privacy policy
Last updated: July 25, 2026
This Privacy Policy explains how Oov ("we," "us," "our") collects, uses, stores, and shares information when you use the Oov mobile app (the "App"). Oov is operated by an individual doing business as Oov, based in India.
If you have questions about this policy or want to exercise any of the rights described below, contact us at motumonkeylabs@gmail.com.
1. Scope
This policy applies to the Oov iOS app. It does not apply to third-party services we rely on (like Apple's App Store), which have their own privacy policies.
2. Information We Collect
| Data | Why we collect it |
|---|---|
| Email address | Used solely to sign you in via a magic-link email (through Firebase Authentication). Stored separately from your public profile and never shown to other users. |
| Handle (@handle) and display name | Shown to your connections so they can identify you. Your handle is also how others find and add you — there is no name-based search. |
| Current emotional state (the emotion word, colour, 2D coordinates, and timestamps) | The core function of the App — this is what gets shared with your mutual connections for 24 hours. |
| Historical log of every emotional state you've ever set | Kept as an internal record. This log is currently write-only — it is not shown back to you or anyone else anywhere in the App, and there is no feature built on it today. We're keeping this section transparent about its existence specifically because it isn't visible in the product. |
| Your connections (who you're connected to, pending requests, mute settings) | Needed to run the mutual-connection feature itself. |
| Nudge events (who nudged whom, and when) | Needed to enforce the once-per-24-hours limit per connection and to deliver the notification. |
| Push notification device token | Needed to deliver nudge notifications to your device via Firebase Cloud Messaging. |
| Account metadata (account creation date, subscription tier, trial status) | Needed to enforce free/paid tier connection limits. |
We do not collect payment card information. Subscriptions are billed entirely through Apple's App Store; Oov's own systems never see or store your payment details.
We do not use advertising or analytics SDKs, and we do not have any social login, contacts-import, or location-tracking features in the App today.
3. How We Use Your Information
We use the information above only to:
- Operate the core features of the App (authentication, sharing your state with mutual connections, nudges, connection management).
- Enforce subscription tier limits and rate limits (like the 24-hour nudge cooldown).
- Maintain the security of the App (e.g., Firestore access rules that restrict who can read what).
- Communicate with you about your account (e.g., sign-in emails, nudge notifications).
We do not sell your personal information, and we do not use your emotional-state data for advertising, profiling, or any purpose beyond operating the App as described above.
4. Who Can See Your Data
- Your current emotional state is visible only to you and your confirmed mutual connections — never one-way followers, never the public. It is enforced at the database level (Firestore security rules), not just hidden in the app's interface.
- Your email address is never visible to other users — only to you and to us (via Firebase Authentication).
- Your handle, display name, and subscription tier are visible to any signed-in user, so that an exact-handle lookup can work when someone tries to add you.
- Your historical state log is not visible to anyone, including you — it is a write-only record.
5. Third Parties We Share Data With
All of Oov's backend infrastructure runs on Google Firebase, under a single Firebase project. We use:
- Firebase Authentication — for email magic-link sign-in.
- Cloud Firestore — as the database for all app data described in §2.
- Firebase Cloud Functions — for server-side logic, such as expiring mood states after 24 hours and enforcing the nudge cooldown.
- Firebase Cloud Messaging (FCM) — to deliver nudge push notifications.
We also rely on Apple's App Store to process subscription payments; Apple acts as the merchant of record for paid subscriptions and handles your payment information under its own privacy policy.
We do not use any other third-party analytics, advertising, or tracking services.
6. International Data Transfers
Because we use Google Firebase and Apple's infrastructure, your data may be stored or processed on servers located outside India, including in the United States or other countries where Google or Apple operate data centers. By using the App, you consent to this transfer and processing, which is protected by Google's and Apple's own security and compliance safeguards as data processors.
7. Data Retention and Deletion
Automatic expiry: Your emotional state becomes invisible to your connections 24 hours after you set it. Connection requests that aren't accepted expire automatically after 30 days.
Account deletion: You can request deletion of your account from within the App or by emailing us at motumonkeylabs@gmail.com. Deleting your account removes your public profile and your connections with others.
We are actively working to extend account deletion to fully and automatically erase all associated data, including your email record, current state, historical state log, push notification tokens, and nudge records. Until that work is complete, some of this data may persist for a limited period after your account is deleted. If you delete your account and want confirmation that all associated data has been removed, email us and we will process that request manually within 30 days. We are not able to guarantee instantaneous, fully automated erasure of every data category at this time, and we'd rather tell you that plainly than promise something the app doesn't yet do.
8. Security
We restrict access to your data using Firestore security rules enforced at the database level, not just in the app's interface — for example, your live emotional state can only be read by you and your confirmed mutual connections, and nudges can only be created through server-side functions that verify the cooldown and mutual-connection requirement. Your historical state log, while write-only and never displayed, is stored as ordinary Firestore data protected by Firestore's standard security rules and Google's infrastructure-level encryption at rest — it is not additionally encrypted with user-specific keys.
No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have rights to access, correct, or request deletion of your personal data, or to object to or restrict certain processing. You can exercise these by emailing motumonkeylabs@gmail.com. We will respond within a reasonable time, and in any event within the timeframes required by applicable law.
If you are located in India, you have rights as a Data Principal under the Digital Personal Data Protection Act, 2023, including the right to access a summary of your personal data and processing activities, and to request correction, updating, or erasure of your personal data. Our contact for grievances under this section is:
Grievance Officer: MotuMonkeyLabs
Email: motumonkeylabs@gmail.com
10. Age Requirement
Oov is intended for users 17 years of age or older. We do not knowingly collect personal information from anyone under 17. The App does not currently include a technical age-verification step at sign-up — this is a known limitation we are addressing; account eligibility currently relies on the representation you make when creating an account (see Terms of Service §1). If you believe a user under 17 has created an account, please contact us at motumonkeylabs@gmail.com so we can investigate and remove it if appropriate.
11. Not a Medical or Emergency Service
Oov is not a mental health, medical, or crisis-response service, and no one monitors the emotional states shared in the App for signs of distress or emergency. The crisis-line resources listed in the App's Settings (including the U.S. 988 Suicide & Crisis Lifeline and an international directory) are provided as informational pointers only. If you are in crisis, please contact those services or your local emergency number directly — do not rely on Oov.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will make reasonable efforts to notify you in-app or via email before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
motumonkeylabs@gmail.com