Skip to content
← Back to osira.tv

Privacy Policy

Last updated: 19 September 2026 Deutsche Fassung

This policy explains what personal data we process when you use the Osira app for iPhone and iPad (the “app”) and the website osira.tv, why we process it, who helps us, and what rights you have.

1. Who is responsible

The controller responsible for your data is:

Osira Labs, Inc.
838 Walker Road, Suite 21-2
Dover, DE 19904
USA
Email: hello@osira.tv

For any privacy question or request, write to the address above. We answer within one month.

2. The website osira.tv

Hosting and server logs

The website is hosted on Cloudflare Pages (Cloudflare, Inc., USA). When you open a page, Cloudflare processes technical access data — your IP address, date and time, the page requested and your browser’s user agent — to deliver the page and protect it against attacks (legal basis: our legitimate interest in a secure, working website, Art. 6(1)(f) GDPR).

Cloudflare Web Analytics

We count visits with Cloudflare Web Analytics, which records pages viewed, referrer, device type, browser, country and load times in aggregate. It sets no cookies, reads nothing from your device and does not track you across websites (Art. 6(1)(f) GDPR).

No cookies

The website sets no cookies and contains no advertising trackers.

Waitlist

If you join the waitlist, we store your email address to tell you when Osira launches. Your consent is the legal basis (Art. 6(1)(a) GDPR); withdraw it any time by emailing us. The waitlist is run with Resend (Resend, Inc., USA). We delete the address when you withdraw or once the launch announcement has gone out.

Emailing us

If you email us, we use what you send to answer you (Art. 6(1)(b) or (f) GDPR) and delete it when it is no longer needed.

3. The Osira app

Using the app without an account

You can watch without signing up. When you first open the app, it creates an anonymous guest account with Firebase Authentication so your favourites and watch progress are kept. For this we process a random account ID, which shows and episodes you open, how far you watch, your favourites and settings, and technical data such as app version, device model, operating system and language. We need this to provide the app you asked for (Art. 6(1)(b) GDPR).

Our servers also log technical request data, including your IP address, to keep the service secure and to fix errors (Art. 6(1)(f) GDPR). These logs are kept for up to 30 days.

Signing in

You can sign in so your library follows you across devices:

  • Sign in with Apple: we receive an account ID and the email address you choose to share (possibly an Apple relay address), and your name if you share it.
  • Sign in with Google: we receive your name, email address, profile picture and a Google account ID.
  • Email code: we send a one-time sign-in code to the email address you enter. The email is delivered by Amazon Simple Email Service (Amazon Web Services, Frankfurt region). We keep the code only in hashed form; it expires after 10 minutes.

Legal basis: providing your account (Art. 6(1)(b) GDPR).

Deleting your account

To delete your account, email us from the address linked to it (or tell us that address). We then delete your account and sign-in record, your profile, favourites and watch history, and remove the link between your account and our analytics records, and confirm when it is done. We are adding a delete option to the app itself.

Streaming

Videos and audio stories are delivered by Mux, Inc. (USA). To stream to you, Mux receives your IP address and technical data about the request and the player (Art. 6(1)(b) GDPR).

Our own usage analytics

The app sends usage events — for example screens viewed, episodes started and finished, searches and taps — to our own servers. The first time you open the app, it asks whether you want to share usage data:

  • If you allow it, events carry a random analytics ID and, when you are signed in, your account ID, so we can understand how Osira is used and recommend better stories (consent, Art. 6(1)(a) GDPR).
  • If you decline or have not decided, events are sent without any ID and are used only for counts and totals (Art. 6(1)(f) GDPR).

You can change your choice at any time in the app (You tab → Share analytics). Our servers derive only your country from your IP address and do not store the IP address with these events. Events are stored with Google Cloud in the European Union and deleted automatically after 14 months.

Google Firebase

The app uses Google Firebase (Google Ireland Ltd. / Google LLC, USA) for sign-in (Firebase Authentication), usage statistics (Google Analytics for Firebase), crash reports (Crashlytics), performance measurement (Performance Monitoring), remote settings (Remote Config), in-app messages (In-App Messaging) and push notifications (Cloud Messaging). These services process app-instance and installation IDs, device and app data, usage events, crash reports and performance data. Google Analytics for Firebase and Crashlytics run from the first launch, independent of the in-app analytics choice above. If you allow tracking in the iOS prompt (see below), Google Analytics for Firebase may also receive your device’s advertising identifier. Legal basis: our legitimate interest in a stable, secure app and in understanding its use (Art. 6(1)(f) GDPR); for the advertising identifier, your consent.

