Privacy Policy
Last updated: September 2026
OULY City lets you reimagine the places around you – speak a vision, capture a live photo, and watch the place become what it could be. This page explains, in plain terms, what we collect, why, who helps us process it, and the rights you hold over your data under the GDPR.
1. Who we are
The data controller for OULY City is Typeface s. r. o., based in Poprad, Slovakia. We decide how and why your personal data is processed when you use the OULY City app and website. If you have any question about this policy or your data, write to us at info@ouly.city. Our full legal identification – company ID, VAT ID and commercial-register entry – is in the very next section.
2. The operator and how to reach us
The OULY City website and app are operated by Typeface s. r. o., a limited liability company incorporated in Slovakia, which decides how your personal data is processed. Registered office: Nové nábrežie 15021/5, 058 01 Poprad, Slovak Republic. Company ID (IČO): 54372330. Tax ID (DIČ): 2121649981. VAT ID: SK2121649981. Entered in the commercial register – Okresný súd Prešov (Commercial Register), Section Sro, Insert No. 43559/P. You can write to us at info@ouly.city.
- Point of contact for authorities (Digital Services Act, Article 11). Our single point of contact for the European Commission, the European Board for Digital Services and Member State authorities is info@ouly.city. We communicate electronically, in Slovak (SK) or English (EN).
- Point of contact for you (Digital Services Act, Article 12). If you need to reach us directly rather than through the forms in the app, write to that same address info@ouly.city. Here too we communicate electronically, in Slovak (SK) or English (EN), and a person answers you – we do not require you to use automated tools.
- Contact point for terrorist content. We accept removal orders under Article 15(1) of Regulation (EU) 2021/784 electronically at info@ouly.city, around the clock, in Slovak or English.
- Supervisory authority. Our obligations towards you as a consumer are supervised by the Slovak Trade Inspection (SOI) – Inšpektorát SOI pre Prešovský kraj, Obrancov mieru 6, 080 01 Prešov 1, Slovakia. The supervisory authority for personal data protection is the Office for Personal Data Protection of the Slovak Republic – the same authority your right to lodge a complaint below points to.
3. What we collect
We collect only what we need to run OULY City. Specifically:
- Account. Your email address and name, a hashed password (if you sign up with email), OAuth tokens when you sign in with Google or Apple, your profile image, your chosen interface language, the time you confirmed you are at least 16 – our record of the age floor – and, if we have had to act on your account, the ban record: its reason and when it expires. The age record and the ban record are kept for as long as the account exists and are deleted with it.
- Content. The photos you capture – these are live camera captures only, never uploads from your gallery – along with your voice recordings, the transcripts of those recordings, your vision text and pulses.
- Location. The precise GPS coordinates of the visions you submit, and a one-off city “check-in” that tells us which city you are contributing to. On the public web you can also ask us to find where you are – your position (about 11 metres) is then stored in the ouly.geo.user cookie for 180 days so the map opens near you; no account is needed and it is only stored when you ask for it. Location is collected in the foreground only – we never track your location in the background.
- Technical. Your IP address, device and user-agent details, and session information needed to keep you signed in securely.
- Email engagement. When we send you a transactional or bulk email, our email provider records delivery, open and click events so we can confirm delivery and improve reliability.
4. Why we use it & legal basis
Every kind of processing has a lawful basis under the GDPR:
- To provide the service – creating your account, storing your visions, and generating your “after” visions. Basis: performance of a contract.
- To publish your vision – your vision, its photo and its location are public on the city map so other residents can see them. That is the service itself, not a side effect. We never show your name publicly next to a vision – even if you do not choose “anonymous”. Only the admins of the city where you post it and OULY City administrators see it (more in section 8). Basis: performance of a contract.
- To secure & improve it – preventing abuse, fixing bugs, and making the product better. Basis: legitimate interest.
