Legal
Privacy Policy
Last updated September 28, 2026
overOne ("overOne", "we", "us", "our") makes a social content and distribution product for apps and software businesses. This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it and the choices and rights you have. It applies to the website and web app at overone.app, its subdomains (including presence.overone.app) and any related emails and support (together, the "Service").
overOne is based in San Francisco, California, United States. If you have questions, contact Ajay Kumar Yadav at support@overone.app or support@overone.ai.
- Account information. Your name, email address, password (stored only as a hash by our authentication provider) or Google sign-in profile (name, email address and profile picture). We never receive your Google password.
- Workspace and brand information. The website address you give us, your brand name, logo, product description, audience, tone, colours, company size and the other answers you give during onboarding.
- Content. Captions, posts, schedules, drafts, notes, to-dos, library folders, files you upload (video, images, audio) and content you create or edit in the Service.
- Automations. The rules you set up, such as keywords, reply templates, posting schedules and news categories.
- Support and feedback. What you send us by email, forms or surveys.
- Waitlist. Your email address and, if you choose, your company website.
When you connect a social account (for example Instagram, Facebook, TikTok, YouTube, LinkedIn, X, Threads or Bluesky) you authorise us through that platform's own sign-in screen. Depending on the platform and the permissions you grant, we receive:
- the account or page identifier, username, display name, profile picture and follower count;
- access tokens that let us act on your instructions (stored by our publishing provider, never in your browser);
- posts published on the account, with their captions, media and performance metrics (views, likes, comments, shares, saves, reach);
- comments on your posts and direct messages sent to your account, including the sender's public username, display name and profile picture, and the message text and attachments;
- new-follower events, where the platform provides them and you turn on a welcome-message automation.
We only use this information to provide the features you use: publishing and scheduling, the unified inbox, automations (replies and messages you configured) and analytics.
- Device and usage data. IP address, browser type, device type, pages viewed and the date and time of requests, recorded in our hosting and server logs for security and troubleshooting.
- Cookies and local storage. See section 8 and our Cookie Policy.
- Public website data. When you (or anyone) request a brand presence report or start onboarding, we fetch the public web page at the address supplied and the public social profiles it links to.
- Payment provider. Our payment provider tells us your subscription status, plan, billing country and the last four digits and brand of your card. We never receive your full card number.
We use personal information to:
- create and secure your account and workspaces;
- generate content for your brand, publish and schedule it where you tell us to, and run the automations you set up;
- show your inbox, calendar and analytics;
- process payments, enforce plan limits and prevent fraud and abuse;
- send service messages (sign-in, billing receipts, security notices, product changes) and, where permitted, occasional product news you can opt out of at any time;
- answer support requests;
- maintain, debug and improve the Service;
- comply with law and enforce our Terms of Service.
AI processing. To write captions and choose media we send your brand information and prompts to AI model providers that process it on our behalf. We do not allow them to use your data to train their models, and we do not use your private content or your social inbox to train models of our own.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share it only:
- With service providers that process it for us under contract (listed below).
- With social platforms, when you ask us to publish, reply, message or read analytics on your behalf. What you publish becomes subject to that platform's own privacy policy.
- For legal reasons, when we believe in good faith that the law, a court order or a government request requires it, or to protect the rights, safety or property of our users, the public or overOne.
- In a business transfer, such as a merger, acquisition or sale of assets, in which case this policy continues to apply to your information.
- With your consent or at your direction.
The service providers that process personal information for us under contract are:
- Google Firebase / Google Cloud — authentication, database, file storage, cloud functions and hosting;
- Amazon Web Services — media storage and delivery (S3, CloudFront) and AI model hosting (Amazon Bedrock);
- Zernio — the social publishing layer that connects to the platforms, stores access tokens, publishes posts and delivers comments, messages and analytics;
- Dodo Payments — subscription checkout, billing and invoicing, acting as our merchant of record;
- Firecrawl — fetching public web pages for onboarding and brand presence reports;
- Google Workspace (Gmail) — sending service email;
- Trustpilot — the review widget, loaded only if you allow third-party cookies.
- YouTube. If you connect a YouTube channel, you are also agreeing to the YouTube Terms of Service, and Google's use of data is governed by the Google Privacy Policy. You can revoke our access at any time from your Google security settings. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- Meta (Instagram, Facebook, Threads). We use Meta platform data only to provide the features you enabled and in line with Meta's Platform Terms. You can remove our access from your Meta account's business integrations settings.
