Privacy Policy

Last updated: 20 August 2026

1. Who We Are

This privacy policy explains how Odlogo ("we", "us", "our") collects, uses, and protects your personal data when you use soundtovision.com (the "Service").

We are the data controller responsible for your personal data under the UK GDPR and, where applicable, the EU GDPR.

Contact details:

Company name: Odlogo

Address: London, UK

Contact: via our contact form

2. What Data We Collect

We collect the following categories of personal data:

Data typeExamplesHow it's collected
Identity data First name, last name; and, if you choose to sign in with Google, your Google account name and profile photo You provide this when registering/using the Service, or, if you choose the "Continue with Google" option, it is provided via AWS Cognito's federated sign-in with Google
Contact data Email address You provide this when registering or contacting us
Usage data Pages visited, features used, session duration, actions taken within the app Automatically collected as you use the Service
Cookie data Cookie identifiers, session tokens Stored on your own device by your browser — we do not retain cookie data on our servers
AI query logs Prompts/queries submitted to AI features, along with associated account identifiers Logged automatically when you use AI-powered features; retained for 1 week, then deleted
Billing data Purchase history, token balance/transactions, billing address, last 4 digits of card (via Stripe) Collected when you buy tokens/credits through our Stripe checkout/portal
User content Audio/visual files and projects you create using the Service Created by you and stored locally on your own device — we do not upload, store, monitor, or have access to your content on our servers

We do not store full card numbers, CVV, or other sensitive card details ourselves — these are collected and processed directly by Stripe. We do not use analytics or tracking tools (e.g. Google Analytics). We do not collect special category data (e.g. health, religion, ethnicity) or knowingly collect data from children (see Section 9).

3. How We Use Your Data

We use your personal data for the following purposes:

PurposeData usedLegal basis (UK/EU GDPR)
Creating and managing your account Name, email Performance of a contract (Art. 6(1)(b))
Providing and maintaining the Service Usage data Performance of a contract / Legitimate interests (Art. 6(1)(b)/(f))
Providing AI-powered features AI query logs Performance of a contract (Art. 6(1)(b))
Communicating with you (support, updates, service notices) Email, name Performance of a contract / Legitimate interests
Processing payments and managing your token balance Billing data, email Performance of a contract (Art. 6(1)(b))
Fulfilling tax, accounting, and legal record-keeping obligations Billing data Legal obligation (Art. 6(1)(c))
Marketing communications (if opted in) Email Consent (Art. 6(1)(a))
Security, fraud prevention, and legal compliance Usage data Legitimate interests / Legal obligation

You can withdraw consent at any time where processing is based on consent (e.g. marketing emails).

4. Cookies and Similar Technologies

We use a limited number of cookies to operate the Service, primarily for login sessions and core functionality (e.g. keeping you signed in, remembering preferences).

Important: these cookies are stored on your own device by your browser. We do not retain or collect cookie data on our servers, and we do not use them for tracking or analytics purposes. We do not use Google Analytics or any similar third-party analytics/tracking tools.

We do use Google reCAPTCHA on our contact/feedback form, to prevent spam and abuse. This sets a cookie and may collect information such as your IP address and browser behaviour, in accordance with Google's Privacy Policy and Terms of Service.

"Continue with Google" sign-in is separate from cookies. If you choose to sign in with Google, this only happens when you actively click that option — it does not load any Google script or set any Google cookie automatically on page load. Instead, you're taken through AWS Cognito, our authentication provider, which federates the login to Google. See Section 5 for details.

You can view, manage, or delete cookies at any time through your browser settings. Blocking the reCAPTCHA cookie will prevent the contact form from working.

5. Who We Share Your Data With

We may share your data with:

We do not sell your personal data.

6. International Data Transfers

Your data is primarily stored and processed within the EU/EEA — our servers, email sending, and AWS Cognito (authentication) are all hosted in eu-west-1 (Ireland). Some service providers, including Stripe and Google, are based outside the UK/EEA (e.g. in the United States) and may process data internationally — this applies when you buy tokens (Stripe), submit the contact form (Google reCAPTCHA), or choose to sign in with Google (Google, via our Cognito authentication flow). Where this happens, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the provider's own certified transfer mechanisms.

7. Data Retention

We retain personal data only as long as necessary for the purposes described above:

You can request deletion of data we control at any time (see Section 8), though billing records may be retained where we have a legal obligation to keep them.

8. Your Rights

Under UK/EU GDPR, you have the right to:

To exercise any of these rights, contact us via our contact form. We will respond within one month as required by law.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or your local EU data protection authority if you're based in the EU.

9. Children's Privacy

The Service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and regular security reviews. No system is 100% secure, but we take reasonable steps to protect your information from unauthorised access, loss, or misuse.

11. Changes to This Policy

We may update this privacy policy from time to time. We'll notify you of material changes via email or a notice on the Service. The "Last updated" date at the top reflects the most recent revision.

12. Contact Us

If you have questions about this policy or how we handle your data, contact us at:

Odlogo

Contact: via our contact form

Address: London, UK

This document is a template and does not constitute legal advice. Depending on your specific features (e.g. payments, third-party integrations, marketing tools), you may need additional clauses. Consider having it reviewed by a solicitor or data protection professional, particularly given GDPR compliance requirements.