← Ollage
DRAFT — pending legal review. Published for transparency while counsel review is underway.

Privacy Policy

Version 2026-08-21-draft2 · Last updated 2026-08-21 · Effective 2026-08-21

1. Scope and Effective Date

This Privacy Policy describes how Ollage, LLC ("Ollage", "we", "us", "our") collects, uses, and discloses personal information in connection with your access to and use of Ollage (the "Site"), our mobile applications, and related services (collectively, the "Services"). This policy applies to all visitors and registered users globally. It is written from our actual data flows and applies to personal data as defined under GDPR, UK-GDPR, and CCPA/CPRA.

2. Who We Are

Data Controller/Business: Ollage, LLC, a limited liability company organized under the laws of Delaware, United States.

Data Protection Officer: [Data Protection Officer — pending appointment] ([email protected])

EU Representative (GDPR Art. 27): [EU representative — pending appointment (GDPR Art. 27)]

UK Representative (UK-GDPR Art. 27): [UK representative — pending appointment (UK GDPR Art. 27)]

General Inquiries: [email protected]

3. What Personal Data We Collect

Below is a comprehensive inventory of personal data we collect, organized by category. The information describes both what we collect and how it appears in our systems.

CategorySpecific Data PointsCollection MethodPurpose
Account IdentifiersUsername, email address, account creation date, last login timestamp, account role (user, curator, admin)Provided by you at registrationAuthentication, account management, communication, access control
Authentication CredentialsPassword (bcrypt hash only — we never store plaintext), password reset tokens (temporary)Provided by you; generated at resetSecure account access, password recovery
Session DataPersistent bb_session cookie (HttpOnly, Secure, SameSite=Lax; 90 days for registered users, 30 days for anonymous visitors), login tokens, IP address at session creation, user-agent stringAutomatically collectedMaintaining signed-in state, deduplicating votes and analytics for anonymous users, security
Age Verification DataAttestation method (self-assertion or commercial provider reference), provider reference ID (anonymized token — never document images or numbers), birth year (reduced from full DOB), region, verification timestamp, verification result (approved/failed)Provided by you or via age-verification providerCompliance with legal age-assurance obligations (18+ only requirement). No government ID, biometric data, or photos stored by us.
Account Settings & PreferencesTerms of Service version accepted + timestamp, email notification preferences, language and display preferencesProvided by you; auto-set on registrationConsent tracking, customization, communication preferences
Behavioral & Preference DataTaste events: clip views, likes/saves, album selections (1–5 staging groups), vote patterns across clips and creators, search queries, scroll signals, watch duration per clip; per-user taste model coefficients (inferred from your interactions)Automatically collected when you interact with contentPersonalized ranking and recommendations, improving the core discovery product, training our quality models
Content Moderation SubmissionsContent reports you file: clip identifiers, category of report (spam, abuse, copyright, NCI, other), message text, your contact email (if you request a response), timestamp; removal requests: your name, email, URLs, detailed explanation, case ID assignedProvided by you via report button or removal formAbuse handling, legal compliance (DMCA, NCII, takedown), tracking and resolving reports
Technical & Performance DataIP address (on every request), browser type/version, operating system, device type, viewport dimensions, connection type (detected via JavaScript), geographic region (inferred by Cloudflare from IP), page load timings (Navigation Timing API), Web Vitals (Core Web Vitals, user-centric metrics like LCP/FID/CLS), errors and stack traces from your browserAutomatically collectedPerformance monitoring, debugging, security (fraud/bot detection), infrastructure optimization. Self-hosted — no third-party analytics trackers.
Media MetadataClip metadata originally published by creators: title, description, tags, thumbnail hash, source platform (RedGifs), creator username, view count, like count, duration, resolution, bitrate, fps, aspect ratio; no personal data from creators is stored unless you are a curator verifying contentScraped from source platforms or provided by curatorsOrganizing the content library, discovery, quality assessment

4. What We Do NOT Collect

  • No government ID images, numbers, or scans — age-verification providers hold these and we receive only an attestation reference.
  • No biometric data (facial scans, fingerprints, etc.) — age verification via commercial provider may involve biometric capture, but those artifacts are retained by the provider, not us.
  • No full date of birth — we accept birth year only and discard month/day to minimize sensitive data at rest.
  • No payment or financial data — there is currently no payment system on the platform.
  • No phone numbers (unless you voluntarily provide one in a support message).
  • No behavioral cookies for third-party advertising — we run no ad network and place no tracking pixels for external platforms.