- Emails – confirming your address and telling you when something happens to your vision. Basis: performance of a contract. We send these service emails regardless of whether you agreed to news. We send news (bulk emails) to registered users only with their consent. When you sign up there is an unticked box “I want to receive news from OULY City”; if you tick it, we store the consent together with the time. If you sign up with Google or Apple you do not see the box, so you get no news until you turn it on in your profile in the app or on the ouly.city website. Consent also covers an account whose address you have not yet verified – an administrator can send a campaign to such accounts too, but never without consent. You can withdraw consent at any time with the switch in your profile in the app or on the ouly.city website or with the unsubscribe link that every bulk email carries. Basis: your consent. If you leave your email in a form on the website (for example for news or a city launch), you become an interested person: we store the address, your name if given, the city, the language and the page it came from, and we send you news. Basis: your consent, which you tick in the form; we store it together with the time. Contacts added in bulk from a list of contacts (for example city contacts) and addresses an administrator types in one by one receive a bulk email only when their consent is documented: the record holds the source of the consent (for example a sign-up sheet from an event) and the time we added the address. Without a documented source we store the address but send it no bulk email. After you unsubscribe we send you no further bulk email: we delete your interested-person record and keep only the address on our unsubscribe list so that it stays that way. How long we otherwise keep an interested person’s data is set out in the retention section.
- Minimal analytics – understanding errors and aggregate usage to keep the app stable. Basis: your consent (Art. 6(1)(a) GDPR) – without it we do not start analytics. You can withdraw consent at any time: on the website via “Cookie settings” in the footer, which brings back the cookie bar, and in the app with the “Usage measurement” switch in your profile.
5. Who processes your data
We rely on a small set of subprocessors. Each receives only the data it needs to do its job. Data also reaches city admins – people a city appoints to moderate visions – and OULY City administrators: for a vision in their city they see the author’s name (unless the author chose “anonymous”), and for every new vision they get an email with its title, a link and the author’s name. Content reports reach OULY City moderators by email; one of their mailboxes is a Gmail mailbox, so Google receives them too (more in the section on reporting content). We have signed a data processing agreement with OpenAI and PostHog; the one with Railway is signed on our side and awaiting theirs. Cloudflare, Neon, Vercel, Resend, Trigger.dev, Expo and Forward Email include it in their terms of service. Transfers outside the European Union: with OpenAI, the transfer to the United States relies on the Standard Contractual Clauses in the signed agreement. Google sign-in is handled for users in the European Economic Area by Google Ireland Limited, and for Google Maps the contracting party for EEA customers is also Google Ireland Limited; for Google Maps Platform, transfers outside the EEA rely on Standard Contractual Clauses. The parent company Google LLC in the United States is certified under the EU-U.S. Data Privacy Framework, as is Amazon Web Services (AWS Terrarium) in the United States. Apple sign-in is handled for users in the EEA by Apple Distribution International in Ireland, which bases transfers outside the EEA on Standard Contractual Clauses. Mail you send us is forwarded by Forward Email LLC in the United States, and the transfer relies on the Standard Contractual Clauses in its data processing agreement. Nominatim is run by the OpenStreetMap Foundation from the United Kingdom, which is covered by a European Commission adequacy decision; according to the Foundation, its servers are in the United Kingdom and in other countries. Overpass (overpass-api.de), which receives the coordinates of the place, runs on servers of the German association FOSSGIS. OpenFreeMap is operated by the Hungarian company Hyperknot Software Kft.; it does not say where or with whom its servers run, and it may use Cloudflare as a content delivery network. For the other subprocessors that process data outside the EU, we have not yet documented the transfer mechanism – ask us and we will find out and tell you:
- OpenAI (United States) – voice transcription, the chat assistant, photo analysis, content checks and AI image generation. Your audio, photos, the text of your chat and the address of the vision’s place are processed by OpenAI to create your visions. Our agreement is with OpenAI Ireland Ltd., and the transfer to the United States relies on the Standard Contractual Clauses in it.
- Cloudflare R2 – media storage for your photos and generated images. Note that generated images are served via public URLs.
- Resend – sending transactional and bulk email and tracking delivery. It receives your address, your name if the email contains it, and the content of the email. Our internal notice that a new interested person signed up on the website also goes through Resend.
- Forward Email (United States) – receiving and forwarding mail. Every email you send us at an ouly.city address – including a request to exercise your rights – passes through it, so it receives your email address and the content of the message. It does not store forwarded mail. The transfer to the United States relies on Standard Contractual Clauses.
