Privacy Policy
Last updated 7 September 2026
Oshan is a marketing platform operated by BlueOshan AI Labs. This policy explains what we collect, why we hold it, who else sees it, and how to get it removed. It is written to be read rather than to be defensible, so if anything below is unclear, tell us and we will rewrite it.
Who we are
BlueOshan AI Labs is the data controller for information you give us directly. For the content and analytics we process from your connected accounts, you are the controller and we act as your processor — we handle that data on your instructions and for no other purpose.
Contact: privacy@blueoshan.com
What we collect
Information you give us
- Your name and email address, so we can identify your account and contact you.
- A password, stored only as a bcrypt hash. We never store your password and cannot recover it — a reset replaces it.
- Your organisation name, workspace address, and the websites you add.
- Your notification preferences, timezone and role.
Information from accounts you connect
Oshan is only useful when connected to the tools you already use. You choose which to connect, and you can disconnect any of them at any time. What we read from each:
| Service | What we access | Read or write |
|---|---|---|
| Google Analytics | Traffic, sessions, referral sources for the properties you select | Read only |
| Google Search Console | Search queries, impressions, clicks and positions for your verified sites | Read only |
| Your company page, posts you publish through us, and their engagement | Read and publish | |
| Facebook and Instagram | Pages and business accounts you select, posts published through us, comments and insights | Read and publish |
| HubSpot | Blog posts and authors, for publishing content you approve | Read and publish |
| WordPress | Posts, pages and media on the site you connect | Read and publish |
| Slack, Google Chat, Microsoft Teams | The channel or space you nominate, to deliver notifications | Write only |
We do not read your inbox, your customer lists, your CRM contacts, or anything outside the specific accounts you connect for the purposes above.
Information we generate
- Results of scans we run against your websites — pages crawled, issues found, scores.
- Content drafts, social posts and recommendations produced by the agents.
- A record of actions taken, so you can see what happened and undo it.
- Usage counts, so we can bill accurately and show you where your credits went.
Why we hold it
To provide the service you asked for, to bill for it, to notify you about your own websites, and to keep the service secure. We do not sell personal data, we do not share it for advertising, and we do not use your content to train AI models.
Who else sees it
We use a small number of processors. Each receives only what it needs to do its job:
| Processor | Purpose | Where |
|---|---|---|
| Amazon Web Services | Hosting, database and file storage | United States (us-east-1) |
| Google (Gemini) | Generating and analysing content | United States |
| OpenAI | Testing how AI search engines answer questions about your brand | United States |
| Anthropic | Testing how AI search engines answer questions about your brand | United States |
| Amazon SES | Sending notification and account email | United States |
When the agents write content, the brief and relevant context are sent to the AI provider handling that request. Providers are used under their API terms, which do not permit training on submitted data.
If we are ever required by law to disclose data, we will tell you unless we are legally prevented from doing so.
How it is protected
- Access tokens and refresh tokens for every connected account are encrypted at rest. They are decrypted only at the moment a request is made on your behalf.
- Passwords are hashed with bcrypt and are never stored or logged in readable form.
- Traffic is served over TLS. The database is not reachable from the public internet.
- Each workspace is isolated. Every request is checked against your role, and one organisation cannot read another’s data.
- Error reports shown to you and sent by email are stripped of internal technical detail, so a fault in our systems does not expose how they are built.
How long we keep it
- Account and workspace data: for as long as your account is open.
- Scan results, content and social history: for as long as your account is open, so trends remain meaningful.
- After you delete your account: erased within 30 days, except records we must keep for accounting and tax, which are kept for the period the law requires.
- Disconnecting an integration deletes its stored tokens immediately.
Your rights
You can ask us to show you what we hold, correct it, export it, restrict how we use it, or delete it. You can withdraw consent for any connected account by disconnecting it. If you are in the UK, EU or India, you also have the right to complain to your data protection authority.
The fastest route for deletion is the delete my data page. Otherwise write to privacy@blueoshan.com and we will respond within 30 days.
Cookies
We set a session cookie so you stay signed in, and a small number of preference cookies that remember things like which workspace you last opened. We do not use advertising or cross-site tracking cookies.
Children
Oshan is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If we change this policy in a way that affects you, we will email account owners before it takes effect. The date at the top always reflects the current version.
