Osnova ID

Scope and contact

This notice covers Osnova ID at id.osnova.ai, its administration interface and its sign-in endpoints on participating project domains. The service is operated under the Osnova name. Contact id@osnova.ai for privacy or account questions. Downstream application content, purchases and separate public-site analytics are outside this notice and may have their own policies.

Identity and access data

We store your email address, project membership, assigned role and permissions, status, relevant creation and verification times, key-use counts and invitation status. Google sign-in checks a signed Google identity token and verified email against project access rules. It does not request permission to read your Gmail inbox or Drive. Administrator invitations do not by themselves prove that the recipient controls the email address.

Keys and verification codes

Recoverable personal keys are encrypted with AES-256-GCM so authorized identity administrators can copy or resend them; they are not password hashes only. Authentication also uses keyed digests. Email confirmation codes are stored as keyed digests, expire after ten minutes and have attempt limits. Older hash-only keys cannot be recovered. Encryption does not prevent an authorized recipient from seeing a key in an invitation email.

Sessions and browser storage

A first-party, Secure, HttpOnly session cookie identifies your session. Its normal lifetime is seven days; logout or administrator revocation can end access earlier. Session records include email, project, sign-in method, role, start, expiry and recent activity times. Theme and language preferences are stored locally in your browser. We do not use advertising cookies on Osnova ID.

Activity and security records

We record sign-ins, failed or successful verification, administrator actions and authenticated requests handled by the identity service or connected private APIs. Records may include request path, method, selected parameters, response status, browser user-agent and a keyed IP digest. Unknown query parameters are redacted; raw IP addresses may still appear in infrastructure-provider logs. This is not a recording of every browser click. Logs support security, troubleshooting and service improvement.

Transactional email

We use your email to deliver invitations, confirmation codes, recovery messages and session-start notices. Send times, delivery acceptance identifiers and failures may be retained for troubleshooting. Google Workspace sends these messages through its Gmail API using separately authorized send-only service delegation. Gmail acceptance does not prove inbox delivery or that you have read a message. These messages are not marketing subscriptions.

Storage and access

Identity records and security events are stored in a private Google Cloud Storage bucket. The service runs on Google Cloud Run; branded pages and request routing use Cloudflare. Authorized Osnova identity administrators and project administrators can see data needed for their permitted duties. Operational submission workflows may also use Google Sheets; private downstream files stay subject to their own project permissions. We do not sell identity data.

Retention and your requests

Session expiry ends authentication, not automatic deletion of the stored session or audit record. This release has no automatic account or audit-record deletion schedule. Google Storage soft deletion can retain deleted object versions for seven days, and provider logs, backups and sent emails can have separate retention. Contact id@osnova.ai to request access, correction, account closure or deletion. We verify the requester and explain any records that must be retained for security or applicable obligations.

Updates

We update this notice when service behavior changes and show the revision date here. New downstream functionality can require an additional project-specific notice. Report suspected misuse or an unexpected sign-in email to id@osnova.ai; do not include your personal key or confirmation code in the report.

id@osnova.ai ↗