01
Scope and status
This draft describes currently verified behavior of the OLSA public website and iOS/Android experience. The final controller identity, contact channel, provider list, legal bases, international transfer safeguards, and retention schedule require external legal approval.
This document does not claim full compliance with the GDPR, KVKK, or any other framework. Legal review is required before store or final production release.
02
Information OLSA may process
- Account data such as email, display name, and verification status.
- Experience inputs the user chooses to share, including decisions, scenario answers, and reflection text.
- Product outputs such as free or full results, life routes, and related operation states.
- Optional reference photos, explicit media consents, and generated image or video assets when the user initiates those features.
- Server-authoritative credit balances, ledger records, and verifiable store purchase evidence if a real store integration is activated.
- Limited request, device, session, and security information needed to operate and protect the service.
03
How the information is used
Information may be used to create and secure an account, produce the alternative-life narrative or optional media requested by the user, deliver results, preserve credit and transaction integrity, answer support requests, and protect the service. The OLSA public website contains no ad pixel, behavioral analytics, or third-party tracking script.
04
Providers and disclosures
Limited providers may be needed for hosting, security, content or media generation, and user-initiated transactions. There is no known product behavior that sells personal information. Final provider names, processing locations, transfer mechanisms, and contractual safeguards are not yet published because they require a verified production inventory and legal review.
05
Retention and deletion
This draft does not invent a number of days, months, or years. The final schedule will consider what is needed to provide the account and requested experience, maintain security and transaction integrity, respond to a valid user request, and meet applicable legal duties. OLSA does not promise a deletion operation that the public product contract does not support.
06
Security and sensitive links
OLSA aims to use technical and organizational safeguards, but no internet service can guarantee absolute security. Password-recovery and email-verification tokens are sensitive bearer credentials. Because Vercel can retain query parameters in request logs, token-based web routing is not considered production-safe until a separate, verified secure edge boundary is in place.
07
Choices, rights, and contact
Optional reference-photo and media features begin only through user action and the explicit consents required by the product. The process for access, correction, deletion, objection, or other privacy requests will be published with the approved controller identity and support channel. OLSA does not display a fabricated contact address while that input is missing.