allographallograph
How it worksGroupsCollectionsPartners

Legal

Privacy Policy

Effective July 25, 2026Atriumn Inc.

1. Introduction

Welcome to allograph. Atriumn Inc. ("allograph", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and related services (collectively, the "Service").

Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use the Service.

This Privacy Policy is incorporated into and subject to our Terms of Service. Any capitalized terms not defined here have the meanings given in the Terms of Service.

2. Information We Collect

We collect several types of information from and about users of our Service:

2.1 Information You Provide to Us

Account Information: When you create an account, we collect:

  • Email address
  • Password (encrypted)
  • Display name (optional)
  • Profile photo (optional)
  • Age information used only to determine your eligibility and access tier under our age rules (for example, a declared date of birth or age band). This is age-assurance data and is handled under our age-data firewall — see Section 7.

Authentication via Third-Party Services: If you sign in using Apple Sign-In or other third-party authentication services, we receive:

  • Your name and email address from the authentication provider
  • A unique identifier from the authentication provider
  • Profile photo (if provided by the authentication service)

User Content: We collect content you create, upload, or share on the Service, including:

  • Photos and images you upload
  • Drawings and overlays you create
  • Comments and interactions with other users
  • Metadata associated with your content (timestamps, device information, etc.)

Communications: If you contact us, we collect your name, email address, message content, and any attachments you send.

2.2 Information Collected Automatically

Usage Data: We automatically collect information about your interaction with the Service:

  • Device information (device type, operating system, a first-party app install identifier, and — if you enable notifications — a push notification token)
  • App usage data (features used, time spent, frequency of use)
  • IP address, processed transiently to serve requests. For anonymous web submissions we additionally retain a one-way hashed (pseudonymized) form of the IP for abuse rate-limiting only, deleted within 24 hours; raw IP addresses are never stored for that purpose
  • Approximate location signals you generate by using place features (for example, the general market/city your app last reported, used to show relevant local marks)
  • Browser type and version (for web users)
  • Crash and diagnostic reports provided by Apple and Google's platform services, subject to your device settings

Cookies and Tracking Technologies: We use only strictly-necessary, first-party cookies and similar local storage for authentication and session management. We do not use advertising trackers, web beacons for behavioral profiling, or any cross-app or cross-site tracking technologies. See Section 10 for details.

Analytics: We use only privacy-preserving, first-party, aggregated product analytics to understand how features are used and to keep the Service reliable. Raw analytics events are automatically deleted after 90 days. We do not use third-party analytics or advertising SDKs, and our analytics never include age-assurance data (see Section 7).

2.3 Automated Content Moderation

Safety screening: Photos and drawings you submit are automatically screened for prohibited content (for example, adult or violent imagery) using Google Cloud Vision SafeSearch before they can appear to other users. The image is sent to that service solely to produce a safety verdict; it is not used by us to train AI models or build profiles about you.

Generative AI: We do not send your content to generative AI services. Illustrative example images that appear on some surfaces are generated from our own materials, are never presented as user content, and are labeled as examples.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 To Provide and Maintain the Service

  • Create and manage your account
  • Process your drawings, photos, and overlays
  • Store and display your User Content
  • Provide customer support
  • Send you service-related notifications

3.2 To Improve and Develop the Service

  • Analyze usage patterns to improve features
  • Develop new features and functionality
  • Conduct first-party research and analytics

3.3 To Personalize Your Experience

  • Recommend content and features
  • Customize your user interface
  • Remember your preferences and settings

3.4 For Security and Fraud Prevention

  • Detect and prevent fraudulent activity
  • Monitor for security threats
  • Enforce our Terms of Service
  • Comply with legal obligations

3.5 For Marketing and Communications (with your consent)

  • Send promotional emails and notifications
  • Present sponsored marks and contextual local offers based on the place you chose to engage with — not on behavioral targeting or profiling. See Section 3A for how our presence-based advertising works.
  • Announce new features and updates

3.6 For Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and prevent harm
  • Protect our rights and property

3A. Advertising & No Tracking

allograph is ad-supported, but it is not a surveillance advertising platform. This section consolidates our advertising and tracking commitments in one place.

3A.1 Presence- and Context-Based Advertising

Our advertising is based on real-world presence and context — the place you chose to engage with — not on who you are or what you do across the internet. When a business sponsors a mark or offers a contextual local deal, it reaches people because they showed up at or engaged with a real place, in the moment. We do not perform behavioral profiling, build advertising profiles about you, engage in cross-app or cross-site tracking, or participate in real-time bidding.

3A.2 No Third-Party Tracking or Advertising SDKs

We do not embed third-party advertising SDKs, third-party analytics SDKs, or cross-app tracking technologies in our apps. We do not sell or share your personal information for cross-context behavioral advertising. Any product analytics we run are first-party, privacy-preserving, and aggregated.

