Privacy policy

This Privacy Policy describes how Our Oase ApS ("Oase", "we", "us") collects, uses, stores, and protects personal information when you use the Oase app and platform (the "App").

Who we are: Our Oase ApS, CVR 43969161, Præstegårds Allé 50, 2700 Brønshøj, Denmark. For anything related to data protection, write to dpa@oase.app.

Our roles — who is responsible for your data

Oase is built around communities called oases. Oases can be grouped under a plenum, owned by an organization (for example a residential institution, a school, or an association) that pays for the service.

  • Oases under a plenum: the organization that owns the plenum is the data controller for the personal data in its oases, and Oase processes that data on the organization's behalf under a data processing agreement. If you use Oase through such an organization, requests about your data should as a starting point go to that organization.
  • Oases without a plenum: Oase is the data controller.
  • Billing contacts: for the contact details of paying organizations (see below), Oase is the data controller.

Organizations can enter into our data processing agreement whether or not they own a plenum yet (for example a municipality preparing to adopt Oase) — the agreement then covers the oases under their plenum from the moment one is created or transferred to them. Contact dpa@oase.app.

Information we collect

About users:

  • Name
  • Profile picture
  • Birth year and month (never your full birth date)
  • Content you create: messages, posts, events, polls, images, files
  • A push notification token for your device

About paying organizations: organization name, contact person, and email address. This is stored in readable form (not encrypted) because we need it for invoicing and administration. Legal basis: performance of the contract (GDPR art. 6(1)(b)) and our legitimate interest in administering customer relationships (art. 6(1)(f)). We keep it for the duration of the customer relationship and as required by Danish bookkeeping rules.

What we do not collect

  • Phone numbers
  • Your full birth date
  • Persistent logs of IP addresses — our own systems keep none; the only exception is the web host's standard access logs, deleted after 30 days (see "Using Oase in the browser" below)
  • Location data
  • No third-party analytics, advertising, or tracking in the App — we only run our own internal analytics and technical error reporting

We do not sell your data, use it for marketing, or use it for profiling or automated decision-making.

Login

Login is handled by Promise, an independent authentication service that acts as its own data controller (similar to "Sign in with Google"). Your email address is processed by Promise, not by Oase, and is not stored in readable form. See Promise's privacy policy for how they handle your data.

Encryption — the heart of how we protect you

Everything you share in an oase is encrypted on your device (AES-GCM) before it leaves it: messages, posts, names, images, and files. Media files have been encrypted on-device since the summer of 2025. Audio and video calls are end-to-end encrypted. File names are anonymized before upload.

The encryption keys are stored exclusively with Scalingo SAS in France — on European-owned infrastructure, separate from everything else — and are only usable by members of the oase the content belongs to. The services that store your encrypted content never have the keys.

When content is deleted, we delete the encryption keys (crypto-shredding), which instantly and permanently makes the encrypted data unreadable.

Two exceptions you should know about:

  • Calendar feeds: when an event is available in a personal calendar feed (iCal), the event's title, description, location, and the oase's name are also stored in readable form, so your calendar app can display them. You can choose per event whether it is available in a calendar feed. Event start and end times are always stored in readable form for technical reasons.
  • Older media: media uploaded before on-device media encryption was rolled out (and from older app versions) is stored unencrypted with Cloudflare, Inc. (US). This material is being migrated to encrypted storage in the EU, and Cloudflare is being phased out.

Where your data lives

Your personal data is stored in EU regions:

  • Database: Supabase, in AWS Frankfurt with a replica in Paris
  • Files and media: Scaleway, Paris
  • Application hosting: Gigalixir, in Google Cloud's Belgium region
  • Encryption keys: Scalingo, Strasbourg
  • Application logs (never your content, since it is encrypted before it reaches our servers): self-hosted with Hetzner, Germany, deleted automatically after 31 days

The one exception is the older unencrypted media at Cloudflare (US) described above, which is being phased out.

Using Oase in the browser: if you open Oase at oase.app instead of the native app, the web version is delivered by Netlify, Inc. (US) through its global content delivery network. Netlify serves the app's files and renders the preview of shared join links. Like any web host, it sees the IP address, browser type, and requested URL of each request and keeps standard access logs for 30 days, after which they are deleted. Your content never passes through Netlify: the web app talks directly to our EU servers, and everything is encrypted on your device before it is sent. The native iOS and Android apps do not use Netlify.

