privacy.
last updated july 2026
oda is a personal library of taste. the whole product is "your stuff, kept carefully" — so this page is short, honest, and written to be actually read. oda is currently in a small testing phase; if anything here changes materially, the date above changes with it.
what we store
your email address — used only to send you a 6-digit sign-in code. there are no passwords. your handle and profile (display name, bio, avatar). your library — shelves, entries, notes, tags, dates, and photos you upload. that's the list.
we don't run ads, we don't sell or share your data with data brokers, and we don't track you across the web. there is no analytics script on these pages today. if the app crashes in your browser, a short technical crash report (the error text and page address — never your library) is sent to our own server logs so we can fix it.
who can see what
every shelf has a visibility: public (on your profile), unlisted (only people with the direct link), or private (only you — enforced by row-level security in the database, not just hidden in the interface).
one honest caveat: uploaded photos are stored on public object storage behind unguessable random URLs. the app never reveals a private shelf's photo URLs, but if you share such a link yourself, it opens for whoever has it — so skip truly sensitive photos for now.
profiles aren't offered to search engines unless you choose "search indexed" in settings; the default is link-only.
where it lives
your data sits in a Supabase Postgres database and object storage, and the app runs on Railway. sign-in code emails are delivered via Resend. these providers process data on our behalf and nothing more.
what leaves for third parties
when you search for things to add, your search words are forwarded to the matching public index: TMDb (films), Deezer (music), Open Library (books), OpenStreetMap / Nominatim (places), Wikipedia (everything else). pasting a link fetches it from YouTube or Google Maps. place map thumbnails come from Geoapify. cover images are loaded from those sources' servers, which see your browser's requests like any image on the web.
none of them receive your email, handle, or library.
cookies & local storage
no tracking cookies. your browser's local storage holds your session token (so you stay signed in — unless you untick "keep me signed in", which scopes it to the tab), your light/dark theme choice, and, during signup, your not-yet-saved handle and picks.
your controls
export — settings → "your data" downloads your whole library as JSON. delete — settings → "delete library" permanently removes your account, profile, shelves, entries, and uploaded files. it's immediate and irreversible.
contact
questions, worries, or requests: [email protected].