Legal

Privacy Policy

Last updated: 8 October 2026 · Effective: 8 October 2026 · Version 1.2

The short version

  • We collect your email address only when you join the Oystro waitlist, plus basic technical logs (IP address, browser, pages viewed) that any web server records automatically.
  • We use it for one thing: to confirm your signup and tell you when Oystro Standard launches, along with occasional product news you can opt out of at any time.
  • We confirm every signup by email (double opt-in). If you do not click the confirmation link, we do not email you marketing.
  • We do not sell, rent or trade your email address to anyone, and we do not share it for third-party advertising.
  • You stay in control: unsubscribe from any email, or ask us to access, correct or delete your data by writing to [email protected].

1. Who we are

This Privacy Policy is issued by Oystro (“Oystro”, “we”, “us” or “our”), operated from India by George Koshy.

For the purposes of applicable data protection law, we are the controller (and data fiduciary under India's Digital Personal Data Protection Act, 2023) of the personal information described in this policy. Our contact details are set out in Section 15.

2. What this policy covers

This policy applies to the Oystro marketing and teaser website at https://oystro.com and its subdomains (the “Website”), including the waitlist forms, and to email communications we send to waitlist subscribers.

It does not cover:

  • The Oystro open-source protocol (Oystro OSS), which is distributed under its own licence through github.com/oystro/oystro-oss. Code you run on your own machines never passes through this Website.
  • Any future Oystro product, dashboard or account portal, which will be governed by its own terms and privacy policy when launched.
  • Third-party websites, tools or services that we link to (see Section 13).
By ticking the consent box and submitting your email address through a waitlist form on this Website, you confirm that you have read and agree to this Privacy Policy. If you do not agree with it, please do not submit your information.

3. Information we collect

3.1 Information you give us

  • Email address and your consent tick — the waitlist forms ask for an email address and an unticked checkbox confirming you have read and agree to this Privacy Policy. Both are voluntary; you can read the whole Website without giving us anything.
  • Anything you write to us — if you email our support or privacy address, we keep that correspondence and your return address so we can reply.

We do not ask for, and you should not send us, payment card details, identity documents, or sensitive personal data through this Website.

3.2 Information collected automatically

Like virtually every website, our hosting infrastructure automatically records:

  • IP address (which also gives us your approximate country/region),
  • browser type and version, operating system and device type,
  • the page you came from (referrer) and the pages you view on this Website, with date and time stamps,
  • request volume and error data used for security, abuse prevention and reliability.

The waitlist forms are protected by Cloudflare Turnstile, an anti-bot verification challenge. When the form runs, Cloudflare processes your IP address and browser signals to decide whether a human is interacting with the page; we receive only the verification result and never use it for advertising.

This information sits in server and security logs. It is not combined with your email address for advertising purposes.

3.3 Information stored in your browser

We use your browser's local storage for one small thing: to remember your light/dark theme preference (oystro_theme). This data stays on your device, is never transmitted to us, and you can clear it at any time through your browser settings. Email addresses and consent choices are never stored in your browser.

3.4 What we do not collect on this Website

  • No precise geolocation, camera, microphone or contacts access.
  • No advertising identifiers and no data from social networks or data brokers.
  • No payment information — checkout, if and when we launch, will be handled separately by our payment providers.

4. How and why we use your information

What we doWhy (purpose)Legal basis
Process your waitlist signup and send the confirmation emailTo deliver what you asked for and verify the address is realYour consent; performance of a request you made
Send the launch announcement, early-access invitation and founding-member pricingThe reason you joined the listYour consent (withdrawable at any time)
Send occasional product news about OystroTo keep you informed about what you signed up to hear aboutYour consent; our legitimate interest in telling interested people about our own product
Reply to emails and support requestsTo answer youLegitimate interest; your request
Operate, secure and improve the Website; prevent spam, bots, fraud and abuse; produce aggregated, non-identifying statisticsTo keep the site safe and workingLegitimate interest (not overridden by your rights)
Keep records of your consent and subscription statusTo prove, if ever asked, that you agreed — and to honour your opt-outsLegal obligation; legitimate interest
Comply with court orders, lawful requests and applicable lawBecause we are required toLegal obligation

We will not use your email address for a purpose that is incompatible with the ones above without telling you and, where required, asking for your consent first.

We do not sell personal information, we do not rent or exchange email lists, and we do not disclose information to anyone for that party's own direct marketing.

