

Privacy Policy
Last updated: September 1, 2026
O'llo helps you remember the people in your life and the right time to say hello. This policy explains what information we collect, how we use it, which providers help operate the service, and how you can contact us about your data.
Information we collect
When you sign in with Google, Apple, or another supported provider, we may receive basic account information such as your name, email address, provider identifier, and profile image if the provider supplies it. Apple may provide name and email only on first consent, and you may choose Hide My Email. We store an encrypted Apple refresh token so the connection can be revoked.
When you use O'llo, you may add information about people in your network, including names, relationship context, birthdays, workplaces, locations, notes, groups, reminders, interaction history, avatars, availability poll responses, venue preferences, and appointment details.
If you create or share an availability poll, people who receive the public poll link may submit display names, availability, and venue votes without creating an O'llo account.
You can connect up to two Google Calendar accounts. O'llo may read titles, start and end times, all-day status, busy/free status, and Google Meet links from calendars you select so it can display schedules and block busy poll slots, and create Calendar events with Meet links through the account you choose. O'llo stores each account email, calendar names and selection state, granted scopes, and an encrypted refresh token, but does not store external Google event descriptions or Meet links.
Connecting iPhone Calendar is optional. Events from every calendar available to O'llo are merged with O'llo events on the device by default. When a Live Activity is shown, its Activity push token, start and end times, and anonymous event identifier are stored on the server so it can be ended. If you enable Automatic Live Activities, event titles, locations, and reservations up to 30 days ahead are also sent to the server so activities can start after the app closes and show travel guidance; notes and attendees are not sent. If you enable birthday notifications, O'llo stores the APNs device token, app language, and iPhone time zone and uses saved birthdays and time zones to schedule alerts.
If you enable Calendar weather, O'llo rounds your current location to approximately 1 km before requesting a 10-day forecast from Google Weather. Coordinates and forecasts are not stored in O'llo's database or persistent device storage; only whether weather is enabled on that device is stored.
If you import from Google Contacts, O'llo may read contact names, email addresses, phone numbers, and birthdays for preview and selected import. Google Contacts import is optional; only the people you choose are saved in O'llo, and no one is notified or invited.
If you explicitly enable O'llo News, OneSignal may process your Supabase user ID, app language, device push subscription status, and notification delivery and open events. O'llo does not send OneSignal people's names, contacts, birthdays, relationship records, calendar content, or location.
If you use a RevenueCat web Funnel, RevenueCat and Stripe may process your selected responses, funnel progress and conversion events, checkout email, and transaction information. Anonymous purchases are linked to your app account through a one-time redemption link that is valid for 60 minutes.
When the native app uses the RevenueCat SDK, your Supabase user ID is sent as the RevenueCat App User ID, and RevenueCat may process App Store product information, purchase and restore results, subscription and Pro entitlement status, and app or device metadata required to operate the SDK. O'llo does not send RevenueCat people, contacts, relationship records, or calendar contents.
How we use information
We use your information to provide authentication, store your relationship records, calculate reminders, show your network, coordinate availability polls, recommend places, manage billing, respond to feedback, and improve reliability.
If AI features are enabled, relevant context may be sent to OpenAI to draft suggested messages, outreach drafts, summaries, or gift ideas. AI features are optional and are not required to use core relationship tracking.
If you connect Google Calendar or request place recommendations, relevant calendar, location, search, venue, and meeting information may be processed to provide those features. Google Calendar event data is used to show schedules, detect time conflicts, and create Calendar events with Meet links for online appointments; it is not used for advertising.
If Calendar weather is enabled, the rounded current location is used only to display a 10-day Google Weather forecast and is not used for advertising.
iPhone event data is used only to show calendars and widgets, end Live Activities, and, when enabled by the user, automatically show Live Activities even after the app is closed. Birthdays, time zones, and APNs device tokens are used only to send birthday notifications the user enables. They are not used for advertising.
If you import from Google Contacts, contact information is used only to show a preview, identify possible duplicates, and create the people you select.
OneSignal data is used only to send O'llo News you separately enable and to measure delivery and opens. Operational birthday, travel, and Live Activity notifications continue to use separate delivery paths.
RevenueCat payment information is used only for App Store purchase and restore, linking web purchases, checking subscription status, synchronizing cross-platform Pro entitlement, and payment support.
Google user data sharing and Limited Use
O'llo may process Google user data with the following service providers only as needed to provide the service. Supabase stores the Google account email, encrypted Calendar connection token, and short-lived Contacts preview sessions; Neo4j stores contacts the user selects to import as O'llo person records; and Vercel hosts the O'llo application and server requests.
When a user directly invokes an optional AI feature for a person saved from Google Contacts, the minimum relevant person context, such as a name or birthday, may be sent to the OpenAI API to create a message draft, recipient recommendation, or gift idea. Google OAuth tokens, the raw Contacts list, phone numbers, email addresses, and Google Calendar event data are not sent in OpenAI prompts.