Our website and blog: this policy, our blog at blog.oase.app, and our dev blog at changelog.oase.app are hosted by Vercel, Inc. (US). Like Netlify, Vercel sees the IP address and browser type of each visit in its request logs, which it keeps for at most a day; we run no analytics or tracking on the site. Vercel never handles any data from the App.

Our landing page at hi.oase.app is served by GitHub Pages (GitHub, Inc., US) through its content delivery network; GitHub logs visitor IP addresses for security purposes under its own privacy statement. The only analytics on that page is our own, self-hosted on our servers in the EU: no cookies, no third party, and used solely to count page views and clicks.

Some data transits non-EU services: push notifications are delivered via Apple, Google, and Expo (US), but their content is encrypted and only decrypted on your device. Technical error reports go to Sentry (US) with personal identifiers scrubbed before sending.

Some of our providers are established outside the EU (Gigalixir in the US; Supabase in Singapore) even though the data itself is stored in EU regions. Those transfers rest on the EU Standard Contractual Clauses, supplemented by the on-device encryption described above (in line with the EDPB's recommendations 01/2020) — and the keys never leave the EU. Netlify (US), which only handles the web version's files and request metadata, is certified under the EU-U.S. Data Privacy Framework, with the Standard Contractual Clauses as fallback.

Our service providers

We use a small set of service providers to run Oase, each bound by a data processing agreement or equivalent terms:

ProviderWhat they do
Gigalixir (Vesper Summit, LLC), USApplication hosting (encrypted content only), EU region
Supabase Pte. Ltd., SingaporeDatabase (encrypted content, push tokens, calendar feed data), EU regions
Scaleway SAS, FranceFile and media storage (encrypted)
Transloadit-II GmbH, GermanyUpload processing (encrypted files, anonymized names), EU region
Hetzner Online GmbH, GermanyCall infrastructure (end-to-end encrypted calls) and self-hosted application logs (no content), deleted after 31 days
Scalingo SAS, FranceEncryption key storage
Google LLC (FCM), USPush notifications, Android (encrypted payload)
Apple Inc. (APNs), USPush notifications, iOS (encrypted payload)
650 Industries, Inc. (Expo), USPush token registration (being phased out)
Functional Software, Inc. (Sentry), USError reporting (identifiers scrubbed)
Netlify, Inc., USDelivery of the web version at oase.app (app files and join-link previews); standard access logs with IP address, deleted after 30 days
Vercel, Inc., USHosting of blog.oase.app (including this policy) and changelog.oase.app; request logs with IP address, kept at most a day
GitHub, Inc., USHosting of the landing page at hi.oase.app (GitHub Pages); visitor IP addresses logged for security under GitHub's privacy statement
Google Cloud EMEA Ltd, IrelandInternal analytics, EU region
Cloudflare, Inc., USOlder unencrypted media only (being phased out)

Payments are handled by Vipps MobilePay AS (Norway), which is an independent data controller for payment data under its own terms.

Cookies and tracking

Neither the App nor our websites use cookies or any other tracking mechanisms. The only analytics on our landing page is our own self-hosted, cookieless page-view counter; no third party is involved.

Your rights

Under the GDPR you have the right to access, rectify, and delete your personal data, to data portability, and to object to processing. Deletion is carried out by crypto-shredding, as described above.

Your use of Oase can span both worlds at once: some of your oases may belong to an organization's plenum, while others sit outside any plenum. For your oases under a plenum, the organization that owns it is the data controller, and requests about your data in those oases should as a starting point go to that organization — we help them fulfil your rights. For your oases outside a plenum, contact us directly at dpa@oase.app.

You can complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

Data retention

Content is stored for as long as the oase it belongs to exists, or until it is deleted. There is no separate retention period beyond that: deletion is effected by destroying the encryption keys.

Policy updates

We may update this Privacy Policy from time to time. If a change meaningfully affects how your data is handled, we will let you know.

Questions? Write to dpa@oase.app.