Skip to content

Legal

Privacy policy

Last updated 20 July 2026

OS3 is an internal work-management platform built and operated by Illumination Labs. This policy explains, in plain terms, what data OS3 handles, why it handles it, how long it keeps it, and how you get it deleted. It covers the OS3 web application and the marketing site at os-3.io.

We collect the minimum needed to make the product work. We do not run advertising, we do not build advertising profiles, and we do not sell data.

Who we are

Illumination Labs is the data controller for the information described here. You can reach us about anything in this policy at contact@os-3.io.

What we collect, and why

Account information

When you sign in, our identity provider (WorkOS) gives us your name, email address, and the organisation you belong to. We use it to identify you inside the product, to decide what you are allowed to see, and to attribute the work you record. There is no other use.

Work you create in the product

Clients, contracts, projects, tasks, time entries, knowledge-base pages, invoices and their attachments are stored so the product can show them back to you and to the colleagues who are allowed to see them. Access is scoped per user: contractors and employees see only the projects they are assigned to and, for time and invoicing, only their own hours.

Google Calendar data

If you choose to connect your Google account, OS3 requests read-only access to your Google Calendar (the https://www.googleapis.com/auth/calendar.readonly scope). We read the events on your calendar — their times, titles, conferencing links, and the list of participants.

We use this for exactly one purpose: to know when the meetings you attend are scheduled, so our meeting-notes bot can join those calls, transcribe them, and file a summary into the right project in your knowledge base. Calendar data is not used for any other feature, is not used to build a profile of you, and is never used for advertising.

The access is read-only by design. OS3 cannot create, edit, move, cancel or delete anything on your calendar, and it does not invite anyone on your behalf. You can disconnect your Google account at any time from your settings in OS3, or revoke access directly from your Google account permissions page. Disconnecting stops all further calendar reads immediately.

Google Gmail sending

Separately and optionally, a contractor can connect their own Google account so OS3 can send their monthly invoice from their own email address. That connection is used only to send that message, at the moment they ask for it. OS3 does not read, search, or store your mailbox.

Meeting recordings, transcripts and summaries

When the meeting-notes bot joins a call, it produces a transcript of what was said and a written summary. Both are associated with the project the meeting relates to and are visible to the colleagues who have access to that project.

Connected third-party tools

If your organisation connects a tool such as Jira, Slack or HubSpot, OS3 stores the connection and exchanges data with that tool to keep the two in sync. Authorisation tokens are held in a dedicated secret store, never in our application database, and are never exposed to a browser.

Basic operational logs

Our servers keep short-lived request logs (timestamps, IP address, request path, error details) so we can keep the service running, diagnose faults, and defend against abuse. On the marketing site, if you submit the contact form we receive the name, email address and message you typed, and use them only to reply to you.

Google API Services User Data Policy

OS3's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, that means:

  • We use Google user data only to provide and improve the features you asked for — for calendar data, that is scheduling and producing your meeting notes.
  • We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, and in each case subject to the same protections described here.
  • We do not sell Google user data, and we do not use or transfer it for advertising, ad targeting, ad personalisation, or to build marketing profiles.
  • We do not allow humans to read Google user data unless we have your explicit consent for a specific case, it is necessary for security purposes or to comply with the law, the data is aggregated and anonymised for internal operations, or you have made the data publicly available.
  • We do not use Google user data to develop, train or improve generalised artificial-intelligence or machine-learning models. The AI processing OS3 performs is per-meeting summarisation carried out to produce your own notes, and the content is not retained by us for model training.

How long we keep things, and what we delete

  • Meeting transcripts are kept for 180 days from the date of the meeting, and are then deleted automatically. Their purpose is to let you check a summary against what was actually said; after six months that need has passed.
  • Meeting summaries are retained as part of your knowledge base, because they are the working record of the project. You can delete any summary yourself at any time.
  • Google Calendar data is not warehoused. We read your calendar to schedule the bot and hold only what is needed to do that — the event's time, title, conferencing link and participants — for as long as your Google account stays connected. Disconnecting removes the stored authorisation and stops further reads.
  • Work records (projects, tasks, time entries, invoices) are retained for as long as your organisation uses OS3, and afterwards only as long as needed for tax, accounting and legal obligations.
  • Operational logs are kept for a short period, on the order of weeks, and then rotate out.
  • Contact-form messages are kept in our email only as long as needed to handle your enquiry.

How to request deletion

Email contact@os-3.io from the address associated with your account and tell us what you would like removed — your Google connection, your meeting transcripts and summaries, or your account and all data associated with it. We will confirm the request and complete it within 30 days, except where we are legally required to retain a record (for example, an issued invoice).

You can also delete much of this yourself: disconnect Google from your settings, and delete individual pages, meeting summaries or tasks from inside the product.

How we protect it

Data is encrypted in transit and at rest. The application database is on a private network with no public address. Authorisation tokens for Google, Jira and other connected tools live in a managed secret store, separate from the application database, and are never sent to a browser. Access to production systems is limited to the people who need it to operate the service.

Who else processes your data

We use a small number of service providers to run OS3: Google Cloud (hosting and database), Vercel (web hosting), WorkOS (authentication), Anthropic (AI summarisation), Resend (transactional and contact email), and the meeting-recording provider that supplies the notes bot. They process data on our instructions and for no independent purpose of their own.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete the personal data we hold about you, and to object to certain processing. Email contact@os-3.io and we will help. We do not charge for this and we will not discriminate against you for asking.

Children

OS3 is a workplace tool. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes to this policy

If we change how we handle data in a way that affects you, we will update this page and move the “last updated” date at the top. Material changes will also be communicated to account holders by email.

Contact

Questions, requests, or anything unclear: contact@os-3.io.