Privacy Policy

Last updated 14 September 2026 · Ospry Suite Ltd, United Kingdom

Who we are

Ospry Suite Ltd (company number 17455389), registered at 7 Walnut Way, Leicester, LE8 5TJ, runs the service and is the data controller for the personal data described here. Registered with the Information Commissioner's Office, reference ZC246894. Contact: hello@osprysuite.com.

What we hold and why

  • Account details — your email, name and a hashed password. To run your account. Legal basis: contract.
  • Your websites' data — audit results, rankings, crawl data, reports about sites you add. To provide the service. Legal basis: contract.
  • Connected-service credentials — for example a WordPress application password or CRM key you choose to connect. Encrypted before they touch our database; shown back to nobody, including us, once saved.
  • Photos you or your clients upload — re-encoded on arrival, with location and camera metadata permanently removed before storage.
  • CRM activity counts — if you connect a CRM, we read counts of calls and enquiries to include in your reports. We don't store the conversations themselves.
  • Security records — failed sign-in attempts against a hashed IP address, kept for 24 hours, purely to slow attackers.
  • How the service is used — the dates you signed in, and counts of things like sites added and audits run. We use this to see which parts of the product work and which are being abandoned, and to notice if you get stuck. It is dates and counts about your account, not a record of what you looked at, and never the contents of your audits or your clients' data. Legal basis: legitimate interest in running and improving the service.
  • Our customer records — when you sign up, your name and email go into our own customer system (run on GoHighLevel) so we can support you and manage your account. Legal basis: legitimate interest in looking after our customers.

Accounts you connect, including Google

Ospry can connect to accounts you already own so it can read how you are doing and, where you ask it to, act on your behalf. Nothing connects on its own: every connection is a button you press, and the provider's own sign-in screen shows you exactly what is being asked for before you agree. We never see or store your password for any of them.

Ospry's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google APIs will adhere to that policy: it is used only to show you your own results and to do the things you asked for, it is never sold, never used for advertising, never used to train or improve any machine-learning or AI model, and no person at Ospry reads it except to fix something you asked us to look at or where the law requires it.

Scope by scope, each Google permission is used for this and nothing else:

  • Search Console (read only) — the queries, clicks, impressions and positions of your own sites, on your Metrics screen and in your reports.
  • Analytics (read only) — sessions and traffic sources for your own properties, shown beside the search data.
  • Business Profile — listing your locations and checking the name, address and phone match your website.
  • Google Calendar (events) — when a visitor books a callback through the Cue chat on your site, reading whether you are free at that time and writing that one booking into your calendar. Nothing else on it is read.
  • YouTube (read only) — listing your channel and recent videos so you can choose which channel a scheduled video goes to.
  • YouTube (upload) — uploading a video you scheduled in Ospry's publishing calendar, to your channel, at the time you chose. Nothing is deleted or edited on your channel.

You can see and remove Ospry's access to your Google account at any time at myaccount.google.com/permissions, or from Connections inside Ospry. When you do, we delete the data that access gave us. Where Ospry works with YouTube it uses YouTube API Services, so the YouTube Terms of Service and Google's Privacy Policy also apply to those parts.

How sensitive data is protected

  • In transit — every connection to Ospry, and every call Ospry makes to a connected provider, is encrypted with TLS. Nothing sensitive travels in the clear.
  • At rest — OAuth access and refresh tokens, API keys and connected-service passwords are encrypted with AES-based encryption (Fernet) before they are written to the database. The key that decrypts them is held only on the application server, outside the database, so a copy of the database alone reveals no credential. Account passwords are stored as salted hashes, never as passwords.
  • Access — the servers holding this data are reachable only by the people who run Ospry, over key-based authentication, with no password login. Staff tooling shows account facts, not the contents of your audits or your clients' data; reading a workspace's data for support needs a key you generate and can revoke, and every use of it is logged where you can see it.
  • Isolation — everything a connected account shares is stored inside your own workspace and is never visible to any other customer.
  • Backups — nightly, encrypted, kept for 14 days, in the United Kingdom.
  • Deletion — disconnecting an account revokes our access at the provider and deletes the stored tokens straight away; deleting your workspace removes the data those connections gave us, and backups age out within 14 days.
  • If something goes wrong — if we became aware of a breach affecting your data we would tell you promptly and directly by email, and meet our obligations under UK data protection law, including to the ICO where required.

Where AI is involved

Some features draft text for you: audit explanations, suggested replies in the Cue chat, captions, and answers in Ask Ospry. By default these run on a language model that we host ourselves, on our own server, in the United Kingdom. Your data, including anything received from Google APIs, is processed locally on that server and is never transmitted to the model's provider or to any third-party AI service, and is never used to train or improve any model, ours or anyone else's.

If you choose to connect your own Claude API key in Connections, those same features run through your own Anthropic account instead, under your own agreement with Anthropic. Anthropic's commercial API terms do not train on customer data. You can disconnect the key at any time and the default returns to the self-hosted model. Data from Google APIs is only ever included in a request to the extent needed to answer the question you asked about your own sites, and is not retained by us beyond that answer other than as part of the results you already hold.

What we don't do

  • No advertising trackers, no analytics cookies. The only cookie is the one that keeps you signed in.
  • We don't sell or share your data with anyone for marketing.
  • No marketing email unless you ticked the separate opt-in box at signup — and you can withdraw that any time by unsubscribing or asking us.
  • We don't email the businesses you audit.

Where it lives

On our own infrastructure in the United Kingdom, with nightly backups kept for 14 days. If you connect a third-party service (for example WordPress or a CRM), data flows to that service under its own privacy terms — you chose that connection and can revoke it in Settings at any time.

How long, and your rights

We keep your data while your account exists. Deleting your workspace from Settings removes your sites, audits, reports, photos and credentials from our systems, and your backups age out within 14 days. Under UK GDPR you can ask us for a copy of your data (there's an export button in Settings that does it instantly), ask us to correct it, or complain to the ICO (ico.org.uk) if you think we've handled it badly.