Privacy Policy

Effective: 13 August 2026

Last updated: 13 August 2026

Operator: David Jameson trading as DeskJockey Digital

Address: Office 15396, 182–184 High Street North, East Ham, London, E6 2JA

Contact: hello@deskjockeydigital.co.uk

Governing law: England & Wales

This Privacy Policy explains how Oriva ("we", "us", "our") collects, uses, and protects your personal information when you use the Oriva website at oriva.dev and the Oriva mobile apps for iOS and Android (together, the "Service"). Oriva is operated by David Jameson trading as DeskJockey Digital. For the purposes of UK GDPR and EU GDPR, we are the data controller of personal data processed through the Service.

The iOS and Android apps are thin native shells (built with Capacitor) around the same Oriva web experience. Everything in this policy applies equally to the web and the native apps, except where a section calls out a native-only or web-only difference.

1. Who can use Oriva

Oriva is intended for adults aged 18 and over. When you create an account you must confirm that you are 18 or older; this confirmation, together with its timestamp, is stored on your profile as an immutable audit record. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.

2. Information we collect

  • Account data: email address and a securely hashed password (or a linked Google/Apple identifier if you sign in with a social provider, including Sign in with Apple on iOS). We do not receive or store your social-provider password. We also store your 18+ age confirmation and its timestamp.
  • Profile data: display name, username, biography, avatar image, profile header style, profile visibility setting (private/public), discoverability flag, and consent records (terms acceptance and privacy acknowledgement timestamps).
  • Content you create: countries you mark as visited, lived in, or wishlisted; places (name, coordinates, country) resolved from third-party place-search results and cached; memories (title, notes, date, country, optional linked place); uploaded photographs (stored in a private object-storage bucket and only made accessible via time-limited signed URLs, or via public read paths when you have opted a memory into your public world); collections that group countries, places, or memories. Coordinates are only recorded for places you explicitly choose from search results — Oriva does not access your device GPS.
  • Trust & safety data: reports you submit through the in-app "Report" action on a profile or memory (reason, optional detail, timestamp, and the account or content being reported), and the list of accounts you have blocked from Settings → Blocked accounts. Reports are visible only to us and are used to review potential policy violations. Authorised moderators may access the reported account and inspect the reported content, including a memory that is otherwise private, solely for trust and safety review.
  • Share activity: a lightweight record of share actions you initiate (which share card, which surface) used to power personal referral attribution and abuse-prevention rate limits. We do not receive information back from the destination platform.
  • Usage and device data: log data such as IP address, browser/user-agent string, device identifiers, requested pages, and timestamps, collected transiently by our hosting and CDN providers for security, abuse prevention, and operational diagnostics. On iOS and Android, the operating system may also collect standard crash and performance telemetry through the App Store / Google Play channels.
  • Product analytics and error data (only with your Analytics consent): if you turn Analytics on, we use PostHog (EU-hosted endpoint) for product analytics. This covers three things: named product events we send deliberately — such as creating, updating or deleting a memory, changing a country status, updating your profile, changing profile visibility, completing onboarding, and sharing or exporting; page views within the app; and PostHog’s configured autocapture behaviour, which records generic interaction signals such as clicks on elements and the page they occurred on. We also send error/exception reports. Where you are signed in, these events are linked to your Oriva user ID and email address. Session recording (session replay) is not enabled, IP data is discarded by our PostHog project configuration rather than retained against your events, and we do not use PostHog for advertising, cross-site tracking or data brokerage. Under our current consent gate PostHog is not initialised and captures nothing at all before you grant Analytics consent; if you withdraw consent, capture is stopped and the PostHog identity is reset.
  • Place search queries: when you search for a place, the text you type is sent server-side to the Photon geocoding service (operated by Komoot) to return matching results. We do not collect precise device location.
  • Email and lifecycle data: we send your email address, first name, Oriva user ID, signup date, signup source, marketing subscription state, and limited lifecycle event names and properties (for example memory_created, memory_count_reached, country_completed, onboarding_completed, profile_updated, country_status_set, bucket_list_updated) to our email provider, Loops. Memory text, photographs and place coordinates are not sent to Loops.
  • Communications: messages you send us through support, feedback, or bug reports (these open your own email client — Oriva does not host an in-app inbox).

Oriva does not currently offer in-app messaging, comments, likes, follows, or any other social-interaction surface beyond public discovery, in-app reporting, and blocking. If we introduce further social features, we will update this policy before they launch.

3. Lawful bases for processing (UK & EU GDPR)

  • Contract (Art. 6(1)(b)): to create and operate your account and deliver the Service you've signed up for.
  • Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent abuse, understand how the product is used, and improve it. We balance these interests against your rights.
  • Consent (Art. 6(1)(a)): for optional features such as making your profile public, and for any non-essential cookies or analytics where consent is required.
  • Legal obligation (Art. 6(1)(c)): where we must comply with applicable law (for example responding to lawful requests).

