Privacy Policy
Last updated: July 8, 2026
This Privacy Policy explains how Solo Dolo Labs LLC ("Solo Dolo Labs," "Ozma," "we," "us") collects, uses, and shares information when you use ozma.app, our API, gateway, MCP server, and related services (the "Service"). Ozma is a product of Solo Dolo Labs LLC. Our studio site is solodololabs.com. By using the Service, you agree to this policy.
1. Information we collect
- Account data: email address, display name, organization name, and authentication tokens.
- Billing data: Stripe customer ID, payment method metadata (last four digits, brand), transaction history, and Connect account identifiers for providers.
- Usage data: API endpoints called, timestamps, latency, success/failure, charge amounts, key prefixes, and aggregate spend metrics.
- Technical data: IP address, user-agent, and request headers used for rate limiting, abuse prevention, and security logging.
- Communications: support emails and feedback you send us.
- Cookies: see our Cookie Policy.
We do not intentionally collect sensitive categories of personal data. Do not submit regulated health, financial account, or government ID data through API request bodies unless an upstream API explicitly requires it.
2. How we use information
- Authenticate requests and manage accounts
- Meter usage, process payments, and pay providers
- Display analytics, merit rankings, and spend alerts
- Prevent fraud, signup abuse, and security incidents
- Improve the Service and communicate product updates
- Comply with legal obligations
We do not sell personal data.
3. Legal bases (EEA/UK)
Where GDPR or UK GDPR applies, we process personal data based on: (a) contract performance (providing the Service); (b) legitimate interests (security, analytics, product improvement); (c) consent (where required, e.g., non-essential cookies); and (d) legal obligations.
4. Sharing & subprocessors
We share data with service providers that help us operate the Service:
- Stripe — payment processing and Connect payouts
- Cloudflare — hosting, Workers, and edge security
- Neon — Postgres database hosting
- Email delivery providers — verification and transactional email
We may also share data when required by law, to protect rights and safety, or in connection with a merger or acquisition. Providers receive usage and payout data necessary to operate their listings.
5. International transfers
Solo Dolo Labs LLC operates Ozma from the United States. If you access the Service from outside the U.S., your data may be transferred to and processed in the U.S. and other countries where our subprocessors operate. We use appropriate safeguards such as Standard Contractual Clauses where required.
6. Retention
We retain account, usage, and billing records while your account is active and as needed for tax, payment reconciliation, dispute resolution, and legal compliance. Abuse-prevention logs may be retained for a shorter or longer period based on security needs. You may request deletion subject to legal retention requirements.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact privacy@ozma.app. You may also lodge a complaint with your local supervisory authority.
8. Security
We use industry-standard measures including encryption in transit, hashed API key storage, access controls, and abuse monitoring. No method of transmission or storage is 100% secure.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children.
10. Enterprise & DPA
Business customers processing personal data through Ozma on behalf of their end users may request our Data Processing Addendum.
11. Changes & contact
We may update this policy from time to time. Material changes will be posted here with an updated date. Questions: privacy@ozma.app.