Website privacy policy
Last updated: 28.09.2026
This policy explains what personal data we process when you visit the public website of Oscar or join its waitlist. The public website is the home page at /, the pages of this policy and of the terms of use, and, while we publish them, the developer docs at /docs and the file /llms.txt.
Oscar is in pre-launch. We do not offer the accounting service to new clients yet. You can join a waitlist, and we tell you when we launch.
We use no analytics, no advertising and no tracking. We process the technical data that a web server needs, the error reports of the website, the e-mail address that you give us for the waitlist, and the e-mails that you send to us.
1. Who we are
OscarAI OÜ is the controller of your personal data. We are an Estonian private limited company.
- Registry code: 17608438
- Address: Pärnu mnt 105, 11312 Tallinn, Estonia
- E-mail: [email protected]
"Oscar" is our brand name. In this policy, "we" and "us" mean OscarAI OÜ.
2. What this policy covers
This policy covers a visitor of the public website and a person on the waitlist.
It does not cover the accounting service. The service starts when you sign up or log in, for example at /signup or /login. A separate client agreement and its own privacy notice govern the use of the service. You receive both before onboarding. That notice also covers the session and security cookies that the service sets.
3. What data we process
Server logs
When your browser requests a page, our servers receive technical data. This is true for every website. The data is:
- your IP address
- the date and time of the request
- the requested URL
- the user agent (the name and version of your browser and operating system)
- the response status and size
We use this data to deliver the pages, to keep the website secure, to find errors and to stop abuse.
Error reports
When a page of the website fails in your browser or on our servers, the website sends an error report to our error tracking provider. The report holds the error, the address of the page without its query string, and the name and version of your browser and operating system. We set it up so that a report holds no cookie, no form content, no request header and no name or e-mail address. We use the reports only to find and fix errors.
The waitlist
When you join the waitlist, we store:
- your e-mail address
- the date and time when you joined and gave your consent
- the version of this policy that you saw
We use this data only to tell you when Oscar launches and to invite you to become a client. We send you no other e-mail, no newsletter and no advertising, and we do not give your e-mail address to another company for its own use. At the moment we send no e-mail to the waitlist. We will write to you when we launch.
E-mails to us
When you write to [email protected], we receive your e-mail address, your name if you give it, and the content of your message. We use this data to answer you and to handle your request.
Data we do not collect
- We use no analytics tools.
- We use no advertising or tracking pixels.
- The home page loads no content from third parties. It has no embedded videos, maps or social media widgets.
- Our fonts are part of our own website. Your browser does not request them from Google or from another font service.
- The only form of the public website is the waitlist form. It asks only for your e-mail address.
4. Cookies and browser storage
The public website sets no cookies for analytics, advertising or tracking. It uses only storage that is strictly necessary:
- Your choice of the light or the dark theme, in the local storage of your browser. This value stays on your device. We do not receive it.
- When you send the waitlist form, a security cookie can protect the form against forged requests (cross-site request forgery).
- Our network provider Cloudflare can set a security cookie that helps it tell people from automated attacks.
Under § 102 of the Electronic Communications Act (elektroonilise side seadus), storage that is strictly necessary for a service that you request needs no consent. That is why the website shows no cookie banner. You can delete these values at any time in the settings of your browser.
The API reference at /docs/api has a "try it" console. If you paste an API key into it, the key stays in the memory of the page only. The page does not store the key in your browser. The console sends your test request to our own website, not to a third party.
5. Why we process data, and the legal basis
We process personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act (isikuandmete kaitse seadus).
- Server logs and error reports: our legitimate interest to operate the website, to fix its errors and to keep it secure (GDPR Article 6(1)(f)).
- The waitlist: your consent (GDPR Article 6(1)(a)). You give it when you tick the box and join. You can withdraw it at any time (section 8). The withdrawal does not affect the processing before it.
- E-mails: our legitimate interest to answer the people who contact us (GDPR Article 6(1)(f)). If you ask about becoming a client, we also process the data to take steps at your request before a contract (GDPR Article 6(1)(b)).
- Legal duties: when a law requires us to keep or to disclose data (GDPR Article 6(1)(c)).
We make no automated decisions about you, and we do not build profiles of visitors.
6. Who receives the data
We do not sell personal data. We do not share it for advertising.
These service providers (processors) process data for us, under a contract and only on our instructions:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: our hosting provider. It runs the servers of the website and the database of the waitlist in its data centre in Finland, in the EU
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA: the network and security provider in front of our servers. It receives each request before our servers do
- Functional Software, Inc. (Sentry), USA: our error tracking provider. It stores the error reports in its EU region, in Germany
- Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland (Google Workspace): our e-mail provider. It receives and stores the e-mails that you send to us
When we launch, we send the e-mail to the waitlist through our e-mail sending provider, Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA. It sends the e-mails from Ireland, but it stores its data, including the e-mail addresses and the logs, in the United States.
We also disclose data to an authority or a court when a law requires it.
7. Transfers outside the EU
We keep the data in the European Economic Area (EEA) when we can. If a provider processes data outside the EEA, we transfer it only on a legal basis that the GDPR allows. This is an adequacy decision of the European Commission, or the standard contractual clauses of the European Commission. You can ask us for a copy of the safeguards.
Cloudflare, Sentry and Resend are companies in the United States. For a transfer to them we rely on the EU-U.S. Data Privacy Framework, which the European Commission found adequate, for a company that is certified under it. Where that framework does not apply, the standard contractual clauses in the data processing agreement of the provider apply. Google Cloud EMEA Limited is in Ireland. When it transfers data to Google LLC in the United States, Google relies on the same framework, and on the standard contractual clauses as the fallback.
8. How long we keep the data
- Server logs: up to 30 days, then we delete them. We keep a log longer only when we need it to investigate a specific security incident.
- Error reports: up to 90 days, then our provider deletes them.
- The waitlist: until you leave the waitlist, or at the latest 12 months after we send the launch e-mail. If we have not launched 24 months after you joined, we delete your data then. If you become a client, the client privacy notice applies from then on.
- E-mails: as long as we need them to handle your request and any follow-up. If an e-mail becomes part of a contract, an accounting record or a legal claim, we keep it for as long as the law requires.
How to leave the waitlist
You can leave the waitlist and withdraw your consent at any time. Write to [email protected] from the address on the waitlist, or use the link to leave the waitlist in any e-mail that we send you. We then delete your e-mail address from the waitlist.
9. Your rights
Under the GDPR you have these rights:
- to get access to your personal data and a copy of it
- to correct data that is wrong
- to have your data deleted
- to restrict the processing
- to object to processing that is based on our legitimate interest
- to withdraw a consent at any time
- to receive your data in a portable format, where this right applies
To use a right, write to [email protected]. We answer within one month. We can ask you for information to confirm your identity. For server logs, we can often not link a log entry to you without more data from you.
You also have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. We ask you to contact us first, so that we can try to solve the problem.
10. Links to other websites
The website names and can link to other services, for example Claude, ChatGPT and banks. When you open another website, its own privacy policy applies. We do not control how other websites process data.
11. Changes to this policy
We can change this policy when the website or the law changes. We publish the new version on this page and change the date at the top. If a change is significant, we show a notice on the website. If a change affects the waitlist in a significant way, we tell you by e-mail.
12. Contact
For every question about this policy or your personal data, write to [email protected].