5. Double opt-in and email consent

We use double opt-in for every waitlist signup:

  1. You enter your email address, tick the box confirming you have read and agree to this Privacy Policy, and submit the form.
  2. We send a confirmation message to that address. Your address sits in an unconfirmed state and is not used for marketing while it is unconfirmed.
  3. You click the confirmation link. Only then is your subscription marked as confirmed and do you start receiving launch and product emails.
  4. If you never confirm, we remove the unconfirmed address from our active list (see Section 9).

For each signup we record the date and time, the address, the source of the signup, your explicit consent tick (with the version of this policy you accepted), and the IP address associated with the signup (the consent grant). We keep these records so that we can demonstrate consent if a regulator, payment partner or you ever asks.

Every marketing email we send contains a working unsubscribe link, and every message is sent from an identifiable sender with a valid postal address and a way to reach us, as required by anti-spam rules in India, the United States, the United Kingdom and the European Union. Opting out is immediate and permanent: we will keep your address on a suppression list purely so that we remember not to email you again.

Transactional messages are separate. Confirmations, security notices and messages about this policy are not marketing and will still be sent where they are necessary — though in practice we send almost nothing beyond the confirmation itself.

6. Cookies, local storage and tracking

This Website runs without advertising cookies, without tracking pixels, and without third-party behavioural advertising. There is no cookie banner because there is nothing of that kind to consent to today.

What we do use:

  • Essential server-side logging (IP, timestamps) for security and reliability — see Section 3.2.
  • Local storage for your theme choice only — see Section 3.3. Local storage is not a cookie, does not track you across sites, and never holds your email address or consent choices.
  • Infrastructure cookies that our host sets strictly to deliver the page and defend it against attacks. These are exempt from consent under most laws because the site cannot function or be secured without them.
  • YouTube video embeds — the demo videos on the home page are click-to-play: nothing loads from YouTube until you press play. Pressing play embeds a privacy-enhanced iframe from www.youtube-nocookie.com, after which Google may process your IP address and device and browser information and may set cookies, governed by Google's privacy policy. We never receive that data.

If we later add audience analytics or any non-essential technology, we will update this section and, where the law requires it, ask for your consent before setting those technologies.

Do Not Track / Global Privacy Control: we do not sell or share personal information for cross-context behavioural advertising, so there is no sale or sharing for such opt-out signals to switch off. If that ever changes, we will honour legally recognised opt-out signals and update this section.

7. Who we share information with

We share your information only with the categories of recipients below, and only for the purposes described in this policy:

  • Cloudflare, Inc. (United States) — hosting, CDN, DDoS protection, the serverless function that forwards your signup, and Turnstile bot verification. As our infrastructure provider it processes IP addresses and request data on our instructions.
  • Email delivery provider — Brevo (Sendinblue SAS, France). It stores your address, subscription status and consent records, sends the double opt-in confirmation, and delivers launch and product emails on our instructions.
  • Other service providers we may engage for email, analytics, customer support or security — each bound by written terms requiring them to process data only on our instructions, to keep it confidential, and to protect it.
  • Professional advisers such as auditors, lawyers and accountants, on a need-to-know basis.
  • Authorities and courts where we are legally required to disclose, or where disclosure is necessary to protect our rights, our users or the public.
  • A successor entity in the event of a merger, acquisition, reorganisation or sale of all or part of our business, who will have to honour the commitments in this policy.

We do not sell your personal information, we do not rent or trade mailing lists, and we do not permit our providers to use your information for their own marketing. We have no reason to disclose your email address to any other third party for its own use.

8. International transfers

We operate from India. Your information may be processed in India and in other countries where our providers operate — in practice, principally the United States (Cloudflare) and France (Brevo, our email provider). Data protection laws in those countries may differ from the laws where you live.

Where information originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with the receiving provider, together with the technical and organisational measures those providers apply. A copy of the relevant transfer mechanism can be requested from [email protected].

By submitting your information on this Website you acknowledge that it may be transferred to and processed in these countries as described above. We would not transfer it for any reason inconsistent with this policy.

9. How long we keep your information

DataRetention period
Confirmed waitlist email address and subscription recordUntil you unsubscribe, ask us to delete it, or we end the launch campaign — whichever happens first. If the waitlist is not carried into the launched product, it is deleted within 12 months of the campaign ending.
Unconfirmed (pending) email addressesRemoved from our active list within 30 days if the confirmation is not completed.
Suppression list (addresses you asked us not to email)Kept indefinitely, and only for the narrow purpose of honouring your opt-out. It is never used to contact you.
Consent and signup records (date, time, source, IP of signup/consent grant, policy version)Up to 3 years after your last interaction with us, so we can evidence consent and respond to disputes.
Server, security and error logsUp to 90 days, after which they are deleted or aggregated so they no longer identify you.
Support and privacy correspondenceUp to 3 years after the matter is closed.