- Google & Apple – sign-in, when you choose to authenticate with them.
- Trigger.dev – background jobs, such as voice transcription, photo analysis and image generation. Each job receives only the data it needs.
- Nominatim / OpenStreetMap – refining where a vision is. During nightly processing our server sends Nominatim the text of the vision's description that you wrote (at most the first 500 characters), together with an area around the vision centred on the vision’s exact point – so the point can be calculated from it precisely. Nominatim looks for a place mentioned in the text. If the place it finds lies close to the vision’s point (within roughly half a kilometre), we store the address Nominatim returned with the vision; the vision’s point on the map does not change. This address may be part of the public vision. The request comes from our server, not your device, so it does not receive your IP address or device details.
- Overpass / OpenStreetMap – when you start a conversation about a vision, our server sends it the coordinates of the place to learn what the surroundings are like (shops, greenery, housing). The request comes from our server, not your device, so it does not receive your IP address or device details.
- OpenFreeMap – map tiles and fonts. Receives your IP address and the map view you are looking at.
- Google Maps – map imagery on the web and in the app. Receives your IP address and the map view. (This is a different service from Google sign-in above.)
- AWS Terrarium (United States) – terrain elevation tiles for the 3D map. Receives your IP address and the map view.
- PostHog – analytics and diagnostics, hosted in the EU region. We send your account identifier so an error can be seen in context – not your name, e-mail or the contents of your visions.
- Hosting – Railway, Neon, and Vercel power our application, database, and web delivery.
- Expo (EAS Update) – delivering app updates. When the app checks for or downloads an update, it receives your IP address, your platform (iOS or Android), the app version and a random installation identifier – not your account.
6. Retention
We keep data only as long as it is useful:
- Sessions expire after 7 days.
- A city check-in lasts 1 year.
- When you delete your account, we anonymise your visions – they are kept as a civic record of what your city looked like and what it could become – and we delete your pulses. The photo and the AI image of a published vision stay at their public address: a vision is a record of a place, and it makes no sense without them. Your voice recording and its transcript are always deleted, published visions included – a voice can identify you. Your drafts go entirely, from the database and from storage. The app shows you these counts before you confirm, so you know before you delete, not after. The full steps, and what stays behind, are on the Delete account page.
- Backups: the database can be restored to a point in time at most 6 hours back – after that window, deleted rows are beyond our reach too. When a photo or generated image is deleted, the deletion is immediate and irreversible: the storage has no versioning enabled, so a deleted file has no older version to fall back on. (What gets deleted when is covered by the lines below – a published vision keeps its photo.)
- A published vision stays on the map until you or a city admin delete it – it is a public record of the city.
- Security records: anti-abuse records are deleted after 2 days (both stores – ours and the one behind sign-in). The IP address stored with a session is erased once that session expires. The IP address on a city-change record is erased after 12 months, while the record of who made the change remains.
- A pulse without an account: we do not store the address, only a fingerprint of it, so the same pulse is not counted twice. After 30 days, once it no longer serves that purpose, the fingerprint is erased too – the pulse itself remains.
- An unfinished vision: a draft left untouched for 30 days (no new message, image or edit) is deleted together with its photo, voice recording, its transcript, the whole conversation and the generated images – from the database and from storage. Published visions are not affected.
- Abandoned media (for example, a photo from a vision you never submitted) is cleaned up on a best-effort basis.
- Content reports: the text you write in your own words when reporting is deleted 90 days after we dismiss the report, and one year after we act on it. While a report is still waiting to be handled, we keep the text – we are still deciding on it. The record itself (reason, time, outcome) stays afterwards as moderation statistics – without the text it no longer describes anyone.
- Interested people (an email left in a form on the website or added from a list of contacts): when you unsubscribe, we delete the interested-person record straight away and keep only the address on our unsubscribe list. If you do not unsubscribe, we delete it once 2 years have passed without activity – that is, since you last gave consent (including by submitting the form again), opened one of our emails or clicked a link in it. We also delete it at your request and when an account with the same address is deleted.
