1. Who is responsible for your data
Ooni is currently a pre-launch project run jointly by its founders, Hind Naaman and Jamil Mansour, pending the incorporation of the dedicated operating company that will succeed them (the "Future Company").
Until that incorporation, the founders act as joint Data Controllers within the meaning of Article 26 of Regulation (EU) 2016/679 (GDPR). They are jointly responsible for deciding why and how your personal data is processed in connection with the Ooni platform and mobile app (together, the "Platform"), and they act through the project name "Ooni".
Public contact point: privacy@ooni.education — for any privacy-related question, request or right under the GDPR. This mailbox is monitored regularly and is the single point of contact for data subjects.
As a data subject, you have the right to know the identity of the natural persons acting as joint Data Controllers. Their full identification details (name, ID number, contact address) are available on written request to privacy@ooni.education and will be provided promptly. From the date of incorporation of the Future Company, that company will become the sole Data Controller and its full identification details (legal name, NIF, registered office) will be published in this Policy.
This Policy is provided in compliance with Articles 13 and 14 of the GDPR and Spanish Organic Law 3/2018 of 5 December (LOPDGDD).
2. What this Policy covers
This Policy explains how Ooni collects and uses your personal data when you use the Platform, whether as:
- an "Oonster" — a prospective student who uses the Platform to watch videos, read profiles, and book paid chats and video calls with current students; or
- an "Ooner" — a current student or recent alumnus who applies to share their academic and life experience through the Platform and receives compensation for chats and video calls.
The Platform is intended only for adults aged 18 or over. We do not knowingly collect data from anyone under 18. If we become aware that a person under 18 has created an account, we will delete it.
This Policy should be read together with our Terms and Conditions and, for Ooners, the Image and Video Marketing Consent.
3. What personal data we collect
3.1 All users
- Account data: email address (used for one-time-code login), name, and the profile information you choose to provide.
- Usage data: content you view, searches, bookings, and interactions on the Platform.
- Communications: messages exchanged in Platform chats, and recordings of video calls made through the Platform. Chats and calls take place exclusively through the Platform, and calls are recorded for safety, moderation and dispute resolution — both participants are notified at the start of each call.
- Technical data: IP address, device type and identifiers, operating system, app version, crash logs and similar log data generated automatically when you use the Platform.
3.2 Ooners (additional)
- Application data: educational institution, programme, field of study, city and country of study, languages, year of study or graduation, and the information in your application.
- Verification documents: a copy of your student ID or equivalent proof of enrolment or alumni status, which you upload for identity and status verification.
- Video and profile content: the introductory and additional videos, photographs and written content you create or upload. Optional marketing use of your image and voice is governed by the separate Image and Video Marketing Consent.
- Payout data: the information needed to pay you, collected and processed by our payment provider Stripe (see Section 5). Ooni does not store your full bank or card details.
3.3 Oonsters (additional)
- Preference data: the field of study, city or country you are interested in.
- Purchase data: wallet top-ups, credit balance and transaction history. Payments are processed by Stripe; Ooni does not store your full card details.
We do not knowingly collect special categories of data (health, religion, ethnicity, political views, sexual orientation, etc.). Please do not include such information in free-text fields, chats or videos.
