Privacy Policy
This policy explains how the Overinker mobile app and the overinker.app website (together, "Overinker") collect, use, share, and delete personal data. Overinker is operated by Paulo Oblepias, an individual developer based in the Philippines ("we", "us"). We are the personal information controller for the data described here.
1. Data we collect
1.1 When you browse as a guest
You can browse the feed and catalog without an account. We don't ask guests for any personal data. Like any internet service, our servers and content delivery network receive your IP address and basic request information (such as the time of the request and the address requested) when the app loads content. We use this only to deliver content, keep the service secure, and fix problems. See Retention for how long these logs are kept.
1.2 When you create an account
You sign in with Google or Sign in with Apple. We never see your Google or Apple password.
| Data | Where it comes from | Why we use it |
|---|---|---|
| Email address | Google or Apple, when you sign in. If you use Apple's "Hide My Email", we receive a private relay address instead. | To identify your account, prevent duplicate accounts, and contact you about your account or a privacy request. Your email is never shown to other users. |
| Account identifier | Created by Firebase Authentication when you first sign in, plus an internal Overinker user ID. | To link your sign-in to your Overinker account, your posts, and your settings. |
| Name and profile photo held by our sign-in provider | Firebase Authentication may receive the name and profile photo address on your Google account, or the name you choose to share with Apple. | These stay with the sign-in service. We don't copy them into your Overinker profile and we don't show them to anyone. |
1.3 Your profile and what you post
| Data | Why we use it |
|---|---|
| Display name (we generate a random one such as "Inky-Nib-0421" that you can change), bio, and avatar photo | To show your public profile to other users. |
| Swatch posts: photos, captions, and details such as ink, pen, nib, paper, lighting, and notes | To publish your swatches to the community and the ink catalog. |
| Discussion posts, comments, and @mentions | To publish your contributions to the community. |
| Likes and follows | To show reactions and to build your feed. Follows and like counts are visible to others. |
| Notifications (for example, "someone commented on your swatch") | To show your in-app inbox. |
| Reports you submit (reason and optional details) and moderation records | To keep the community safe and enforce our Terms. |
| Account settings and plan (for example, your role and posting limits) | To run the app and apply fair-use limits. |
Photos and location: the app only accesses photos you choose from your photo library. Before a photo is uploaded, the app removes its embedded metadata (EXIF), including any GPS location, and our servers re-process images again before they are published. We do not collect your location.
1.4 Technical data
- Request and security logs. Our servers record technical information about each request, such as IP address, time, the address requested, a random request ID, error details, and your user ID when you're signed in. We use this to operate, secure, and debug the service and to enforce rate limits.
- Audit records. We keep a record of important account actions (for example, that an account was deleted or a post was removed by a moderator), linked to user IDs.
- Data stored only on your device. The app keeps small settings on your phone, such as when you were last active (to manage sign-in sessions) and the status of an upload in progress. This stays on your device.
1.5 What we don't collect
We don't collect your precise or approximate location, contacts, phone number, payment information, health data, or browsing history. The current version of the app has no advertising, no in-app purchases, no analytics SDKs, and no crash-reporting SDKs, and we do not track you across other companies' apps or websites. If we add advertising, subscriptions, push notifications, or analytics in a future version, we will update this policy and the store privacy labels before that version is released.
2. How we use your data
We use personal data only to:
- create and run your account and let you sign in;
- publish the content you choose to share and show it to other users;
- operate community features such as follows, likes, comments, mentions, and notifications;
- moderate content, handle reports, and prevent spam, abuse, and fraud;
- keep the service secure, reliable, and working, and fix bugs;
- reply to your support and privacy requests; and
- comply with the law.
Legal bases. We process your data to perform our agreement with you (providing the app), for our legitimate interests in keeping the service safe and working (security logs, moderation, reports), and to meet legal obligations. Where the law requires consent, we will ask for it.
We don't sell or rent personal data, we don't use it for advertising, and we don't make automated decisions about you that have legal or similarly significant effects.
3. What other users can see
Your display name, bio, avatar, swatch posts, discussion posts, comments, likes, and follows are public inside Overinker, including to people browsing as guests. Please don't post personal information you don't want to be public. Your email address is never shown to other users.
