Privacy Policy
Effective date: 2026-10-03 Last updated: 2026-10-03
This policy explains what the Oculo mobile app (“Oculo”, “the app”) does with information, and what it deliberately does not do. It is written to be read, not to be skimmed past.
Contents
- The short version
- Who is responsible
- What this policy covers
- What Oculo does not do
- Information that stays on your device
- Diagnostics you can turn on and off
- Purchases and subscriptions
- Reminders and voice cues
- Backups
- Who else processes information, and where
- How long information is kept
- Children
- Your rights
- Notice for California residents
- Security
- Changes to this policy
- How to contact us
1. The short version
| Question | Answer |
|---|---|
| Do I need an account? | No. Oculo has no sign-up, no login and no user profile on any server. |
| Where is my practice history stored? | In a database on your phone. It is not uploaded anywhere by Oculo. |
| Does Oculo collect analytics? | Only if you switch diagnostics on. It is off by default, and you can switch it off again at any time in Settings. |
| Are there ads? | No. There is no advertising SDK in the app and no advertising identifier is read. |
| Is anything sold or shared with data brokers? | No. Never. |
| Does Oculo work offline? | Yes. The only feature that needs a network connection is a purchase. |
| Does Oculo know anything about my eyes or my health? | No diagnosis, no prescription, no clinical data - we never ask for any of it, and there is nowhere in the app to enter it. What Oculo stores is activity: which exercise you did, for how long, and which of three goals you picked at the start. |
2. Who is responsible
The controller of the limited personal data described below is:
Oleksii Kravchenko Carrer de Les Barraques del Figuero Email: privacy@oculo.day
If you are in the European Economic Area, the United Kingdom or Switzerland, this means we are the “controller” for the purposes of the GDPR and equivalent laws.
3. What this policy covers
This policy covers the Oculo app for iOS and Android, and the pages on https://oculo.day.
It does not cover the App Store, Google Play, or anything else operated by Apple or Google. When you buy a subscription, the purchase happens inside Apple’s or Google’s own systems, under their own privacy policies, and we never see your payment details.
The website at https://oculo.day sets no cookies, uses no analytics, embeds no third-party scripts and loads no third-party fonts. Visiting it leaves nothing on your device and tells us nothing about you beyond what any web server unavoidably receives from your browser to send the page back (your IP address, the requested page, your browser’s user-agent string) - our hosting provider processes those request logs on our behalf for security and reliability. The legal basis for that is our legitimate interest in keeping the site available and secure, Article 6(1)(f) GDPR.
Your browser may cache the page, the font files and the images, exactly as it does for any website. Nothing else is stored on your device by visiting it.
The site has one button that opens a message to us, Tell me when it ships. Nothing is sent until you send it yourself from your own mail app. If you do write to us asking to be told when Oculo ships, we keep your email address for that single purpose, send one message at launch and delete the address afterwards. You can ask us to remove it sooner at privacy@oculo.day. Nothing else is done with it, it is never used for any other message, and it never goes to anyone else. The legal basis is your consent, Article 6(1)(a) GDPR, which you can withdraw at any time.
4. What Oculo does not do
To be explicit, because “we respect your privacy” means nothing on its own. Oculo does not:
- ask you to create an account, and does not have one to create;
- read, request or store your name, email address, phone number, contacts or calendar;
- use the camera or the microphone - there is no eye tracking and no blink detection in the app;
- request or use your location;
- read your advertising identifier (IDFA or Android Advertising ID), and therefore never presents the iOS “Allow tracking” prompt, because there is nothing to track you with;
- contain any advertising, attribution or marketing SDK;
- track you across other apps or websites;
- ask for or store a diagnosis, a prescription or any clinical information, and does not infer any health condition from your answers;
- send your practice history to us or to anyone else;
- sell, rent or trade personal information. There is no price at which this changes.
5. Information that stays on your device
Almost everything Oculo knows about you never leaves your phone. It is stored in a local database and in local app settings, and it is readable only by the app itself:
| What | Example |
|---|---|
| Your onboarding answers | your goal, roughly how much screen time you have, how often you want to practise |
| Your daily plan | which exercises were picked for a given date |
| Your practice history | which exercise, in which order, planned and actual duration, and whether you finished or skipped it |
| Your favourites | exercises you starred in the library |
| Your streak | current and best run of days |
| Your settings | reminder time and preset, sound and voice volume, background music, session speed, whether diagnostics are allowed |
| A random identifier | a UUID generated on first launch, used as the anonymous customer id for the subscription service (see section 7). It contains nothing about you and is not linked to your name, email or device identifiers. |
We cannot read any of this. There is no server of ours for it to arrive at.
