Privacy Policy

Effective September 2026

oodbo is a forward-only writing tool. This policy describes what information we collect, how we use it, and how your writing is stored.

What we collect

We do not use analytics, behavioural tracking, or advertising cookies.

Your writing

Your projects are stored in your browser on your own device and, if you sign in with Google or Microsoft, in a hidden app folder in your own Google Drive or OneDrive. Project files are encrypted on your device before they sync, and — apart from a public share link you choose to create (see Shared content below) — we do not store your projects on our own servers or read their contents. Because that sync copy is encrypted before it leaves your device, the file held in your Google Drive or OneDrive is stored as ciphertext rather than readable text — it is not exposed in a form that can be mined or used to train AI models.

How sign-in works

Magic link: We send a one-time sign-in link to your email via Resend. The link expires in one hour and can only be used once.

Google / Microsoft: We use OAuth 2.0. Your credentials go directly to Google or Microsoft — we never see your password. We receive only your email address and the tokens needed to access your Drive app folder.

Cloud storage

If you sign in with Google or Microsoft, your project files (.oodbo) are saved to a hidden app-specific folder in your Google Drive or OneDrive. This folder is not visible in your Drive or OneDrive interface. Only oodbo can access it. You can export your projects at any time using the Export .oodbo option, or retrieve them via Google Takeout or Microsoft's data export tools.

Shared content

If you create a public share link for a project or section, a snapshot of that content is copied to and stored on our servers so it can be shown on a public page. Unlike your synced files, this snapshot is not encrypted — it has to be readable to display. Anyone with the link can view it and no sign-in is required, so treat a share link as public. Shared pages are marked “no index” so search engines do not list them.

You can update or remove a share link at any time from Shared Links in the app. Removing it takes the public page offline immediately; we retain the deactivated record for abuse handling and audit, and it is deleted if you delete your account. Content rules for shared pages are set out in the Sharing Policy.

Third-party services (subprocessors)

The following third parties process personal data on our behalf. We will provide at least 14 days notice before adding any new subprocessor that has access to personal data.

Data retention

Your account record (email, paid status) is kept for as long as your account exists. Magic link tokens are deleted after use or expiry. OAuth tokens are replaced on each sign-in. Active session records are deleted when you sign out. Auth event logs (sign-in attempts, rate-limit events) are automatically deleted after 90 days. If you would like your account deleted, email us at hello@oodbo.io and we will remove it within 30 days.

Your rights

You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Contact us at the address below.

Changes to this policy

If this policy changes, the updated version will be posted at this URL with a revised effective date.

Contact

Questions about this policy: hello@oodbo.io