Privacy Policy

Last updated 2 August 2026

The short version

Reading the library requires no account, sets no tracking cookies, and runs no analytics. If you never sign in, we hold nothing that identifies you.

If you do sign in, we hold your email address, your handle, and the summaries you saved. That's the whole list.

1. Who is responsible

oratilo is run by its individual operator, not a company. For data-protection purposes the operator is the controller of your data, and — as permitted for small operators under Korea's Personal Information Protection Act — also serves as the privacy officer.

Privacy contact: getoratilo@gmail.com. Requests are answered by the operator directly.

2. What we collect, and why

DataWhyBasis
Email addressTo identify your account and let you recover itPerformance of a contract
Handle, display name, bioYour public page at /u/<handle>Performance of a contract
Saved summaries (stars)To build your libraryPerformance of a contract
Error reports you submitTo correct summariesLegitimate interest — accuracy
Sign-in provider ID (Google / GitHub)To sign you inPerformance of a contract
Server logs (IP, user agent, timestamps)Security, abuse prevention, keeping the service upLegitimate interest — security

What we do not collect: no analytics, no advertising identifiers, no behavioural tracking, no third-party cookies, no payment information (the service is free), and no special category data.

If you sign in with Google or GitHub, we receive your email address and an account identifier from them. We do not receive your password, your contacts, or anything else from your account there.

3. Cookies and local storage

We set no cookies for advertising or analytics. The site keeps a small amount of data in your browser's local storage:

These stay on your device. Clearing your browser storage removes them and signs you out.

Video plays through youtube-nocookie.com, and the player is not loaded until you click it. Until you press play, YouTube receives nothing from the page. Once you do, YouTube's own privacy policy applies to that playback. Thumbnails are loaded from YouTube's image servers with a no-referrer policy.

4. Who processes data for us

ProcessorPurposeWhere
Supabase (and its infrastructure provider)Database and authenticationThe region configured for our database project
VercelSite hosting and deliveryGlobal edge network

We do not sell personal data, and we do not share it for advertising. We disclose data only to these processors, or where we are legally required to.

Data may be processed outside your country, including in the United States. Our providers handle international transfers under their standard contractual protections, and both publish a data processing agreement that applies to the data they hold for us.

5. How long we keep it

6. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your data, to receive a copy in a portable format, and to withdraw consent. To exercise any of these, write to getoratilo@gmail.com.

You can delete your account yourself at any time from your account menu.

If you are in the EEA or UK you may complain to your local data protection authority. If you are in Korea you may contact the Personal Information Protection Commission (privacy.go.kr, 118). If you are in California: we do not meet the CCPA's thresholds and we sell no data — but we honor access and deletion requests from anyone, anywhere, regardless.

7. Children

oratilo is not directed at children. You may not create an account if you are under 14. If we learn that we hold data from a child below that age, we delete it.

8. If the project changes hands

If oratilo is ever handed to a successor operator or becomes part of an acquisition or reorganisation, the data described here may be transferred to the successor as part of that. The recipient remains bound by a privacy policy at least as protective as this one, and we will make the change visible on the site before it takes effect. If you object, you can delete your account beforehand.

9. Security

Access to your data is enforced at the database level: rows are readable only by the account that owns them or, for public profiles, by anyone — enforced by row-level security policies rather than by application code alone. Error reports are write-only for the public and readable only by the operator. Passwords are stored hashed by our authentication provider; we never see them.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authority as required by law.

10. Changes

We will post any change here and update the date at the top. Material changes will be flagged on the site before they take effect.