privacy policy
Last updated: August 28, 2026
This Privacy Policy explains how oov ("we," "us," "our") collects, uses, stores, and shares information when you use the oov mobile app (the "App"). oov is operated by an individual doing business as oov, based in India.
If you have questions about this policy or want to exercise any of the rights described below, contact us at hello@oovme.com.
1. Scope
This policy applies to the oov iOS app. It does not apply to third-party services we rely on (like Apple's App Store), which have their own privacy policies.
2. Information We Collect
| Data | Why we collect it |
|---|---|
| Email address | Used to sign you in via a magic-link email (through Firebase Authentication), and to send you notifications about your account — a connection request, someone accepting your request, or a reminder that a request or your pro access is about to expire. We never email you about anyone’s emotional state, and we never send marketing email. Every notification email has a one-click unsubscribe link, and you can turn each kind off in Settings → notifications. Stored separately from your public profile and never shown to other users. |
| Handle (@handle) and display name | Shown to your connections so they can identify you. Your handle is also how others find and add you — there is no name-based search. |
| Current emotional state (the emotion word, colour, 2D coordinates, and timestamps) | The core function of the App — this is what gets shared with your mutual connections for 24 hours. |
| Historical log of every emotional state you've ever set | Kept as an internal record. This log is currently write-only — it is not shown back to you or anyone else anywhere in the App, and there is no feature built on it today. We're keeping this section transparent about its existence specifically because it isn't visible in the product. |
| Your connections (who you're connected to, pending requests, mute settings) | Needed to run the mutual-connection feature itself. |
| Nudge events (who nudged whom, and when) | Needed to enforce the once-per-24-hours limit per connection and to deliver the notification. |
| Push notification device token | Needed to deliver push notifications to your device via Firebase Cloud Messaging — nudges, a connection request or acceptance, and a peer sharing a new state. |
| Account metadata (account creation date, connection-limit tier, trial status) | Needed to enforce your connection limit. oov is currently free for everyone (see Terms of Service §6) — this field exists for a future paid-tier feature that is not yet available. |
| Your email address, if you join the mailing list on our website | Collected only if you type it into the signup form at oovme.com — this is separate from your app account, and joining the list does not create one. Used solely to email you when something you asked to hear about is ready, such as the Android app. Deleting your oov account does not remove you from this list, because the two are not linked; email hello@oovme.com to be taken off it. |
| Feedback you choose to submit (a reason for deleting your account, or beta-testing feedback) | Entirely optional — only collected if you submit it. Kept in a separate record tied to your account ID, used only to help us understand and improve the App. See §7 for how this interacts with account deletion. |
| Crash and error diagnostic data (via Firebase Crashlytics) | Collected automatically when the App crashes or hits an unexpected error, in release builds only (never during our own development/debug builds), to help us find and fix bugs. Not linked to your account, email, or handle. |
We do not collect payment card information, and oov does not currently offer any paid subscriptions — the entire App is free to use. If we introduce paid tiers in the future, payment will be handled entirely through Apple's App Store; oov's own systems will never see or store your payment details.
We do not use advertising or analytics SDKs, and we do not have any social login, contacts-import, or location-tracking features in the App today.
3. How We Use Your Information
We use the information above only to:
- Operate the core features of the App (authentication, sharing your state with mutual connections, nudges, connection management).
- Enforce connection limits and rate limits (like the 24-hour nudge cooldown).
- Maintain the security of the App (e.g., Firestore access rules that restrict who can read what).
- Communicate with you about your account (e.g., sign-in emails, push notifications, and the account notification emails described in §2).
We do not sell your personal information, and we do not use your emotional-state data for advertising, profiling, or any purpose beyond operating the App as described above.
4. Who Can See Your Data
- Your current emotional state is visible only to you and your confirmed mutual connections — never one-way followers, never the public. It is enforced at the database level (Firestore security rules), not just hidden in the app's interface.
- Your email address is never visible to other users — only to you and to us (via Firebase Authentication).
- Your handle and display name are visible to any signed-in user, so that an exact-handle lookup can work when someone tries to add you.
- Your historical state log is not visible to anyone, including you — it is a write-only record.
