intelligence

Privacy policy

Last updated September 12, 2026

This app is operated by OVRFLW Digital LLC for its content clients. It is not open to the public — accounts exist only by invitation. This page explains what the app stores, why, who else sees it, and how to have it removed.

Who this covers

Two different groups, with different relationships to us, and it matters which one you are.

People with accounts — our staff and our clients' teams. You signed in, so you know you are here.

Creators on a watch list — public social accounts whose posts a client asked us to study. You did not sign up, you may not know this app exists, and you still have rights over what it holds. The section on removal below is written for you.

What we store about account holders

Email address and name

To sign you in, to address you in the app, and to attribute an approval to a specific person rather than to nobody.

Password

Held by our authentication provider as a salted hash. We never see it and cannot recover it — a reset replaces it.

Profile picture, theme and accent colour

Appearance settings, stored per person rather than per workspace.

What you did and when

Approvals, comments, edits and deletions are logged with your identity. For clients in regulated industries this record is the point: it can show who approved which version of which words, on what date.

What we store about a client's work

Scripts, slides, hooks and notes

The content being produced, including every revision so an earlier version can be recovered or compared.

Shoot dates, times and locations

Including the address of a filming location and its map coordinates, so a shoot can be found on a map. Addresses are supplied by the client, not collected from a device.

Published post performance

Views, likes and comment counts on the client's own posts, to measure what worked.

What we store about creators on a watch list

This is the part most privacy policies do not have, so it is worth being plain about. At a client's direction we collect information from public social media profiles they have asked us to study — typically competitors, peers, or accounts in the same niche.

Handle, profile picture, follower and post counts

Captured daily so growth can be plotted over time rather than guessed at.

Public posts

Caption, hashtags, thumbnail, link, length, and engagement numbers.

Transcripts of public videos

Generated automatically so a video can be read and analysed as text.

Analysis we derive

Topic, hook style, and how a post performed against that account's own typical numbers.

All of it is taken from pages that are public without logging in. We do not access private accounts, we do not log in as anyone, we do not message anyone, and we do not attempt to identify the person behind a handle, find their contact details, or combine this with data from anywhere else. It is used to inform our clients' own content and is never sold, licensed, or shared for advertising.

Who else sees it

We do not sell personal information and we do not share it for advertising. Providers who process data to make the app work:

Supabase

Database, file storage and authentication.

Vercel

Hosting and application logs.

Apify

Collecting public social media data.

Anthropic

AI assistance for drafting and analysis.

OpenAI

Transcribing public video audio to text.

OpenStreetMap (Nominatim)

Turning a typed shoot address into map coordinates.

Resend

Sending invitation and notification email.

Each client's workspace is isolated from every other one at the database level, not merely hidden in the interface. A client cannot see another client's content, watch list, or results.

How long we keep it

Work product is kept for the life of the client relationship and then removed at the client's request. Published-post performance data is kept as long as it is useful for comparison.

Where a client is a registered investment adviser or otherwise regulated, some records must be retained for a period fixed by that client's own obligations rather than by ours. Those terms are set in the agreement with that client.

Having your information removed

If you are a creator on a watch list and you would rather not be, email dylan@ovrflwdigital.com with your handle. We will remove your account and everything collected from it, and add the handle to a permanent exclusion list so it is not picked up again. No explanation required and nothing to prove — a request from the handle itself, or naming it, is enough.

If you have an account, write to the same address to see what is held about you, correct it, or close the account.

Depending on where you live you may have additional rights — access, deletion, correction, portability, and the right not to be discriminated against for exercising them. We apply the removal process above to everyone regardless of location, because running two standards would be harder than running one.

Security

Access is by invitation only and every request is checked against the database itself, so a link alone never grants access to a workspace you are not a member of. Passwords must meet a minimum length and character requirement and are stored only as hashes. The app is not indexed by search engines.

No system is perfect, and we would rather say that plainly than imply otherwise. If you believe you have found a security problem, email dylan@ovrflwdigital.com and we will look at it promptly.

Children

This is a professional tool, not offered to anyone under 18, and we do not knowingly create accounts for minors.

Changes

If this policy changes in substance we will update the date at the top and tell account holders by email. We will not quietly broaden what we collect and rely on you to notice.

Contact

OVRFLW Digital LLC, Georgia, United States
dylan@ovrflwdigital.com

This policy is governed by the laws of the State of Georgia.

Questions about a specific client engagement — what is collected for it, or how long it is kept — are answered in the agreement with that client, which takes precedence over this page where the two differ.