4. Public profiles and discoverability

Each Oriva account has a visibility setting that you control in Settings → Profile visibility. By default profiles are private and are not publicly discoverable.

If you choose Public, you consent to your profile and any content you have marked as public being accessible:

  • via a direct link to your public profile page, public country pages, and public place pages;
  • through current and future search functionality within the Service;
  • through Discover (Search Users, Featured Worlds, Recently Updated Worlds, and Recommended Worlds);
  • through share cards you generate and share externally, and through the Open Graph / social preview metadata rendered for those public URLs;
  • through indexing by search engines that crawl public pages in accordance with our robots.txt and per-page indexing directives.

When your profile is public, the following may be visible to anyone: username, display name, avatar, biography, public memories, public photographs, public world (country) data, public places, public collections, and public statistics. You can return your profile to Private at any time. Switching to Private removes your profile from discovery surfaces and future search-engine crawls; however, copies already shared externally (such as downloaded share cards, cached search results, or links a viewer has already saved) cannot be recalled.

The Oriva landing page at oriva.dev embeds a live, read-only preview of the Oriva app inside a phone-shaped frame. That preview loads the same public routes any visitor could open directly. It does not display private accounts or private content.

5. How we use your information

  • to create and manage your account and authenticate sign-in (including via Google or Apple, including Sign in with Apple on iOS, where you choose those providers);
  • to host, store, process, and display the content you create;
  • to render public profiles, public country/place pages, and share cards when you choose to share;
  • to send essential service emails (verification, password resets, magic-link sign-in, email-change confirmations, security notices) via our email delivery service at notify.deskjockeydigital.co.uk;
  • to send Oriva marketing and lifecycle emails (feature news, travel milestones) via Loops, where you have given marketing consent;
  • to understand product usage and diagnose errors through PostHog, where you have given analytics consent;
  • to return place-search results by sending your search text to the Photon geocoding service;
  • to receive, triage and act on in-app reports and to enforce blocks between accounts;
  • to provide support, respond to feedback, and process bug reports;
  • to keep the Service secure, detect abuse, and enforce our Terms of Use and Acceptable Use Policy;
  • to comply with legal obligations.

5a. Marketing email and consent

Marketing consent is off by default. It is stored against your account (profiles.marketing_consent), and if you make an explicit choice before your account exists, that choice is applied to your account after you sign up. When marketing consent is on, your Loops contact is set to subscribed and added to our “Oriva Users” mailing list; when it is off, your contact is set to unsubscribed and removed from that list. You can withdraw consent at any time from cookie preferences or by using the unsubscribe link in an email, which also clears the marketing consent state on your account. Essential transactional emails (verification, password reset, magic link, email-change, security notices) are sent separately and are not affected by marketing consent.

6. Sharing and sub-processors

We do not sell your personal data, we do not share it with data brokers, and we do not share it for cross-context behavioural advertising. We share data only with service providers ("sub-processors") who help us run the Service:

  • Lovable Cloud (backed by Supabase, Inc.) — application backend, Postgres database, authentication, private object storage for uploaded photographs (memory-photos, avatars), and server-side functions. Primary processor for account data and Your Content.
  • Cloudflare, Inc. — content delivery, DNS, edge runtime for our server functions, and DDoS/edge security. Processes request metadata (IP address, request headers) transiently.
  • Lovable (GPTEngineer AB) — hosting and deployment platform for the web application at oriva.dev, and the transactional email delivery pipeline used for verification, password reset, magic-link, email-change, reauthentication, and other account emails, sent from notify.deskjockeydigital.co.uk.
  • PostHog — product analytics and error/exception monitoring, using the EU-hosted endpoint eu.i.posthog.com. Only initialised after you grant Analytics consent. Receives named product events, in-app page views, PostHog’s configured autocapture interaction signals, and error/exception reports. Where you are signed in, events are linked to your Oriva user ID and email address. Session recording is not enabled, no PostHog integrations or destinations are configured, IP data is discarded by our project configuration, and PostHog is not used for advertising or cross-site tracking.
  • Loops — lifecycle and marketing email delivery. Receives your email address, first name, Oriva user ID, signup date, source, marketing subscription state, and lifecycle event names with limited properties. It does not receive memory text, photographs or place coordinates.
  • Photon (operated by Komoot GmbH) — place/geocoding search. Receives the place-search text you type, sent from our servers. It does not receive precise device location.
  • OpenFreeMap (OpenMapTiles OÜ) — serves the vector base-map tiles used inside the World map view. Tile requests include your IP address and the tile coordinates being requested; no cookies are set by the tile server. Map data © OpenStreetMap contributors.
  • OpenStreetMap — where embedded or static map content is used, loading it may cause network requests to OpenStreetMap infrastructure, which will see your IP address.
  • jsDelivr — public CDN used to deliver world-atlas / TopoJSON map geometry files. Requests include your IP address.
  • Google Fonts — the app loads the Inter and Instrument Serif web fonts from fonts.googleapis.com and fonts.gstatic.com on every page load, so that Oriva renders in its intended typefaces. These requests include your IP address, user-agent and the referring page. No Oriva account data is sent, and Google Fonts is not used for advertising or analytics by us.
  • Google and Apple — identity providers for “Sign in with Google” and “Sign in with Apple”. They process your sign-in under their own privacy notices. They are not Oriva marketing or advertising providers.
  • Public share destinations — when you tap a share-card action (e.g. Instagram, TikTok, WhatsApp, Messages, Mail, or the system share sheet), the image and any link you send are handed to that destination and processed under its own terms and privacy notice. Oriva does not send anything on your behalf.
  • Future payment processor (e.g. Stripe) if and when premium subscriptions are introduced, for payment processing only.