You can delete all of it at once by deleting the app from your device. Note that deleting the app does not cancel a subscription - see section 7.
6. Diagnostics you can turn on and off
Oculo can send anonymous usage statistics and crash reports, which help us find broken screens and exercises people quietly abandon. This is switched off when you install the app, in the app’s configuration itself and not only in its interface: the analytics and crash-reporting SDKs start with collection disabled and with all consent signals set to “denied”. Nothing is collected, nothing is queued locally, and nothing is sent until you opt in.
How you opt in. During onboarding, next to the health disclaimer, there is a checkbox for sharing anonymous diagnostics. It is unchecked by default. You can change your mind at any time in Settings → share anonymous diagnostics. Switching it off stops collection immediately, for the whole app, and the choice survives restarts.
Legal basis (GDPR). Your consent, Article 6(1)(a). You may withdraw it at any time as described above, and withdrawal is as easy as giving it.
If you opt in, two services receive data:
Google Analytics for Firebase receives events about how the app is used. Each event carries a
pseudonymous app-instance identifier generated by the SDK, standard technical context collected by
the SDK (app version, platform, OS version, device model, language, approximate region derived from
IP, which the SDK does not store), and a small set of our own parameters. Our events cover:
onboarding steps and answers (as fixed option names such as relieve_fatigue, never free text),
screen views, button taps, exercise starts, completions and skips with durations and the exercise
identifier, session starts, completions and abandonment, notification permission result, widget
prompts, and paywall views, outcomes and dismissals.
Two things about those events matter more than the list:
- Every parameter value is a fixed identifier from a closed set: an exercise id, a screen name, a number of seconds. There is no field anywhere in the app that accepts free text, so none can be sent.
- Nothing about your health is sent, because the app holds nothing about your health. “You opened the library and finished a three-minute session” is the shape of the data.
Firebase Crashlytics receives crash and non-fatal error reports: the stack trace, the device model, the OS version, the app version and build, and a pseudonymous installation identifier generated by the SDK. A crash report can, in principle, contain fragments of app memory; it never contains anything you typed, because there is nothing to type.
If you do not opt in, neither service collects or transmits anything at all.
No automated decision-making. Your daily plan is assembled on your device by fixed rules, from your answers and your own practice history. It is not a neural network, it makes no decision about you with legal or similar effects, and nothing about you is profiled on a server. That is also why the “AI” in the app’s name describes a plan that adapts, and never a diagnosis.
7. Purchases and subscriptions
Oculo Pro is sold through the App Store and Google Play. We use RevenueCat to check what you are entitled to and to restore purchases on a new device.
When you open the paywall or make a purchase, RevenueCat processes, on our behalf:
- the random identifier from section 5, as your anonymous customer id;
- the purchase receipt or token issued by Apple or Google, and the transaction, product, subscription period, trial and renewal status derived from it;
- the store country, the platform, the app version and basic device information collected by the RevenueCat SDK.
We see purchase and subscription status in the RevenueCat dashboard, tied to that random identifier. We never receive your card number, your bank details, your Apple ID or your Google account, because the payment never passes through us.
The legal basis for this processing is the performance of our contract with you, Article 6(1)(b) GDPR: without it we cannot give you the access you paid for, or restore it on a new device.
Apple and Google act as independent controllers for the payment itself and for your store account. Their privacy policies apply to that part, and we cannot change what they do with it.
Cancelling, refunds and the end of a trial are handled by the store, not by us. Deleting the app does not cancel a subscription. See the Terms of Use for how to cancel.
8. Reminders and voice cues
Reminders are scheduled by your device’s own notification system, locally. There is no push server: nothing leaves your phone to deliver a reminder, and we do not know whether one was shown or tapped unless you have turned diagnostics on (section 6). You can revoke the notification permission at any time in system settings; the rest of the app keeps working.
Voice cues during a session are spoken by the speech engine built into your operating system. Oculo hands it the text of a cue. How that engine works (including whether your platform’s speech engine processes text on the device or on its own servers, depending on the voice you have selected in your system settings) is governed by Apple’s or Google’s settings and policies, not by ours. Oculo never sends audio anywhere and never records anything.
