Privacy Policy

Last updated 31 July 2026 · Version 1.0

ovrl is a self-serve event photo generator. Event organizers upload a design; attendees add their own photo and receive a branded image they can share. This policy explains what we collect, why, and what you can ask us to do about it.

ovrl is operated from Nigeria by an individual sole trader, and is subject to the Nigeria Data Protection Act 2023 (NDPA). Where we handle data belonging to people in the EU or UK, we also apply the GDPR and UK GDPR. In this policy, “we” and “us” mean the operator of ovrl, who is the data controller for the processing described here.

The most important thing

Attendee photos are processed entirely in your browser. When you add a photo to generate an event image, that photo is composited on your own device using a canvas element. It is never uploaded to our servers and we never receive or store it.

There are exactly two exceptions, and both require an explicit choice:

  • The public wall. If an organizer has enabled the event wall and you switch on “Add my photo to the public event wall”, your finished image is uploaded to our storage and displayed publicly on that event’s wall page. That toggle is off by default.
  • Background removal. If an organizer has enabled it, your photo is sent to remove.bg to have its background removed, then returned to your browser. See below.

What we collect

If you create an organizer account:

  • Your name and email address
  • A securely hashed password — we never store it in plain text
  • Session data so you stay signed in
  • Events you create: name, date, description, uploaded design, and settings
  • Emails we send you, such as verification and password reset messages

If you are an attendee using an event link:

  • No account, no name, no email. You are not asked to identify yourself and we do not track you across events.
  • Anonymous usage counts so organizers can see how their event performed: how many images were generated, how many were downloaded, and which platforms were shared to. These records are not linked to any individual.
  • Your IP address, used transiently for rate limiting to prevent abuse. It is held only for the short life of the rate-limit window and is not stored alongside your activity.
  • Your finished image — only if you opt in to the public wall, as described above.

Optional background removal

If an organizer enables AI background removal, your photo is transmitted to remove.bg (Kaleido AI GmbH, Austria), which removes the background and returns the result to your browser. We do not retain a copy. This is the only circumstance in which an un-composited photo leaves your device, and it happens only when the organizer has turned the feature on. If it is disabled, no photo ever leaves your browser.

Lawful basis for processing

Under the NDPA and, where applicable, the GDPR, we rely on the following bases:

  • Contract — to operate your organizer account and run the events you create
  • Consent — to publish an attendee image on a public wall, and to send a photo for background removal. Consent can be withdrawn at any time by contacting us
  • Legitimate interests — rate limiting, abuse prevention, and anonymous aggregate analytics, balanced against the limited data involved
  • Legal obligation — where we must retain or disclose data to comply with law

How we use data

  • To operate your account and the events you create
  • To send transactional email such as verification and password resets
  • To show organizers anonymous, aggregate analytics about their events
  • To prevent abuse through rate limiting
  • To display wall images, where an attendee has explicitly opted in

We do not sell your data. We do not use it for advertising. We do not build profiles of attendees, and we do not carry out automated decision-making that produces legal or similarly significant effects.

Who we share data with

We use a small number of processors to run the service. Each receives only what it needs:

  • Railway — hosting, database, and object storage. Data shared: all account, event, and wall data. Privacy policy
  • Resend — transactional email delivery. Data shared: your email address and message contents. Privacy policy
  • remove.bg — background removal, only when an organizer enables it. Data shared: the attendee photo being processed. Privacy policy

We may also disclose data where required by law, to enforce our terms, or to protect the rights and safety of our users.

Where data is stored

Account data, event records, and analytics are stored in a PostgreSQL database. Rate-limit counters are held briefly in Redis. Uploaded designs and opted-in wall images are stored in S3-compatible object storage. All are hosted on Railway infrastructure in the United States.

If you are in the EU, UK, or Nigeria, this means your data is transferred outside your country. For EU and UK data we rely on Standard Contractual Clauses with our processors as the transfer mechanism. For Nigerian data, transfers are made on the basis of adequate contractual safeguards as contemplated by the NDPA.

Security

All traffic is served over HTTPS. Passwords are hashed, never stored in plain text. Access to production data is limited to those who need it to operate the service. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable measures appropriate to the sensitivity of what we hold — which, for attendees, is deliberately close to nothing.

Cookies

We set only what the service needs to function: a session cookie when you sign in as an organizer, and the security tokens that protect forms. We do not use advertising cookies, tracking pixels, or third-party analytics, so there is no consent banner to dismiss. If you browse an event link as an attendee, no cookie identifies you.

Retention

  • Account and event data — kept until you delete the event or your account
  • Wall images — kept until the associated event is deleted or a removal request is made
  • Anonymous analytics — may be retained in aggregate after an event is removed, as they no longer identify anyone
  • Rate-limit records — expire automatically within minutes

Your rights

Under the NDPA, and under the GDPR or UK GDPR where they apply, you may have the right to access, correct, export, or delete your personal data, to restrict or object to processing, and to withdraw consent at any time. To exercise any of these, email us at the address below. We aim to respond within 30 days.

Wall image removal: if you appear in a photo on a public event wall and want it taken down, contact us and we will remove it. You do not need an account to make this request, and we will not ask you to justify it.

If you believe we have mishandled your data, you may complain to the Nigeria Data Protection Commission. If you are in the EU or UK, you may instead complain to your local supervisory authority.

Children

ovrl is not directed at children under 13, and we do not knowingly collect their data. If an event’s audience includes children, organizers are responsible for obtaining any consent their jurisdiction requires before attendees submit photos to a public wall.

Changes to this policy

We may update this policy as the service changes. The “last updated” date above will always reflect the current version, and we will give notice of material changes to account holders by email.

Contact

For any privacy question, data request, or wall image removal, email hello@ovrl.pics.