Meta (Facebook SDK) and tracking

We advertise Osira on Facebook and Instagram. To measure whether these ads work, the app uses the Facebook SDK (Meta Platforms Ireland Ltd.; Meta Platforms, Inc., USA), which sends app events such as installs and app launches to Meta.

Only if you choose “Allow” in the iOS tracking prompt does Meta also receive your device’s advertising identifier, which it can link to your Meta account to measure and optimise our advertising. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can change this at any time in iOS Settings → Privacy & Security → Tracking. Without that permission, Meta receives the app events without the advertising identifier (Art. 6(1)(f) GDPR). For ad measurement Meta acts as a joint controller with us; Meta’s privacy policy explains how it uses the data.

We do not show ads in the app and we do not sell your data.

Notifications

If you turn on notifications, your device receives a push token from Apple, which Firebase Cloud Messaging uses to deliver messages (consent, Art. 6(1)(a) GDPR). Turn them off any time in iOS Settings.

Purchases

Osira is free during launch. If we offer an Osira Pass subscription, you buy it through Apple’s App Store and Apple handles the payment. We receive a transaction ID, the product, the purchase and expiry dates and the renewal status — never your payment details — to unlock access (Art. 6(1)(b) GDPR).

Test versions

If you test pre-release versions through Apple TestFlight, the app connects to a test server hosted by Oracle Cloud Infrastructure in Mumbai, India, and Apple may share your TestFlight feedback and crash reports with us.

4. Who helps us

We use these providers. Those marked “processor” handle data only on our instructions under a data processing agreement; the others are responsible for their own processing.

  • Google Cloud — servers, database and analytics storage in Belgium and the EU (processor)
  • Google Firebase — sign-in, app analytics, crash and performance reports, messaging (processor)
  • Amazon Web Services — sign-in code emails, Frankfurt region (processor)
  • Mux — video and audio streaming, USA (processor)
  • Cloudflare — website hosting, network and web analytics, USA (processor)
  • Resend — waitlist emails, USA (processor)
  • Oracle Cloud Infrastructure — test server, India (processor)
  • Apple — Sign in with Apple, App Store purchases, TestFlight
  • Google — Sign in with Google
  • Meta — advertising measurement (joint controller, see above)

5. Transfers outside the EU

Osira Labs, Inc. is based in the United States, and some providers process data in the United States or India. Where a recipient is certified under the EU–U.S. Data Privacy Framework, the transfer relies on the European Commission’s adequacy decision; otherwise we rely on the Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR). Ask us for a copy.

6. How long we keep data

  • Account, favourites and watch history: until you delete your account.
  • Our usage analytics events: 14 months, then deleted automatically.
  • Sign-in codes: expire after 10 minutes.
  • Server logs: up to 30 days.
  • Waitlist addresses: until you withdraw or the launch announcement has gone out.
  • Data held by Firebase and Meta: according to those services’ retention settings.

7. Your rights

You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16) or deleted (Art. 17), to restrict its processing (Art. 18) and to receive it in a portable format (Art. 20). You can withdraw any consent at any time, which does not affect processing before the withdrawal.

Right to object: where we rely on legitimate interests (Art. 6(1)(f) GDPR), you can object at any time for reasons arising from your particular situation (Art. 21 GDPR).

To use these rights, email hello@osira.tv. You can also complain to a data protection supervisory authority, in particular the one in the EU country where you live.

8. Children

Osira is not intended for children under 16, and some shows contain violence and mature themes. We do not knowingly collect data from children under 16. If you believe a child has given us data, contact us and we will delete it.

9. Security

Data is encrypted in transit (TLS), and access to our systems is restricted to the people who need it.

10. Changes to this policy

We update this policy when our app or our providers change. The date at the top shows the latest version; for significant changes we will also tell you in the app.

Crime Vertical TV — an Osira Original ✷ osira.tv

© 2026 Osira · Made in Berlin & everywhere

PrivacyTermsImpressum Deutsch

✷