5. Legal Bases for Processing (GDPR Article 6) and Purposes (CCPA Article 1798.100)

We process personal data only where we have a lawful basis under GDPR Article 6 (or equivalent under UK-GDPR). Below are the bases and corresponding purposes:

Legal BasisProcessing ActivityData Categories
Contract Performance
(GDPR 6(1)(b))
Providing the Services: account management, authentication, content delivery, personalized ranking based on your vote history, storage of your collections and curated groupsAccount identifiers, credentials, session data, behavioral preferences
Legitimate Interests
(GDPR 6(1)(f))
Security (fraud detection, bot protection, abuse prevention); content moderation (removal of illegal/violative material); service improvement (analytics, debugging, performance optimization); legal defense (retaining logs and moderation records); marketing of the Services (email communications about features, optional newsletters — consent-based for GDPR users)IP addresses, device data, technical logs, moderation submissions, behavioral signals
Legal Obligation
(GDPR 6(1)(c))
Age assurance (18+ legal requirement in multiple jurisdictions); DMCA takedown handling and record-keeping; NCII (non-consensual intimate imagery) takedown and reporting; audit logs for abuse investigationAge verification data, DMCA/NCII submissions, moderation records, request logs
Explicit Consent
(GDPR 6(1)(a))
Non-essential cookies beyond session management; optional marketing communications; certain data uses flagged at collection timeCookie data, email preferences, marketing signals

6. Data Retention

We retain personal data only for as long as necessary to achieve the purposes listed above, then securely delete it. Specific retention windows are:

Data CategoryRetention PeriodRationale
Account data (username, email, hashed password, role, created_at)3 years after account deletion or inactivityContractual necessity; legal holds; fraud investigation
Session tokens and cookies90 days from creation (or until explicit logout)Service operation; vote deduplication
Age verification attestations (method, provider ref, result, timestamp)7 yearsCompliance evidence; legal defense against underage-user claims
Server logs (request paths, IPs, errors, timings)90 days rolling windowSecurity investigation, debugging, intrusion detection
Behavioral events (taste_events table: views, votes, saves)For the lifetime of your account; deleted upon account erasurePersonalization and product core functionality
Moderation/abuse reports and removal requests3 years (or as required by law)Legal compliance, dispute resolution, pattern detection
Backups (full database snapshots)35 daysDisaster recovery; older backups overwritten

After the retention period expires, data is securely deleted or anonymized. In some cases (e.g., DMCA/NCII requests, legal holds), we may retain data beyond the standard period if required by law or necessary to defend our legal rights.

7. Processors and Sub-Processors

We disclose your personal data to the following service providers, who process it on our behalf under data processing agreements (DPA):

ProcessorPurposeLocationData Transferred
Cloudflare, Inc.CDN and origin hosting; R2 object storage (media); Cloudflare Workers serverless computing; Email Routing (transactional emails); Tunnel (public ingress); IP-to-country geolocation signalUnited States (with global edge)All requests (IP, user-agent, request data); media files; outbound email metadata
Anthropic PBCAI vision tagging and title generation for clips flagged by curators; no user personal data (names, emails, etc.) is sentUnited StatesClip images, metadata (title, tags); inference results only
Replicate, Inc. / RunPod / Atlas CloudImage and video generation for AI-creator personas; internal use only (never applied to real-user content)United StatesPersona parameters and generated assets; no user personal data
Age-Verification Provider
[self-attestation with date-of-birth capture (Tier 0); commercial age-verification (ID or transactional) in enforced tier-1 jurisdictions when provider selection is complete]
Identity and age verification via ID document or transactional method; provider retains ID artifacts; we receive only an attestation referenceUnited States (provider jurisdiction pending selection)Date of birth (year), ID copy (held by provider, not us), geolocation during verification

All sub-processors are bound by written Data Processing Agreements requiring equivalent data protection obligations. We do not sell your personal data to third parties for money or valuable consideration. We do not disclose personal data to advertising networks, data brokers, or other third parties for their own marketing purposes.

8. International Data Transfers

The Services are hosted in the United States via Cloudflare and our origin server. If you are accessing the Services from outside the United States (including the European Economic Area or United Kingdom), your personal data will be transferred to and processed in the United States.

For EU/UK users: We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission and UK ICO to provide an adequate level of protection for data transferred outside the EEA/UK. [EU representative — pending appointment (GDPR Art. 27)] acts as our representative for these transfers. A copy of our SCCs is available upon request to [email protected].

