the production database is limited to operating the service — restoring it, migrating it, or investigating a fault you have reported. It is not browsed, mined, or sampled.
Only people share No assistant has a tool that grants anyone access to anything. Every grant is made by a person, in the app, and is recorded — so no amount of talking to a model widens who can read your project.
Nothing is sold Osmos makes money from subscriptions. Your data is not a second revenue line, and there is no advertising network, analytics vendor, or session recorder anywhere in the product.
Subprocessors

Who else is involved

The whole list, not a representative sample. Each one gets the least it can be given and still do its job.

Render Hosting and the Postgres database. Everything Osmos stores is stored there, in Render's Oregon region, in the United States.
Resend Sends the transactional email: address verification, password resets, and invitations. It receives the recipient's address and that message's contents — never the contents of a context.
Stripe Payments, and only if you buy Pro. It receives the workspace name, a billing email address, and our identifier for the workspace, and it holds the card details Osmos never sees.
Google and GitHub Only if you choose to sign in with one of them. They confirm your account identifier and email address to us; we tell them nothing about your projects. Sign in with an email address and password instead and neither is involved at all.

That is the entire list. If it changes, this page changes with it — and a subprocessor that would receive the contents of a context is a decision we would tell you about before making, not after.

Retention

How long things are kept

Retention never touches the product's actual content. It expires the by-products that would otherwise become a record of their own.

Memory — indefinitely

Shared and private memory is kept until you retract it or delete the context. Nothing is ever removed for a billing reason.

Access history — indefinitely

Small, append-only, and the only way to answer who could see what, and when. Retention does not remove it.

What AI saw — 90 days

Each record lists what one person's assistant was told, including their own private notes. Long enough to answer "what did it know", short enough not to accumulate.

Expired sessions, verification links, and the short-lived pieces of an assistant's authorisation are deleted automatically once they can no longer authenticate anything. A revoked assistant's tokens are kept for 30 days, so "when did this connection lose access" stays answerable. The rate-limit counters, the only place an IP address is held, are deleted after 24 hours.

What you can do

See it Open a context's Memory tab for everything it knows, What AI saw for what each of your assistants was told, and Share for who can read it right now.
Change it Anything wrong can be replaced or retracted, after which assistants stop receiving it. The old version stays in the history so you can see what the project used to believe.
Take it out, or have it deleted Ask us and we will do it. There is no button for either yet — a person handles it by hand, which we would rather say than imply a self-service export that does not exist. Deleting an account removes the account and the contexts you own; memory you published into someone else's shared context stays there, because it is part of a project that is not only yours.
Cookies Three, all first-party, all necessary: one that keeps you signed in, one that protects forms against cross-site submission, and one that exists only for the seconds a Google or GitHub sign-in is in progress. Your light or dark theme choice is stored in your browser and never sent to us. There are no analytics or advertising cookies to consent to, because there are none.

If this changes

A change that affects what is stored, who receives it, or how long it is kept will be announced by email to account holders before it takes effect. Wording that only gets clearer will just appear here, with the date at the top updated.

Questions, or a request about your own data — contact us. If you want the mechanics rather than the policy, the security page describes what is enforced and what is not yet.