Research pilot applications are open. Apply for pilot →
Privacy at Ounias

Privacy designed around research data.

We understand that research data can be highly sensitive. Ounias is therefore designed to keep data use limited, predictable, and under the user's control.

Privacy in plain English

Your data is yours

You retain ownership and control of the data you upload to Ounias.

You can download your datasets and analytical outputs at any time, or delete them when you no longer want them stored in Ounias.

We use your data only for your work

Ounias processes your data to perform the analyses you request.

We do not use your datasets to train general Ounias models, models for other customers, or for unrelated internal research.

We don't sell, advertise with, or track your data

Ounias does not sell your data, share it with advertisers, or use it for behavioral advertising.

We also do not use advertising or behavioral-tracking cookies or third-party tracking tools.

Your raw data stays in Ounias

Raw datasets are not sent from Ounias to connected third-party services.

If you choose to export work to another service, only the analytical outputs, models, summaries, or other results you select are sent.

You control deletion and publication

You can delete your data and associated analyses whenever you choose.

If a subscription ends, Ounias keeps the user's work for up to 90 days before deletion so that returning users can reactivate without unexpectedly losing their work.

Your projects and analyses are private unless you deliberately publish something. Snapshots are an explicit publishing action and do not expose the underlying raw dataset.

Legal

Full Privacy Policy

Effective date
To be filled in on launch
Operator
Ounias Ltd., Tel Aviv, Israel

Ounias (“Ounias”, “we”, “us”, or “our”) provides a research data analysis platform for generating, evaluating, comparing, explaining, and preserving analytical outputs derived from structured datasets.

This Privacy Policy explains how Ounias collects, uses, stores, shares, and protects personal information when you use the Ounias website, application, and related services (the “Service”).

Legal

Full Privacy Policy

Effective date
To be filled in on launch
Operator
Ounias Ltd., Tel Aviv, Israel

Ounias (“Ounias”, “we”, “us”, or “our”) provides a research data analysis platform for generating, evaluating, comparing, explaining, and preserving analytical outputs derived from structured datasets.

This Privacy Policy explains how Ounias collects, uses, stores, shares, and protects personal information when you use the Ounias website, application, and related services (the “Service”).

1. Our Role in Processing Information

Ounias may process information in different capacities depending on the context.

For information that Ounias collects for its own purposes—such as account information, service usage information, security records, support communications, and subscription information—Ounias generally determines how and why that information is processed.

When a user or organization uploads or imports a research dataset into Ounias, that user or organization generally determines the purpose for which the dataset is being processed. Ounias processes that data to provide the analyses and functionality requested by the user, subject to applicable law and any applicable agreement with the customer.

For institutional customers, additional data-processing terms may apply.

2. Information We Collect

2.1 Account Information

When you create or use an Ounias account, we may collect:

  • Email address
  • OAuth provider identifier
  • Basic profile information provided by the authentication provider
  • Account and authentication metadata

Ounias uses OAuth-based authentication and does not store user passwords.

2.2 Customer Data

Users may upload or import structured datasets into Ounias for analysis (“Customer Data”).

Customer Data remains under the control of the user or organization that provides it. Ounias does not claim ownership of Customer Data.

Ounias systems process Customer Data as necessary to perform functionality requested by the user, such as preprocessing, profiling, clustering, supervised learning, dimensionality reduction, evaluation, explainability, stability analysis, longitudinal analysis, comparison, and reporting.

Authorized personnel may have technical access to Customer Data where reasonably necessary to operate, maintain, secure, troubleshoot, or support the Service, investigate misuse or security incidents, or comply with applicable law.

2.3 Analytical Outputs

Ounias generates analytical information and artifacts from Customer Data as part of the Service.

Depending on the analyses performed, these may include:

  • Dataset and compatibility profiles
  • Feature mappings and preprocessing information
  • Labels and clustering outputs
  • Embeddings and projection coordinates
  • Trained or fitted models
  • Metrics and evaluation results
  • Feature-importance outputs
  • Rules and analytical explanations
  • Stability results
  • Longitudinal and trajectory outputs
  • Comparisons
  • Reports
  • Run configurations, lineage, and related analytical metadata

For purposes of this Privacy Policy, these customer-specific analytical outputs are treated as part of Customer Data unless otherwise stated.

