Privacy Policy
Last updated: 2026-10-05
Account and authentication information
Ovelo stores your account name, email, verification status and role. Passwords are stored as password hashes. Google sign-in uses a verified identity/email; Discord uses the identify scope by default. Provider account identifiers are stored for explicit linking. OAuth code exchanges take place server-side; provider secrets and access tokens are not exposed to frontend JavaScript.
Your inventory and documents
The service stores the item details you supply, values, locations and optional coordinates/Maps links, warranties, repairs, supporting files and ownership activity. File metadata includes name, type, size and checksum. Image processing removes metadata such as EXIF; document content remains private to authorized accounts.
Sessions, cookies and security
Random HttpOnly cookies identify database-backed sessions. Session-token and CSRF hashes, expiry and optional user-agent information are stored server-side. Administrator sessions are separate and have shorter lifetimes. OAuth state and rate-limit entries use Redis with expiration; rate-limit subjects are HMAC-derived rather than public raw identifiers. The host-only web administrator gate is bound to the live administrator session.
Logs and administration
Operational errors, request identifiers, login/security events and item activity help operate and secure the service. Administrator audit entries record actor, action, target, time, result, request ID and user agent where provided. Audit logging excludes passwords, session cookies, reset tokens, provider tokens and connection credentials. Hosting/reverse-proxy infrastructure may maintain its own request logs.
Configured SMTP is used for verification and password-recovery messages. Recovery tickets are expiring, hashed server-side and consumed once. The SMTP provider processes the recipient and message to deliver the email. Availability is dependent on actual mail configuration.
Infrastructure and optional integrations
The deployment uses PostgreSQL for metadata, Redis for security/queues and the configured storage provider for files. Production currently uses external Aiven PostgreSQL, TLS Redis and local container storage. Google/Discord receive information during sign-in. Google Maps/Places may receive a search when optional server-side search is configured or you open a Maps link. Optional Drive/Bunny storage applies only when configured.
Camera and scanning
Camera permission is requested only after choosing to scan. Frames and uploaded scan images are decoded locally in your browser and are not sent to a third-party scanner. The decoded code is sent to Ovelo to resolve your authorized item.
Retention and deletion
Records remain while needed for your account and configured service operation. Archiving an item preserves its history. Document deletion removes the attached stored file through the provider; account deletion revokes sessions and removes or de-identifies associated records according to application deletion behavior. Security and administrator audit history may be retained for accountability; provider backups may persist until their retention expires. We do not promise immediate erasure from every backup.
Your choices and contact
You can update records, delete documents, revoke sessions, unlink by contacting support where a self-service option is unavailable, and request account export/deletion through account controls or support. Contact contact@lightsout.in for privacy questions or requests applicable to your circumstances. This policy describes actual functionality and does not claim legal certification.