

Privacy Policy
Last updated: July 20, 2026
O'llo helps you remember the people in your life and the right time to say hello. This policy explains what information we collect, how we use it, which providers help operate the service, and how you can contact us about your data.
Information we collect
When you sign in with Google or another supported provider, we may receive basic account information such as your name, email address, provider identifier, and profile image if the provider supplies it.
When you use O'llo, you may add information about people in your network, including names, relationship context, birthdays, workplaces, locations, notes, groups, reminders, interaction history, avatars, availability poll responses, venue preferences, and appointment details.
If you create or share an availability poll, people who receive the public poll link may submit display names, availability, and venue votes without creating an O'llo account.
If you connect Google Calendar, O'llo may read calendar event titles, start and end times, all-day status, and busy/free status so it can display your calendar and block busy slots while you create availability polls, and create Calendar events with Meet links when you confirm online appointments. O'llo stores an encrypted Google refresh token so you can stay connected, but it does not store external Google event descriptions by default.
If you import from Google Contacts, O'llo may read contact names, email addresses, phone numbers, and birthdays for preview and selected import. Google Contacts import is optional; only the people you choose are saved in O'llo, and no one is notified or invited.
How we use information
We use your information to provide authentication, store your relationship records, calculate reminders, show your network, coordinate availability polls, recommend places, manage billing, respond to feedback, and improve reliability.
If AI features are enabled, relevant context may be sent to OpenAI to draft suggested messages, outreach drafts, summaries, or gift ideas. AI features are optional and are not required to use core relationship tracking.
If you connect Google Calendar or request place recommendations, relevant calendar, location, search, venue, and meeting information may be processed to provide those features. Google Calendar event data is used to show schedules, detect time conflicts, and create Calendar events with Meet links for online appointments; it is not used for advertising.
If you import from Google Contacts, contact information is used only to show a preview, identify possible duplicates, and create the people you select.
Google user data sharing and Limited Use
O'llo may process Google user data with the following service providers only as needed to provide the service. Supabase stores the Google account email, encrypted Calendar connection token, and short-lived Contacts preview sessions; Neo4j stores contacts the user selects to import as O'llo person records; and Vercel hosts the O'llo application and server requests.
When a user directly invokes an optional AI feature for a person saved from Google Contacts, the minimum relevant person context, such as a name or birthday, may be sent to the OpenAI API to create a message draft, recipient recommendation, or gift idea. Google OAuth tokens, the raw Contacts list, phone numbers, email addresses, and Google Calendar event data are not sent in OpenAI prompts.
O'llo disables application storage for its OpenAI API requests and does not use or permit Google user data to be used to develop, improve, or train generalized AI or ML models. OpenAI does not use API data for model training unless a customer explicitly opts in, but it may retain abuse-monitoring logs for up to 30 days to protect its services.
O'llo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used or transferred for advertising, retargeting, creditworthiness, lending, data brokerage, sale, or unrelated purposes.
Service providers
O'llo uses third-party infrastructure providers such as Supabase for authentication, structured data, and storage; Neo4j for relationship graph data; OpenAI for optional AI features; Stripe for web paid plan checkout, subscription, and billing management; Apple App Store for in-app subscription purchase and restore; Google services for OAuth, Calendar, Meet, Contacts, and Maps/Places features; Kakao for supported sign-in or client integrations where enabled; and Vercel for hosting and analytics.
These providers process information only as needed to operate O'llo and related services.
Data protection
O'llo uses HTTPS when transmitting Google user data over external networks and encrypts Google Calendar refresh tokens at rest with AES-256-GCM. OAuth client secrets and encryption keys are managed only on the server.
Stored Google connection information and Contacts preview sessions are protected through authentication, ownership checks, per-user access restrictions, and Supabase Row Level Security. Google Contacts access tokens are used only during the import request and are not stored.
AI features have no tool permission to operate a Google account or Calendar, and generated results are returned only as drafts for the user to review. O'llo limits data access to personnel and service providers that need it to operate the service.
Cookies and analytics
O'llo may use essential cookies, browser storage, or app storage to keep you signed in, protect your account, verify sessions, and provide the service.
O'llo may use Vercel Analytics to understand usage statistics such as visitors, page views, referrers, browsers, operating systems, and countries. Vercel Web Analytics does not use cookies and provides analytics in an aggregated and anonymized way.
Supabase and Vercel may process operational data such as request logs, user agents, IP-based location information, and response status codes for authentication, API request handling, error analysis, security, and service reliability.
Data retention and deletion
Google Calendar events are retrieved on demand for display and conflict detection, and external event descriptions are not stored by default. The Google account email, granted scopes, and encrypted refresh token are retained while Calendar remains connected. Disconnecting Calendar in settings deletes the connection record and token and stops future synchronization.
Google Contacts access tokens are not stored. Contact preview sessions expire after 30 minutes and are deleted by daily maintenance within 24 hours after expiration. Contacts the user does not select are not saved as O'llo person records.
Contacts the user selects to import and Calendar or Meet identifiers and links created by O'llo are retained while the related person or appointment record is provided. Users can update or delete people, groups, reminders, polls, appointment details, and interaction records from inside O'llo where those controls are available.
To request account deletion or data export, contact us at the email address below. Verified account deletion requests are processed to delete account-related data and Google connection information from active systems within 30 days unless longer retention is required for legal, security, or dispute-resolution purposes. Limited backups and security logs may be deleted later according to service-provider retention cycles.
Contact
For privacy questions or data requests, contact: jaewon.moon@mail.mcgill.ca.