Ocuva

Privacy Policy

Last updated: July 4, 2026

This policy explains what personal data Ocuva collects, why, and what rights you have over it. It applies to the Ocuva web app, website, APIs, and browser extension.

1. Who We Are (Data Controller)

Ocuva is currently operated as a sole proprietorship by:

Manuel Lopez

Regensburger Strasse 16

10777 Berlin, Germany

Email: info@ocuva.app

When Ocuva is converted to a GmbH or other legal entity, this policy will be updated to reflect the new controller name, registered address, and company details.

2. Data Protection Contact

For any data protection matter, you can contact our data protection contact directly:

Florian Meeuwsen

Email: info@ocuva.app

3. Minimum Age

Ocuva is intended for users aged 16 and older. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has created an account, please contact us at info@ocuva.app and we will delete the account and associated data promptly.

4. Data We Collect and Why

We collect only what is necessary to provide Ocuva. Each category below lists the data, why we process it, and the legal basis under GDPR Article 6.

Account and authentication data

Email address, hashed password, authentication tokens, OAuth provider tokens (if you sign in with Google or similar).

Purpose: Creating and securing your account; authenticating you across sessions and devices.

Legal basis: Performance of contract (Art. 6(1)(b))

Library content

Saved articles, web clips, uploaded documents (EPUB, PDF, Word, plain text), extracted page text, YouTube transcripts, images, cover images, source URLs, titles, authors, tags, folders, and notes.

Purpose: Providing your reading library and syncing it across your devices.

Legal basis: Performance of contract (Art. 6(1)(b))

Reading progress and session data

Word position, reading speed (words per minute), session timestamps, session duration, reading statistics, and vocabulary interactions.

Purpose: Saving your place, providing reading statistics, and enabling study and vocabulary features.

Legal basis: Performance of contract (Art. 6(1)(b))

App preferences and settings

Display preferences, language settings, AI feature toggle per library item, and notification preferences.

Purpose: Personalising your reading experience.

Legal basis: Performance of contract (Art. 6(1)(b))

Technical and operational data

IP address (server logs), browser type, device type, error reports, crash logs, and anonymised page interaction events.

Purpose: Operating and maintaining Ocuva, diagnosing errors, and improving reliability.

Legal basis: Legitimate interests (Art. 6(1)(f)) — our interest in providing a stable and reliable service

Billing data

Subscription tier, subscription status, and transaction history. Full payment card details are never stored by Ocuva; they are handled exclusively by RevenueCat and the underlying payment provider.

Purpose: Managing your subscription and complying with commercial and tax record-keeping obligations.

Legal basis: Performance of contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for accounting records

5. Browser Extension

The Ocuva browser extension only activates when you explicitly click it. It uses the browser's active-tab permission to read the content of the current page, extract readable text (or available YouTube captions), and optionally fetch the page's cover image. The extracted content is then saved to your Ocuva account. The extension does not continuously monitor your browsing activity, does not run in the background, and does not collect data from pages you do not deliberately save.

Authentication tokens used to connect the extension to your account are stored locally in your browser in encrypted extension storage and are not shared with third parties.

6. AI Features and Content Processing

Ocuva offers optional AI-powered features such as vocabulary analysis, reading difficulty scoring, summaries, and study tools. These features are disabled by default and must be explicitly enabled for each library item.

When you enable AI for a specific item, the text content of that item is transmitted to Anthropic, Inc. for processing. When AI is disabled (the default), no content from that item is ever sent to Anthropic. You can disable AI for any item at any time; doing so revokes consent for further AI processing of that item going forward.

Anthropic processes this data solely to generate the requested features and acts as our data processor under a Data Processing Agreement. The legal basis for this processing is consent (Art. 6(1)(a) GDPR) — your deliberate per-item opt-in.

7. Third-Party Processors

We engage the following service providers. Each processes personal data only on our documented instructions and under a Data Processing Agreement.

Supabase, Inc.

Database, file storage, and authentication

Location: Germany (EU) — data does not leave the EEA · Transfer basis: No transfer — data stored within the EU

Anthropic, Inc.

AI features — only when enabled per library item

Location: USA · Transfer basis: Standard Contractual Clauses

Vercel, Inc.

Hosting, serverless functions, and analytics

Location: USA / EU edge · Transfer basis: EU-US Data Privacy Framework

Functional Software, Inc. (Sentry)

Error monitoring and crash reporting

Location: USA · Transfer basis: EU-US Data Privacy Framework / SCCs

RevenueCat, Inc.