Anyone can request a public brand presence report for a website. Reports contain information about businesses — their public website and public social profiles — not private personal data. If you represent a business and want a report corrected or removed, email support@overone.app and we will act on it.
We keep account, workspace and content data while your account is open. When you delete your account it is frozen immediately and kept for a 30-day grace period, during which you can restore it by signing in. After that we permanently delete your personal information, content and uploaded files (usually within one more day), apart from what we must keep for legal, tax, accounting or fraud-prevention reasons (for example billing records, usually 7 years). Access tokens are deleted when you disconnect an account. Server logs are kept for up to 90 days. Rate-limiting records store only a one-way hash of an IP address and expire automatically.
Data is encrypted in transit (HTTPS) and at rest. Access tokens are held server-side and never sent to your browser, media is served through signed, expiring links, and access to production systems is limited to people who need it. No system is perfectly secure; please use a strong, unique password and tell us straight away if you suspect unauthorised access.
We use strictly necessary cookies and browser storage to keep you signed in, remember your open workspace and store the settings you choose. Optional categories — analytics and third-party embeds — stay off until you opt in through the cookie banner, and you can change your choice at any time from "Cookie settings" in the site footer. We honour Global Privacy Control signals as an opt-out. Because there is no common standard for browser "Do Not Track" signals, we respond to GPC instead. Details are in our Cookie Policy.
- Edit your account, brand and workspace details in the app.
- Disconnect any social account from the Connections page, or revoke access in the platform's own settings.
- Turn off or delete any automation at any time.
- Unsubscribe from product news with the link in any such email (service messages cannot be turned off while you have an account).
- Change your cookie choices from "Cookie settings" in the footer.
Depending on where you live, you may have the right to:
- know / access the personal information we hold about you and receive a portable copy;
- correct inaccurate information;
- delete your information;
- opt out of the sale or sharing of personal information and of targeted advertising (we do not sell or share it, but you may still send a request);
- limit the use of sensitive personal information (we do not collect sensitive personal information as defined by California law);
- object to or restrict processing, and withdraw consent where processing relies on it;
- not be discriminated against for exercising these rights.
To make a request, email support@overone.app from the address on your account. We will verify your identity, may ask for more information to do so, and will respond within the time the law requires (45 days under California law). You may use an authorised agent, who must provide written permission from you. If we refuse a request you may appeal by replying to our decision; if you are in the EU/UK you can also complain to your local data protection authority.
This section supplements the above for residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA). In the past 12 months we collected these categories of personal information, for the purposes in section 2, from the sources in section 1, and disclosed them for business purposes to the service providers in section 3:
| Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Name, email address, account IDs, IP address | No |
| Customer records | Billing country, subscription and invoice records | No |
| Commercial information | Plan, purchase history | No |
| Internet activity | Usage of the Service, server logs | No |
| Audio/visual information | Media you upload or publish | No |
| Professional information | Company size, stage, website | No |
| Inferences | Brand profile generated from your inputs | No |
We do not sell or share personal information and have no actual knowledge of selling or sharing the personal information of consumers under 16. California "Shine the Light" requests can be sent to the same email address.
Where the GDPR applies, we process personal information to perform our contract with you (running the Service), for our legitimate interests (security, improving the Service, preventing abuse — which we balance against your rights), to comply with legal obligations, and with your consent (optional cookies, marketing email). overOne is the controller. Our service providers are in the United States and elsewhere; where personal information leaves the EEA/UK we rely on Standard Contractual Clauses or another lawful transfer mechanism.
The Service is for businesses and is not directed at children. You must be at least 18 (or the age of majority where you live) to create an account. We do not knowingly collect personal information from children under 16; if you believe a child has given us information, contact us and we will delete it.
We are based in the United States and process information there and in other countries where our providers operate. Those countries may have different data protection laws from yours.
We may update this policy as the Service or the law changes. We will change the "Last updated" date above and, if a change materially affects you, tell you in the app or by email before it takes effect.
overOne — San Francisco, California, United States
Privacy contact: Ajay Kumar Yadav
Email: support@overone.app or support@overone.ai
Something here unclear?
Contact Ajay Kumar Yadav — overOne, San Francisco, California.