5. Third Parties We Share Data With
All of oov's backend infrastructure runs on Google Firebase, under a single Firebase project. We use:
- Firebase Authentication — for email magic-link sign-in.
- Cloud Firestore — as the database for all app data described in §2.
- Firebase Cloud Functions — for server-side logic, such as expiring mood states after 24 hours and enforcing the nudge cooldown.
- Firebase Cloud Messaging (FCM) — to deliver nudge push notifications.
- Firebase Crashlytics — to detect and diagnose app crashes and errors, in release builds only.
One service sits outside Firebase:
- Resend — to deliver the account notification emails described in §2. Your email address and the text of those notifications pass through Resend in order to be sent. Nothing about your emotional states is ever included.
oov does not currently offer any paid subscriptions, so no payment processor is involved today. If we introduce paid tiers in the future, we'll rely on Apple's App Store to process those payments — Apple would act as the merchant of record and handle your payment information under its own privacy policy.
We do not use any other third-party analytics, advertising, or tracking services.
6. International Data Transfers
Because we use Google Firebase and Apple's infrastructure, your data may be stored or processed on servers located outside India, including in the United States or other countries where Google or Apple operate data centers. By using the App, you consent to this transfer and processing, which is protected by Google's and Apple's own security and compliance safeguards as data processors.
7. Data Retention and Deletion
Automatic expiry: Your emotional state becomes invisible to your connections 24 hours after you set it. Connection requests that aren't accepted expire automatically after 30 days.
Account deletion: You can delete your account at any time from within the App. Deletion is immediate and automatic: as soon as you confirm it, we erase your profile, email record, current state, historical state log, push notification tokens, and nudge records, remove both sides of any connections you had, and delete your underlying Firebase Authentication record. You don't need to email us or wait for us to process anything manually.
One exception: if you submitted a reason when deleting your account, or ever sent us beta-testing feedback, that feedback is kept in a separate record (see §2) and is not automatically erased along with the rest of your account — we keep it, tied to your now-deleted account ID rather than to you personally, to help us understand why people leave and improve the App. If you'd like that feedback removed too, email us at hello@oovme.com and we will process that request within 30 days. The same is true of the website mailing list (see §2): it is not linked to your account, so account deletion does not remove you from it — email us and we will.
8. Security
We restrict access to your data using Firestore security rules enforced at the database level, not just in the app's interface — for example, your live emotional state can only be read by you and your confirmed mutual connections, and nudges can only be created through server-side functions that verify the cooldown and mutual-connection requirement. Your historical state log, while write-only and never displayed, is stored as ordinary Firestore data protected by Firestore's standard security rules and Google's infrastructure-level encryption at rest — it is not additionally encrypted with user-specific keys.
No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have rights to access, correct, or request deletion of your personal data, or to object to or restrict certain processing. You can exercise these by emailing hello@oovme.com. We will respond within a reasonable time, and in any event within the timeframes required by applicable law.
If you are located in India, you have rights as a Data Principal under the Digital Personal Data Protection Act, 2023, including the right to access a summary of your personal data and processing activities, and to request correction, updating, or erasure of your personal data. Our contact for grievances under this section is:
Grievance Officer: MotuMonkeyLabs
Email: hello@oovme.com
10. Age Requirement
oov is intended for users 16 years of age or older. We do not knowingly collect personal information from anyone under 16. The App does not currently include a technical age-verification step at sign-up — this is a known limitation we are addressing; account eligibility currently relies on the representation you make when creating an account (see Terms of Service §1). If you believe a user under 16 has created an account, please contact us at hello@oovme.com so we can investigate and remove it if appropriate.
11. Not a Medical or Emergency Service
oov is not a mental health, medical, or crisis-response service, and no one monitors the emotional states shared in the App for signs of distress or emergency. The crisis-line resources listed in the App's Settings (including the U.S. 988 Suicide & Crisis Lifeline and an international directory) are provided as informational pointers only. If you are in crisis, please contact those services or your local emergency number directly — do not rely on oov.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will make reasonable efforts to notify you in-app or via email before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
hello@oovme.com