Sub-processors process personal data on our instructions under appropriate contractual terms. We may also disclose information where required by law, to enforce our terms, or to protect the rights, property, or safety of Oriva, our users, or others.

Oriva does not use advertising networks, cross-site trackers, fingerprinting, session replay, or data brokers, and there is no advertising identifier (IDFA / App Tracking Transparency) implementation in the iOS app.

7. International data transfers

Some of our sub-processors are located outside the UK and EEA, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or adequacy decisions.

8. Data retention and account deletion

We retain your account data and content for as long as your account is active. When you delete your account from Settings → Delete account, we remove your core account and content data from the live Service, including your profile, countries, memories, user-place links, share records, subscription record, uploaded avatar and memory photographs, and your authentication account.

Deleting your authentication account also removes records that are linked to it in our database, including reports you have submitted, your block list, and the lifecycle-event records used to avoid sending you the same milestone email twice. In other words, we do not keep a shadow moderation history about you in the live database after deletion.

A limited set of records is not removed:

  • Canonical place records — shared, non-personal reference data (a place name, coordinates and country) that other people’s memories also point at. These are not your personal account content.
  • Email suppression / unsubscribe records and email delivery records — retained so that an unsubscribe or bounce continues to be honoured and so we can evidence deliverability. These hold your email address and the suppression reason, and nothing else about you.

Residual copies may also persist in encrypted backups for a limited period before being overwritten, and our processors run their own retention processes. In particular, deleting your Oriva account does not currently delete your contact record at our email provider, Loops — that contact (email address, first name, Oriva user ID, signup date and subscription state) may remain with Loops until it is removed separately. We cannot guarantee that every record held by every processor is deleted immediately. If you would like your processor-side records removed, contact us at hello@deskjockeydigital.co.uk and we will action it where we are able to.

9. Your rights

Under UK GDPR, EU GDPR, and applicable North American privacy laws, you have the following rights:

  • access a copy of the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request deletion of your data (the "right to erasure");
  • request that we restrict or object to certain processing;
  • request data portability;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local EU supervisory authority.

You can exercise most of these rights directly in the app (edit profile, change visibility, delete account). For other requests, contact us at hello@deskjockeydigital.co.uk.

10. Security

We use encryption in transit (TLS), database-level row-level security, and industry standard password hashing. Uploaded photographs are re-encoded on your device before upload using a canvas pipeline that writes out only the visible pixels, so embedded metadata such as EXIF GPS coordinates, camera identifiers and thumbnail chunks is not carried into the stored file. This behaviour depends on your device's browser or WebView and we cannot guarantee it in every environment. No service can be guaranteed 100% secure; please use a strong, unique password and keep your credentials confidential.

11. Cookies, local storage and native device storage

On the web, Oriva uses cookies and browser local/session storage to keep you signed in and to remember preferences. In the iOS and Android apps the equivalent state (auth session, preferences, guest world data) is held in the app's own sandboxed storage on your device rather than in browser cookies, but is used for the same purposes and is removed if you delete the app or your account. See our Cookie Policy for the full list.

12. Future premium features

If and when Oriva introduces premium subscriptions or other paid features, payments will be processed by a third-party payment provider (such as Stripe). We will only receive the billing information necessary to manage your subscription; full card details are handled by the payment provider under their own terms and privacy notice.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Effective" date above and, where changes are material, notify you in-app or by email.

14. Contact

Questions about this Privacy Policy or your data can be sent to hello@deskjockeydigital.co.uk, or by post to David Jameson trading as DeskJockey Digital, Office 15396, 182–184 High Street North, East Ham, London, E6 2JA.