Legal
Privacy Policy
Last updated: July 28, 2026
This policy explains what data SGA Tech (“Ostra”, “we”) collects when you use ostra.run, api.ostra.run, and the AI Computers you create through them — and, just as importantly, what we don't collect. The short version: computers are disposable, and so is most of the data inside them.
01What We Collect
- Account data. Email address, name, and authentication details when you sign up. API keys are stored hashed.
- Billing data. Wallet balance, top-up history, and hourly usage records per computer. Card details go directly to our payment processor — we never see or store full card numbers.
- Operational metadata. Deployment metadata (service, plan, environment, timestamps, resource usage), exposed endpoints, and platform logs. We need this to run the service, meter hourly billing, and enforce budget caps.
- Site analytics. Basic, privacy-respecting usage analytics on ostra.run. No advertising trackers, no cross-site profiling, no sale of data.
02What's Inside Your Computers
The code, files, and data inside an AI Computer belong to you. We do not read, mine, or train models on the contents of your computers. Our systems access computer contents only when:
- you ask us to (e.g. a support request),
- automated abuse detection flags activity prohibited by our Terms & Conditions (illegal content, attacks on third parties), or
- we are legally required to.
When a computer is destroyed, its virtual disk is destroyed with it and is not recoverable. Snapshot templates you explicitly save persist until you delete them.
03How We Use Data
- Providing and operating the service — booting computers, exposing endpoints, SSH access.
- Hourly billing, budget-cap enforcement, and fraud prevention.
- Security: detecting isolation-escape attempts, attacks, and prohibited content.
- Service communications — incidents, billing notices, and material changes to terms. Marketing email only with your consent, always with one-click unsubscribe.
04Sharing
We do not sell personal data. We share data only with the processors required to run Ostra — payment processing, cloud infrastructure, and email delivery — each bound by data processing agreements, and with authorities when a valid legal request requires it.
05Retention
- Computer contents: destroyed with the computer. Gone means gone.
- Account and billing records: kept while your account is active and afterwards only as long as tax and accounting law requires.
- Platform logs: retained for a limited period for security and debugging, then deleted.
06Your Rights
Depending on where you live (including under GDPR and KVKK), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Deleting your account removes your personal data except records we must keep by law; any remaining wallet balance is handled per our Refund Policy.
To exercise any of these rights, email legal@ostra.run. We respond within 30 days.
07Security
Every computer runs in a hardware-isolated microVM; customer workloads never share a kernel. Data is encrypted in transit, and access to production systems is restricted and audited. No system is perfectly secure — if a breach affects your personal data, we will notify you as required by law.
08Changes to This Policy
We may update this policy from time to time. Material changes will be announced on this page with an updated date and, where practical, by email. Continued use of Ostra after changes take effect constitutes acceptance.
Questions about this policy? Contact us at legal@ostra.run.