O'llo disables application storage for its OpenAI API requests and does not use or permit Google user data to be used to develop, improve, or train generalized AI or ML models. OpenAI does not use API data for model training unless a customer explicitly opts in, but it may retain abuse-monitoring logs for up to 30 days to protect its services.
O'llo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used or transferred for advertising, retargeting, creditworthiness, lending, data brokerage, sale, or unrelated purposes.
Service providers
O'llo uses third-party infrastructure providers such as Supabase for authentication, structured data, and storage; Neo4j for relationship graph data; OpenAI for optional AI features; Stripe for web checkout and subscription management; RevenueCat for App Store purchase and restore, cross-platform Pro entitlements, and web Funnels; OneSignal for O'llo News push notifications you enable; Apple App Store for in-app payments; Google services for OAuth, Calendar, Meet, Contacts, Maps/Places, and Weather features; Kakao for supported sign-in or client integrations where enabled; and Vercel for hosting and analytics.
These providers process information only as needed to operate O'llo and related services.
Data protection
O'llo uses HTTPS when transmitting Google user data over external networks and encrypts Google Calendar refresh tokens at rest with AES-256-GCM. OAuth client secrets and encryption keys are managed only on the server.
Live Activity push tokens, iPhone event titles used for background auto-start, and APNs device tokens for birthday notifications are encrypted at rest with AES-256-GCM using a separate server key and protected by Supabase Row Level Security and server-only access. Live Activity push tokens are deleted after ending or cancellation. Birthday notification reservations do not store person names; names are resolved only at delivery time.
Stored Google connection information and Contacts preview sessions are protected through authentication, ownership checks, per-user access restrictions, and Supabase Row Level Security. Google Contacts access tokens are used only during the import request and are not stored.
AI features have no tool permission to operate a Google account or Calendar, and generated results are returned only as drafts for the user to review. O'llo limits data access to personnel and service providers that need it to operate the service.
Cookies and analytics
O'llo may use essential cookies, browser storage, or app storage to keep you signed in, protect your account, verify sessions, and provide the service.
O'llo may use Vercel Analytics to understand usage statistics such as visitors, page views, referrers, browsers, operating systems, and countries. Vercel Web Analytics does not use cookies and provides analytics in an aggregated and anonymized way.
Supabase and Vercel may process operational data such as request logs, user agents, IP-based location information, and response status codes for authentication, API request handling, error analysis, security, and service reliability.
Data retention and deletion
Google Calendar events are retrieved on demand for display and conflict detection, and external event descriptions are not stored. Account email, calendar metadata and selection state, granted scopes, and encrypted refresh token are retained while that account remains connected. Disconnecting one account deletes its connection, token, and calendar selections and stops synchronization for that account.
Calendar weather coordinates and forecasts are processed in memory only while requesting and displaying the forecast and are not retained in a database, server or CDN cache, or persistent device storage.
iPhone event reservations cover at most the next 30 days. Event titles are removed after delivery and reservation identifiers are deleted 24 hours after the event ends. Birthday notification reservations are deleted 24 hours after their delivery time. Device registrations for either feature are deleted after 45 days without synchronization, and turning off a feature or signing out removes that device registration and its unsent reservations.
Google Contacts access tokens are not stored. Contact preview sessions expire after 30 minutes and are deleted by daily maintenance within 24 hours after expiration. Contacts the user does not select are not saved as O'llo person records.
Turning off O'llo News opts the device out of OneSignal push and stops future product-news messages. RevenueCat and OneSignal transaction or delivery records may be retained as needed for payments, security, dispute handling, and each provider's retention policy.
Contacts the user selects to import and Calendar or Meet identifiers and links created by O'llo are retained while the related person or appointment record is provided. Users can update or delete people, groups, reminders, polls, appointment details, and interaction records from inside O'llo where those controls are available.
You can immediately and permanently delete your account from settings on the web or in the native app. Deletion removes account data, Google connections, Sign in with Apple authorization, the RevenueCat customer, and the OneSignal user record from active systems and deletes the Stripe customer, subscription, and saved payment methods when present. The app cannot cancel an App Store subscription; manage it separately in Apple subscription settings because billing may continue after account deletion. Limited backups, payment records, and security logs may be deleted later according to legal and service-provider retention periods. Contact us below to request a data export.
Because another device or delayed payment processing can recreate the same external identifier and Stripe subscription during deletion, O’llo temporarily retains only the Supabase user UUID in a server-only deletion queue until late Stripe customer and subscription cleanup and RevenueCat and OneSignal re-deletion all succeed. The queue stores no other personal information such as email, contacts, relationship or calendar content, and no raw provider payloads or error details. The first re-deletion becomes eligible one hour after completion and runs with daily maintenance, which can add up to about 24 hours of scheduling delay; failures are retried until success, after which the UUID record is removed.
Contact
For privacy questions or data requests, contact: jaewon.moon@mail.mcgill.ca.