Privacy Policy
Osmarium is operated by Osmarium LLC (“Osmarium,” “we,” “us”). This policy explains what information we collect when you use app.osmarium.com, why we collect it, who we share it with, and what control you have over it.
We have written this policy to describe only what Osmarium actually does today. It contains no placeholder sections for services we do not use. When that changes, this policy changes with it.
1. Information we collect
Account information. When you sign in with Google, we receive and store your email address, display name, and Google account ID. We do not receive or store your Google password.
Content you create. We store the content you create in Osmarium: reviews, ratings, shelves, favorites, and encounter logs, along with the timestamps and account association needed to display them back to you.
Server logs. Our hosting provider automatically records standard technical information when you visit the site, including your IP address, browser type and version, the pages you request, and the time of each request.
Rate-limiting data. We temporarily hold IP addresses in memory to limit the rate of requests and protect the service from automated abuse. This data is never written to our database and is discarded continuously.
We do not collect payment information, precise location, contacts, or any special categories of sensitive personal data.
2. Cookies
Osmarium uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session token | Keeps you signed in between page loads | 30 days |
| OAuth state | Protects the Google sign-in flow against request forgery (CSRF) | Deleted immediately after sign-in |
Osmarium sets only strictly necessary cookies. We do not use analytics cookies, advertising cookies, or any cookies that track you across other websites. The cookies above are required for the site to function — to keep you signed in and to protect against abuse — and Osmarium does not work correctly without them.
3. Third parties
Osmarium relies on three service providers. Each receives only what it needs to perform its function.
| Provider | Role | What it receives |
|---|---|---|
| Railway | Hosting and infrastructure | Server logs, including IP addresses |
| Neon | Database | Account information and the content you create |
| OAuth sign-in | Your Google account information, at the moment you sign in |
Web fonts are served from our own servers. No font provider receives your IP address or any other information when you visit Osmarium.
We do not use analytics services, advertising networks, or affiliate tracking. We do not sell your personal data.
4. How we use your information
We use your information to:
- create and maintain your account and keep you signed in;
- store and display the reviews, ratings, shelves, favorites, and logs you create;
- operate, maintain, debug, and secure the service;
- protect against fraud, abuse, and automated attacks; and
- respond to you when you contact us.
We do not use your information for advertising, and we do not profile you for third parties.
5. De-identified and aggregated data
Osmarium may create de-identified and aggregated data from how the service is used — for example, statistics about which fragrances are commonly logged together, or how scent preferences are distributed across a population of users. This data does not identify you and cannot reasonably be linked back to you.
We may use, publish, and share de-identified and aggregated data for any purpose, including research, product development, and commercial arrangements with brands, retailers, and other partners.
When we create de-identified data, we maintain it in de-identified form. We will not attempt to re-identify it, and we will require by contract that anyone we share it with does not attempt to re-identify it either.
6. How long we keep your information
Account information and your content are retained until you delete them or delete your account.
Sessions expire automatically and are not retained after expiry.
Server logs are retained by Railway for 7 days under our current plan. Retention may change with our hosting configuration, but will not exceed 90 days.
Rate-limiting data is held only in memory and is never persisted.
7. Deleting your account and your data
You can delete your account at any time from your Settings page. You may also request deletion by emailing info@osmarium.com from the address associated with your account.
We process email deletion requests within 30 days. Deleting your account removes your account record and, by cascade, the reviews, ratings, shelves, favorites, and encounter logs associated with it.
Server logs already written by our hosting provider are not individually deletable and will age out under the retention period described above. De-identified and aggregated data created before your deletion request does not identify you and is not deleted.
8. Your rights
Regardless of where you live, you may:
- Access the personal data we hold about you;
- Correct inaccurate personal data;
- Delete your account and associated data;
- Obtain a copy of the data you provided to us, in a portable format.
To exercise any of these rights, email info@osmarium.com from the address associated with your account. We will not discriminate against you for exercising them.
9. Children
Osmarium is not directed to children under 13, and we do not knowingly collect personal data from anyone under 13.
If you believe a child under 13 has created an account, contact info@osmarium.com and we will delete the account and its associated data.
10. Security
We take reasonable measures to protect the information we hold.
- All traffic between your device and Osmarium is encrypted in transit using TLS.
- Data stored in our database is encrypted at rest by our database provider, Neon.
- Osmarium does not store passwords. Sign-in is handled entirely by Google OAuth, so we never see or hold your Google password.
- Access to production systems and user data is limited to personnel who need it to operate the service.
- Sessions expire automatically, and rate limiting is applied to protect against automated abuse.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you as required by applicable law.
11. Disclosure required by law
Osmarium may disclose personal data if we are required to do so by law, or if we believe in good faith that disclosure is reasonably necessary to:
- Comply with a subpoena, court order, warrant, or other valid legal process;
- Enforce our Terms of Service or investigate potential violations;
- Detect, prevent, or address fraud, security, or technical problems; or
- Protect the rights, property, or safety of Osmarium, our users, or the public.
Where we are legally permitted to do so, we will make reasonable efforts to notify you before disclosing your personal data in response to a legal request.
12. Business transfers
If Osmarium LLC is acquired, merges with another company, or sells all or part of its assets — including the Osmarium database — personal data may be transferred as part of that transaction.
We will notify you before your personal data is transferred and becomes subject to a different privacy policy. Notice will be given by email to the address associated with your account, or by a prominent notice on the site, and will be given far enough in advance for you to delete your account first if you prefer.
Personal data transferred in this way remains subject to this Privacy Policy until you are notified of and it becomes subject to a replacement policy.
13. Changes to this policy
We may update this Privacy Policy as Osmarium changes. When we do, we will revise the version number and effective date at the top of this page.
14. Contact
Osmarium LLC
info@osmarium.com