Oxstory Logo Oxstory

Privacy Policy

Last Updated: October 6, 2025

At Oxstory, we are committed to safeguarding your privacy. This Privacy Policy describes the types of personal data we collect, the purposes for which we use it, and the steps we take to protect it. Your use of our website, mobile application, APIs, or any related services constitutes your acceptance of this policy.

1. Data Controller

2. Scope of This Policy

This policy applies to all users, visitors, authors, and anyone who interacts with our platform — including the website, mobile applications, APIs, and other related services.

3. What Data We Collect

We collect both Personal Data (data that identifies you) and Anonymous Data (data that does not).

Category Examples Source
Identity & Contact Info Name, email, profile picture, password During account registration
Third-Party Account Data Google login info (email, name, date of birth) When signing in via third-party services
User Content Stories, comments, messages, profile descriptions Provided directly by you
Technical & Behavioral Data IP address, browser, device type, pages visited, login/logout logs Collected automatically during usage
Cookies & Device Identifiers Cookie IDs, device IDs, analytics data, session data Via cookies and tracking tech
Interaction Data Bookmarks, likes, views, followers, voting behavior Based on your actions on the platform

4. Purpose & Legal Basis for Processing

We only process your data where we have a valid legal basis, such as your consent, a contract with you, or our legitimate interests.

Purpose Legal Basis
Provide and manage your account Contractual necessity
Display and publish your content Consent / legitimate interest
Communicate with you (e.g., notifications) Consent / legitimate interest
Send security, system, or legal notices Legal obligation
Improve platform, analyze trends Legitimate interest
Ensure platform safety and prevent abuse Legitimate interest
Show personalized content or ads Consent

5. Email Communications

We use your email for the following purposes:

  • Account verification and password recovery
  • Story notifications and social activity (e.g., followers, messages)
  • Important service updates and legal notices

Essential communications (e.g., password reset, security alerts) will always be sent to your account to ensure its safety and proper functioning.

6. Cookies & Tracking Technologies

We use cookies and similar technologies for:

  • Platform functionality (essential cookies)
  • Analytics and marketing (optional, consent required)
  • Device and session tracking

You can manage cookies in your browser or app settings. We do not enable non-essential cookies without your explicit consent, which is obtained through your acceptance of this privacy policy and app usage.

7. Public Profile & Visibility

Oxstory is a social storytelling platform. Information you choose to make public (e.g., your username, stories, profile description, comments) is visible to other users and may appear in search results.

8. Sharing Your Data

We do not sell your personal data. We may share your data in these cases:

  • Service Providers: Hosting, analytics (e.g., Firebase, PostHog, Google Analytics)
  • Legal Compliance: When required by law or regulation
  • Business Transfers: If oxstory merges or is acquired
  • Anonymized Data: Shared with partners for analytics or research — not linked to you
  • With Your Consent: For optional services or integrations

All partners and processors must meet strict confidentiality and security standards.

9. Data Storage & Retention

We retain your data only as long as necessary:

  • Your data is deleted or anonymized once it's no longer needed.
  • Upon account deletion, your profile and all associated data are deleted immediately, unless retention is required otherwise by law.
  • Currently, upon account deletion, all your comments, stories, and public content are deleted immediately. In the future, we may retain certain anonymized public content for service continuity, in which case this policy will be updated accordingly.

If local laws specify retention periods, we comply accordingly.

10. International Data Transfers

Although our application is available internationally, all user data is stored and processed exclusively within the European Union. We ensure compliance with applicable data protection laws (e.g., GDPR) to protect your privacy and data security.

11. Data Security

We implement industry-standard technical and organizational measures to protect your data:

  • HTTPS/TLS-encrypted data transmission
  • Role-based access control
  • Log monitoring for suspicious activity
  • Employee data protection training

Despite our efforts, no system is 100% secure. You use the Service at your own risk.

12. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data
  • Correct or update inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time

To exercise any of these rights, email us at [email protected] . We may require identity verification before fulfilling your request.

13. Your Right to Object

Where we rely on legitimate interest to process your data, you have the right to object — especially for analytics, marketing, or profiling.

You can change your preferences or contact us to opt out.

14. Children's Privacy

The Service is not intended for users under 13 years of age, or the minimum legal age in their country. If we become aware that a child has registered, we will delete the account.

Parents can contact [email protected] to request the removal of their child's data.

15. Third-Party Services and Links

Our Service may link to or integrate with third-party websites, services, or content (e.g., social media). We are not responsible for the privacy practices of those third parties.

Please review their privacy policies independently.

16. Changes to This Policy

We may update this policy periodically. The "Last Updated" date will reflect the most recent changes.

  • For significant changes, we'll notify you via email or in-app notification.
  • Continued use of the Service after updates means you accept the revised policy.

17. Contact Us

If you have any questions or requests regarding this Privacy Policy or your data: [email protected]

© 2025 Oxstory. All rights reserved.