Ezra ← Back to the site
Legal

Privacy policy

Last updated 5 August 2026

The short version: Ezra reads only the systems your workspace connects, only through the permissions each person already has, and never more than the person asking could see themselves. Nothing your workspace sends is used to train a model — ours or a provider’s. Nothing is sent, posted or written anywhere without a human clicking approve.

Who we are

Ezra is operated by Strata Systems LLC, a New York limited liability company. Process may be served on our registered agent at c/o Northwest Registered Agent LLC, 418 Broadway, Ste N, Albany, NY 12207. For anything in this policy, write to hello@ontara.io.

What we collect

What we do not collect

How we use it

To answer questions, do the work asked of Ezra in your workspace, keep the audit log, meter usage for billing, and diagnose faults. That is the complete list. We do not sell data, we do not share it for advertising, and we do not build profiles from it.

Training

Your workspace’s content is not used to train or fine-tune any model, ours or a provider’s. Model providers are engaged under terms that exclude API content from training.

Who we share it with

Ezra runs on a small number of sub-processors, each doing one job: Slack, the surface he works in; Google, for Drive, Gmail, Calendar and Sheets when you connect them; Pipedream and Composio, the two layers through which other applications are authorised and read; Nebius Token Factory and OpenRouter for model inference; Tavily for web search when a question needs a public source; Inngest for scheduling standing orders; Stripe for payment and usage metering; and Fly.io for hosting and compute. Workspace records are held in a managed PostgreSQL database.

Content sent to an inference provider serves that one request. It is not retained for training, by us or by them. If your security team needs this list in a form they can review or subscribe to, write to us and we will send it.

Where it lives and how long

Data is encrypted in transit and at rest. When a source is disconnected, the data Ezra held from that source is deleted. When a workspace uninstalls Ezra, workspace content is deleted within 30 days; billing records are kept as long as the law requires.

Your rights

If you are in the UK, EU or another region with equivalent law, you can ask us to access, correct, export or delete your personal data, and object to or restrict processing. Workspace admins can export the audit log at any time. Write to hello@ontara.io and we will respond within 30 days.

Security

OAuth only, no stored passwords. Encryption in transit and at rest. An audit log of what Ezra read, when, and for whom. SOC 2 Type II is in progress and not yet complete — we say so on the site rather than implying otherwise.

Children

Ezra is a workplace product and is not directed at anyone under 16.

Changes

If this policy changes materially, workspace admins get notice in Slack before the change takes effect.