Privacy Policy
Last updated: August 3, 2026
1. Information We Collect
Account information: When you sign in, we receive your name, email address, and profile photo from your authentication provider (Google, Apple, or Facebook). We store this to operate your account.
Page content: The profile information, links, and style preferences you add to your Low Ocean page are stored to render your public page.
Usage data: We collect basic analytics about page views and feature usage to improve the Service. This data is aggregated and not sold to third parties. Creator page analytics are counted on our servers and stored only as aggregate totals — analytics records contain no visitor IP addresses and no user-agent strings. Our homepage and sign-in and signup pages additionally use Google Analytics.
Reports and moderation records: If someone reports a public page, we store the reported username, resolved page/account identifiers, report reason, optional details, timestamps, and limited authenticated reporter information when available. Staff role changes and moderation activity are recorded in a server-authored audit log.
Preview product feedback: When an authenticated user sends feedback, we store its category and message, page and app context, account identity, optional follow-up permission, workflow metadata, and timestamps. We use it to improve the Preview and to reply only when requested; follow-up permission is not marketing or waitlist consent. The primary feedback record—including its message, contact email, account and page identifiers, context, and staff note text—is removed with its island or account and is not ported into the future production service. A data-minimized, append-only security receipt may remain to preserve audit-chain integrity. That receipt contains the staff actor, opaque feedback target, status, version, note-presence indicator, and timestamps. It excludes the submitter UID, internal page ID, raw feedback ID, message, contact email, context, page content, and note text.
2. How We Use Your Information
We use your information solely to: operate and improve the Service; render your public page; authenticate your identity; review reports and enforce our Terms; maintain security and audit records; communicate with you about your account; and comply with legal obligations.
3. Data Storage
Your data is stored on Google Cloud Platform (Firebase) infrastructure in the United States. We implement industry-standard security measures to protect your data.
Low Ocean may keep an expiring recovery copy of unsaved editor changes in your browser solely to restore interrupted editing. It is removed after a successful save, explicit discard, or account deletion. Recovery copies expire after seven days and are removed when Low Ocean next opens in that browser; ordinary account saving remains the only server persistence path.
4. Data Sharing
We do not sell your personal information. We share data only with: Google Cloud Platform (infrastructure provider); your chosen authentication provider; Google Analytics to measure visits to our homepage and sign-in and signup pages; and law enforcement when required by law.
A configured email processor receives only the feedback category, opaque feedback ID, public page username, redacted admin context, and item-specific console URL containing only an opaque lookup key. It does not receive the feedback message, verified contact email, Firebase UID, internal page ID, page content, or staff note. Email delivery may be disabled or unavailable without affecting the stored record.
5. Public Pages
When you publish a page, the content you add (display name, bio, profile photo, and links) becomes publicly accessible at your chosen URL. Unpublished pages are not visible to the public.
6. Cookies
We use essential first-party cookies to operate the Service: __session for authentication (httpOnly, secure, expires after 14 days) and lo_csrf, a security token that protects against cross-site request forgery (secure). When you view a creator's public page we set one additional first-party cookie, _lov, scoped to that page, which records only that the visit has already been counted so that a returning visitor is not counted twice; it contains no identifier and is not readable by any third party. On our homepage and our sign-in and signup pages — never on creator pages, and never on this policy or our Terms — we use Google Analytics, which sets its own first-party analytics cookies to measure visits to those pages, and Google Identity Services may also set g_state, a first-party cookie on the homepage and sign-in pages that remembers One Tap sign-in prompt state, only when One Tap is enabled. We do not use advertising cookies.
7. Your Rights
You can: access your data through your account settings; update your information at any time through the editor; delete your account and all associated primary data through the Settings page; and request a copy of your data by contacting us. The narrow exception is the data-minimized append-only security receipt described above, which may remain solely to preserve audit-chain integrity and excludes feedback content and submitter identifiers.
8. Children's Privacy
Low Ocean is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice within the Service.
10. Contact
For privacy-related questions, contact us at work@jackalo.pe.
Low Ocean is operated by Jackalope Technologies, Inc.