3A.3 Age-Data Firewall

Age-assurance data (such as a declared age band or a platform age signal) is siloed in a separate gating store and is used only to determine eligibility and comply with age laws. It is neverused for advertising, marketing, profiling, or analytics. See Section 7 for details on our age-assurance approach.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 With Other Users

When you share User Content publicly on allograph, other users can view, share, and download your content according to your sharing settings. Your profile information (display name, profile photo) is visible to other users when you interact with them.

4.2 With Service Providers

We share your information with third-party service providers who perform services on our behalf:

  • Supabase: Database, authentication, and storage services
  • Vercel: Website hosting
  • Apple:Authentication (Sign in with Apple), push notifications (APNs), and — where you allow it — the Declared Age Range signal used for age assurance
  • Google: Authentication (Google Sign-In on Android), push notifications (Firebase Cloud Messaging), automated content-safety screening (Cloud Vision SafeSearch, Section 2.3), and map embeds on our website

These service providers have access to your personal information only to perform specific tasks on our behalf and are obligated not to disclose or use it for other purposes.

4.3 For Legal Reasons

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders, etc.)
  • Requests from law enforcement or government agencies
  • Situations involving potential threats to public safety
  • Protection of our rights, property, or safety

4.4 Business Transfers

If Atriumn Inc. is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership.

4.5 With Businesses That Sponsor Marks

When a business sponsors a mark or offers a local deal, we report on that mark’s activity in aggregate only— for example, how many people participated, on which days, how many returned, and how many offers were redeemed. Sponsors do not receive your name, your account, your contact information, your location history, or your photos.

Two things reach a business only because you choose them: if you redeem an offer, that business necessarily sees that a redemption happened at their location; and if you explicitly opt in to share a specific photo with a business or event, that photo is shared. Both are actions you take deliberately, and neither carries your broader history with it.

Accounts in our restricted 13–15 tier are never included in anything beyond simple totals, and never in any breakdown. We do not sell your personal information to sponsors, and sponsors cannot export raw activity data — they see reports, not records.

4.6 With Your Consent

We may share your information for any other purpose with your explicit consent.

5. Data Retention

Active Accounts: We retain your personal information for as long as your account is active or as needed to provide you with the Service.

Deleted Accounts: When you delete your account, we delete your personal information within 90 days, except:

  • Information required for legal compliance, dispute resolution, or enforcement of our agreements may be retained for up to 7 years
  • Backup copies may be retained for up to 90 days for technical recovery purposes
  • User Content that other users have shared or downloaded may remain accessible

Usage Data and Analytics: Raw first-party analytics events are deleted automatically after 90 days. We may retain aggregated, anonymized statistics (which no longer identify you) beyond that for analytics and research purposes.

Abuse-prevention data: Pseudonymized (hashed) IP records used to rate-limit anonymous submissions are deleted within 24 hours.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

6.1 General Rights (All Users)

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal exceptions)
  • Data Portability: Request a copy of your data in a common machine-readable format by emailing privacy@ovrly.co
  • Opt-Out: Opt out of marketing communications at any time

6.2 California Residents (CCPA/CPRA Rights)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collected, the sources, purposes, and third parties we share it with
  • Right to Delete: Request deletion of personal information we collected from you
  • Right to Opt-Out of Sale: We do not sell personal information. If we ever do, you can opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
  • Right to Limit Use of Sensitive Personal Information: Request limits on use of sensitive personal information

6.3 European Residents (GDPR Rights)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Obtain confirmation of processing and access to your personal data
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restriction: Request restriction of processing
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

6.4 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@ovrly.co or through the app settings. We will respond to your request within 30 days (or as required by applicable law).

Identity Verification: For your security, we may need to verify your identity before processing your request.

7. Age Requirement & Children's Privacy

Minimum Age: You must be at least 13 years old to create an account. Where local law sets a higher minimum age (for example, 16 in some countries and regions), that higher age applies and accounts below it are not permitted.

Ages 13–15 — the restricted experience:Users aged 13–15 receive a restricted version of the Service designed for safety:

  • Their content is never publicly visible— it can be shared only within private groups they join (for example, a classroom or family group)
  • Location-based features are disabled — no location discovery, no place-based marks, and therefore no sponsored local offers
  • Where required by applicable law, a parent or legal guardian must approve the account before the teen can participate. Approval works through a secure, expiring email link sent to the parent; participation is blocked server-side until approval. Parents can review or revoke their consent at any time by contacting privacy@ovrly.co

Ages 16 and up receive the full Service.

