Privacy information · Effective August 13, 2026
Privacy is a boundary, not a setting you have to earn.
Ross helps people operate a shared space without turning one person’s private information into shared property. This page describes the data handling implemented for the current private beta.
Identity and membership
Ross uses Sign in with Apple. Apple supplies a stable provider subject that Ross uses to recognize the account. Ross stores a name or email address only when Apple supplies it; an email address is not used to authorize a space or link identities implicitly.
Ross also stores the account’s space memberships and administrative role. Signing in is not enough to read a space: an active membership, server authorization, and PostgreSQL row-level security are required.
Private and shared content
Ross stores the Inbox and open-loop content members create, including titles, optional details, state, responsibility, dates, and visibility. New items default to Only me. A member may explicitly choose Shared in Dillyfor information intended for the space.
- Only-me records are visible only to their owning member.
- Shared records are visible to active members of that space.
- An OWNER can administer a space but cannot read another owner’s private records.
- A shared fact may hide private source evidence instead of exposing it.
Security, diagnostics, and TestFlight
Ross records privacy-safe security and operational events such as opaque identifiers, request identifiers, event names, result states, reason codes, and timing. Better Auth stores the IP address and user-agent metadata associated with a session for session and security operations. Operational logs are designed not to contain content, enrollment codes, cookies, bearer tokens, Apple identity tokens, private source material, or personal email addresses.
Apple may make TestFlight crash information and tester feedback available to the beta operator under Apple’s TestFlight service. Ross does not include a separate crash-reporting or analytics SDK. Feedback a tester chooses to send may contain what the tester includes.
What this beta does not connect
The current private beta does not connect or ingest:
- Gmail
- Calendar
- Drive
- banks or Plaid
- health data
- contacts
- location
- an AI model
Retention and deletion
Account and space data remains while needed to operate the private beta or until it is deleted under the account flow. Application and database operational logs are retained for about 30 days. Encrypted database recovery points are retained for seven days. Sanitized security, deployment, billing, and organization-control records may follow separate operational retention periods.
In-app account deletion revokes Ross sessions and Apple authorization material, removes the member’s private content and membership, and produces a minimal privacy-safe receipt. Shared space records may remain for other active members, with direct creator attribution removed or pseudonymized. If the person is the space’s only member, the space and its content are deleted.
See the account and deletion guide for the current flow and export path.
Questions and security reports
For privacy or account help, email support@our-os.app. For a suspected security issue, email security@our-os.app. Do not email passwords, session material, private enrollment codes, or private household content.