Legal
Privacy Policy
What OSMARA collects, why we collect it, who processes it with us, and how to reach us about it.
Last updated August 11, 2026 · Version 2026-08-11OSMARA by TradeFlow is operated by ERYNTO LLC.
Who is responsible
OSMARA is operated by:
ERYNTO LLC
Registered in New Mexico, USA
Entity ID: 0008054284
1209 Mountain Road PL NE, Ste NAlbuquerque, NM 87110United States
ERYNTO LLC decides what personal data OSMARA processes and why. Privacy questions and requests go to info@erynto.com.
What we process
Account and authentication data. Your email address, an encrypted password credential, and account timestamps such as when the account was created and last signed in. This is handled by Supabase on our behalf. We never see or store your password in readable form.
Subscription and payment records. If you subscribe to OSMARA Pro, we store the identifiers and status needed to know whether your subscription is active — the Stripe customer and subscription references, plan, status, and period dates. Payment card details are collected and processed by Stripe, not by OSMARA. We do not receive or store your full card number.
Product usage data you create. Items you add to your watchlist, and — if you take part in the referral programme — referral and commission records associated with your account.
Service and security logs. Our infrastructure records technical information such as request times, error conditions and coarse diagnostics, which we use to keep the service running and to investigate abuse or faults.
Product analytics. A small set of named product events — for example that a landing page was viewed or a signup completed — sent to PostHog. See the section below for exactly how this is configured.
Support communications. If you email us, we keep that correspondence so we can deal with your request and keep a record of what was agreed.
Product analytics, specifically
We use PostHog to understand which parts of OSMARA are used. It is configured deliberately narrowly:
- Analytics identity is held in memory only. OSMARA's analytics does not write cookies, localStorage or sessionStorage for analytics purposes, and identity does not persist after you close the tab.
- Session replay is disabled. We do not record your screen, your mouse movements or your keystrokes.
- Autocapture is disabled. We do not collect a generic stream of every click and form interaction.
- Heatmaps, dead-click tracking and rageclick tracking are disabled.
- Only a fixed, named set of product events is captured — such as viewing the landing page, completing signup, viewing the feed, opening a transaction, starting checkout, and completing a purchase.
- For signed-in users, the analytics identifier is your account's internal identifier, together with whether your plan is free or pro. We do not send your email address, your name, your payment details or your bank details to analytics.
- We do not use analytics for advertising, and we do not run advertising or cross-site tracking technology in OSMARA.
The only cookies OSMARA sets are the ones the product needs to work: your authentication session, and — if you arrive through a referral link — a referral cookie that stores nothing but an opaque referral code.
Why we process it
- To provide the service: creating and authenticating your account, and delivering the features you use.
- To operate subscriptions: taking payment through Stripe, and knowing whether your access is Free or Pro.
- To keep the service secure and reliable: detecting faults, preventing abuse, and protecting accounts.
- To improve the product: understanding at an aggregate level which features are used.
- To communicate with you: answering support requests and sending service messages about your account.
- To meet legal and accounting obligations, including keeping records of transactions.
Where the law that applies to you requires a legal basis for processing, we rely on performance of our contract with you (providing the service and your subscription), our legitimate interests (security, preventing abuse, and understanding product usage at an aggregate level), and compliance with legal obligations.
Who processes data with us
We use a small number of service providers, each for a specific purpose:
- Supabase — authentication and database hosting.
- Stripe — payment processing, subscription billing, and the customer billing portal. Stripe acts as an independent controller for parts of its own payment and fraud processing under its own privacy policy.
- PostHog — product analytics, configured as described above.
- Our hosting infrastructure — running the application itself and its logs.
We do not sell personal data, and we do not share it with third parties for their own marketing.
International processing
ERYNTO LLC is established in the United States, and our service providers may process data in the United States, the European Union or other countries where they operate infrastructure. This means your data may be processed outside the country where you live.
Where a transfer of personal data out of your jurisdiction requires a specific safeguard under the law that applies to you, we rely on the mechanisms offered by the relevant provider — such as contractual data protection terms — for that transfer. If you would like to know how a specific provider handles this, contact us at info@erynto.com.
How long we keep it
We keep account data for as long as your account exists. If you close your account, we delete or de-identify account data, except where we need to retain records for a longer period — principally billing, tax, accounting and referral-commission records, which we keep for as long as the applicable retention obligations require.
Service and security logs are kept for a short operational period. Product analytics events are retained by PostHog according to its retention settings and are not tied to a persistent browser identifier.
Security
Access to production data is restricted and authenticated. Data is transmitted over encrypted connections, and our database enforces row-level access rules so that account-scoped data is reachable only through authenticated, server-side paths. Sensitive administrative and financial records are not readable by a browser role at all.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will act on it and notify you and any relevant authority where the law requires it.
Your rights
Depending on where you live, you may have rights over your personal data — commonly including the right to access a copy of it, to have inaccurate data corrected, to have data deleted, to restrict or object to certain processing, and to receive your data in a portable form.
To make a request, email info@erynto.com from the address associated with your account. We will respond within the period required by the law that applies to you, and we may need to verify your identity before acting.
If you are unhappy with how we have handled a privacy request, you may be entitled to complain to the data protection or privacy authority in your country.
Children
OSMARA is not directed at children and is not intended for use by anyone who is not old enough to form a binding contract in their jurisdiction. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the product changes. The version and date at the top of this page identify the current text, and we will give notice of material changes before they take effect.
Contact
Privacy questions and requests: info@erynto.com.
ERYNTO LLC
Registered in New Mexico, USA
Entity ID: 0008054284
1209 Mountain Road PL NE, Ste NAlbuquerque, NM 87110United States