Ozer

Privacy Policy

Effective September 22, 2026

Ozer Labs (“we”, “us”, “our”) operates Ozer, an AI-powered autonomous operator. This policy describes what data we collect, how we use it, and your rights regarding that data.

Information we collect

Account information. When you sign up via Google OAuth, we receive your name and email address. We do not receive or store your Google password.

Integration data. If you connect Gmail or Google Calendar, Ozer reads your messages and events to generate your daily brief. This data is processed transiently and is not stored beyond the brief generation cycle.

Email replies. If you ask Ozer to reply to an email, Ozer finds that email in your Gmail and reads its thread, then writes a reply as a draft in your Gmail. Ozer sends that draft only after you approve it. Ozer never sends an email you have not approved, and it does not delete, archive or label your mail. The approval request, including the text of the draft, is kept in your task history in Ozer.

Payment information. Subscriptions are processed by Stripe. We do not store your card number, expiration date, or CVC. Stripe handles all payment data under their own privacy policy.

Usage data. We log events generated during your use of Ozer (brief generation, task execution, integration syncs) to provide the service and improve it.

How we use your information

Google user data

Ozer’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data from Google APIs is used only to do the task you asked for. It is never used to improve or train AI models, never used for advertising, and never sold. People at Ozer do not read it, except with your permission, when needed for security, or when the law requires it.

Data sharing

We do not sell your data. We share data only with the following third-party services, each processing only what is necessary to provide the service:

Data retention

Account data is retained while your account is active. Integration data (emails, calendar events) is processed transiently for brief generation and not stored long-term. If you delete your account, all associated data is deleted.

Security

All data is encrypted in transit (TLS) and at rest. Integration credentials are encrypted using AES-256-GCM with a master encryption key. Your Gmail connection is held by Composio and is never given to the environment where Ozer’s AI works. Our database is hosted on Neon with enforced SSL connections.

Your rights

You can access, correct, or delete your data at any time. To exercise these rights or ask questions about your data, email us at hello@useozer.com.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email to the address associated with your account. Continued use of Ozer after changes constitutes acceptance of the updated policy.

Contact

Questions or concerns? Reach us at hello@useozer.com.