Privacy Policy
Effective date: 2026-07-03 Last updated: 2026-08-08
This Privacy Policy explains what personal information PeeOV (the "App"), operated by Porcelain Labs LLC ("we," "us," or "our"), collects, how we use it, who we share it with, and the choices and rights you have. By using the App you agree to the practices described here. This policy should be read together with our Terms of Service.
1. Summary
- The App is a community catalog of public bathrooms. Much of what you post — bathroom entries, reviews, ratings, photos, and Stall Wall marks — is public to other users by design.
- We collect the identity you sign in with (Apple or Google), your precise location (only while you use the App, with your permission), the photos you choose to upload, and the content you create.
- We use a small set of third-party processors to run the App (hosting, maps, search, crash reporting, moderation). We list them in §6.
- We do not sell your personal information, and we do not use it for cross-app advertising.
- You can delete your account and content from inside the App (Profile → Delete account), or by emailing us.
2. Information we collect
2.1 Information you provide
- Account identity. When you sign in with Apple or Google, we receive a unique account identifier and, depending on the provider and your choices, your name and email address. Apple offers a private relay/hide-my-email option, which we support. Your name is stored as your editable display name; you may also set a @handle and a profile photo.
- User content. Bathroom entries (name and location), reviews (a 1–5 rating and sub-ratings, an optional written comment, optional amenities), photos, Stall Wall graffiti marks (optionally anonymous), reactions (hearts/votes), bookmarks (private to you), reports you file, and who you follow.
- Communications. If you email support, we receive your message and contact details.
2.2 Information collected automatically
- Precise location. With your permission, the App uses your device's GPS location to center the map, load nearby bathrooms, and sort your feed by distance. Location is used in real time to query nearby content; we do not build a continuous background location history of you. When you create a bathroom, the location you pin is stored as part of that public entry. You can revoke location permission at any time in your device settings.
- Device identifier. Before you sign in, the App generates a local device identifier so you can post reviews; when you sign in, that pre-auth content is linked to your account.
- Diagnostics / crash data. If crash reporting is enabled in a given build, we use Sentry to collect crash and error reports (stack traces, device model, OS version, app version, and the update bundle id). These reports are tagged only with your account identifier — never your name, email, or handle.
- Product telemetry. We record coarse, non-identifying search signals (e.g. zero-result rates by approximate region) to improve the venue catalog.
- Push tokens. If you enable notifications, we store the push token needed to deliver them.
2.3 Information in photos
Photos you upload may contain metadata (such as capture time). We resize photos before upload and may generate derivative renditions. Do not upload photos that reveal other people in private contexts or that contain sensitive personal information — see the Terms.
3. How we use information
- Provide and operate the App: show nearby bathrooms, publish your reviews and photos, run the Stall Wall, and power search.
- Authenticate you and maintain your account.
- Maintain safety and integrity: filter prohibited language, process reports, enforce rate limits, auto-hide heavily reported content, and act on violations of our Terms.
- Diagnose crashes and fix bugs.
- Communicate with you about your account, support requests, and material changes to our policies.
- Comply with legal obligations and enforce our Terms.
4. Legal bases (EEA/UK users)
Where the GDPR (or UK GDPR) applies, we rely on: performance of a contract (to provide the App you signed up for); legitimate interests (to keep the App safe, prevent abuse, and improve it); consent (for device location and push notifications, which you can withdraw at any time); and legal obligation (to respond to lawful requests and meet retention duties).
5. How your information is shared
- Publicly, by design. Bathroom entries, reviews, ratings, photos, graffiti marks, reactions, and public profile fields (display name, @handle, avatar) are visible to other users and may appear in shareable preview/link cards. Content you post anonymously is not attributed to your handle, but is still associated with your account server-side for safety and moderation.
- With service providers (processors). See §6. They process data only to provide their service to us.
- For legal reasons. We may disclose information if required by law, to respond to lawful requests, to enforce our Terms, or to protect the rights, safety, and property of users, the public, or us.
- In a business transfer. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
- We do not sell your personal information and do not share it for cross-context behavioral advertising.
6. Third-party processors
| Processor | Purpose | Data involved |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | Account identity, all user content, photos |
| Apple, Inc. | Sign in with Apple, Apple Maps, App Store, push | Account identifier, name/email at sign-in |
| Google LLC | Google Sign-In, Google Maps (Android/production) | Account identifier, name/email at sign-in |
| Expo (Expo, Inc.) | App runtime, over-the-air updates, push delivery | Device/app diagnostics, push tokens |
| Cloudflare, Inc. | Share links, web hosting, edge routing | Request metadata (IP, user agent) |
| Photon by komoot / OpenStreetMap | Place/geocoder search fallback | Your search query text and map area |
| Sentry (Functional Software, Inc.) | Crash and error reporting | Diagnostics + account identifier only |
| OpenAI and Amazon Web Services (Rekognition) | Automated content moderation | Submitted review text and photos, for policy screening |
| Resend | Operational/moderation email | Operator email only (not user-facing) |
This list may change as the App evolves; we will update this policy when it does. Each provider processes data under its own terms and privacy policy.
7. Data retention
- Account and content are retained while your account is active.
- When you delete your account, we anonymize and scrub your personal identifiers. Some contributed content — such as bathroom entries and reviews — may remain in the shared catalog in de-identified form (attributed to a generic label rather than your handle) to preserve its integrity, as described in the Terms.
- We may retain limited information as needed for backups, security, fraud-prevention, and legal compliance for a reasonable period, after which it is deleted or further anonymized.
- Crash/diagnostic data is retained per our crash-reporting provider's default retention window.
8. Your rights and choices
- In-app deletion. Profile → Delete account deletes your account and scrubs your personal data (see §7). This satisfies deletion "initiated from within the app."
- Access, correction, deletion, portability. Depending on where you live (including the EEA/UK under GDPR and California under the CCPA/CPRA), you may request access to, correction of, deletion of, or a copy of your personal information, and you may object to or restrict certain processing. Email trust@peeov.app to exercise these rights. We will not discriminate against you for exercising them.
- California "Do Not Sell/Share." We do not sell or share personal information as those terms are defined under California law, so no opt-out is necessary; you may still contact us with questions.
- Location. Manage or revoke location permission in your device settings.
- Notifications. Manage or disable push notifications in your device settings or in the App.
- Complaints. EEA/UK users may lodge a complaint with their local data protection authority.
9. International transfers
We and our processors may store and process information in the United States and other countries whose data-protection laws may differ from yours. Where required, transfers of EEA/UK personal data rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Children
The App is not directed to children. You must be at least 17 years old (the App's App Store age rating) to create an account. We do not knowingly collect personal information from children under 13 (or the equivalent age in your jurisdiction). If you believe a child has provided us personal information, contact trust@peeov.app and we will delete it.
11. Security
We use industry-standard measures — including authenticated access, Row-Level-Security policies on our database, and encrypted transport — to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the App or by another reasonable means before they take effect. The "Last updated" date above reflects the latest revision.
13. Contact
Questions or requests about this policy or your personal information: trust@peeov.app, or Porcelain Labs LLC, 418 Broadway, Ste R, Albany, NY 12207, United States.