9. Backups
So that you do not lose your streak when you change phones, Oculo relies on the backup mechanism your platform already provides:
- on Android, Android Auto Backup, stored in your Google account;
- on iOS, the iCloud Key-Value Store, stored in your iCloud account.
These backups are made and kept by Google and Apple in your account, under your control and their terms. We have no access to them. You can disable backups for the app in your system settings; the app keeps working, and the data stays on the device only.
10. Who else processes information, and where
| Service | What it is for | Privacy policy |
|---|---|---|
| Google Ireland Limited / Google LLC (Firebase: Analytics, Crashlytics) | Anonymous usage statistics and crash reports, only after you opt in | https://firebase.google.com/support/privacy |
| RevenueCat, Inc. | Subscription status, entitlements, restoring purchases | https://www.revenuecat.com/privacy |
| Apple Inc. / Google LLC (App Store, Google Play) | Distribution, payment, refunds, backups | https://www.apple.com/legal/privacy · https://policies.google.com/privacy |
| Our website hosting provider | Serving the pages on https://oculo.day and its request logs | see section 3 |
Firebase and RevenueCat are based in, or process data in, the United States. Where personal data is transferred out of the EEA, the UK or Switzerland, those transfers rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies.
We do not add new processors silently: if one is added, this policy is updated before the change ships, and section 16 explains how you learn about it.
11. How long information is kept
- On your device: until you delete it in the app or delete the app. We set no expiry on your practice history - it is yours.
- Diagnostics (if you opted in): usage data is retained by Firebase Analytics for no longer than 14 months and then deleted automatically. Crash reports are retained for up to 90 days.
- Subscription records: kept by RevenueCat for as long as the app has an active project with them, because entitlement and restore depend on the purchase history. Store records are kept by Apple and Google under their own retention rules, including for accounting and tax purposes.
- Website request logs: short-lived, kept by the hosting provider for security and reliability.
12. Children
Oculo is made for adults and is not directed to children. You must be at least 16 years old to use it. We do not knowingly collect personal data from children. If you believe a child has used the app and that diagnostics were enabled, write to privacy@oculo.day and we will help as far as the pseudonymous nature of that data allows (see section 13).
13. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access, rectify, erase, restrict and object to the processing of your personal data, to data portability, and to withdraw consent at any time. Similar rights exist under other privacy laws.
Here is how those rights work in practice for an app with no accounts, stated plainly rather than hidden behind a form:
- Withdraw consent: Settings → share anonymous diagnostics. Immediate, and no explanation needed.
- Erase everything held locally: delete the app from your device.
- Access or erase diagnostics data: write to privacy@oculo.day. Be aware of a real limitation - diagnostics records are tied to a randomly generated installation identifier, not to you. We usually have no way to tell which records are yours, and GDPR Article 11 does not require us to collect more data in order to be able to identify you. We will tell you honestly what we can and cannot do in your case, and we will not ask you for an ID document.
- Erase subscription data: write to privacy@oculo.day and include the store order id from your receipt. We can delete the customer record held by RevenueCat. Apple and Google keep their own transaction records regardless, and we cannot delete those.
- Complain: you may lodge a complaint with your local data protection authority. If you are in the EEA, a list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
We answer requests within 30 days.
14. Notice for California residents
In the last 12 months we have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not offer financial incentives for personal information, and nothing in the app is priced differently depending on privacy choices. The categories of information involved, their sources, purposes and recipients are described in sections 5 to 10. California residents may exercise their rights by writing to privacy@oculo.day; we do not discriminate against anyone for doing so.
15. Security
Your practice history is held in your device’s app sandbox, protected by your operating system and your device passcode. Traffic to Firebase, RevenueCat and the stores uses TLS. The app has no server of ours to attack and holds no credentials of yours to steal, which removes whole classes of risk rather than mitigating them.
No method of transmission or storage is perfectly secure, and we do not claim otherwise.
16. Changes to this policy
If this policy changes, the new version is published at https://oculo.day/privacy with a new effective date, and the previous text is kept available on request. If a change means we start processing data in a way that needs your consent, we will ask for it in the app before the change takes effect - not afterwards.
17. How to contact us
Privacy questions and requests: privacy@oculo.day Everything else: support@oculo.day Postal address: Oleksii Kravchenko, Carrer de Les Barraques del Figuero
A person reads that mailbox, not a ticket robot.