Legal

Privacy Policy

Effective date: 1 July 2026  Β·  Last updated: 7 July 2026

πŸ”’ The short version: your letter photos never leave your device. Ostrando performs OCR on-device, redacts your personal data locally, and only sends anonymised text for AI analysis. You sign in with your Google account. We receive your Google ID and display name only; no password is stored by Ostrando.

1. Who we are

Ostrando ("we", "us", "our") is the provider of the Ostrando Android application and the website at ostrando.com. For GDPR purposes, Ostrando acts as the data controller for any personal data processed in connection with your use of the app or this website.

Contact: privacy@ostrando.com

2. What data we collect β€” and what we don't

What we do NOT collect

  • Sign in with Google β€” we receive your Google account ID and display name only. No password is stored by Ostrando.
  • No letter photographs β€” the photo you take is processed entirely on your device and is never transmitted to any server.
  • No raw letter text β€” the full OCR output stays on your device.
  • No location data, contacts, or call logs.
  • No advertising identifiers or cross-app tracking.

What we DO process

  • Anonymised letter text (AI analysis). Before any text leaves your device, Ostrando's on-device redaction engine automatically replaces personally identifiable information β€” Steuer-ID, IBAN, Aktenzeichen (case reference numbers), personal names, and postal addresses β€” with typed placeholders (e.g. [NAME], [STEUERID]). Only this anonymised, redacted text is transmitted to Ostrando's AI analysis API for generating the plain-language explanation.
  • Letter vault (local only). Scanned letters, explanations, extracted deadlines, and case status are stored in an encrypted local database on your device. This data never leaves your device unless you explicitly export it.
  • Crash and diagnostics data. If the app crashes, anonymised crash reports may be collected via Google Play Services to help us fix bugs. These reports contain device model, OS version, and a stack trace β€” no letter content.
  • Subscription and billing. If you purchase Ostrando Plus, payment is processed entirely by Google Play. We do not receive or store your payment card details. Google may share a purchase token with us solely to verify your subscription status.
  • Support emails. If you contact us at support@ostrando.com, we process your email address and the content of your message to respond to your enquiry. We do not use support emails for marketing.

3. Legal basis for processing (GDPR Article 6)

  • AI analysis of anonymised text: Legitimate interest (Article 6(1)(f)) β€” the anonymised text contains no personal data after redaction; the legal basis is therefore moot, but we rely on legitimate interest for completeness.
  • Subscription verification: Performance of a contract (Article 6(1)(b)) β€” processing the Google Play purchase token is necessary to verify your Plus subscription.
  • Crash reports: Legitimate interest (Article 6(1)(f)) β€” improving app stability and security.
  • Support correspondence: Legitimate interest (Article 6(1)(f)) β€” responding to your enquiry.

4. On-device OCR and PII redaction

Ostrando uses Google ML Kit Text Recognition v2, which runs entirely on your device β€” no text is sent to Google for OCR processing. After on-device OCR, Ostrando's own redaction pipeline identifies and replaces the following categories of personal data with typed placeholders before any text is transmitted:

  • German tax identification numbers (Steuer-ID / Steuernummer)
  • IBAN and bank account numbers
  • Case reference numbers (Aktenzeichen)
  • Full names (detected via NER)
  • Postal addresses
  • Date-of-birth strings

The redaction is performed locally before transmission. Even if our AI API were compromised, the anonymised text it receives contains no data that could identify you.

5. AI analysis API and sub-processors

The anonymised, redacted text is sent to Ostrando's backend API (hosted on servers within the EU/EEA) which in turn calls a large language model API to generate the plain-language explanation. We contractually require our AI sub-processor to:

  • Not use submitted text to train their models.
  • Process data only as instructed (data processor relationship under GDPR Article 28).
  • Maintain appropriate technical and organisational security measures.

Our current AI sub-processor and its data processing location are available on request at privacy@ostrando.com.

6. Data retention

  • Letter vault: Stored on your device until you delete it. Uninstalling the app deletes the vault. We do not hold copies.
  • Anonymised text (AI analysis): Not retained after the API call returns a response. Logs are purged within 30 days.
  • Subscription tokens: Retained for the duration of your subscription and 30 days after cancellation to handle disputes.
  • Crash reports: Retained for 90 days.
  • Support emails: Retained for 2 years from last contact, then deleted.

7. Your rights under GDPR

If you are located in the EU/EEA, you have the following rights regarding your personal data:

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate data.
  • Right to erasure (Article 17): Request deletion of your personal data. For letter vault data, deletion is entirely in your control β€” delete within the app or uninstall it.
  • Right to restriction (Article 18): Request that we limit processing of your data.
  • Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
  • Right to object (Article 21): Object to processing based on legitimate interest.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. In Germany, the relevant authority is the Bundesbeauftragte fΓΌr den Datenschutz und die Informationsfreiheit (BfDI) at bfdi.bund.de.

To exercise any of these rights, contact us at privacy@ostrando.com. We respond within 30 days.

8. Children's privacy

Ostrando is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted personal data to us, please contact privacy@ostrando.com and we will delete it promptly.

9. International data transfers

Ostrando's backend API is hosted within the EU/EEA. If anonymised text is processed by an AI sub-processor outside the EU/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses under GDPR Article 46). Because the text has been fully anonymised before transmission, it does not constitute personal data under GDPR and transfer restrictions do not apply β€” but we apply these safeguards regardless.

10. Security

We implement appropriate technical and organisational measures to protect data against unauthorised access, alteration, disclosure, or destruction. The local letter vault is encrypted at rest. All data transmissions use TLS 1.2 or higher. Our API endpoints are protected by authentication and rate limiting.

11. Third-party links

This privacy policy applies only to Ostrando. Our app and website may contain links to third-party services (e.g. Google Play Store). We are not responsible for the privacy practices of those services and encourage you to read their privacy policies.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified in the app or via an in-app banner on this website. The "last updated" date at the top of this page will always reflect the most recent version. Continued use of the app after a change constitutes acceptance of the updated policy.

13. Contact

For any privacy-related questions, requests, or complaints:


This Privacy Policy was written in plain English to be as clear as possible. If any section is unclear, please email us β€” we are happy to explain.