Privacy Policy
Last updated: 2026-06-12
This policy describes how Ovriven collects, uses, and shares your data. We follow GDPR and CCPA principles regardless of where you live.
Data we collect
- Account information (email, display name, optional profile fields).
- Workspace data (simulations, source materials, knowledge corpus).
- Usage telemetry (pages visited, runs created — anonymized at aggregate).
- Payment metadata (held by Stripe; we never see card numbers).
- Session metadata (IP, user-agent — for security only, retained 30 days).
How we use it
- To run simulations you request and surface the results back.
- To bill you accurately + recover failed payments.
- To detect abuse, fraud, and product bugs.
- To send transactional email (verification, security, payment failures).
Subprocessors
We share data only with vetted subprocessors. The complete, authoritative list — with the category of data each one processes — is maintained at /sub-processors. Each is bound by a Data Processing Agreement that meets GDPR Article 28 requirements, and we notify customers before adding a new subprocessor.
Your rights
- Access — download all your data anytime from Account → Privacy.
- Erasure — delete your account anytime from Account → Privacy.
- Rectification — edit any profile field from your public Profile or Account.
- Portability — your data export is provided as machine-readable JSON.
- Objection — contact privacy@ovriven.com to object to specific processing.
Cookies & tracking
Essential — a single session cookie for authentication (pu_session) and per-user localStorage for UI preferences (language, theme, pinned items, recently viewed). These are required for the product to work and carry no tracking.
Analytics (opt-in) — with your consent, we store a first-party anonymous identifier (pu_anon_id) in your browser and record a small set of product events (e.g. landing-page view, signup started). No events are sent and no identifier is created unless you allow the Analytics category in the cookie banner; withdrawing consent removes the identifier immediately.
Marketing — we use no marketing or third-party advertising cookies at all.
You can change your choices anytime via "Cookie preferences" in the site footer or under Account → Privacy.
Retention
How long each category of data lives, and what removes it:
- Simulation results and the inputs you provide — retained until you delete them. Deleted simulations sit in your Library trash (restorable by you) before permanent removal. Team workspaces can additionally set an automatic retention policy (archive after N days, permanently delete after M days) under Workspace → Retention; when set, the policy is enforced by a scheduled sweep.
- Uploaded source materials — removed (including the stored file object) when you delete them individually or in bulk. Simulations that already used a material keep their saved text excerpts.
- Account data — retained while your account is active. Deletion requests start a 30-day grace window by default (you can shorten it to as little as 0 days or extend to 90 in the request); after the window your account and the data in your personal workspace are permanently deleted.
- Audit and security logs — administrative audit records are retained for compliance and tamper-evidence; session metadata (IP, user-agent) is retained 30 days for security only.
- Payment records — card data is held by Stripe under its own retention policy; we retain local transaction records (purchases, refunds, credit ledger entries) for accounting and audit purposes.
- Backups — encrypted database backups are rotated automatically; deleted data ages out of the backup set as old archives are pruned.
Questions? Email privacy@ovriven.com.