For all international users: By using the Services, you consent to the transfer, processing, and storage of your personal data in the United States and other countries where our service providers maintain infrastructure. If you do not consent to such transfers, please discontinue use of the Services.

9. Cookies and Similar Technologies

We use cookies and similar tracking technologies to operate the Services. For detailed cookie information, please see our Cookie Policy. In summary:

  • Essential cookies: bb_session (anonymous session ID, HttpOnly, Secure, SameSite=Lax) and CSRF tokens (optional, depending on form implementation). These are required for the Services to function.
  • Performance/Analytics cookies: We use self-hosted analytics (no Google Analytics, no third-party trackers). Page load timings and Web Vitals are collected via our own beacon endpoint and stored in the `perf_navigations` and `perf_resources` tables. These are anonymized and never shared with external parties.
  • No third-party advertising cookies: We do not place cookies or pixels for social media platforms (Facebook, X, etc.) or advertising networks.

You may disable cookies via your browser settings, though this may limit your ability to use certain features. See our Cookie Policy for more details.

10. Children and Minors

Ollage is an adults-only service intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect sensitive data (including data concerning sex life, gender identity, or sexual orientation) from minors.

If we discover that we have collected data from a user under 18, we will immediately delete all such data, including the associated account and all related records. If you are aware of a minor using the Services, please contact us immediately at [email protected].

Parental rights (COPPA): If you are the parent or guardian of a child under 13 and believe we have collected information from that child, please contact [email protected] and we will remove the data within 7 business days.

11. Non-Consensual Intimate Imagery (NCII) and Content Removal

We take reports of non-consensual intimate imagery extremely seriously and have a separate, expedited removal process.

Reporting NCII: If you believe intimate imagery of yourself has been posted without your consent, contact [email protected] with:

  • Your name and contact email (for case tracking)
  • URL(s) to the material on Ollage
  • A brief statement confirming you did not consent to the imagery being posted
  • Any additional context (date it was discovered, where it originated, etc.)

Response target: We aim to respond to NCII reports within 24 hours and remove content upon verification. For full removal options and to file a removal request via web form, visit /content-removal.

Legal recourse: The U.S. TAKE IT DOWN Act provides a private right of action for victims of NCII. More information and resources are available at justice.gov/civil/vawa/take-it-down.

12. Content Moderation and Legal Compliance

We receive and process content reports, DMCA takedown notices, and removal requests from users and copyright owners.

Reports you file: When you flag a clip as spam, abusive, or violative, we collect your report category, message, and email (optional). These are retained for 3 years to detect patterns and defend against frivolous claims.

DMCA compliance: We respond to valid DMCA takedown notices within 48 hours. Our DMCA agent is [Designated DMCA Agent — pending USCO registration] ([email protected]). Full details are in our DMCA Policy.

Content Removal Process: For detailed instructions on removing content, visit /content-removal.

13. Your Privacy Rights

13a. GDPR Rights (EU/EEA users)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:

  • Right to Access (Art. 15): You can request a copy of the personal data we hold about you. We will provide it in a structured, commonly used, machine-readable format (CSV/JSON) within 30 days.
  • Right to Rectification (Art. 16): You can ask us to correct inaccurate or incomplete data. You can edit much of your account information directly in your account settings.
  • Right to Erasure (Art. 17): You can request deletion of your personal data, subject to legal exceptions (e.g., if we must retain data to comply with law or defend legal claims). Account deletion removes your account row, sessions, behavioral events, and associated preferences.
  • Right to Restrict Processing (Art. 18): You can ask us to limit how we use your data while a dispute is being resolved.
  • Right to Data Portability (Art. 20): You can request a machine-readable export of your data to transfer to another service.
  • Right to Object (Art. 21): You can object to processing based on legitimate interests (e.g., marketing emails) or for purposes of profiling. We will stop the processing unless we can demonstrate compelling legitimate grounds.
  • Right not to be subject to automated decision-making (Art. 22): Our personalized ranking uses your taste model but does not produce legal or similarly significant effects (no automatic bans, auto-suspensions, etc.). Any such decision is made by humans with an opportunity for you to appeal.
  • Right to withdraw consent: If we rely on consent for processing, you can withdraw it at any time. This does not affect processing before withdrawal.

How to exercise GDPR rights: Email [email protected] with "GDPR Request" in the subject line, specify which right you are exercising, and provide sufficient detail to identify your account. We will respond within 30 days.

Right to lodge a complaint: If you believe we have violated your rights, you can lodge a complaint with your national data protection authority (e.g., UK ICO, EDPB).

