OGMagic

Legal

Privacy Policy

Effective: October 1, 2026 · Version 2026-10-01

This is a dated copy. View the current policy. You can print or save this page for your records.

1. Who is responsible for your data

Noah Larsen, trading as BetterOWR, is the controller for personal data used to operate OGMagic. BetterOWR is not a separately registered company. Address: Aeroevej 1, 6710 Esbjerg V, Denmark. For privacy questions or requests, email noah@betterowr.com or use contact form.

This policy covers our website, editor, API, hosted images, purchases, support and newsletter. It explains our own processing; Stripe / Sold through Link separately determines how it processes data for its merchant-of-record, payment, fraud-prevention and legal responsibilities. Its notice is at stripe.com.

2. Access, purchases and support

Email access: we receive the address you submit for an access link and store it encrypted, alongside a keyed email identity, customer identifier and creation information. API keys, management sessions and single-use link tokens are stored as hashes; we also retain a short API-key prefix for identification. We use these records to authenticate you, provide the service and apply your plan. No password or public profile is required. Providing an email is necessary for hosted creation and recovery, but you can browse and try previews without email access.

Purchases: Stripe collects checkout email, payment and billing information. We receive the checkout email, Stripe checkout/payment identifiers, payment amount and currency, status and refund/dispute information needed to fulfil and administer Pro. We generate and encrypt a license key and store its lookup hash. For checkouts using our agreement checkbox, we also retain the terms/privacy versions, Stripe's recorded agreement result and when we recorded that evidence. We do not store your full card number or security code. Starting checkout does not by itself record acceptance.

Support and withdrawals: we process the name, email, message, order details and other information you provide, our replies, and delivery status. Contact submissions are saved and emailed to our support mailbox. Online withdrawal declarations include a request identifier and submission time; we store the declaration encrypted and send it to the confirmation address you specify and our support mailbox. Do not send card numbers, API keys or other secrets in a message. Access, license, withdrawal and support emails are transactional and never sign you up for the newsletter.

3. Images, requests and security

Artwork: we process the text, template and styling options you submit to render previews and saved images. Hosted records include artwork options, customer ownership, deduplication information, creation status, the PNG and its public location. Anyone with a hosted image URL can view it without authentication. Search engines, social platforms and other recipients can retain their own copies. Do not put confidential or sensitive personal information in artwork. Deletion cannot recall copies already obtained by others.

Usage and security: our infrastructure receives IP addresses, request URLs, browser/device and connection information. Our accounting database uses keyed hashes of IP addresses (IPv6 grouped by network), rather than raw IP addresses, for abuse prevention. It also records request status, quota windows, customer or license identities, image/template identifiers, timestamps and aggregate activity. Hashing and encryption reduce exposure but do not make identifiable records anonymous. Hosting, security and payment providers may process raw network information in their own systems.

Vercel BotID validates a browser challenge when you establish a preview session or request an email access link. Automated security and quota checks can reject or delay a request. They are used to protect the service, not to make legal or similarly significant decisions about you. Contact us if a check appears incorrect.

The URL-checking tools fetch the public URL you submit; the destination website and its infrastructure receive our server's request. When a tool displays that site's external image, your browser requests it directly, so the image host receives your IP address and browser request information. The editor keeps artwork text in shareable URLs, and checking tools keep the checked URL in the page address. Those addresses may remain in browser history or be disclosed when you share or copy them. Do not put private information in share links or submit private or token-bearing URLs.

4. Newsletter and site measurement

The newsletter is optional and uses a separate signup and confirmation email. Listmonk, software we operate for the newsletter, stores your email, subscription/confirmation status, timestamps and suppression or unsubscribe records. Amazon SES delivers the messages and processes delivery, bounce and complaint information. We use this data to send the requested newsletter and subscriber offer and respect opt-outs. You can unsubscribe through any newsletter's link or by contacting us; purchasing or requesting an access link is not a newsletter subscription.

Vercel Web Analytics and Speed Insights measure page visits, referrals, browser/device categories, approximate country, page performance and interactions such as template selection, downloads and newsletter placement. Our custom events do not intentionally include email addresses, API keys, artwork text or template-search text. We remove query strings and fragments from the URLs sent by our analytics integration. Measurement is not used for cross-site advertising or to sell personal information. Provider details: vercel.com and vercel.com.

5. Why we process personal data

Under the GDPR, we rely on performance of a contract or steps you request before entering one (Article 6(1)(b)) for email access, rendering and hosting images, supplying Pro, purchase communication and service support. Without the data needed for those functions we cannot supply them.

We rely on legal obligations (Article 6(1)(c)) where applicable for tax/accounting records, consumer withdrawals and responding to legally valid requests. Our legitimate interests (Article 6(1)(f)) support proportionate fraud and abuse prevention, network security, defending legal claims, general enquiries, and limited service reliability and usage measurement. Those interests are keeping OGMagic secure, understanding whether it works, and resolving disputes; they must be balanced against your rights. You can object as explained below.

Optional newsletter marketing relies on your consent (Article 6(1)(a)). You may withdraw it at any time without affecting earlier lawful processing or your access to OGMagic. Minimal suppression information may still be needed to honour your opt-out. Accepting the Terms or acknowledging this policy is not blanket privacy consent. Where a technology requires separate consent by law, it must be requested separately; a purchase does not provide it.

