This Privacy Policy describes how Ollage, LLC ("Ollage", "we", "us", "our") collects, uses, and discloses personal information in connection with your access to and use of Ollage (the "Site"), our mobile applications, and related services (collectively, the "Services"). This policy applies to all visitors and registered users globally. It is written from our actual data flows and applies to personal data as defined under GDPR, UK-GDPR, and CCPA/CPRA.
Data Controller/Business: Ollage, LLC, a limited liability company organized under the laws of Delaware, United States.
Data Protection Officer: [Data Protection Officer — pending appointment] ([email protected])
EU Representative (GDPR Art. 27): [EU representative — pending appointment (GDPR Art. 27)]
UK Representative (UK-GDPR Art. 27): [UK representative — pending appointment (UK GDPR Art. 27)]
General Inquiries: [email protected]
Below is a comprehensive inventory of personal data we collect, organized by category. The information describes both what we collect and how it appears in our systems.
| Category | Specific Data Points | Collection Method | Purpose |
|---|---|---|---|
| Account Identifiers | Username, email address, account creation date, last login timestamp, account role (user, curator, admin) | Provided by you at registration | Authentication, account management, communication, access control |
| Authentication Credentials | Password (bcrypt hash only — we never store plaintext), password reset tokens (temporary) | Provided by you; generated at reset | Secure account access, password recovery |
| Session Data | Persistent bb_session cookie (HttpOnly, Secure, SameSite=Lax; 90 days for registered users, 30 days for anonymous visitors), login tokens, IP address at session creation, user-agent string | Automatically collected | Maintaining signed-in state, deduplicating votes and analytics for anonymous users, security |
| Age Verification Data | Attestation method (self-assertion or commercial provider reference), provider reference ID (anonymized token — never document images or numbers), birth year (reduced from full DOB), region, verification timestamp, verification result (approved/failed) | Provided by you or via age-verification provider | Compliance with legal age-assurance obligations (18+ only requirement). No government ID, biometric data, or photos stored by us. |
| Account Settings & Preferences | Terms of Service version accepted + timestamp, email notification preferences, language and display preferences | Provided by you; auto-set on registration | Consent tracking, customization, communication preferences |
| Behavioral & Preference Data | Taste events: clip views, likes/saves, album selections (1–5 staging groups), vote patterns across clips and creators, search queries, scroll signals, watch duration per clip; per-user taste model coefficients (inferred from your interactions) | Automatically collected when you interact with content | Personalized ranking and recommendations, improving the core discovery product, training our quality models |
| Content Moderation Submissions | Content reports you file: clip identifiers, category of report (spam, abuse, copyright, NCI, other), message text, your contact email (if you request a response), timestamp; removal requests: your name, email, URLs, detailed explanation, case ID assigned | Provided by you via report button or removal form | Abuse handling, legal compliance (DMCA, NCII, takedown), tracking and resolving reports |
| Technical & Performance Data | IP address (on every request), browser type/version, operating system, device type, viewport dimensions, connection type (detected via JavaScript), geographic region (inferred by Cloudflare from IP), page load timings (Navigation Timing API), Web Vitals (Core Web Vitals, user-centric metrics like LCP/FID/CLS), errors and stack traces from your browser | Automatically collected | Performance monitoring, debugging, security (fraud/bot detection), infrastructure optimization. Self-hosted — no third-party analytics trackers. |
| Media Metadata | Clip metadata originally published by creators: title, description, tags, thumbnail hash, source platform (RedGifs), creator username, view count, like count, duration, resolution, bitrate, fps, aspect ratio; no personal data from creators is stored unless you are a curator verifying content | Scraped from source platforms or provided by curators | Organizing the content library, discovery, quality assessment |
We process personal data only where we have a lawful basis under GDPR Article 6 (or equivalent under UK-GDPR). Below are the bases and corresponding purposes:
| Legal Basis | Processing Activity | Data Categories |
|---|---|---|
| Contract Performance (GDPR 6(1)(b)) | Providing the Services: account management, authentication, content delivery, personalized ranking based on your vote history, storage of your collections and curated groups | Account identifiers, credentials, session data, behavioral preferences |