13b. UK-GDPR Rights (UK users)

If you are located in the United Kingdom, you have identical rights to those listed above under UK-GDPR. [UK representative — pending appointment (UK GDPR Art. 27)] acts as our UK representative. You can lodge a complaint with the UK Information Commissioner's Office (ICO).

13c. California CCPA/CPRA Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know (Cal. Civ. Code § 1798.100): You can request the categories and specific pieces of personal information we have collected, the sources of collection, the purpose of collection, and the categories of third parties with whom we share it.
  • Right to Delete (§ 1798.105): You can request deletion of personal information we have collected from you, subject to exceptions (e.g., if we must retain it to comply with law or complete a transaction).
  • Right to Correct (§ 1798.120): You can request that we correct inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing (§ 1798.120(e)): We do not sell your personal information for monetary compensation. We do not share your personal information with third parties for cross-context behavioral advertising. There is nothing to opt out of — you already have full protection.
  • Right to Limit Use and Disclosure of Sensitive Personal Data (§ 1798.121): We do not use or disclose sensitive personal data (birth year, sex-related information) for purposes other than those necessary to provide the Services, unless you have consented.
  • Right to Non-Discrimination (§ 1798.125): We will not penalize or deny goods/services if you exercise your CCPA rights.

How to exercise CCPA/CPRA rights: Email [email protected] or submit a request via our online form at /content-removal. Include "CCPA Request" in the subject line. We will verify your identity and respond within 45 days (or up to 90 days for complex requests).

Right to appeal: If we deny part or all of your request, you have the right to appeal the denial. We will provide appeal instructions in our response.

Authorized agent: You may authorize another person or business to submit a request on your behalf, but we may require written permission and identity verification.

13d. Other U.S. State Privacy Rights

Residents of Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Virginia (VAMCP), and other states with privacy laws may have similar rights to California residents. Contact [email protected] to exercise rights under your state's law.

14. Data Security Measures

We maintain reasonable organizational, technical, and physical safeguards to protect your personal data from unauthorized access, alteration, disclosure, or destruction:

  • Transmission security: All data in transit is encrypted via HTTPS/TLS 1.2+.
  • At-rest encryption: Sensitive data (passwords, session tokens) are hashed with bcrypt before storage.
  • Cookie security: Session cookies are HttpOnly (not accessible to JavaScript), Secure (HTTPS only), and SameSite=Lax (CSRF protection).
  • Access controls: Personnel access to personal data is restricted on a need-to-know basis. Admin access is logged and audited.
  • Cloudflare edge protection: Cloudflare's WAF and DDoS protection shield our infrastructure from common attacks.
  • No client-side storage of sensitive data: Passwords, tokens, and PII are never stored in browser localStorage or sessionStorage.

Breach notification: If we discover a breach of your personal data, we will notify affected users within 7 days (or as required by law) via email to the address associated with your account. We will also notify the relevant supervisory authorities (ICO, CNIL, etc.) without undue delay.

Limitation of liability: While we maintain security measures, no system is 100% secure. We cannot guarantee the absolute security of your personal data. You acknowledge the inherent risks of internet transmission.

15. Third-Party Links and Services

Ollage may contain links to third-party websites and services (e.g., creator profiles, external platforms, payment processors). This Privacy Policy applies only to the Services; third-party sites have their own privacy policies. We are not responsible for their practices, and we encourage you to review their privacy policies before interacting with them.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on this page with a revised effective date;
  • Sending you an email to the address associated with your account (if you have one);
  • Requiring re-consent to the updated terms upon your next sign-in (if the changes are material).

Your continued use of the Services after such notification constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.

17. Contact Us

If you have questions about this Privacy Policy, your personal data, or your privacy rights, contact us:

Privacy Inquiries & DSAR: [email protected]
Abuse & Content Removal: [email protected]
DMCA/Legal: [email protected]
General Inquiries: [email protected]
Mailing Address:
Ollage, LLC
[Registered address — pending entity formation]
[City, State ZIP]
United States

For GDPR/UK-GDPR complaints: You may lodge a complaint with your national supervisory authority:

  • EU/EEA: European Data Protection Board (EDPB) — contact your national data protection authority.
  • UK: Information Commissioner's Office (ICO) — 0303 123 1113 or email [email protected]

For CCPA/CPRA complaints: You may file a complaint with the California Attorney General or other applicable state attorney general.

TermsPrivacyCookiesDMCAAcceptable Use§2257Content Removal