7.1 How We Assure Age

We use a layered, risk-based approach to determine your age tier:

  • Self-declaration:You tell us your date of birth at sign-up through a neutral age screen. Declarations below your region's minimum age are blocked from creating an account, and repeat attempts to re-declare a different age are refused.
  • Platform age signals:Where available, we use Apple's Declared Age Range and Google Play's Age Signals, which return an age band (not a birthdate), to help confirm eligibility.

7.2 Age-Data Firewall

Age-assurance data — including any declared age band and any platform age-signal band — is stored in a separate gating store and is used only to gate access and comply with age laws. It is never used for advertising, marketing, profiling, or analytics, and it never enters our advertising or analytics systems. This boundary is architecturally enforced.

7.3 Children Under 13 (COPPA)

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13, consistent with the Children's Online Privacy Protection Act (COPPA). Declarations under 13 are permanently blocked from creating an account. If we discover that we have collected personal information from a child under 13, we will delete that information promptly. If you are a parent or guardian and believe a child under 13 has provided us with personal information, please contact us at privacy@ovrly.co.

7.4 Minors Under 18

If you are under 18 (or the age of majority in your jurisdiction), you should review this Privacy Policy with your parent or legal guardian to ensure you both understand your rights.

8. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

8.1 Security Measures

  • Encryption: Data in transit is encrypted using TLS/SSL. Data at rest is encrypted using industry-standard encryption services.
  • Access Controls: We restrict access to personal information to employees, contractors, and agents who need access to perform their job functions.
  • Authentication: We use secure authentication mechanisms, including OAuth 2.0.
  • Monitoring: We monitor our systems for security threats and vulnerabilities.
  • Regular Audits: We conduct regular security audits and assessments.

8.2 Your Responsibility

You are responsible for maintaining the security of your account credentials. Use a strong, unique password and do not share it with others. Notify us immediately if you suspect unauthorized access to your account.

8.3 No Guarantee

While we strive to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

9. International Data Transfers

Your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from your country.

Safeguards: When we transfer data internationally, we use appropriate safeguards such as:

  • Standard Contractual Clauses approved by regulatory authorities
  • Data Processing Agreements with our service providers
  • Compliance with applicable data protection frameworks

10. Cookies and Tracking Technologies

10.1 What Are Cookies?

Cookies are small text files placed on your device. We use only strictly-necessary, first-party cookies and similar local storage — primarily to keep you signed in and to maintain your session. We do not use advertising cookies, web beacons or pixels for behavioral profiling, or any cross-app or cross-site tracking technologies.

10.2 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function (session management, authentication)
  • Preference Storage: Remembers your settings and preferences

We do not use advertising or third-party tracking cookies, and we do not embed third-party advertising or analytics SDKs. See Section 3A for our full advertising and no-tracking commitments.

10.3 Managing Cookies

You can control cookies through your browser settings. However, disabling strictly-necessary cookies may affect your ability to sign in or use certain features of the Service.

  • Browser Settings: Most browsers allow you to refuse cookies or delete cookies
  • Do Not Track:Because we do not track you across apps or sites for advertising, there is no cross-site tracking for a "Do Not Track" signal to disable.

11. Third-Party Links and Services

The Service may contain links to third-party websites, applications, and services that are not operated by us. This Privacy Policy does not apply to third-party services.

We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you interact with.

11.1 Social Media Integrations

When you connect social media accounts or share content to social platforms (YouTube, Instagram, TikTok, X/Twitter, Reddit, Snapchat), those platforms' privacy policies apply to the information they collect.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

12.1 Notification of Changes

If we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on this page
  • Updating the "Effective Date" at the top of this policy
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice within the app

12.2 Your Acceptance

Your continued use of the Service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you must stop using the Service and may delete your account.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Atriumn Inc.

2669 Haddassah Dr

Naperville, IL 60565

United States

Email: privacy@ovrly.co

Phone: (312) 282-9879

For privacy-related inquiries, please use privacy@ovrly.co. For general legal matters, you may contact legal@ovrly.co.

14. Summary of Key Points

This summary provides an overview of key points in our Privacy Policy. Please read the full policy for complete details.

What We Collect

Account info, User Content (photos, drawings), usage data, device info

How We Use It

Provide Service, improve features, personalize experience, security

Who We Share With

Other users (public content), service providers, legal authorities

Your Rights

Access, correct, delete your data; CCPA & GDPR rights; opt out of marketing

Data Security

Encryption, access controls, regular security audits

Advertising & Tracking

Presence- and context-based ads only; no behavioral profiling, no cross-app tracking, no third-party ad or analytics SDKs

Age & Children's Privacy

13+ minimum (higher where law requires); ages 13–15 get a restricted, groups-only, no-location experience with parental consent where required; age data siloed and never used for ads or analytics; not directed to children under 13 (COPPA)

allographallograph
  • How it works
  • Groups & families
  • Partners
  • Support
  • Privacy
  • Terms
© 2026 allograph. All rights reserved.