| Legitimate Interests (GDPR 6(1)(f)) | Security (fraud detection, bot protection, abuse prevention); content moderation (removal of illegal/violative material); service improvement (analytics, debugging, performance optimization); legal defense (retaining logs and moderation records); marketing of the Services (email communications about features, optional newsletters — consent-based for GDPR users) | IP addresses, device data, technical logs, moderation submissions, behavioral signals |
| Legal Obligation (GDPR 6(1)(c)) | Age assurance (18+ legal requirement in multiple jurisdictions); DMCA takedown handling and record-keeping; NCII (non-consensual intimate imagery) takedown and reporting; audit logs for abuse investigation | Age verification data, DMCA/NCII submissions, moderation records, request logs |
| Explicit Consent (GDPR 6(1)(a)) | Non-essential cookies beyond session management; optional marketing communications; certain data uses flagged at collection time | Cookie data, email preferences, marketing signals |
We retain personal data only for as long as necessary to achieve the purposes listed above, then securely delete it. Specific retention windows are:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account data (username, email, hashed password, role, created_at) | 3 years after account deletion or inactivity | Contractual necessity; legal holds; fraud investigation |
| Session tokens and cookies | 90 days from creation (or until explicit logout) | Service operation; vote deduplication |
| Age verification attestations (method, provider ref, result, timestamp) | 7 years | Compliance evidence; legal defense against underage-user claims |
| Server logs (request paths, IPs, errors, timings) | 90 days rolling window | Security investigation, debugging, intrusion detection |
| Behavioral events (taste_events table: views, votes, saves) | For the lifetime of your account; deleted upon account erasure | Personalization and product core functionality |
| Moderation/abuse reports and removal requests | 3 years (or as required by law) | Legal compliance, dispute resolution, pattern detection |
| Backups (full database snapshots) | 35 days | Disaster recovery; older backups overwritten |
After the retention period expires, data is securely deleted or anonymized. In some cases (e.g., DMCA/NCII requests, legal holds), we may retain data beyond the standard period if required by law or necessary to defend our legal rights.
We disclose your personal data to the following service providers, who process it on our behalf under data processing agreements (DPA):
| Processor | Purpose | Location | Data Transferred |
|---|---|---|---|
| Cloudflare, Inc. | CDN and origin hosting; R2 object storage (media); Cloudflare Workers serverless computing; Email Routing (transactional emails); Tunnel (public ingress); IP-to-country geolocation signal | United States (with global edge) | All requests (IP, user-agent, request data); media files; outbound email metadata |
| Anthropic PBC | AI vision tagging and title generation for clips flagged by curators; no user personal data (names, emails, etc.) is sent | United States | Clip images, metadata (title, tags); inference results only |
| Replicate, Inc. / RunPod / Atlas Cloud | Image and video generation for AI-creator personas; internal use only (never applied to real-user content) | United States | Persona parameters and generated assets; no user personal data |
| Age-Verification Provider [self-attestation with date-of-birth capture (Tier 0); commercial age-verification (ID or transactional) in enforced tier-1 jurisdictions when provider selection is complete] | Identity and age verification via ID document or transactional method; provider retains ID artifacts; we receive only an attestation reference | United States (provider jurisdiction pending selection) | Date of birth (year), ID copy (held by provider, not us), geolocation during verification |
All sub-processors are bound by written Data Processing Agreements requiring equivalent data protection obligations. We do not sell your personal data to third parties for money or valuable consideration. We do not disclose personal data to advertising networks, data brokers, or other third parties for their own marketing purposes.
The Services are hosted in the United States via Cloudflare and our origin server. If you are accessing the Services from outside the United States (including the European Economic Area or United Kingdom), your personal data will be transferred to and processed in the United States.
For EU/UK users: We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission and UK ICO to provide an adequate level of protection for data transferred outside the EEA/UK. [EU representative — pending appointment (GDPR Art. 27)] acts as our representative for these transfers. A copy of our SCCs is available upon request to [email protected].
For all international users: By using the Services, you consent to the transfer, processing, and storage of your personal data in the United States and other countries where our service providers maintain infrastructure. If you do not consent to such transfers, please discontinue use of the Services.