4. Who we share data with
We share personal data only with service providers that host and run Overinker for us. They process it on our instructions and are not allowed to use it for their own purposes.
| Provider | What they do for us | Data involved |
|---|---|---|
| Google (Firebase and Google Cloud Platform) | Firebase Authentication (sign-in), Cloud Firestore (short-lived upload status), Cloud Run (our servers), Cloud SQL (our database), Memorystore (caching and rate limits), and Cloud Logging | Account data, profile, posts, technical logs |
| Cloudflare | R2 storage and content delivery for photos, and hosting for this website | Photos you upload, IP address and request data when content is delivered |
| Google Sign-In and Apple (Sign in with Apple) | Let you sign in with your existing account | Covered by Google's and Apple's own privacy policies when you sign in with them |
| Apple App Store and Google Play | Distribute the app | The stores may collect data under their own policies when you download the app. We receive only aggregated, non-identifying statistics from them. |
We may also disclose data if required by law or a valid legal request, to protect the safety of users or the public, or to investigate violations of our Terms. If Overinker is ever transferred to a new operator, your data may be transferred too, and this policy will continue to apply to it.
International transfers. Our providers may store and process data on servers outside the Philippines, including in the United States and other countries. We rely on their contractual safeguards (such as data processing terms and, where applicable, standard contractual clauses) to protect it.
Security. Data is encrypted in transit (HTTPS) and stored with providers that encrypt data at rest. Access to production systems is limited to the operator. No system is perfectly secure, but we will notify you and the authorities of a personal data breach where the law requires it.
5. How long we keep data
| Data | How long |
|---|---|
| Account and profile data | Until you delete your account (or we close it) |
| Published posts, comments, and photos | Until you delete them, a moderator removes them, or you delete your account (see Deleting your account) |
| Deleted posts and comments | Removed from the app immediately. Hidden copies may remain in our database for up to 30 days before permanent deletion. |
| Upload status records (Firestore) | Deleted when the upload finishes, or within 24 hours |
| Reports and moderation records | As long as needed to keep the community safe and handle repeat abuse, up to 24 months |
| Audit records of account actions | Up to 24 months |
| Server request and error logs | Typically about 30 days |
| Database backups | Deleted data can persist in encrypted backups until they are overwritten, within 7 days |
We may keep specific data longer if the law requires it or to resolve a dispute or safety investigation.
6. Deleting your account
You can delete your account in the app at any time: open the You tab, tap the Settings (gear) icon, then tap Delete account. If you no longer have the app, you can ask us to delete it by email. Full instructions are on our account deletion page.
When you delete your account we:
- delete your sign-in account from Firebase Authentication and remove your email address from our database;
- remove your display name, bio, and avatar. Your profile shows as "Deleted user";
- remove your discussion posts and comments from the app;
- delete your likes, the accounts you follow, your notifications, and any uploads in progress.
Your swatch posts stay. Swatch photos and their details remain in the community catalog, shown as posted by "Deleted user" and no longer linked to your name or email. If you'd like your swatches removed too, delete them in the app before you delete your account, or email us and we'll remove them.
If you used Sign in with Apple, you can also stop using your Apple ID with Overinker on your iPhone in Settings → [your name] → Sign-In & Security → Sign in with Apple. For Google, go to your Google Account under Security → Your connections to third-party apps & services.
7. Your rights
Depending on where you live, you may have the right to:
- be informed about how your data is processed (this policy);
- access your data and get a copy of it;
- correct it (you can edit your profile and posts in the app);
- delete it, or object to or restrict how we process it;
- data portability: get your data in a common, machine-readable format;
- withdraw consent where we rely on consent; and
- complain to a data protection authority.
Philippines. Under the Data Privacy Act of 2012 (Republic Act No. 10173), you have the rights to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, and to damages. You may file a complaint with the National Privacy Commission (privacy.gov.ph).
European Economic Area, United Kingdom, and Switzerland. If the GDPR or UK GDPR applies to you, you have the rights listed above, and you can complain to your local supervisory authority.
How to make a request. In the app, use Settings → Request my data, or email support@overinker.app. We may need to confirm that you own the account, for example by asking you to write from the email address you sign in with. We respond within 30 days. Please request a copy of your data before deleting your account, because deletion removes the email we use to find your records.
8. Children
Overinker is not directed at children under 16, and we don't knowingly collect personal data from them. You must be at least 16 years old to create an account (or older, if your country requires a higher age to consent to data processing). If you believe a child has given us personal data, contact us and we will delete the account.
9. Changes to this policy
We will post any changes on this page and update the date above. If a change is significant, for example new types of data or new uses such as advertising, we will let you know in the app before it takes effect.
10. Contact
Paulo Oblepias (developer of Overinker)
Email: support@overinker.app
Address: Taguig City, Philippines
Overinker