← Back to Osyo!

Privacy Policy

Last updated: September 2026

1. About the platform

Osyo! is a catalog of Ukrainian apps, online services, and digital products available at osyo.app. This policy explains what data we receive and how we use it.

2. Data we receive

When you register or sign in, we may receive your email address, name, username, profile image, and technical data required to operate your account. When you sign in with Google, we receive only the information you allow Google to share on its consent screen.

3. How we use data

We use data for authentication, profile features, publishing products and articles, important service messages, and platform security. We do not sell personal data or share it with advertisers.

4. Infrastructure and storage

Osyo! uses Supabase for the database and authentication, Cloudflare R2 for media storage, Cloudflare for hosting and content delivery, and Google OAuth for optional Google sign-in. These providers process data under their own privacy policies.

5. Cookies and analytics

We use necessary first-party cookies and browser storage to keep you signed in and provide site features. An anonymous identifier helps count views fairly and prevent abuse. We do not store your IP address. Accepted technical events are retained for up to 180 days; rejected anti-fraud events and anonymous performance metrics for up to 90 days. Google Analytics 4 loads only with your separate consent, which you can change through Cookie settings in the footer.

Analytics availability diagnostics

Separately from Google Analytics, we count anonymous diagnostics: analytics consent or refusal and script availability. One sample per page load after 15 seconds or on leaving. Only daily counters are retained for up to 90 days, without person or session identifiers, IP addresses or page URLs. These are not unique visitors. Blocked requests are not retried; declining Google Analytics remains effective.

6. Recommendations

For guests, viewed-product history is stored only in the browser. After sign-in, it may sync across devices and is retained for up to 90 days. You can disable personalization and delete this history in profile settings.

7. Chats and messages

If you use chats, we store messages, participants, timestamps, read status, blocks, and reports. Administrators cannot freely browse private conversations. A report reveals only limited context, and access is logged. Deleted messages and conversations are permanently removed after 30 days together with their attachments.

8. Connecting AI agents

With your separate consent, a third-party AI client may receive OAuth access to a limited set of account features: private collections, owned-product statistics, and creating or editing drafts. Agent OAuth tokens do not grant admin access, publishing, deletion, visibility changes, or file uploads. You can revoke a previously granted authorization in the authentication settings.

9. Your rights

You can review and edit your profile data and request deletion of your account and associated data.

9. Contact

For privacy questions, email osyo.admin@gmail.com.