Privacy policy

What personal data Ontoshire holds about you, why, who else sees it, and what you can ask us to do with it.

Who controls your data#

The data controller is CI CODERS LTD, a company registered in England and Wales under company number 12099279, registered office 3rd Floor 86-90 Paul Street, London, England, EC2A 4NE. Contact us about anything on this page at support@ontoshire.com.

What we collect#

We collect as little as the service can work with. When you sign in with GitHub, we receive and store:

DataWhere it comes fromWhy we hold it
Your GitHub numeric user IDGitHub OAuthIdentifies your account, and survives a username change
Your GitHub username and profile URLGitHub OAuthAttribution and display
Your display nameGitHub OAuthDisplay
Your avatar image URLGitHub OAuthDisplay
The date your account was createdGenerated on first sign-inAccount administration
Your plan, and your Stripe customer IDGenerated when you subscribeAccess control and billing
Which GitHub organisations you belong toGitHub API, at sign-inOrg access control and per-seat billing
API tokens you createStored only as a hash, with a label, a device name, and the last-used and expiry dates. The token itself is shown to you once and never stored.Authenticating API and client requests
A session recordCreated when you sign inKeeping you signed in
We do not store your email address. When you subscribe, Stripe collects and holds an email for billing and receipts, but it is not passed back to us or stored on our systems.

We also keep ordinary server and error logs, which can include IP addresses, request paths, timestamps and user agents.

Why we are allowed to hold it#

  • To perform our contract with you — running your account, access control, publishing, validation and billing.
  • Our legitimate interests — keeping the service secure, preventing abuse, diagnosing faults and understanding load. We limit what we keep to what those purposes need.
  • Legal obligation — retaining financial records for the period tax law requires.

We do not sell your data, we do not use it for advertising, and we do not do any automated decision-making that produces legal effects for you.

Who else processes it#

ProcessorWhat they handleWhere
GitHubAuthentication, and reading repositories and organisation membership you authoriseUnited States
StripePayments, card details, billing email and invoices. We never see or store card details.United States and Ireland
Amazon Web ServicesHosting, databases, storage and backupsUnited States (us-east-1)
SentryError monitoring, where enabled. Reports can include request context.United States

Sending data outside the UK#

Our infrastructure runs in the United States, so your personal data is transferred there. Those transfers rely on the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or on the UK extension to the EU-US Data Privacy Framework where the recipient is certified under it.

Content you publish#

Anything you publish as a public ontology is public: readable by anyone, served through the public SPARQL endpoint and API, and able to be cached, indexed or copied by third parties. Do not put personal data into a public ontology that you would not want published.

Private ontologies are never made public by us. If a paid plan lapses, private content is locked rather than published: it stays private, and only its owner can still reach it, to view or export. Ending a subscription cannot disclose your content.

How long we keep it#

  • Account data, for as long as your account exists.
  • Session records expire automatically. API tokens last until they expire or you revoke them.
  • Logs and error reports, for up to 90 days.
  • Billing records, for seven years, because UK tax law requires it. This is why closing your account does not erase your invoices.
  • Backups, on a rolling schedule, so deleted data can persist in backups for a short period after deletion.

Your rights#

Under UK data protection law you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct it, if it is wrong;
  • delete it, subject to records we must keep by law;
  • restrict or object to how we use it;
  • give it to you, or another provider, in a portable form.

Email support@ontoshire.com and we will respond within one month. Note that most of your profile data comes from GitHub: correcting it there and signing in again updates it here.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first, so we can put it right.

Cookies#

We set one cookie, ontoshire_sid, which keeps you signed in. It is strictly necessary for the service to work, so it does not require consent, and we do not use advertising or analytics cookies. Signing out clears it.

Changes#

We will update this page when our processing changes, and give notice of anything significant. See also our terms of service.


Last updated 2 September 2026.