Privacy Policy
Last updated: July 4, 2026
This policy explains what personal data Ocuva collects, why, and what rights you have over it. It applies to the Ocuva web app, website, APIs, and browser extension.
1. Who We Are (Data Controller)
Ocuva is currently operated as a sole proprietorship by:
When Ocuva is converted to a GmbH or other legal entity, this policy will be updated to reflect the new controller name, registered address, and company details.
2. Data Protection Contact
For any data protection matter, you can contact our data protection contact directly:
Florian Meeuwsen
Email: info@ocuva.app
3. Minimum Age
Ocuva is intended for users aged 16 and older. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has created an account, please contact us at info@ocuva.app and we will delete the account and associated data promptly.
4. Data We Collect and Why
We collect only what is necessary to provide Ocuva. Each category below lists the data, why we process it, and the legal basis under GDPR Article 6.
Account and authentication data
Email address, hashed password, authentication tokens, OAuth provider tokens (if you sign in with Google or similar).
Purpose: Creating and securing your account; authenticating you across sessions and devices.
Legal basis: Performance of contract (Art. 6(1)(b))
Library content
Saved articles, web clips, uploaded documents (EPUB, PDF, Word, plain text), extracted page text, YouTube transcripts, images, cover images, source URLs, titles, authors, tags, folders, and notes.
Purpose: Providing your reading library and syncing it across your devices.
Legal basis: Performance of contract (Art. 6(1)(b))
Reading progress and session data
Word position, reading speed (words per minute), session timestamps, session duration, reading statistics, and vocabulary interactions.
Purpose: Saving your place, providing reading statistics, and enabling study and vocabulary features.
Legal basis: Performance of contract (Art. 6(1)(b))
App preferences and settings
Display preferences, language settings, AI feature toggle per library item, and notification preferences.
Purpose: Personalising your reading experience.
Legal basis: Performance of contract (Art. 6(1)(b))
Technical and operational data
IP address (server logs), browser type, device type, error reports, crash logs, and anonymised page interaction events.
Purpose: Operating and maintaining Ocuva, diagnosing errors, and improving reliability.
Legal basis: Legitimate interests (Art. 6(1)(f)) — our interest in providing a stable and reliable service
Billing data
Subscription tier, subscription status, and transaction history. Full payment card details are never stored by Ocuva; they are handled exclusively by RevenueCat and the underlying payment provider.
Purpose: Managing your subscription and complying with commercial and tax record-keeping obligations.
Legal basis: Performance of contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for accounting records
5. Browser Extension
The Ocuva browser extension only activates when you explicitly click it. It uses the browser's active-tab permission to read the content of the current page, extract readable text (or available YouTube captions), and optionally fetch the page's cover image. The extracted content is then saved to your Ocuva account. The extension does not continuously monitor your browsing activity, does not run in the background, and does not collect data from pages you do not deliberately save.
Authentication tokens used to connect the extension to your account are stored locally in your browser in encrypted extension storage and are not shared with third parties.
6. AI Features and Content Processing
Ocuva offers optional AI-powered features such as vocabulary analysis, reading difficulty scoring, summaries, and study tools. These features are disabled by default and must be explicitly enabled for each library item.
When you enable AI for a specific item, the text content of that item is transmitted to Anthropic, Inc. for processing. When AI is disabled (the default), no content from that item is ever sent to Anthropic. You can disable AI for any item at any time; doing so revokes consent for further AI processing of that item going forward.
Anthropic processes this data solely to generate the requested features and acts as our data processor under a Data Processing Agreement. The legal basis for this processing is consent (Art. 6(1)(a) GDPR) — your deliberate per-item opt-in.
7. Third-Party Processors
We engage the following service providers. Each processes personal data only on our documented instructions and under a Data Processing Agreement.
Supabase, Inc.
Database, file storage, and authentication
Location: Germany (EU) — data does not leave the EEA · Transfer basis: No transfer — data stored within the EU
Anthropic, Inc.
AI features — only when enabled per library item
Location: USA · Transfer basis: Standard Contractual Clauses
Vercel, Inc.
Hosting, serverless functions, and analytics
Location: USA / EU edge · Transfer basis: EU-US Data Privacy Framework
Functional Software, Inc. (Sentry)
Error monitoring and crash reporting
Location: USA · Transfer basis: EU-US Data Privacy Framework / SCCs
RevenueCat, Inc.
