1. Who we are
Ostati.AI (“we”, “us”) runs the website ostati.ai, the student app app.ostati.ai, the admin panel admin.ostati.ai and their API at api.ostati.ai. We are based in Tbilisi, Georgia. For anything about personal data, write to hello@ostati.ai.
2. Our role
Ostati.AI is mostly used by businesses — restaurants, cafés, hotels and chains (a “customer”). The customer decides which employees to add and why, so for employee data the customer is the controller and we process that data on its behalf and on its instructions, as a processor. If your employer added you, you can also contact them about your data.
We are the controller for data about website visitors, the demo request form, the public demo and customers’ contact persons.
3. What we collect
- Account: name, mobile number, role, venue and organisation. For managers and authors, also an email address and a password, which we store only as a salted hash.
- Sign-in: a one-time code sent by SMS. We keep only a hash of it, for 5 minutes. After you sign in, a session cookie is stored in your browser.
- Learning: lessons opened and finished, quiz and exam answers and scores, 3D exercise results, XP, streaks, achievements, certificates and the time you were last active.
- AI assistant: questions you type or dictate, the assistant’s answers, and your “helpful / not helpful” ratings. Voice messages are sent for transcription and are not stored by us.
- Organisation content: venue tips, custom lessons, images and other uploads.
- Demo requests: name, phone, email, venue name, number of venues, message and page language.
- Technical data: IP address, browser type, request times and logs — for security, abuse prevention and troubleshooting. Actions in the admin panel are recorded in an audit log.
We do not ask for special categories of data (such as health data). Please don’t enter such information in the AI assistant or in venue tips.
4. How we use it, and on what basis
- Providing the service — lessons, quizzes, 3D practice, certificates and the AI assistant. Basis: our contract with the customer and the customer’s instructions.
- Sign-in and security — SMS codes, sessions, rate limits and auditing. Basis: our and the customer’s legitimate interest in keeping accounts safe.
- Showing progress to managers — who is learning what, where they struggle, who hasn’t been in for 5+ days. Basis: the customer’s legitimate interest in training its team.
- In-app notifications — streak reminders and alerts for managers.
- Answering demo requests — at your request.
- Improving the content — using aggregated statistics, for example which question people get wrong most often.
- Meeting legal obligations.
We do not sell personal data, do not use it for advertising, and do not train AI models on your content.
5. Who can see your data
- Managers and owners in your organisation see their staff’s names, progress, scores, certificates, activity, and the questions whose answers were rated “not helpful” — so they can improve their venue tips.
- Teammates see each other’s names and XP on the leaderboard, if your organisation has it switched on.
- Anyone with a certificate link or code sees the name, organisation, level, score and issue date. That is how an employer checks a certificate is genuine.
- The Ostati.AI team accesses data only for support and running the service, and only as far as needed.
6. Service providers
To run the service we use a small number of providers. Each receives only what it needs for its task:
- Cloudflare, Inc. (USA, global network) — hosting, database, file storage, content delivery and Workers AI.
- Anthropic PBC (USA) — AI assistant answers (Claude models).
- OpenRouter, Inc. (USA) — routes AI requests to model providers such as Google and Anthropic: answers, speech-to-text and text-to-speech.
- SMS gateway — smsoffice.ge (Georgia) or Twilio Inc. (USA) — only to deliver sign-in codes.
- Google — the website ostati.ai loads its fonts from Google Fonts, so Google sees your IP address. The student app and admin panel serve their own fonts.
We may also disclose data to public authorities where the law requires it.
7. International transfers
Some providers’ servers are outside Georgia. We transfer data only to providers with appropriate safeguards in place (such as standard contractual clauses), as required by the Law of Georgia on Personal Data Protection and, where it applies, the EU GDPR.
8. How long we keep it
- AI assistant conversations — 90 days, then deleted automatically.
- In-app notifications — 60 days.
- SMS codes — 5 minutes. Sessions — until you sign out, at most 30 days.
- Account and learning history — while the account is active. Within 90 days of an employee being removed or a customer’s contract ending, we delete or anonymise the data, unless the customer asks sooner or the law requires us to keep it longer. Once an account is deleted, its certificates can no longer be verified.
- Demo requests — up to 24 months after the last contact.
- Server logs and backups — up to 30 days.
9. Security
All connections are encrypted with HTTPS. The session cookie is not readable by JavaScript, passwords and SMS codes are stored only as hashes, organisations’ data is kept separate, access depends on role, requests are rate-limited and administrative actions are logged. No system is perfectly secure; if an incident happens, we will notify the customer and, where required, the supervisory authority within the time the law sets.
10. Your rights
Under the Law of Georgia on Personal Data Protection and, where it applies, the GDPR, you have the right to: be told what data we process and get a copy; have inaccurate data corrected; have data deleted or blocked; object to processing; receive your data in a machine-readable format; and withdraw consent at any time where processing relies on consent.
Send your request to hello@ostati.ai. We reply within 10 working days; in complex cases this may be extended by another 10 working days, and we will tell you in advance. If we process the data for your employer, we will pass the request to them and help them fulfil it.
You can complain to the Personal Data Protection Service of Georgia (personaldata.ge) or, in the EU, to your national supervisory authority.
11. Children
Ostati.AI is a professional training service and is not intended for people under 16. If a customer adds an employee who is a minor, the customer is responsible for obtaining any consent the law requires.
12. Changes to this policy
We may update this policy. The date of the latest version is shown at the top of this page. We will tell customers about material changes by email or in the admin panel at least 14 days before they take effect.