Privacy at Osera

The honest version. This policy is written to match the product as it exists today.

  • Permissions are opt-in. Health, location, photos, contacts, calendar, reminders, camera, microphone, speech recognition, music, notifications, and WeatherKit-backed features all depend on OS or in-app permission flows.
  • Health data is now processed. When Apple Health sync is enabled, Osera sends derived wellness states and a daily numeric health snapshot to our backend for cards, briefings, chat context, and proactive check-ins.
  • Location is not automatically deleted after 48 hours. The system uses recent location for context, but location pings, visits, and derived place profiles are retained while your account is active unless you delete your account.
  • AI providers receive context. Messages, files, tool results, and relevant personal context may be sent to third-party AI providers in multiple jurisdictions to generate responses.
  • We don't sell your data. We do not sell personal information, use HealthKit data for advertising, or share SMS opt-in data for marketing.
  • Retention is mostly account-lifetime. Several older timed-deletion promises are no longer true. Most core data is retained to power memory and personalization until you delete your account or remove a connected integration.

Privacy Policy

Last updated: June 9, 2026

Bloom Street LLC ("Bloom Street," "we," "us," or "our") operates Osera, a personal AI application and related services, including the iPhone app, desktop daemon, backend services, admin systems, and website at osera.io. This Privacy Policy explains what information we collect, how we use it, where it may be processed, and the choices you have.

Osera is designed to be personal. That means it can process sensitive context, including messages, health signals, location, calendar events, reminders, photos metadata, contacts, files, voice notes, music context, and data from connected accounts when you choose to grant access.


1. AI and Safety Disclosure

Osera is powered by artificial intelligence. You are not talking to a human, therapist, doctor, lawyer, financial advisor, emergency service, or crisis counselor. AI responses can be inaccurate, incomplete, inappropriate, or unexpectedly personal because they are generated from your conversation and context.

Do not use Osera for emergencies. If you may harm yourself or someone else, call or text 988 in the United States, contact local emergency services, or reach a trusted person immediately. Osera may show crisis resources when our systems detect self-harm or crisis language, but those systems are not guaranteed to detect every emergency.

2. Information We Collect

2.1 Account and Authentication

2.2 Messages, Memory, and Personalization

2.3 Files, Images, Camera, and Photos

2.4 Apple Health and Fitness Data

If you enable Apple Health sync and grant HealthKit access, Osera reads workouts, sleep, sleep stages when available, steps, active energy, exercise minutes, distance, flights climbed, resting heart rate, heart-rate variability, and cardio fitness.

When sync is enabled, Osera sends two layers to our backend:

We use this data for morning cards, briefings, chat answers, pattern recognition, and proactive check-ins. HealthKit data is not sold, used for advertising, used for marketing data mining, or shared with data brokers. Relevant health context may be sent to AI providers when needed to answer you or generate a proactive message.

2.5 Location, Weather, and Places

2.6 Calendar, Reminders, Contacts, and Connected Accounts

2.7 Voice, Audio, Speech, and Music

2.8 Desktop Daemon and Local Workers

If you use the Mac desktop daemon, Osera may process daemon status, worker installation and health, local command results, machine connection state, logs, and local integration outputs. Some desktop flows can access local tools or Apple services on your Mac only after local OS permission or user setup. The desktop app is intended as a setup and worker dashboard, not the primary chat surface.

2.9 Device, Usage, Analytics, and Diagnostics

3. Apple Permission Strings and App Permissions

The current iOS app declares permission use for Health sharing and updating, location When In Use and Always, photo library read/write and add-only save, camera, microphone, speech recognition, calendars, reminders, contacts, Apple Music, notifications, WeatherKit, Sign in with Apple, associated domains, Live Activities, and communication notifications.

Permissions can be revoked through iOS Settings. Turning off an Osera toggle or revoking an OS permission stops new collection for that feature, but it does not automatically delete data already synced to our backend unless the feature specifically offers deletion or you delete your account.

4. How Data Reaches AI Providers

To generate responses, route tools, summarize context, create proactive messages, process files, or power voice features, Osera may send relevant information to third-party AI providers. This can include your message, previous conversation context, memory, files, image attachments, tool results, calendar/reminder context, location/weather/place context, photo-derived context, health and nutrition context, and connected-service results.