Subscription management and billing
Location: USA · Transfer basis: Standard Contractual Clauses
We may add PostHog or similar product analytics providers in the future. We will update this policy and notify you before any such addition takes effect.
8. International Data Transfers
Some of our processors are headquartered in the United States. Transfers of personal data from the EU/EEA to these providers are governed by one of the following safeguards recognised under Art. 46 GDPR:
- EU-US Data Privacy Framework — an adequacy decision adopted by the European Commission in July 2023, applicable where our provider is certified under the framework.
- Standard Contractual Clauses (SCCs)— the European Commission's approved model clauses (2021/914) where the DPF does not apply.
You can request a copy of the applicable transfer documentation by writing to us at info@ocuva.app.
9. Cookies and Local Storage
Strictly necessary — authentication
Session cookies and local storage entries set by Supabase to keep you logged in across page loads. These are essential for the service to function and do not require separate consent under TTDSG §25(2).
Analytics — Vercel Analytics
Vercel Analytics collects aggregated, anonymised page-view data (URL, referrer, device type) via edge middleware. It does not use persistent cookies, does not fingerprint individual users, and does not track you across other websites.
We do not use advertising cookies or cross-site tracking.
10. Data Retention
Account and library data
Retained for the lifetime of your account, then deleted within 30 days of an account deletion request.
Reading session and progress data
Retained for the lifetime of your account.
Error and crash logs (Sentry)
90 days.
Server access logs
Up to 30 days.
Billing and transaction records
10 years, as required by German commercial and tax law (§§ 238, 257 HGB; § 147 AO).
After the applicable period, data is permanently deleted or irreversibly anonymised.
11. Security
We apply appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS) for all data exchanged with Ocuva.
- Encryption at rest for library content stored in our database.
- Row-level security ensuring each user can only access their own data.
- Strict access controls limiting staff access to personal data on a need-to-know basis.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you without undue delay, as required by Art. 33–34 GDPR.
12. Your Rights — EU, EEA, and German Residents
Under the GDPR you have the following rights. To exercise any of them, contact us at info@ocuva.app. We will respond within 30 days.
Right of access (Art. 15)
Request a complete copy of all personal data we hold about you.
Right to rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to erasure (Art. 17)
Request deletion of your personal data — the "right to be forgotten". Applies unless we have a legal obligation to retain specific records (e.g. billing records).
Right to restrict processing (Art. 18)
Request that we limit processing of your data while a dispute or objection is being resolved.
Right to data portability (Art. 20)
Receive your data in a structured, commonly used, machine-readable format. Applies to data we process on the basis of contract or consent.
Right to object (Art. 21)
Object to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
Right to withdraw consent (Art. 7(3))
Where processing is based on consent (e.g. AI features), withdraw it at any time without affecting the lawfulness of prior processing.
Right to lodge a complaint (Art. 77)
You may lodge a complaint with the supervisory authority in the EU/EEA member state where you live, work, or where an alleged infringement occurred.
Competent supervisory authority for Germany
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstrasse 219, 10969 Berlin
mailbox@datenschutz-berlin.de
13. California and Other US State Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you the following rights:
- Right to know — what personal information we collect, use, and disclose.
- Right to delete — request deletion of your personal information.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell or share your personal information with third parties for their own advertising or marketing purposes.
- Right to non-discrimination — we will not penalise you for exercising any of these rights.
- Right to limit use of sensitive personal information — you may request that we restrict the use of any sensitive personal information to what is necessary to provide the service.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other US states with privacy legislation have substantially similar rights. To exercise any of these rights, contact us at info@ocuva.app. We will respond within 45 days as required by CCPA, or within the period required by your state's law.
14. Changes to This Policy
We may update this policy from time to time. When we make material changes — such as adding new processors, changing legal bases, or transitioning the controller to a GmbH — we will notify you by email and through a prominent notice in the app at least 14 daysbefore the change takes effect. The “Last updated” date at the top of this page always reflects the current version. Continued use of Ocuva after the effective date constitutes acceptance of the updated policy.
15. Contact
For any privacy-related question, access request, deletion request, or complaint, contact:
Data Protection Contact — Florian Meeuwsen
Controller
Manuel Lopez
Regensburger Strasse 16, 10777 Berlin, Germany