OSL

Early access. OSL is being built toward its v1 launch, so some of what you see here is still being finished.

See what works today

Privacy policy

Working draft. This privacy policy is a draft prepared for legal review. Final language will be reviewed by counsel before launch and may change. Last updated: May 2026.

What we collect, what we don't, and what we do with it.

What we collect #

We collect the minimum data needed to run the service:

  • Email address: only if you choose to contact us. Neither card nor crypto checkout requires OSL to email you a code — it is revealed in the checkout browser.
  • Website analytics: none. We don't use Google Analytics, Plausible, or any third-party analytics service. We don't set tracking cookies.
  • Server logs: Cloudflare, our CDN, retains standard request logs (IP address, user agent, requested URL, timestamp) for a short period for security and abuse detection.
  • Payment information: purchase checkout is currently paused. For earlier or test transactions, Stripe receives card and billing details; OSL does not receive card numbers, copy the returned email into its database, or create an OSL customer profile. There is no stored card or recurring mandate. OSL stores the minimum opaque Stripe identifiers, payment status and activation-delivery records needed to prove and deliver a transaction. Bitcoin and Monero invoice records contain the address, amount, status, confirmation facts and encrypted activation delivery.
  • Download counts: the download route records an anonymous event so OSL can count downloads. It does not create a user profile.
  • License validation: Pro users' OSL clients periodically check that their activation is valid. These requests include the license key and a timestamp.

What we don't collect #

From within OSL itself, we do not collect your message content or connected-service contacts:

  • Readable social messages, email content, or contacts from connected services. Supported protected content is processed locally.
  • Private identity keys: the reviewed Hub source requires a persistent TPM or operating-system credential-store sealer before identity creation. Public identity keys are published to the key server. The main password is a separate gate and file-storage-key source. This does not describe every local record and is not verification of installed release bytes.
  • Usage analytics. OSL doesn't phone home with telemetry.
  • Cross-site tracking via cookies.
  • Device identifiers or fingerprints from inside the application.

How we use what we collect #

  • Email: to answer a message you choose to send us. We do not require email to reveal an activation code in the checkout browser.
  • Payment data: to handle earlier transactions, refunds or disputes, and deliver an issued activation code. OSL stores activation code hashes rather than readable activation codes after issuance. No redemption record exists yet; current licence rows contain a licence hash and status without an account, email, device fingerprint, install identifier or joined payment identifier attached.
  • What the payment records never contain: the payment and credit records contain no message text, no conversation names, no carrier text and no recipient identity. Nothing you write, and nobody you write to, is linked to a payment. This holds for the planned processing credits too: if credits are ever sold, redemption is designed to use short-lived tokens rather than attaching each request to a billing identity.
  • License validation requests: to verify your paid tier is active. The validation server does not need your conversations, groups, recipients, or connected service activity.
  • Server logs: for security and abuse detection only. We don't analyze them for marketing or analytics purposes.

Third parties #

We use the following third-party services:

  • Cloudflare: CDN and DDoS protection for oslprivacy.com.
  • Stripe: card payment processing for Pro activation codes. Bitcoin and Monero payments do not go through Stripe or any other payment processor — OSL runs those invoices itself.

We do not use Google Analytics, Facebook Pixel, ad-retargeting trackers, or any other cross-site tracking infrastructure.

Your rights #

If you're in the EU (GDPR) or California (CCPA), you have the right to:

  • Request a copy of any personal data we hold about you.
  • Request correction of that data.
  • Request deletion of that data.
  • Object to processing.
  • Withdraw consent at any time.

To exercise any of these rights, email OSLPrivacy@gmail.com. We'll respond within 30 days.

Contact #

For privacy questions, complaints, or data requests, email OSLPrivacy@gmail.com.