OYOM Privacy Policy
Effective date: September 7, 2026
OYOM (OneYearOneMedia, at oyom.app) is a free, non-commercial app where friends send each other one media recommendation per year. It is built and run by one person in New Zealand, not a company. This policy explains, in plain language, what data OYOM collects, why, and what you can do about it. It applies to the website, including when installed on a Home Screen, and the current Android internal-testing app.
OYOM collects the minimum it needs to work, shows no ads, runs no tracking, and never sells your data. Profiles are public by design, so read that section carefully.
Who is responsible for your data
The data controller is the individual developer of OYOM, based in New Zealand. Contact: oneyearonemedia@gmail.com.
What we collect and why
Account details. When you sign in with Google, we receive and store your email address, a username derived from the part of your email before the @, and your Google profile picture URL. We use these to create and identify your account and to send you emails you’ve opted into. We never see or store a password; authentication is handled by Google through Supabase Auth.
Your public profile and prescriptions. Your username, profile picture, join date, “your word” score (a completion-rate health score), friends list, and prescriptions: the media you’ve recommended and received, including title, type, poster image, link, and status (completed, failed, and so on). This is the content of the app; it exists so your friends, and anyone else (see below), can see it.
Private messages. You can attach an optional text message when sending a prescription, and the recipient can write a response. These are visible only to the two people involved, and to the developer at the database level (see “Who can see your data”).
Friendships and friend requests. Stored so the app knows who your friends are.
Notifications. In-app notification records, so you can see what’s happened.
Invitee email addresses. If you invite someone who isn’t on OYOM, we store the email address you entered and the invite’s status, and send them an invite email from invites@oyom.app. This is data about a person who hasn’t signed up; see “If someone invited you” below.
Push notification endpoints. If you enable push notifications, we store either a Firebase Cloud Messaging token for the Android app or a Web Push subscription endpoint and the encryption material needed by your browser. We use these only to deliver notifications to that installation.
Media search queries. When you search for media to prescribe, your query is sent from our server to third-party catalog APIs (TMDB, AniList, Jikan/MyAnimeList, TVmaze, OMDb, IGDB/Twitch, RAWG, Deezer, iTunes, Open Library, Google Books). Results are cached on our server keyed by the query text only, so the cache is not linked to your account.
We do not collect analytics, location, contacts, device identifiers (beyond the push endpoint you opt into), or anything else not listed here.
Profiles are public by design
OYOM profiles are visible to anyone on the internet, without logging in. That includes your username, profile picture, join date, your word score, friends list, and your full prescription history with statuses. Private messages attached to prescriptions are not public.
Please don’t put anything in your username, profile picture, or prescriptions that you wouldn’t want public. If you delete your account, your profile and its content are removed.
If someone invited you (data about non-users)
If an OYOM user invited you by email, we hold your email address and the invite status, solely to send and track that invite. We got it from the person who invited you, not from you. If you’d like it removed, email oneyearonemedia@gmail.com and it will be deleted. You can also just ignore the invite; we don’t use invitee emails for anything else, and we never send marketing.
Who can see your data
- Anyone: your public profile (see above).
- The two people in a prescription: the private messages on it.
- The developer: has database-level access to everything, used only to run, debug, and moderate the app.
- Nobody else. We don’t sell data, share it with advertisers, or use tracking or analytics SDKs.
Service providers (processors)
OYOM runs on third-party infrastructure that processes data on our behalf:
- Supabase: database and authentication, hosted in Sydney, Australia (ap-southeast-2)
- Vercel: website hosting (Sydney, syd1)
- Resend: sends invite and notification emails
- Google Firebase Cloud Messaging: delivers push notifications
- Apple Push Notification service and Mozilla Push Service: deliver Web Push notifications for browsers that use them
- Google: sign-in
These providers process data only to provide their service, under their own privacy and security commitments, which offer protection consistent with this policy. The categories of provider may change (for example, an error-monitoring service such as Sentry may be added); if a change meaningfully affects your data, this policy will be updated.
Where your data lives
Primary data is hosted in Sydney, Australia. Some providers (email delivery, push notifications, sign-in) may process data in other countries, including the United States, as part of providing their service. Because profiles are public, profile content is viewable worldwide.
Emails, push notifications, and your choices
We send transactional emails (invites, notifications about prescriptions and friend activity) via Resend, plus optional native Android and Web Push notifications. Every notification type has its own on/off switch at /knobs, where Web Push can also be enabled or disabled for the current browser. No marketing emails, ever.
Cookies
Essential cookies only, used by Supabase Auth to keep you signed in. No advertising or analytics cookies.
Retention
We keep your data while your account exists. When you delete your account, your account and associated personal data are removed. Invitee emails are kept until the invite is accepted (at which point they become part of the new account), or until removal is requested. Cached search results aren’t linked to you and are periodically refreshed. Some residual data may persist briefly in database backups before those cycle out.
Deleting your account
Delete your account at the bottom of the /knobs page, in the app or at oyom.app/knobs in any browser, so you can delete your account and data even if you’ve uninstalled the app. Deletion removes your account and associated personal data as described under Retention.
Your rights
You can access, correct, or delete your data. Most of it is visible in the app already; account deletion is self-serve at /knobs; for anything else (a copy of your data, a correction, removal of an invitee email), email oneyearonemedia@gmail.com.
If you’re in the EU/EEA or UK, you also have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your local data protection authority. Where OYOM processes your data, it does so to provide the service you signed up for (contract), and for basic service operation and moderation (legitimate interests).
OYOM is run by an individual in New Zealand as a personal, non-commercial project; this policy is written to meet good-practice standards (in the spirit of the New Zealand Privacy Act 2020) regardless of which laws technically apply at this scale.
Children
OYOM is for people aged 13 and over. We don’t knowingly collect data from anyone under 13; if we learn we have, we’ll delete it. Contact oneyearonemedia@gmail.com if you believe a child under 13 has an account.
Changes to this policy
If this policy changes materially, we’ll update the effective date above and note the change in the app or by email. Continued use after a change means you accept the updated policy.
Contact
Questions, requests, or concerns: oneyearonemedia@gmail.com.