Subscription management and billing

Location: USA · Transfer basis: Standard Contractual Clauses

We may add PostHog or similar product analytics providers in the future. We will update this policy and notify you before any such addition takes effect.

8. International Data Transfers

Some of our processors are headquartered in the United States. Transfers of personal data from the EU/EEA to these providers are governed by one of the following safeguards recognised under Art. 46 GDPR:

  • EU-US Data Privacy Framework — an adequacy decision adopted by the European Commission in July 2023, applicable where our provider is certified under the framework.
  • Standard Contractual Clauses (SCCs)— the European Commission's approved model clauses (2021/914) where the DPF does not apply.

You can request a copy of the applicable transfer documentation by writing to us at info@ocuva.app.

9. Cookies and Local Storage

Strictly necessary — authentication

Session cookies and local storage entries set by Supabase to keep you logged in across page loads. These are essential for the service to function and do not require separate consent under TTDSG §25(2).

Analytics — Vercel Analytics

Vercel Analytics collects aggregated, anonymised page-view data (URL, referrer, device type) via edge middleware. It does not use persistent cookies, does not fingerprint individual users, and does not track you across other websites.

We do not use advertising cookies or cross-site tracking.

10. Data Retention

Account and library data

Retained for the lifetime of your account, then deleted within 30 days of an account deletion request.

Reading session and progress data

Retained for the lifetime of your account.

Error and crash logs (Sentry)

90 days.

Server access logs

Up to 30 days.

Billing and transaction records

10 years, as required by German commercial and tax law (§§ 238, 257 HGB; § 147 AO).

After the applicable period, data is permanently deleted or irreversibly anonymised.

11. Security

We apply appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) for all data exchanged with Ocuva.
  • Encryption at rest for library content stored in our database.
  • Row-level security ensuring each user can only access their own data.
  • Strict access controls limiting staff access to personal data on a need-to-know basis.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you without undue delay, as required by Art. 33–34 GDPR.

12. Your Rights — EU, EEA, and German Residents

Under the GDPR you have the following rights. To exercise any of them, contact us at info@ocuva.app. We will respond within 30 days.

Right of access (Art. 15)

Request a complete copy of all personal data we hold about you.

Right to rectification (Art. 16)

Request correction of inaccurate or incomplete personal data.

Right to erasure (Art. 17)

Request deletion of your personal data — the "right to be forgotten". Applies unless we have a legal obligation to retain specific records (e.g. billing records).

Right to restrict processing (Art. 18)

Request that we limit processing of your data while a dispute or objection is being resolved.

Right to data portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format. Applies to data we process on the basis of contract or consent.

Right to object (Art. 21)

Object to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent (Art. 7(3))

Where processing is based on consent (e.g. AI features), withdraw it at any time without affecting the lawfulness of prior processing.

Right to lodge a complaint (Art. 77)

You may lodge a complaint with the supervisory authority in the EU/EEA member state where you live, work, or where an alleged infringement occurred.

Competent supervisory authority for Germany

Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstrasse 219, 10969 Berlin
mailbox@datenschutz-berlin.de

13. California and Other US State Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you the following rights:

  • Right to know — what personal information we collect, use, and disclose.
  • Right to delete — request deletion of your personal information.
  • Right to correct — request correction of inaccurate personal information.
  • Right to opt out of sale or sharing — we do not sell or share your personal information with third parties for their own advertising or marketing purposes.
  • Right to non-discrimination — we will not penalise you for exercising any of these rights.
  • Right to limit use of sensitive personal information — you may request that we restrict the use of any sensitive personal information to what is necessary to provide the service.

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other US states with privacy legislation have substantially similar rights. To exercise any of these rights, contact us at info@ocuva.app. We will respond within 45 days as required by CCPA, or within the period required by your state's law.

14. Changes to This Policy

We may update this policy from time to time. When we make material changes — such as adding new processors, changing legal bases, or transitioning the controller to a GmbH — we will notify you by email and through a prominent notice in the app at least 14 daysbefore the change takes effect. The “Last updated” date at the top of this page always reflects the current version. Continued use of Ocuva after the effective date constitutes acceptance of the updated policy.

15. Contact

For any privacy-related question, access request, deletion request, or complaint, contact:

Data Protection Contact — Florian Meeuwsen

info@ocuva.app

Controller

Manuel Lopez

Regensburger Strasse 16, 10777 Berlin, Germany