- Analytics: events in PostHog (without your IP address, without text you write and without session recording; console logs are not collected) are kept by PostHog under our plan for at most 7 years. PostHog is rolling this period out gradually and has not yet applied it to our project, so older events are not deleted automatically today. When you delete your account, we ask PostHog to delete your person and its events as well.
7. Your GDPR rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data (“the right to be forgotten”).
- Portability – receive your data in a portable format.
- Restriction of how we process your data.
- Objection to processing based on legitimate interest.
- Withdraw consent at any time, where processing relies on consent.
- Lodge a complaint with a supervisory authority. In Slovakia this is the Úrad na ochranu osobných údajov SR (Office for Personal Data Protection of the Slovak Republic).
How to exercise them. You can export your data and delete your account directly in the app at any time. You can also email us at info@ouly.city and we will help.
8. A note on “anonymous”
We never show your name publicly next to a vision, whatever you choose here. Choosing “anonymous” also hides it from city admins: in moderation they see “Anonymous” instead of your name, and the email about a new vision does not contain it. It is display-only: the vision stays linked to your account until you delete it. We won’t overstate this – anonymity here means you are not shown to other people, not that the vision is untraceable to us.
9. Location precision
To make visions useful, we store the precise coordinates of the visions you submit and show them on a public map. Please keep this in mind when deciding what to share and where.
10. Security
We protect your data with sensible, layered measures: data is encrypted in transit and at rest, passwords are hashed, access is controlled, and each city’s data is isolated from the others. We do not claim end-to-end encryption. The app saves your photo without the file’s metadata (EXIF) – that is, without location or device data – as soon as it is taken, and shrinks a large photo before uploading; if shrinking fails, it uploads it at its original size. We do not remove or blur people in the photo – if they are in the shot, they stay in the stored photo. When generating an image, only the realistic style is instructed not to add people; the playful style adds LEGO figures to the image, and the historical style repaints people in the shot in period clothing.
11. Content reports
When you report a vision, we store the reason you picked, any free text you wrote, your good-faith statement, the time, and who you are – without that we would have nobody to reply to. We do this on the basis of our legal obligation under Article 16 of the Digital Services Act and our legitimate interest in a safe platform. Your identity is not disclosed to the author of the vision – they learn that the vision was reported and how it was decided, not by whom. How long we keep a report, and when we erase the free text from it, is covered by the retention section below; if you delete your account, the report goes with it. If you report through the form on the website without an account, the notice reaches our moderators by email and is not stored in our database; if you gave an email address, a record of the confirmation we sent (address and time) remains. We delete that record no later than 13 months after we received the notice. Every report – in the app and through the form without an account – also reaches our moderators by email: from the app the vision’s title and the reason, from the form the whole notice. One of the moderators’ mailboxes is a Gmail mailbox, so Google is a recipient too. Copies of notices in the moderators’ mailboxes are not deleted automatically – we delete them manually and do not yet have a fixed period for it. How to report content, step by step, is in Help and contact.
If it was your vision that got reported, we also process data about you that we did not receive from you but from the reporter: what the report concerns, the reason given and anything written alongside it. You are informed of this when we tell you the outcome under Article 17 of the Digital Services Act. All of your rights in section 7 apply here too – including the right to object and the right to have the decision reviewed by a human. We will not tell you who reported you; the reporter has the same right to privacy as you, and disclosing it would turn reporting into a tool of retaliation.
12. Cookies
We keep cookies to a minimum. We use essential cookies to sign you in and keep your session active – without these the app cannot function. Others remember your language, the city you are looking at, and your position if you ask us to find it. We also use minimal analytics to understand errors and aggregate usage, but only with your consent in the cookie bar; you can withdraw it via “Cookie settings” in the footer. We do not use advertising or cross-site tracking cookies. The full list with lifetimes is on the Cookie policy page.
13. Children
OULY City is not for children under 16. Sixteen is a hard floor and there is no parental-consent exception. We do not knowingly collect personal data from anyone younger, and if we learn that an account belongs to someone under 16, we close it and delete the data associated with it. If you believe a child has provided us with personal data, please contact us. We publish our child-safety standards separately on the Child safety page.
14. Changes & contact
We may update this policy as OULY City evolves. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify you in the app. For anything related to your privacy or this policy, reach us at info@ouly.city.