Privacy Policy
Last updated: June 2, 2026
This Privacy Policy explains how Astra AI (“we,” “us”) collects, uses, and protects information in connection with the Osiris platform and the Ozzie analyst (the “Service”). By using the Service, you agree to this Policy.
1. Information we collect
- Account & billing. When you subscribe, our payment processor (Stripe) collects your email and payment details. We receive a customer identifier and subscription status from Stripe — we do not store your full card number.
- Queries you submit. The targets you investigate (domains, IPs, organizations, people, wallets) and your chat messages are processed to produce results and may be logged for reliability, abuse prevention, and improving the Service.
- Usage & device data. Standard logs such as IP address, timestamps, and basic request metadata.
- Session cookies. We use a signed, HttpOnly session cookie to maintain your login and entitlement state. We do not use third-party advertising trackers.
2. How we use information
- To provide, operate, and secure the Service and produce intelligence results.
- To process subscriptions and prevent fraud and abuse.
- To maintain and improve reliability and quality.
- To comply with legal obligations and enforce our Terms and Acceptable Use Policy.
3. Data from public and third-party sources
The Service retrieves information about the targets you query from public records and third-party OSINT providers. That information originates from those sources, not from us. If you believe information surfaced about you is inaccurate or should not be processed, contact us at the address below and we will review the request consistent with applicable law and our source agreements.
4. The MIND connection
5. How we share information
We do not sell your personal information. We share data only with service providers that help us operate — notably Stripe (payments) and our infrastructure/hosting and model providers used to process requests — under appropriate confidentiality obligations, and where required by law or to protect the Service and users.
6. Data retention
We retain account and billing records for as long as your account is active and as required for legal, tax, and audit purposes. Query logs are retained for a limited period for reliability and abuse prevention, then deleted or aggregated. Connected MIND keys are retained only until you disconnect.
7. Security
We use industry-standard safeguards, including TLS in transit and encryption at rest for sensitive credentials such as connected MIND keys. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal information, and to data portability (for example under the EU/UK GDPR or the California CCPA/CPRA). To exercise these rights, contact us at the address below. We will not discriminate against you for exercising them.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children.
10. International transfers
We operate in the United States and may process information there and in other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
11. Changes
We may update this Policy; we will revise the date above and, for material changes, provide notice where appropriate.
12. Contact
Privacy questions or requests: anthony@theastraway.com.
