Privacy Policy
Last updated: July 19, 2026
Information We Collect
OverlayPhoto is designed with your privacy in mind. We collect minimal data necessary to provide and improve our services:
- Camera & Photo Access: OverlayPhoto accesses your device camera only after permission is granted. Native captures and browser-selected photos are processed on-device. Choosing Share hands the resulting file to the operating system's share sheet; it does not upload the file to an OverlayPhoto server.
- Account Information: If an available sign-in method is used, we receive the account information needed for identification. Unverified purchase management is not enabled in this release.
- Website Analytics: The website uses self-hosted Plausible Analytics for aggregate page and feature events. The current native app does not transmit its internal feature-event log; those events remain local debug output.
- Diagnostics: The website may send technical runtime errors to our self-hosted error monitor when it is configured. Selected photos are not attached. The current native app does not include a remote crash-reporting SDK.
- Advertising: Advertising is not enabled in the current web or unreleased native experience. Any future advertising flow will be disclosed only after consent, premium suppression, and provider evidence are verified.
- Purchases: Paid access and in-app purchases are not enabled in this release. No purchase provider lifecycle is presented as active.
How We Use Information
- To provide and maintain the OverlayPhoto service
- To manage available account state
- To understand aggregate website usage and diagnose configured website runtime errors
- To operate only the release features that are currently available
Browser Storage & Offline Access
The web app stores your language and theme preferences in browser storage. If you sign in, authentication tokens are also kept in browser storage so the session can be restored. You can remove that local state by signing out and clearing site data in your browser.
OverlayPhoto's service worker caches only versioned public code, icons, the web manifest, and a generic offline page. It does not cache photos, account pages, authenticated API responses, or cross-origin requests. Old OverlayPhoto cache versions are removed when the service worker is upgraded.
Data Retention
Photos are stored locally on your device. Account data is retained while your account is active. You can start an authenticated deletion request from app settings or the account deletion page. Those controls fail closed: they do not report deletion unless the protected account service accepts the request. Until that backend route is enabled, the account remains active; contacting support is not presented as completed deletion.
Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and data
- Request information about the data associated with an available account
- Use the local-device export in mobile Settings only when it is visible in a signed mobile release. That JSON export covers local settings, recipes, streaks, and gallery metadata; it excludes photos, file paths, account/server data, authentication, purchases, and advertising identifiers.
- Request a protected account or server-data export only after that separate control is released and verified. It is not available in the current public browser release.
Contact Us
If you have questions about this privacy policy, contact us at support@overlayphoto.com