Last updated: June 10, 2026
Welcome to Ozorys. As a sovereign personal-finance application, our philosophy is simple: Your data belongs to you. We can neither read it, nor sell it, nor analyse it.
Ozorys runs on an "Offline-First" model. All your transactions, amounts, categories and receipts are encrypted locally on your device using the AES-256-GCM algorithm, the industry's most battle-tested encryption standard. The decryption key (your PIN code) is never transmitted to our servers.
For the strict purpose of operating the application, we process the absolute minimum of information:
The legal basis justifying the encrypted synchronisation is the performance of a contract (provision of the synchronised vault service). The shared vault is identified by an anonymous key; no email address is transmitted to or processed by Ozorys. In accordance with the GDPR, you retain full control over your information:
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint directly with the CNIL, the French data protection authority.
For Tribu Mode, our encrypted data is stored via Google Firebase (ISO 27001 certified and GDPR compliant), hosted in secured data centres. No unencrypted data is accessible to Google.
For any question regarding the processing of your digital-sovereignty data, you can reach our dedicated privacy contact point at: contact@ozorys.com.
The data controller for this website is the publisher identified in the legal notice. The site is hosted by OVH SAS (Roubaix, France); like any host, OVH keeps technical connection logs (IP address, timestamp) for service security.
When you write to us, we process only: the chosen subject, the optional plan, your message and, if you provide it, your e-mail address. Purpose: reading your message and, where relevant, replying (legitimate interest and pre-contractual steps, Art. 6(1)(b) and 6(1)(f) GDPR). The message goes straight to our OVH-hosted mailbox; nothing is stored in any server database. It is kept for the time needed to handle your request. An anti-abuse counter keeps, for at most 24 hours, a truncated, salted fingerprint of the IP address with a timestamp — enough to count, not to identify; it purges itself.
This site sets no cookies and uses no trackers. Your preferences (language, Junior Academy theme, module progress) are kept in your browser's local storage, on your device, and are never sent to us. Fonts are self-hosted: no request ever leaves for a third party.
You have the rights of access, rectification, erasure, objection and restriction (Art. 15–21 GDPR): write to the address above. You may lodge a complaint with your supervisory authority, e.g. the CNIL (cnil.fr).