2.4 Connected Services

Ounias may allow users to connect third-party data or workflow services, including services such as Google Drive, Google Sheets, OneDrive, MLflow, Vertex AI, Notion, or other supported integrations where available.

When a user selects a connected service as a data source, Ounias may retrieve Customer Data or other resources specifically selected or authorized by the user for import into Ounias.

Ounias does not transmit raw Customer Data to connected third-party services.

Where Ounias supports exporting information to a connected service, transmitted information is limited to user-selected derived analytical outputs, artifacts, summaries, models, visualizations, metadata, or similar results generated through the Service.

Ounias may also receive or transmit account identifiers, authorization information, file or resource metadata, and other technical information necessary to provide the requested integration.

Ounias uses access to connected services only to provide functionality initiated or configured by the user.

Third-party services are also governed by their own terms and privacy practices.

2.5 Technical and Usage Information

Ounias may collect technical and operational information necessary to operate, secure, maintain, and improve the Service, including:

  • IP address
  • Browser and device information
  • Session and authentication identifiers
  • Internal user, project, dataset, run, and job identifiers
  • File size and file type
  • Dataset dimensions such as row and column counts
  • Upload and processing duration
  • Compute usage
  • Service events
  • Error and diagnostic information
  • Security-related events

Operational logs are designed not to contain raw row-level dataset values.

Technical metadata may, in limited circumstances, include schema information such as feature or column names. Users handling particularly sensitive datasets may choose to standardize or replace sensitive feature names before uploading data.

Ounias may use anonymized or aggregated operational information to understand system performance, reliability, resource usage, errors, and compute requirements.

2.6 Payment and Subscription Information

Purchases and subscriptions may be processed by Paddle, which acts as Merchant of Record for transactions made through its services.

Paddle collects and processes payment and billing information under its own privacy practices.

Ounias does not receive or store full payment card details.

Ounias may receive information necessary to provide and administer purchased services, including transaction identifiers, subscription information, customer information, payment status, and refund information.

2.7 Communications

If you contact Ounias for support, pilot participation, product questions, or other purposes, we may collect the information you provide in those communications.

3. How We Use Information

Ounias uses information to:

  • Provide and operate the Service
  • Authenticate users
  • Process Customer Data according to user instructions
  • Generate and preserve requested analytical outputs
  • Maintain projects, datasets, runs, and analytical lineage
  • Provide connected-service functionality
  • Monitor reliability and diagnose errors
  • Protect the Service against abuse and security threats
  • Estimate and account for compute and storage usage
  • Manage subscriptions and purchases
  • Provide customer support
  • Communicate important service information
  • Comply with applicable legal obligations

Ounias does not sell Customer Data or personal information to advertisers.

Ounias does not share Customer Data with advertisers or use Customer Data for behavioral advertising.

4. Model Training and Secondary Use

Ounias may fit or train analytical models on Customer Data when requested by the user as part of an Ounias analysis or evaluation workflow.

Models and model artifacts generated from Customer Data are used to provide the requested Service and are subject to the applicable Customer Data retention and deletion controls.

Ounias does not use Customer Data to train general-purpose Ounias models, models for unrelated customers, or models for advertising purposes.

Ounias does not use raw Customer Data for unrelated internal research or unrelated secondary analytical purposes.

Ounias may use anonymized or aggregated technical and operational information to improve performance, reliability, compute estimation, and Service functionality.

5. Personal, Sensitive, and Research Data

Research datasets may contain personal, health-related, or otherwise sensitive information.

Ounias encourages users to minimize the amount and precision of identifying information included in datasets where that information is not necessary for the intended analysis.

Where appropriate, users may remove, generalize, or replace information that is more identifying than necessary. For example, a dataset may use age instead of an exact date or year of birth where the more precise information is not analytically necessary.

Users may also replace direct identifiers before upload. Ounias can generate internal identifiers where an identifier is required but not supplied.

These measures can reduce identifying information but do not necessarily make a dataset anonymous. Other variables or combinations of variables may still permit an individual to be identified.

Ounias does not independently inspect Customer Data for the purpose of determining whether a dataset is anonymous, de-identified, pseudonymized, sensitive, legally protected, or lawfully obtained.

