Back to Oxyria

Privacy Policy

Last updated 16 September 2026

Oxyria helps landlords keep track of their properties, tenancies, rent, documents and maintenance. This page explains exactly what the app stores, why, who else is involved, and the choices you have.

Who is responsible for your data

Oxyria is operated by Tomaž Česnik, Cesta IV. Prekomorske 38b, 5270 Ajdovščina, Slovenija. Privacy questions and requests can be sent to the contact email below.

For any privacy question or request, contact hello@oxyria.app.

What Oxyria stores

Only what you put in, plus what the app needs to run your account:

  • Your account: email address, name if you give one, time zone, preferred currency and notification settings.
  • Your properties: address, type, purchase and value details you enter.
  • Your tenants: the name, contact details, tenancy dates and rent terms you record about the people renting from you.
  • Leases and rent: lease terms, rent schedules, payments you record and their status.
  • Expenses, reminders, maintenance jobs and equipment, including service and warranty dates.
  • Documents you upload — leases, invoices and photos — stored privately and reachable only through short-lived links issued to your account.
  • Activity history and alerts Oxyria created for you, and push notification subscriptions for the devices you allowed.
  • Billing status: your plan, its state and the identifiers your payment provider needs. Card details are never held by Oxyria.

Your records are private to your account. Another landlord using Oxyria cannot read, change or delete anything of yours, and uploaded files are kept in private storage that is only opened through short-lived links issued to you.

Information about your tenants

When you record a tenancy or import a lease, Oxyria stores the tenant details contained in it so it can show you rent due, tenancy dates and history. You decide what to enter. You remain responsible for telling your tenants that you keep their details in a property management tool.

Why Oxyria is allowed to hold it

To provide the service you signed up for and to take payment for it (performance of a contract), to keep the service secure and working, and to meet legal obligations such as keeping billing records. Where you turned on push alerts, that is because you chose to.

Services Oxyria relies on

These are the only outside services involved, and only for the purposes shown:

  • Lovable Cloud — Hosts the app, database, private file storage and sign-in. Your data is stored here.
  • Lovable AI Gateway (Google Gemini and OpenAI transcription models) — Reads a document or recording when you ask Oxyria to import a lease, scan an invoice, identify equipment or take a voice note. Content is sent for that request only and is not used to train models by Oxyria.
  • Stripe — Takes subscription payments and runs the billing portal. Stripe holds your payment method; Oxyria never sees full card details.
  • Firecrawl — Looks up public replacement prices for equipment when you ask Oxyria to research a price.
  • Email delivery from notify.oxyria.app — Sends account emails such as sign-up confirmation and password reset.
  • Meta Platforms (Meta Pixel) — Measures how our advertising performs and lets us show ads to people who visited Oxyria. It loads only if you choose "Accept all" on the cookie banner, and receives page views and a few non-identifying signals — never your account, property, tenant, document or payment data.
  • Web push (your browser's push service) — Delivers Guardian alerts to the devices where you turned notifications on. You can turn them off at any time.

Your data is never sold, and it is not shared for advertising.

AI features

When you import a lease, scan an invoice, identify equipment or record a voice note, the file or recording is sent to the AI service listed above so it can be read back to you as structured information. It is used to answer that one request. Oxyria does not use your documents to train AI models.

Cookies and advertising measurement

Essential cookies keep you signed in, protect your account and make billing work. They are always on, because the app cannot run without them.

Meta Platforms (Meta Pixel) is used for advertising measurement and remarketing. It is loaded only on the basis of your consent, given by choosing "accept all" on the cookie banner. Until then no request is made to Meta at all. What Meta receives:

  • Pages you view on the Oxyria website and the actions behind our four measurement events (a call to action, a plan choice, starting sign-up, starting checkout).
  • The plan tier, billing period and place on the page for those events — short labels only.
  • Device and browser information Meta collects itself, including cookie and browser identifiers and an IP address.

Nothing about your account, properties, tenants, leases, documents or payments is sent to Meta — no email address, name, user identifier, payment identifier or web address.

Use the "Cookie settings" button at the bottom of any public Oxyria page to reopen the cookie panel and switch to "Reject non-essential" at any time. The change takes effect immediately; it does not affect what was already collected.

Meta is based in the United States, so this data may be transferred outside the UK and EEA under Meta's own transfer safeguards.

Security

Account access is protected by sign-in. Database access rules keep each landlord's records separate, and uploaded documents are held in private storage. Oxyria uses short-lived links when it needs to show a private document. No internet service can be guaranteed completely secure, so suspected account misuse should be reported to the contact email above.

How long it is kept

Your records stay in your account for as long as your account exists, because a landlord needs the history. When you ask for deletion, your account and its records are removed; billing records are kept only where the law requires it. No fixed retention period is claimed here beyond that.

Your rights

  • Ask for a copy of the personal data Oxyria holds about you.
  • Ask for anything inaccurate to be corrected.
  • Ask for your account and its data to be deleted.
  • Ask Oxyria to restrict or stop certain processing, and object to it.
  • Ask for your data in a portable form.
  • Complain to your data protection authority — in the UK, the Information Commissioner's Office.

Requests are normally answered within one calendar month. If a request is complex or there are several requests, the law may allow more time; Oxyria will explain this when it applies. The quickest route is the Your data page in your account, which prepares the email for you.

Changes to this policy

If this policy changes, the date at the top changes with it and the current version is always the one published here.