Privacy policy
What personal data Ontoshire holds about you, why, who else sees it, and what you can ask us to do with it.
Who controls your data#
The data controller is CI CODERS LTD, a company registered in England and Wales under company number 12099279, registered office 3rd Floor 86-90 Paul Street, London, England, EC2A 4NE. Contact us about anything on this page at support@ontoshire.com.
What we collect#
We collect as little as the service can work with. When you sign in with GitHub, we receive and store:
| Data | Where it comes from | Why we hold it |
|---|---|---|
| Your GitHub numeric user ID | GitHub OAuth | Identifies your account, and survives a username change |
| Your GitHub username and profile URL | GitHub OAuth | Attribution and display |
| Your display name | GitHub OAuth | Display |
| Your avatar image URL | GitHub OAuth | Display |
| The date your account was created | Generated on first sign-in | Account administration |
| Your plan, and your Stripe customer ID | Generated when you subscribe | Access control and billing |
| Which GitHub organisations you belong to | GitHub API, at sign-in | Org access control and per-seat billing |
| API tokens you create | Stored only as a hash, with a label, a device name, and the last-used and expiry dates. The token itself is shown to you once and never stored. | Authenticating API and client requests |
| A session record | Created when you sign in | Keeping you signed in |
We also keep ordinary server and error logs, which can include IP addresses, request paths, timestamps and user agents.
Why we are allowed to hold it#
- To perform our contract with you — running your account, access control, publishing, validation and billing.
- Our legitimate interests — keeping the service secure, preventing abuse, diagnosing faults and understanding load. We limit what we keep to what those purposes need.
- Legal obligation — retaining financial records for the period tax law requires.
We do not sell your data, we do not use it for advertising, and we do not do any automated decision-making that produces legal effects for you.
Who else processes it#
| Processor | What they handle | Where |
|---|---|---|
| GitHub | Authentication, and reading repositories and organisation membership you authorise | United States |
| Stripe | Payments, card details, billing email and invoices. We never see or store card details. | United States and Ireland |
| Amazon Web Services | Hosting, databases, storage and backups | United States (us-east-1) |
| Sentry | Error monitoring, where enabled. Reports can include request context. | United States |
Sending data outside the UK#
Our infrastructure runs in the United States, so your personal data is transferred there. Those transfers rely on the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or on the UK extension to the EU-US Data Privacy Framework where the recipient is certified under it.
Content you publish#
Private ontologies are never made public by us. If a paid plan lapses, private content is locked rather than published: it stays private, and only its owner can still reach it, to view or export. Ending a subscription cannot disclose your content.
How long we keep it#
- Account data, for as long as your account exists.
- Session records expire automatically. API tokens last until they expire or you revoke them.
- Logs and error reports, for up to 90 days.
- Billing records, for seven years, because UK tax law requires it. This is why closing your account does not erase your invoices.
- Backups, on a rolling schedule, so deleted data can persist in backups for a short period after deletion.
Your rights#
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you;
- correct it, if it is wrong;
- delete it, subject to records we must keep by law;
- restrict or object to how we use it;
- give it to you, or another provider, in a portable form.
Email support@ontoshire.com and we will respond within one month. Note that most of your profile data comes from GitHub: correcting it there and signing in again updates it here.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first, so we can put it right.
Cookies#
We set one cookie, ontoshire_sid, which keeps you signed in. It is strictly necessary for the service to work, so it does not require consent, and we do not use advertising or analytics cookies. Signing out clears it.
Changes#
We will update this page when our processing changes, and give notice of anything significant. See also our terms of service.
Last updated 2 September 2026.