Users and organizations are responsible for determining:

  • Whether they are authorized to upload and process the data
  • Whether direct identifiers should be removed or replaced
  • Whether information should be generalized or otherwise minimized
  • Whether consent or another legal basis is required
  • Whether additional contractual, ethical, institutional, or regulatory requirements apply
  • Whether the Service is appropriate for the intended use of the data

Ounias processes Customer Data for the functionality requested by the user rather than for the purpose of determining the meaning, accuracy, provenance, or legal status of individual data values.

6. How We Share Information

Ounias shares information only where necessary to provide, secure, administer, or legally operate the Service.

Google Cloud Platform

Ounias uses Google Cloud Platform for application hosting, compute, database services, and storage.

Google Cloud processes Customer Data in accordance with its applicable data-processing, security, and privacy terms.

Learn more about Google Cloud data processing and security.

Authentication Providers

OAuth providers process information necessary to authenticate users and connect services authorized by the user.

Paddle

Paddle processes purchases, subscriptions, billing, taxes, fraud prevention, and related transaction functions as Merchant of Record.

Connected Services

Connected services may provide Customer Data, models, files, or other resources specifically selected by the user for import into Ounias.

Ounias does not transmit raw Customer Data from Ounias to connected third-party services.

Where supported, users may choose to transmit derived analytical outputs, artifacts, summaries, models, visualizations, metadata, or similar results generated through Ounias.

Legal Requirements

Ounias may disclose information where reasonably necessary to comply with applicable law, regulation, legal process, or a valid governmental or judicial request, or to protect the security, rights, or integrity of Ounias, its users, or others.

Ounias does not sell Customer Data or personal information for advertising purposes.

7. Snapshots and Public Information

Ounias Snapshots allow users to publish a preserved analytical representation of selected work.

Snapshots may contain analytical outputs, visualizations, summaries, research context, and publication metadata.

The underlying raw dataset is not intentionally made available through a Snapshot.

Current public Snapshots are accessible to anyone who obtains their unique Snapshot link. Users should therefore treat information included in a published Snapshot as public information.

Ounias does not display identifying account information in a Snapshot by default.

Users may choose to publish additional attribution or organizational information, such as:

  • Creator or contributor name
  • Organization or institution name
  • Affiliation
  • Organization or project website
  • Publication or citation information
  • Other metadata deliberately selected for publication

Information intentionally published through a Snapshot may be viewed, copied, referenced, or redistributed by third parties outside Ounias's control.

Ounias may introduce additional Snapshot access controls in the future, such as password-protected or restricted-access Snapshots.

8. Data Retention and Deletion

Ounias retains different categories of information for different periods depending on their purpose.

8.1 Active Customer Data

Customer Data and associated analytical outputs are retained while needed to provide the Service unless the user deletes them or another retention rule applies.

8.2 User-Initiated Deletion

When a user deletes Customer Data or requests deletion, Ounias begins removing the associated data from active systems, including stored dataset files and associated analytical artifacts.

Associated database and operational records may be deleted, scrubbed of user-identifying information, or retained in anonymized form where appropriate.

User-initiated deletion is separate from the post-subscription retention period described below.

8.3 Retention After Subscription Ends

After a subscription ends, Ounias may retain Customer Data and associated analytical outputs for up to 90 days.

This grace period allows users to reactivate their subscription and resume previous work without losing their datasets and analyses.

If the subscription is not reactivated, Customer Data and associated analytical artifacts are deleted or anonymized in accordance with Ounias's deletion procedures, unless a longer period is required by law or an applicable agreement.

8.4 Operational and Security Records

Operational, diagnostic, compute, and security records that remain linked or reasonably linkable to a user may be retained for up to 24 months, unless a longer period is required by applicable law or reasonably necessary for an active security, fraud, legal, or dispute matter.

After the applicable retention period, identifying or linkable information is deleted or anonymized.

Anonymized or aggregated statistics that can no longer reasonably be associated with an identifiable person may be retained for longer periods, including for:

  • System reliability
  • Error analysis
  • Compute estimation
  • Capacity planning
  • Service performance
  • Product and infrastructure planning

8.5 Payment Records

Transaction and accounting information may be retained for periods required by applicable tax, accounting, fraud-prevention, and financial laws.