We use cookies and similar tracking technologies to operate the Services. For detailed cookie information, please see our Cookie Policy. In summary:
bb_session (anonymous session ID, HttpOnly, Secure, SameSite=Lax) and CSRF tokens (optional, depending on form implementation). These are required for the Services to function.You may disable cookies via your browser settings, though this may limit your ability to use certain features. See our Cookie Policy for more details.
Ollage is an adults-only service intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect sensitive data (including data concerning sex life, gender identity, or sexual orientation) from minors.
If we discover that we have collected data from a user under 18, we will immediately delete all such data, including the associated account and all related records. If you are aware of a minor using the Services, please contact us immediately at [email protected].
Parental rights (COPPA): If you are the parent or guardian of a child under 13 and believe we have collected information from that child, please contact [email protected] and we will remove the data within 7 business days.
We take reports of non-consensual intimate imagery extremely seriously and have a separate, expedited removal process.
Reporting NCII: If you believe intimate imagery of yourself has been posted without your consent, contact [email protected] with:
Response target: We aim to respond to NCII reports within 24 hours and remove content upon verification. For full removal options and to file a removal request via web form, visit /content-removal.
Legal recourse: The U.S. TAKE IT DOWN Act provides a private right of action for victims of NCII. More information and resources are available at justice.gov/civil/vawa/take-it-down.
We receive and process content reports, DMCA takedown notices, and removal requests from users and copyright owners.
Reports you file: When you flag a clip as spam, abusive, or violative, we collect your report category, message, and email (optional). These are retained for 3 years to detect patterns and defend against frivolous claims.
DMCA compliance: We respond to valid DMCA takedown notices within 48 hours. Our DMCA agent is [Designated DMCA Agent — pending USCO registration] ([email protected]). Full details are in our DMCA Policy.
Content Removal Process: For detailed instructions on removing content, visit /content-removal.
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:
How to exercise GDPR rights: Email [email protected] with "GDPR Request" in the subject line, specify which right you are exercising, and provide sufficient detail to identify your account. We will respond within 30 days.
Right to lodge a complaint: If you believe we have violated your rights, you can lodge a complaint with your national data protection authority (e.g., UK ICO, EDPB).
If you are located in the United Kingdom, you have identical rights to those listed above under UK-GDPR. [UK representative — pending appointment (UK GDPR Art. 27)] acts as our UK representative. You can lodge a complaint with the UK Information Commissioner's Office (ICO).
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
How to exercise CCPA/CPRA rights: Email [email protected] or submit a request via our online form at /content-removal. Include "CCPA Request" in the subject line. We will verify your identity and respond within 45 days (or up to 90 days for complex requests).
Right to appeal: If we deny part or all of your request, you have the right to appeal the denial. We will provide appeal instructions in our response.
Authorized agent: You may authorize another person or business to submit a request on your behalf, but we may require written permission and identity verification.
Residents of Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Virginia (VAMCP), and other states with privacy laws may have similar rights to California residents. Contact [email protected] to exercise rights under your state's law.
We maintain reasonable organizational, technical, and physical safeguards to protect your personal data from unauthorized access, alteration, disclosure, or destruction:
Breach notification: If we discover a breach of your personal data, we will notify affected users within 7 days (or as required by law) via email to the address associated with your account. We will also notify the relevant supervisory authorities (ICO, CNIL, etc.) without undue delay.
Limitation of liability: While we maintain security measures, no system is 100% secure. We cannot guarantee the absolute security of your personal data. You acknowledge the inherent risks of internet transmission.
Ollage may contain links to third-party websites and services (e.g., creator profiles, external platforms, payment processors). This Privacy Policy applies only to the Services; third-party sites have their own privacy policies. We are not responsible for their practices, and we encourage you to review their privacy policies before interacting with them.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
Your continued use of the Services after such notification constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.
If you have questions about this Privacy Policy, your personal data, or your privacy rights, contact us:
Privacy Inquiries & DSAR: [email protected]
Abuse & Content Removal: [email protected]
DMCA/Legal: [email protected]
General Inquiries: [email protected]
Mailing Address:
Ollage, LLC
[Registered address — pending entity formation]
[City, State ZIP]
United States
For GDPR/UK-GDPR complaints: You may lodge a complaint with your national supervisory authority:
For CCPA/CPRA complaints: You may file a complaint with the California Attorney General or other applicable state attorney general.