Current provider families in code include Anthropic, Google Gemini, MiniMax, DeepSeek, xAI/Grok, OpenAI, Groq, Moonshot/Kimi, Mistral, Together, DeepInfra, Fireworks, and OpenRouter. OpenRouter is an aggregator that may route a request to additional downstream model providers, primarily when our direct providers are unavailable. Provider order can change through configuration for reliability, quality, cost, or latency. These providers and infrastructure may process data in the United States, European Union, China, or other jurisdictions.

We do not intentionally send your account password, payment card number, OAuth tokens, API keys, or integration credentials to AI providers as prompt context. We do not currently guarantee redaction of personal information you include in messages, files, or tool results before they are sent to AI providers.

5. How We Use Information

5.1 Subscription, Consumption Tracking, and Pricing Changes

Osera is a paid subscription at $20 per month. We will notify you before any price change takes effect.

We measure your usage of the service (including message counts, voice minutes, attachment volume, tool invocations, and model/provider token consumption) to operate billing, enforce plan limits, prevent abuse, and give you visibility into how much of the service you have used.

6. How We Share Information

We do not sell personal information. We share information only as needed to run Osera, at your direction, or where legally required.

7. Retention and Deletion

Data Type Current Retention
Messages, cards, memory, threads, health-aware reasons, and most personalization dataRetained while your account is active; deleted during account deletion.
Journal entries, to-dos/task lists, and notebook contentRetained while your account is active; deleted during account deletion.
Food and nutrition logsRetained while your account is active; deleted during account deletion.
User voice memo audioRetained with message history while your account is active; deleted during account deletion.
Assistant-generated voice-note/TTS filesDatabase records are soft-deleted after about 45 days; referenced message audio links may be cleared. Object-storage lifecycle may be separate.
Location pings, location visits, place profiles, and movement stateRetained while your account is active. Recent context windows may use only the latest rows, but raw location rows are not currently auto-deleted after 48 hours.
Apple calendar, reminders, contacts, music, weather, and similar Apple-data sync rowsStored as latest sync rows per data type and overwritten by later syncs; deleted during account deletion.
Health daily states and health snapshotsRetained while your account is active; deleted during account deletion. Code comments refer to a 365-day retention intent, but timed cleanup is not the current enforcement path.
Photo context syncs, photo interest profile, and photo place clustersRetained while your account is active; deleted during account deletion. Brain context uses recent windows and aggregates, but do not rely on automatic per-photo metadata deletion unless a cleanup is later enabled and disclosed.
Connected-service tokens, credentials, and direct API keys you saveRetained until you disconnect/remove them or delete your account.
Device/session/error/usage telemetry and billing recordsRetained while needed for operation, security, analytics, tax, accounting, or legal obligations; account-linked records are deleted or disassociated where supported during account deletion.
Comm signals and some operational eventsSome timed cleanups exist, such as 90-day cleanup for communication signals and old user events.
Shared spacesYour membership is removed and your shared-space messages/facts may be anonymized rather than deleted so other members retain group context.

Account deletion: You can request deletion in the app where available or by contacting privacy@osera.io. The backend starts a multi-phase deletion process that removes high-volume user tables, remaining account-linked tables, tokens, credentials, devices, contacts matches, health rows, photo rows, location rows, memory rows, and the user record. Some records may be anonymized instead of deleted where other users depend on shared context.

Known deletion limitations: Current code notes that some underlying authentication-provider records may not be deleted by the Convex account-deletion flow, and some file object-storage blobs may require separate lifecycle or cleanup beyond deleting database records. We will continue tightening this path and will update this policy when enforcement changes.

8. Security

Osera does not currently provide end-to-end encryption for conversations, and we cannot guarantee that any internet-connected service or third-party provider is perfectly secure.

9. Legal Bases for EEA/UK Users

10. Your Choices and Rights

California users have the right to know, delete, correct, and opt out of sale/share as provided by applicable law. We do not sell personal information.

11. Cookies and Website Tracking

The Osera app does not use advertising SDKs. The website may use server-side analytics without cookies for page views, referrers, UTM parameters, and approximate country. With consent, advertising measurement tools may set cookies or pixels to measure campaign effectiveness. You can reject or clear cookies through browser controls and the consent banner where available.

12. Children

Osera is not intended for users under 18 or the age of majority in their jurisdiction. We do not knowingly collect personal information from minors. If you believe a minor has provided personal information, contact privacy@osera.io.

13. Changes to This Policy

We may update this policy as Osera changes. When changes are material, we will update the date above and use reasonable notice such as email, in-app notice, or website notice.

14. Contact

Bloom Street LLC
Email: privacy@osera.io