Legal

Privacy Policy

Last updated: 14 August 2026

This policy covers the Ostrivo web application (the tool you sign up for and upload data to). It doesn't apply to this marketing/portfolio site itself, which doesn't collect any personal data - no cookies, no forms, no tracking.

Who's responsible for your data

Ostrivo is built and operated by Peter Imoniose, based in the UK. For any privacy questions or requests, contact peterimoniose@live.com.

What data is collected

DataWhy
Full name, email, passwordTo create and secure your account (password is hashed by our authentication provider, Supabase - Ostrivo never sees or stores it in plain text)
Industry preferenceTo tailor analysis and AI wording to your industry
Uploaded file dataAnalysed during your session to generate dashboards, anomaly detection, and summaries
Saved analyses (if you choose to save one)Cleaned dataset, quality scores, anomaly summary, and AI summary are stored so you can reload them later - the original uploaded file itself is not stored
Aggregated activity logsAnonymous session IDs, event types, and timestamps for admin usage stats - never your uploaded data content
AI provider API key (optional)Used only in-session to call your chosen AI provider directly - never stored or logged

Who else processes your data

Ostrivo uses a small number of service providers to operate:

  • Supabase - authentication and database storage for accounts and saved analyses
  • Brevo - sends account verification emails
  • Your chosen AI provider (e.g. Anthropic) - only if you supply your own API key for AI-powered features, and only for that session
  • Streamlit Community Cloud - hosts the running application

These providers may process data outside the UK/EEA. We only use established providers with their own security and compliance practices, and we only share what's necessary for them to provide their service to Ostrivo.

Cookies

Ostrivo sets two cookies (ostrivo_access_token, ostrivo_refresh_token) purely to keep you logged in across page reloads. These are strictly necessary for the app to function and aren't used for tracking or advertising.

How long data is kept

Your account and any saved analyses are kept until you delete them or ask us to. Uploaded files that you don't explicitly save are processed only for your session and aren't retained afterward. Aggregated activity logs reset whenever the app is redeployed.

Your rights

You can delete individual saved analyses yourself from "My Dashboards," or delete your entire account and everything tied to it from the "Delete Account" option in the sidebar - both are immediate and permanent. For anything else, like correcting your details or getting a copy of your data, email peterimoniose@live.com.

Security

Passwords are hashed by Supabase Auth, never handled in plain text by Ostrivo. Per-user data is isolated at the database level using Postgres Row Level Security, not just checks in the application code. Data in transit is encrypted (HTTPS). Ostrivo doesn't hold any formal security certifications (e.g. SOC 2, ISO 27001) - it's an early-stage product built and run by one person.

Changes to this policy

If this policy changes materially, the "Last updated" date above will change. Continued use of Ostrivo after an update means you accept the revised policy.