Payment information independently retained by Paddle is governed by Paddle's own retention practices.

8.6 Backups, Soft-Delete, and Recovery Copies

Ounias and its cloud infrastructure providers may maintain temporary backup, soft-delete, or recovery copies of information for resilience, security, and disaster-recovery purposes.

When Customer Data is deleted from active Ounias systems, residual copies may remain temporarily in protected backup or recovery systems until they expire, are overwritten, or are deleted according to the applicable retention cycle.

Such recovery copies are not used for normal Service operations, analysis, model training, or other secondary purposes.

Ounias configures and manages recovery mechanisms with the aim of limiting retention while maintaining reasonable protection against accidental data loss.

9. International Data Processing

Ounias uses Google Cloud Platform to host and store primary Customer Data and analytical artifacts.

Google Cloud provides data-location controls and regional data-residency commitments for applicable services in accordance with its terms and data-processing policies.

Other categories of information, including authentication, payment, support, or connected-service information, may be processed by service providers in other countries.

Depending on the user's location and the services involved, use of Ounias may therefore involve international transfers of personal information.

Where personal information is transferred internationally, Ounias and its service providers use applicable legal, contractual, and technical safeguards as required by law.

10. Security

Ounias uses technical and organizational measures intended to protect information against unauthorized access, disclosure, alteration, loss, or misuse.

These measures include, as applicable:

  • HTTPS/TLS encryption in transit
  • Encryption at rest through cloud infrastructure
  • OAuth-based authentication
  • Access-controlled cloud storage
  • Application authorization controls
  • Separation of user and project resources
  • Operational and security logging
  • Restricted administrative access
  • Avoidance of raw row-level dataset values in operational logs

Authorized personnel may nevertheless have technical access where reasonably necessary to maintain, secure, troubleshoot, or support the Service, investigate misuse or security incidents, or comply with applicable law.

No system can guarantee absolute security.

12. Your Privacy Rights

Depending on your location and applicable law, you may have rights concerning your personal information, including rights to:

  • Request information about how your personal information is processed
  • Access personal information held about you
  • Correct inaccurate personal information
  • Request deletion of certain personal information
  • Request restriction of certain processing
  • Object to certain processing
  • Request portability of certain information
  • Withdraw consent where processing is based on consent

Requests concerning an Ounias account, Ounias communications, or other information Ounias processes for its own purposes may be submitted to support@ounias.com.

Ounias may need to verify your identity before acting on a request.

Personal Information Contained in Customer Data

If information about you appears inside a dataset uploaded by an Ounias customer, that customer or organization is ordinarily responsible for determining the accuracy, lawfulness, correction, deletion, or permitted use of that information.

If Ounias receives such a request directly, Ounias may:

  • Refer the requester to the relevant customer or organization
  • Assist the customer in responding to the request
  • Take action directly where required by applicable law or valid legal process

Ounias does not independently determine whether individual research data values are scientifically or factually correct.

13. Cookies

Ounias does not use advertising or behavioral-tracking cookies.

The Ounias application may use cookies or similar technologies necessary for:

  • Authentication
  • Login and session state
  • Security
  • Service functionality

Ounias does not currently use cookies for third-party behavioral advertising or cross-site profiling.

Third-party services involved in authentication or other user-initiated integrations may use their own cookies or similar technologies under their respective privacy policies.

14. Children's Privacy

Ounias is not directed to children.

Individuals under the age of 18 may not independently create or use an Ounias account unless their use is authorized through an appropriate institutional or other arrangement permitted by applicable law.

If you believe Ounias has collected personal information from a child contrary to applicable law, contact us at support@ounias.com.

15. Changes to This Privacy Policy

Ounias may update this Privacy Policy as the Service, its infrastructure, or applicable legal requirements evolve.

When changes are material, Ounias may provide notice through the Service, by email, or through another appropriate method.

The effective date at the top of this Policy indicates when the current version became effective.

16. Contact

Questions, privacy requests, or concerns about this Privacy Policy or Ounias's handling of personal information may be sent to:

Ounias Ltd.
Tel Aviv, Israel
support@ounias.com