Privacy policy
This policy describes how Olua (“we”) handles information in the Olua iOS app and on olua.io. Controller: Jonas Perrin, France. Contact: olua@nyzom.com.
What we cannot read
Documents you store in the vault are encrypted on your device before they are sent. Extracted fields are encrypted the same way. We do not have the keys. We cannot decrypt your vault, and we cannot run models on your papers in our cloud. On-device processing (classification, extraction, Face ID unlock) stays on the phone.
What we process
To run the account and sync ciphertext between your devices, we process:
- Your email address and a hashed login password
- Encrypted blobs and encrypted key material we cannot open
- Operational metadata: approximate sizes, timestamps, document counts, and similar service logs
- Technical data such as IP address and device/app version, as produced by ordinary hosting and network logs
- If you share a pack: the fact of a presentation (when it was created, opened, expired, or revoked), not the underlying documents
We do not sell personal data. We do not show ads. We do not use your documents for training. We do not run third-party analytics or crash reporters in the app today.
Permissions on the phone
- Camera — to scan documents. Frames are used to build a proof on the device, then encrypted.
- Photos — if you import an existing image of a document. Same path: encrypt on device.
- Face ID — optional, to unlock the vault on this device. Biometric data is handled by iOS. It is not sent to us.
Why we process it
Account and hosting data are processed to provide the service (contract) and to keep it secure and available (legitimate interests). Where GDPR requires consent for a specific optional feature, we will ask. You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests, and you may complain to your local supervisory authority (in France, CNIL).
Retention
We keep account data and ciphertext while the account exists. If you ask us to delete your account, we delete the account record and associated blobs from our systems, subject to short-lived backups and any legal duty to retain a record. Packs expire; after expiry or revocation they are no longer available to the recipient.
Processors and transfers
We use hosting and infrastructure providers to store ciphertext and account data and to deliver the API. Those providers process data on our instructions. They may be located outside your country. Vault contents remain encrypted with keys we do not hold.
Children
Olua is not directed at children under 16. We do not knowingly create accounts for them.
Changes
If this policy changes in a material way, we will update this page and the effective date. Continued use after the update means the new policy applies.
Contact
Questions or requests: olua@nyzom.com.