Your data

Privacy policy

What Online, Unfortunately processes, why it is needed, where it appears, and how members can control or delete it.

Effective August 12, 2026

01

Information we process

Product-event payloads do not contain meme text, media, message bodies, report details, email addresses, profile biographies, or notification contents.

Items sent to OU through the iOS share sheet are first copied into the app’s private shared container on that device. They remain there until the app imports them, the member discards them, or iOS removes the app data. They are not uploaded merely because the share sheet opened.

Images and videos sent to the OU bot pass through Telegram’s Bot API before OU copies the canonical media into private Supabase Storage. Telegram file identifiers may be cached only to resend the same media through Telegram. OU does not treat Telegram as the canonical media store.

OU keeps Telegram update identifiers for up to 30 days to reject duplicate delivery. Operational logs exclude raw Telegram updates and message text. Notification previews are created when a notification is delivered and are not stored in the outbox.

  • Account and profile data: email address, authentication records, account identifier, linked Telegram identity, Telegram numeric user ID and private bot chat ID, birth date, name, biography, avatar, onboarding state, and discovery state. Other members see only age, not birth date, after profile reveal.
  • Notification data: event and channel preferences, an Apple Push Notification device token when APNs is enabled, Telegram locale and notification state when Telegram is connected, and operational delivery state used to retry or suppress a notification.
  • Content: optional captions, images, videos up to 60 seconds and their audio tracks, thumbnails, private storage paths, media metadata, and fingerprints used to recognize exact or likely duplicate media.
  • Discovery activity: feed deliveries, visible impressions, passes, private Keeps, recurrence, private pairwise presence marks, and Bayesian evidence used for ordering and reveal.
  • Relationship activity: revealed relationships, privacy-suppressed Common ground, blind Say hi choices, relationship endings, blocks, text or meme chat messages, replies, read state, and delivery state.
  • Safety data: report categories and details, reported content, moderation decisions, appeals, and support correspondence.
  • Operations and measurement: request metadata, Apple crash reports, APNs and Telegram delivery results, Telegram update identifiers, short-lived callback tokens, security logs, invitation attribution, and bounded first-party events for activation, recurrence, reveal, Say hi, chat, notifications, safety, and deletion.
02

Information we do not collect

The service does not collect or infer precise or coarse device location, a manually entered city, device address-book contacts, Telegram contacts, Telegram phone numbers, Telegram usernames, Telegram avatars, advertising identifiers, payment data, financial information, or activity across other companies’ apps and websites. OU relationships and chats form an in-app social graph. Discovery is global.

03

How we use information

Model evidence and confidence are not public scores. They are not sold, used for advertising, or made searchable.

  • Create and secure accounts, enforce adult eligibility, keep media privately, publish and moderate memes, and deliver private media.
  • Link an OU account to Telegram only after explicit authentication, bind a verified Mini App session to that identity, and reject collisions instead of merging accounts silently.
  • Balance discovery across creators, build private familiarity through pairwise presence marks, and estimate reciprocal evidence with Bayesian smoothing.
  • Reveal profiles automatically, show Common ground only when enough independently held media overlaps, operate blind and revocable Say hi choices, and provide one relationship and one chat per pair.
  • Accept durable drafts from the iOS share sheet and attribute invitation activation without following the inviter or changing discovery.
  • Deliver optional relationship, message, post review, and authorized moderation notifications through APNs, Telegram, or both, process reports and blocks, prevent abuse, answer support requests, and measure product reliability and safety.
04

What other members can see

Before reciprocal reveal, a member may see a meme and a presence mark private to that pair. They do not see the creator’s name, age, biography, avatar, gallery, private Keeps, followers, confidence, or popularity.

After reveal, the two people can see each other’s profile and approved meme gallery. Common ground may show approved media both people independently kept or published only when there is enough overlap to avoid exposing a sparse private trail. It does not say who kept what or when. A pending Say hi choice remains visible only to the person who made it. Messages are visible only to the conversation participants and authorized moderators acting on a report or safety need.

Reports, blocks, exact birth dates, authentication data, device tokens, and pairwise model evidence are not shown to other members.

05

Service providers

Supabase provides authentication, database, private media storage, realtime delivery, server functions, and operational logs. Resend provides transactional authentication email. Apple provides TestFlight, push-notification delivery, and platform crash reporting. Telegram provides account authentication, bot and Mini App transport, media transit, and Telegram notification delivery.

These providers process information to deliver their services and may process it in different countries. Providers that receive member information must protect it to the standard required by their contracts and applicable law.

06

Sharing and sale

We do not sell personal information or share it for third-party advertising or cross-app tracking. We disclose information to service providers only as needed to run the service.

We may also disclose information when required by law, to respond to valid legal process, to protect someone from credible harm, or to investigate abuse or a security incident.

07

Retention and deletion

Profile, content, relationship, and conversation information remains while an account is active unless the member deletes an item, ends a relationship, or deletes the account. The current installation’s notification token is disabled on sign-out. All notification tokens are disabled when a member turns notifications off and removed on account deletion. Invalid tokens are disabled when Apple rejects them.

Operational notification delivery records expire after the shortest period needed to retry, diagnose, and suppress duplicate notifications.

Processed Telegram update identifiers expire after 30 days. Callback tokens expire with their action. Upload drafts, delivery attempts, cached Telegram file identifiers, and other Telegram operational records expire or are removed when they are no longer needed for delivery, security, or retry handling.

First-party product events are kept for no more than 90 days. Account deletion removes their live account link. Operational logs and encrypted backups expire on the shortest schedule supported for security and disaster recovery and are not restored to resume a deleted account.

Account deletion removes the authentication account, linked Telegram account and private chat mapping, avatar, uploaded media that is not shared canonical media, publications, private Keeps, feed deliveries, pairwise presence and evidence, relationships, Say hi choices, invitation attribution, notification tokens, chats, messages, and pending Telegram deliveries. Shared canonical media may remain when another member still has a lawful live publication of the same media. Reports and moderation records may remain without a live member identifier when needed for safety, fraud prevention, dispute handling, or law.

08

Member controls

Members can edit their profile, pause discovery, remove posts, withdraw a pending Say hi, end a relationship, control APNs and Telegram independently, stop Telegram notifications, disconnect Telegram when another sign-in method remains, block another account, sign out, or delete the account in the iOS app or authenticated Mini App. A block immediately removes both accounts from discovery, relationships, chat, notifications, and new media authorization. Media already delivered to a device cannot be recalled.

Requests for access, correction, deletion, objection, or an enforcement appeal may be sent to support@ou.app. Include the account email, but never send a password or authentication code. Rights vary by location.

09

Adults only

The service is for people aged 18 or older. We use a declared birth date to enforce this boundary and do not perform identity-document verification. Report a suspected underage account immediately. We may suspend it during review.

10

Security, contact, and changes

We use row-level authorization, private storage, scoped server operations, encrypted transport, rate limits, and audited moderation. No system can guarantee absolute security.

Material policy changes will appear here with a new effective date. Send privacy questions or requests to support@ou.app.