When a retention period ends, we delete the data or irreversibly anonymise it so it can no longer be linked to you.

10. Your rights and how to exercise them

Depending on where you live, you may have some or all of the following rights. We extend the core of them to every user, wherever you are located, as a matter of policy:

  • Access — ask whether we hold your data and get a copy of it.
  • Correction — have inaccurate information fixed.
  • Deletion — have your information erased, subject to records we must keep by law.
  • Withdrawal of consent — withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. On this site, the unsubscribe link in any email is the fastest route.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to pause it while a challenge is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format where the right applies (we will supply your email address and signup record as JSON or CSV).
  • Opt-out of sale or sharing — under US state privacy laws. We do not sell or share personal information, so there is nothing to opt out of today; we will not disadvantage you for exercising any of these rights.
  • Non-discrimination — we will not deny you service or charge you a different price because you exercised a privacy right.
  • Lodge a complaint — with your local supervisory authority (see below).

How to make a request

  1. Email [email protected] with the subject line “Privacy request”.
  2. Tell us which right you want to exercise and the email address you used to sign up, so we can verify it is you. We may ask for confirmation from that address before releasing or deleting anything — we will never ask for an ID document unless we genuinely cannot verify you otherwise.
  3. We aim to acknowledge within 72 hours and to respond in full within 30 days. If a request is complex we will tell you within that window and explain why more time is needed.
  4. If you act through an authorised agent, we will need written permission from you and enough detail to verify the agent's identity.

Supervisory authorities. If you are in the EEA, you may complain to the data protection authority of your country of residence or work. If you are in the UK, to the Information Commissioner's Office (ICO). If you are in India, you may raise a grievance with our Grievance Officer (Section 15) and, if dissatisfied, with the Data Protection Board of India once the applicable provisions of the Digital Personal Data Protection Act, 2023 are in force.

11. Children's privacy

This Website and the waitlist are intended for adults and for professionals evaluating a developer tool. They are not directed at children.

We do not knowingly collect personal information from anyone below the age at which they can give valid consent under applicable law — in India, that is 18 years under the Digital Personal Data Protection Act, 2023, and in other jurisdictions generally 13 to 16 years. If you believe a child has submitted information to us, write to [email protected] and we will delete it promptly and in any event without unreasonable delay.

12. Security

We protect your information with measures appropriate to a small, security-conscious team running a public website:

  • Transmission encrypted with TLS, and security headers (HSTS, content-type and framing protections) applied site-wide.
  • Third-party API keys held only as server-side environment variables, never in the browser or shipped source.
  • Access to subscriber data limited to the people who need it, behind individual accounts with multi-factor authentication.
  • Provider-side controls from our hosting and email vendors, including infrastructure-level abuse and bot filtering.
  • Collection minimisation: we ask for an email address and nothing more, which keeps the amount of data at risk small by design.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you should avoid sending us sensitive or confidential information through this Website or in reply to our emails.

13. Third-party links

This Website links to other sites and services — for example our GitHub organisation, our X and YouTube channels, and other social profiles. Those sites are operated by third parties with their own privacy policies, which we do not control and this policy does not cover. Following a link is at your own discretion, and we encourage you to read the relevant policy before giving anyone your information.

If you interact with us on a social platform, that platform's terms and privacy policy govern the interaction, and the platform may retain your data even after you remove it from their side.

14. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top of this page always shows when it was last revised, and the current version is always available at https://oystro.com/privacy.html.

For a minor change (clarifications, new providers in an existing category, editorial fixes) we will simply post the updated version. For a material change — for example a new purpose for your data, a new category of recipient, or a shorter retention period — we will notify you before it takes effect, either by email to the address you gave us or through a prominent notice on this Website, and where the law requires it we will ask for your consent to the new terms. If you do not agree with an update, you can unsubscribe or ask us to delete your data, and the change will not apply to processing that already took place.

15. Contact and grievances

Questions, requests and complaints about this policy or about how we handle your information:

Data controller / fiduciaryGeorge Koshy, operating the Oystro project — [email protected]
Privacy / data protection contact[email protected]
Grievance Officer (Information Technology Act, 2000 & Rules; DPDP Act, 2023)George Koshy, [email protected]. Grievances are acknowledged within 72 hours and resolved within 30 days.
General enquiries[email protected]

Governing law and forum. This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. Subject to any mandatory rights you have in your country of residence, the courts at Mumbai, India shall have exclusive jurisdiction over disputes arising from it. Where EU, UK or other local law gives you the right to bring proceedings in your own courts, that right is unaffected.