Ostinaut — Privacy Policy

Last updated: 8 July 2026

Draft pending final legal review. This policy describes how Ostinaut handles your data. The data controller is Ithilmere, contact privacy@ostinaut.com.

The short version

What we collect

We use third-party payment processors (RevenueCat and Stripe) to take purchases and PostHog for product analytics — see “Who processes your data” below.

What we do NOT collect

Why we’re allowed to (legal basis, GDPR Art. 6)

Retention

Account and practice data are kept while your account exists. Delete your account and everything associated with it is erased from our database (sessions, settings, practice history and the account record). Expired sign-in sessions and verification tokens are purged automatically.

Who processes your data

Your rights

You can access, correct, or delete your data, and object to processing. Account deletion is self-serve in-app (Account → Danger zone → Delete account) and erases everything associated with your account. To request a copy of your data, or for anything else, email privacy@ostinaut.com and we’ll handle it manually. If you’re in the EU/UK you may complain to your local data-protection authority.

Children

Ostinaut is not directed at children under 13 (under 16 in some regions) and we do not knowingly collect their data.

Changes

We’ll update the date above when this policy changes and, for material changes, notify you in-app.

← Back to Ostinaut · Terms of Service