4. Why we use your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| 4.1 Operating the Platform — creating and managing your account, logging you in via one-time email codes, displaying profiles and videos to Oonsters, enabling bookings, chats and video calls, and operating the Wallet | Performance of a contract (Art. 6.1.b GDPR) |
| 4.2 Verifying Ooners — checking identity, age and student/alumni status before an Ooner profile goes live | Performance of a contract (Art. 6.1.b) and legitimate interest in keeping the Platform trustworthy and safe (Art. 6.1.f) |
| 4.3 Payments and payouts — processing Oonster payments and Ooner compensation through Stripe | Performance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) for accounting, tax and anti-fraud rules |
| 4.4 Transactional communications — emails about your account, verification outcome, bookings and payments | Performance of a contract (Art. 6.1.b) |
| 4.5 Displaying Ooner content in-app — showing Ooner videos and profiles to Oonsters inside the Platform, which is the core service Ooners sign up to provide | Performance of a contract (Art. 6.1.b) |
| 4.6 Marketing use of Ooner content — using Ooner videos or images in Ooni's marketing, social media or advertising. This is optional, requires your separate, explicit consent, is off by default, and can be given or withdrawn at any time in your settings without affecting your use of the Platform | Consent (Art. 6.1.a) |
| 4.7 Call recording and chat screening — recording video calls and storing chats held through the Platform, used strictly for safety, moderation, dispute resolution and fraud prevention, and never for marketing. Chats are screened automatically for content prohibited by the Terms (such as attempts to exchange personal contact details, move payments off the Platform, or zero-tolerance behaviour); human review of chats and call recordings takes place only when a report, dispute or legal obligation requires it | Legitimate interest (Art. 6.1.f) |
| 4.8 Safety, security and fraud prevention — protecting the Platform against abuse, enforcing conduct rules, moderating reported content, and maintaining logs | Legitimate interest (Art. 6.1.f) |
| 4.9 Legal compliance — responding to lawful requests from competent authorities and complying with applicable law | Legal obligation (Art. 6.1.c) |
| 4.10 Improving the Platform — aggregated, anonymised analytics to understand how the Platform is used | Legitimate interest (Art. 6.1.f) |
Providing your data is voluntary, but without the minimum information (email, and for Ooners the verification documents) we cannot provide the service.
5. Who has access to your data
Your personal data is accessed only by the Ooni founders and a limited number of service providers acting as processors on our behalf, under contracts that meet Article 28 GDPR:
- Supabase — application database, authentication and secure file storage (including verification documents);
- Mux — video hosting, processing and streaming;
- Stripe — payment and payout processing. Stripe acts as an independent controller for the identity (KYC) data it collects to meet its own legal obligations; see Stripe's privacy policy;
- Resend — transactional email delivery;
- Vercel — website hosting.
Some of these providers are located in, or use infrastructure in, the United States. Where personal data is transferred outside the European Economic Area, we rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, together with additional safeguards where appropriate.
We do not sell your personal data. We do not share your personal data with educational institutions or other third parties for their own purposes without a legal basis, and never without telling you.
6. How long we keep your data
- Account and profile data: for as long as your account is active, then deleted or anonymised within 30 days of account deletion, subject to the exceptions below.
- Verification documents (student ID): kept only as long as needed to complete the verification decision and handle any resubmission, then deleted within 90 days of the final decision.
- Chats: for as long as your account is active, and up to 12 months afterwards where needed for safety, dispute resolution or fraud prevention.
- Call recordings: 90 days after the call, then deleted automatically — kept longer only where a specific recording is needed for an open report, dispute or legal obligation.
- Videos and profile content: until you remove them or delete your account. Content already used under a separately granted marketing consent is governed by the Image and Video Marketing Consent.
- Payment and payout records: up to 6 years after the transaction, as required by Spanish commercial and tax law.
- Security logs: up to 12 months.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interest, and to withdraw any consent at any time (without affecting prior processing).
To exercise any right, write to privacy@ooni.education. We will respond within one month (Art. 12.3 GDPR).
You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or your local supervisory authority.
8. Deleting your account and data
You can delete your account at any time:
- In the app: Settings → Account → Delete account; or
- On the web, without reinstalling the app: visit ooni.education/delete-account or email privacy@ooni.education from your registered address.
When you delete your account we delete your profile, videos, preferences and chat history, subject only to the retention exceptions in Section 6 (for example, payment records we must keep by law, or data needed for fraud prevention). Deletion is permanent and completed within 30 days. If you have a pending payout or booking, we will tell you what needs to be resolved first.
9. Security
We apply appropriate technical and organisational measures, including encryption in transit, access controls, row-level security on our database and storage, and restricted access to verification documents. No system is completely secure; if a personal data breach occurs that is likely to result in a high risk to you, we will inform you and the competent authority as required by Articles 33–34 GDPR.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Platform or by email before they take effect. The "Last updated" date at the top indicates the current version. On incorporation of the Future Company, this Policy will be updated to identify it as the sole Data Controller; the change of controller will not reduce your rights or protections.