OzerPrivacy Policy
Effective September 22, 2026
Ozer Labs (“we”, “us”, “our”) operates Ozer, an AI-powered autonomous operator. This policy describes what data we collect, how we use it, and your rights regarding that data.
Information we collect
Account information. When you sign up via Google OAuth, we receive your name and email address. We do not receive or store your Google password.
Integration data. If you connect Gmail or Google Calendar, Ozer reads your messages and events to generate your daily brief. This data is processed transiently and is not stored beyond the brief generation cycle.
Email replies. If you ask Ozer to reply to an email, Ozer finds that email in your Gmail and reads its thread, then writes a reply as a draft in your Gmail. Ozer sends that draft only after you approve it. Ozer never sends an email you have not approved, and it does not delete, archive or label your mail. The approval request, including the text of the draft, is kept in your task history in Ozer.
Payment information. Subscriptions are processed by Stripe. We do not store your card number, expiration date, or CVC. Stripe handles all payment data under their own privacy policy.
Usage data. We log events generated during your use of Ozer (brief generation, task execution, integration syncs) to provide the service and improve it.
How we use your information
- Generate your daily morning brief from connected sources
- Execute tasks you approve or delegate
- Send service emails (briefs, task notifications, account updates)
- Improve the quality and relevance of Ozer’s output, using usage data only, never data from Google APIs
Google user data
Ozer’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data from Google APIs is used only to do the task you asked for. It is never used to improve or train AI models, never used for advertising, and never sold. People at Ozer do not read it, except with your permission, when needed for security, or when the law requires it.
Data sharing
We do not sell your data. We share data only with the following third-party services, each processing only what is necessary to provide the service:
- Stripe: payment processing
- Google: OAuth authentication, Gmail and Calendar access
- Composio: stores the connection to your Google account and passes Ozer’s requests to Gmail
- Anthropic: AI processing (brief generation, task execution), including the content of any email you ask Ozer to answer. Anthropic does not train its models on this data.
- Resend: email delivery
- Plausible: website analytics, without cookies or personal data
- AgentMail: managed inbox for founder-mode tenants
Data retention
Account data is retained while your account is active. Integration data (emails, calendar events) is processed transiently for brief generation and not stored long-term. If you delete your account, all associated data is deleted.
Security
All data is encrypted in transit (TLS) and at rest. Integration credentials are encrypted using AES-256-GCM with a master encryption key. Your Gmail connection is held by Composio and is never given to the environment where Ozer’s AI works. Our database is hosted on Neon with enforced SSL connections.
Your rights
You can access, correct, or delete your data at any time. To exercise these rights or ask questions about your data, email us at hello@useozer.com.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to the address associated with your account. Continued use of Ozer after changes constitutes acceptance of the updated policy.
Contact
Questions or concerns? Reach us at hello@useozer.com.