Your data

Privacy policy

What Online, Unfortunately processes, why it is needed, where it appears, and how members can control or delete it.

Effective August 3, 2026

01

Information we process

Product-event payloads do not contain meme text, media, message bodies, report details, email addresses, profile biographies, or notification contents.

  • Account and profile data: email address, authentication records, account identifier, birth date, name, biography, avatar, onboarding state, and discovery state. Other members see only age, not birth date, after profile reveal.
  • Notification data: preferences and an Apple Push Notification device token when notifications are enabled.
  • Content: text memes, optional captions, images, short videos, thumbnails, private storage paths, and media metadata.
  • Discovery activity: feed deliveries, visible impressions, skips, positive reactions, recurrence, private pairwise presence marks, and Bayesian evidence used for ordering and reveal.
  • Relationship activity: revealed relationships, blind Say hi choices, relationship endings, blocks, chat messages, read state, and delivery state.
  • Safety data: report categories and details, reported content, moderation decisions, appeals, and support correspondence.
  • Operations and measurement: request metadata, security logs, delivery records, and bounded first-party events for activation, recurrence, reveal, Say hi, chat, notifications, safety, and deletion.
02

Information we do not collect

The service does not collect or infer precise or coarse device location, a manually entered city, contacts, advertising identifiers, payment data, financial information, or activity across other companies’ apps and websites. Discovery is global.

03

How we use information

Model evidence and confidence are not public scores. They are not sold, used for advertising, or made searchable.

  • Create and secure accounts, enforce adult eligibility, publish and moderate memes, and deliver private media.
  • Balance discovery across creators, build private familiarity through pairwise presence marks, and estimate reciprocal evidence with Bayesian smoothing.
  • Reveal profiles automatically, operate blind and revocable Say hi choices, and provide one relationship and one chat per pair.
  • Deliver optional notifications, process reports and blocks, prevent abuse, answer support requests, and measure product reliability and safety.
04

What other members can see

Before reciprocal reveal, a member may see a meme and a presence mark private to that pair. They do not see the creator’s name, age, biography, avatar, gallery, reactions, followers, confidence, or popularity.

After reveal, the two people can see each other’s profile and approved meme gallery. A pending Say hi choice remains visible only to the person who made it. Messages are visible only to the conversation participants and authorized moderators acting on a report or safety need.

Reports, blocks, exact birth dates, authentication data, device tokens, and pairwise model evidence are not shown to other members.

05

Service providers

Supabase provides authentication, database, private media storage, realtime delivery, server functions, and operational logs. Resend provides transactional authentication email. Apple provides TestFlight, push-notification delivery, and platform crash reporting.

These providers process information to deliver their services and may process it in different countries. Providers that receive member information must protect it to the standard required by their contracts and applicable law.

06

Sharing and sale

We do not sell personal information or share it for third-party advertising or cross-app tracking. We disclose information to service providers only as needed to run the service.

We may also disclose information when required by law, to respond to valid legal process, to protect someone from credible harm, or to investigate abuse or a security incident.

07

Retention and deletion

Profile, content, relationship, and conversation information remains while an account is active unless the member deletes an item, ends a relationship, or deletes the account. Notification tokens are removed on sign-out, invalidation, or account deletion.

First-party product events are kept for no more than 90 days. Account deletion removes their live account link. Operational logs and encrypted backups expire on the shortest schedule supported for security and disaster recovery and are not restored to resume a deleted account.

Account deletion removes the authentication account, avatar, uploaded media, posts, feed deliveries, reactions, pairwise presence and evidence, relationships, Say hi choices, device tokens, chats, and messages. Reports and moderation records may remain without a live member identifier when needed for safety, fraud prevention, dispute handling, or law.

08

Member controls

Members can edit their profile, pause discovery, remove posts, withdraw a pending Say hi, end a relationship, mute notifications, block another account, sign out, or delete the account in the app. A block immediately separates the two accounts across discovery, relationships, chat, media, and notifications.

Requests for access, correction, deletion, objection, or an enforcement appeal may be sent to support@ou.app. Include the account email, but never send a password or authentication code. Rights vary by location.

09

Adults only

The service is for people aged 18 or older. We use a declared birth date to enforce this boundary and do not perform identity-document verification. Report a suspected underage account immediately; we may suspend it during review.

10

Security, contact, and changes

We use row-level authorization, private storage, scoped server operations, encrypted transport, rate limits, and audited moderation. No system can guarantee absolute security.

Material policy changes will appear here with a new effective date. Send privacy questions or requests to support@ou.app.