6. Cookies and browser storage

Interactive previews use an essential, first-party HttpOnly session cookie lasting one hour to enforce preview access and abuse limits. Email verification creates an essential HttpOnly management-session cookie lasting 30 minutes; access-link tokens expire after 15 minutes and can be redeemed once. Ending the session clears its management cookie. Security and embedded payment providers may also use storage necessary for fraud prevention, authentication and payment.

We store a browser preference called ogmagic_hide_discount_offer after a successful newsletter signup or verified Pro access so the discount popup stays hidden. It contains no email or credential and persists until you clear site storage. A sessionStorage flag, ogmagic_exit_intent_shown, limits repeat popup display during a tab session. Browser settings let you clear this storage; blocking necessary cookies can prevent previews, sign-in or checkout. Vercel describes its Web Analytics measurement as cookie-free; that does not mean the entire site or checkout uses no cookies.

7. Who receives data and international processing

We use Vercel for hosting, delivery, Blob image storage, security/BotID and site measurement; Neon for PostgreSQL access, purchases, withdrawal records and usage accounting; Amazon Web Services SES for email delivery; and our Listmonk newsletter installation and its hosting infrastructure for subscriptions. Our support mailbox and infrastructure providers also process communications and operational data for their functions. Stripe / Sold through Link receives data necessary for payment and its separate merchant responsibilities. Fonts are bundled locally and are not fetched from Google Fonts.

We may disclose data where legally required or necessary to establish, exercise or defend legal claims. We do not sell personal data or provide it for third-party cross-site advertising. Public images are an intentional disclosure to anyone who obtains their URL; you control the content you publish.

These providers operate internationally, so data may be processed outside Denmark and the European Economic Area, including in the United States. Where GDPR transfer restrictions apply, the applicable provider arrangements must provide a lawful transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses and any necessary supplementary safeguards. Contact noah@betterowr.com for information about the safeguards applicable to your data and how to obtain a copy. Public provider notices include vercel.com, neon.com, aws.amazon.com and stripe.com.

8. How long we keep data

Access and licenses: we keep the customer and entitlement records needed while you use the service or retain an ongoing Pro entitlement. Expired access links and sessions stop working at their stated expiry and are eligible for maintenance cleanup. Rotating an API key removes the previous key record; related usage and security records follow their own retention rules. Ask us to close your customer record if you no longer need it; records required for another lawful purpose are handled separately.

Accounting and security: request reservations become eligible for cleanup 35 days after their expiry, and unreferenced usage buckets after their window has expired for at least 35 days. Cleanup runs in bounded scheduled batches, so eligibility is not an exact deletion deadline. Aggregate template/activity statistics are retained separately; customer-linked records are not treated as anonymous merely because an email is hashed.

Images: saved PNGs and their records remain until you delete them, request closure or they are removed under the service terms. Deletion queues storage removal; technical metadata needed for usage, cleanup or resolving failures may outlast the PNG. CDN and third-party caches can persist after removal. Interactive previews also use bounded, temporary caches in server and browser memory; a preview's cache lifetime is separate from security and usage records.

Purchases, agreement evidence and withdrawals: we retain records needed to honour the ongoing license, process refunds and disputes, comply with applicable bookkeeping obligations and establish or defend legal claims. Where Danish bookkeeping retention applies, the relevant accounting material is normally retained for five years from the end of the financial year it concerns. This does not justify keeping unrelated artwork or messages for that period.

Support and newsletters: we keep correspondence while handling your request and for as long as reasonably needed for related follow-up, obligations or claims. Newsletter records remain while subscribed; after unsubscribe we stop marketing and review records for continued needs such as respecting suppression, demonstrating consent or dealing with delivery complaints and legal claims. These records require administrative review; the app does not promise an automatic timed purge of all support, customer or newsletter data. Provider logs and backups follow the applicable provider arrangements and retention settings. Backups can retain copies until they are overwritten or deleted, separately from removal from the active application.

9. Your choices and rights

Subject to the conditions in applicable law, you may request access and a copy of your data, correction, erasure, restriction, and portability of data processed by automated means on consent or contract grounds. You can object to processing based on legitimate interests for reasons related to your situation, and object to direct marketing at any time. You can withdraw consent at any time. These rights are not all absolute: for example, legal recordkeeping or legal claims can require limited retention.

Email noah@betterowr.com or use contact form. We may ask for proportionate information to verify your identity, but do not send credentials or identity documents unless we explain why they are necessary. We normally respond within one month of receiving a request. If the law permits an extension for complexity or the number of requests, we will tell you within that month and explain the reason; an extension can be up to two further months. Requests are normally free, subject to the limited legal exceptions for manifestly unfounded or excessive requests.

You may complain to the Danish Data Protection Agency, Datatilsynet, at datatilsynet.dk, or the supervisory authority in your place of habitual residence, work or alleged infringement. You do not have to contact us first. For Stripe's independent processing, you can also exercise rights directly through Stripe's privacy channels.

10. Security, children and updates

We use access controls, application encryption for account and purchase email addresses, license keys and online withdrawal declarations, hashed credentials, and encrypted connections to reduce risk. Newsletter, support and mail-delivery systems process addresses and messages in readable form as needed for those services. No online service can guarantee absolute security. The service is not directed to children; if you believe a child has provided personal data without appropriate authority, contact us so we can investigate and take suitable action.

This policy is dated and versioned. We will publish updates and bring material changes to your attention as appropriate, including by email where relevant. A new policy does not create consent for a new incompatible use. Earlier versions remain available at their dated URLs; this version is Privacy Policy (October 1, 2026).