Privacy Notice
Last updated: May 3, 2026
1. Who we are
Osseo ("Osseo", "we", "us") operates the Osseo / Ossie Learn anatomy study service. We are the data controller for the personal data we process about users of the Service.
2. What data we collect and why
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Email, display name, authentication identifiers | Create and operate your account | Performance of contract |
| Profile | Display name, optional avatar, friend connections | Show you in friend lists, leaderboards, challenges | Performance of contract; legitimate interests |
| Study & progress | Quiz attempts, mistakes, flashcard progress, drawings, schedules, checklists | Provide the learning features and your stats | Performance of contract |
| Subscription | Subscription status, plan, billing period, customer ID | Grant Pro access; manage billing lifecycle | Performance of contract |
| Support | Messages you send us, attachments | Respond to support requests | Legitimate interests |
| Telemetry & security | IP address, device/browser info, error and access logs | Security, abuse prevention, debugging, service quality | Legitimate interests; legal obligation |
Payment card data is collected directly by our payment provider Paddle and is not stored by Osseo.
3. Who we share data with
- Service providers / sub-processors — hosting, database, AI gateway, email delivery, analytics, error monitoring. They process data only on our instructions.
- Paddle (Merchant of Record) — for the sale of Osseo Pro, subscription management, payments, taxes, invoicing, and refund handling.
- Professional advisers — lawyers, accountants, auditors where reasonably needed.
- Authorities — where required by law, court order, or to protect rights and safety.
4. International transfers
Personal data may be processed outside the UK / EEA by our service providers. Where it is, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
5. How long we keep data
We keep account and study data for as long as your account is active, and for a limited period after closure to support recovery, fraud prevention, and legal obligations. Webhook and billing records are retained for accounting and tax purposes. We delete or anonymize data when no longer needed.
6. Your rights
Depending on where you live, you may have rights to: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. UK/EEA users also have the right to lodge a complaint with their local supervisory authority. We aim to respond to rights requests within one month.
To exercise a right, contact us via the support page on Osseo.
7. Security
We use appropriate technical and organizational measures — including encryption in transit, role-based access controls, row-level security on our database, and regular monitoring — to protect personal data against unauthorized access, alteration, disclosure, or destruction.
8. Cookies and similar technologies
Osseo uses essential cookies/local storage to keep you signed in and remember preferences. We do not use advertising cookies. Any analytics we use is aggregated and used to improve the Service.
9. Children
Osseo is not directed at children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
10. Changes
We may update this Privacy Notice. Material changes will be notified in-app or by email. The "Last updated" date above reflects the current version.