Last updated: 19 September 2026 (measurement data and cookies added)
Short version. We collect your email address (if you sign up or pay), a Stripe customer ID, and usage counters. We run our own first-party measurement on this site (no Google Analytics, no advertising trackers, no third-party scripts) and we set two small first-party cookies for it. We do not sell or share your data with anyone for marketing.
oganvil ("we", "us") is an OG (Open Graph) image generation API operated as an independent project. The service is reachable at https://oganvil.rowu.workers.dev. For any privacy question or request, contact us at the address in section 8.
| Data | Why | Where / how long |
|---|---|---|
| Email address | To issue your free API key, send quota notifications (50% / 90% / 100% of your monthly limit) and account-related notices. | Database row tied to your account. Kept while the account exists. |
| Billing identifiers — Stripe customer ID, subscription ID, plan, status | To apply the correct monthly quota to your account and to reflect upgrades, cancellations and payment failures. | Database row. Kept while the account exists. |
| API key (derived value) | To authenticate your renders. | Stored on your account row. |
| Usage counters — unique images used this month, anonymous renders today | Quota accounting and abuse/rate limiting. | Key-value store; monthly counter kept for 30 days, per-IP counters for 48 hours. |
| IP address (as a counter key only) | Anonymous tier limit (10 renders/day per IP) and signup rate limiting. We do not build profiles from it and we do not log it with your identity. | Key-value store, 48 hours. |
Render inputs — the title, tag and format you send |
To generate the image and to serve repeats from cache instead of billing you twice. | Rendered image cached for up to 1 hour, then discarded. Inputs are not used for anything else. |
| Measurement data — pages requested, referring page, country/region/city, network organization, browser user-agent, language, connection details (protocol, TLS version, round-trip time), and on-page events you generate (time on page, how far you scrolled, clicks on outbound links) | To understand how the site and the API are actually used — including which AI crawlers read it — so we can improve them. We run this measurement ourselves; there is no third-party analytics vendor. | Stored in our own database. We do not store your IP address — we store a one-way hash of it combined with your user-agent, used only to recognise repeat visits. |
Cookies — om_vid (1 year, a random visitor identifier) and om_sid (30 minutes, a session identifier) |
To tell a new visit from a repeat one and to group page views into a session. Both are first-party, set by us, and used only for measurement. | Expire as stated. You can clear them at any time in your browser; the site works exactly the same without them. |
Card numbers, CVCs and full payment details never reach us. Payments are processed by Stripe, Inc.; we only receive the resulting customer and subscription identifiers.
om_vid, om_sid) described below. No localStorage is used for tracking.We use a small number of processors, each for one purpose only: Cloudflare (hosting, edge compute, key-value store and database), Stripe (payment processing and subscription billing), and Resend (transactional email delivery). Each processes data on our instructions and under its own terms.
Where the GDPR applies: we process your email and account data to perform our contract with you (providing the service you signed up for), and we process usage counters and IP keys on the basis of our legitimate interest in keeping the service available and free from abuse.
You can ask us to access, correct, export or delete the data we hold about you, and you can object to processing based on legitimate interest. Write to the contact address below and we will respond within 30 days. Deleting your account revokes your API key and removes your account row; anonymised usage counters expire on their own.
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.
Privacy questions and data requests: privacy@oganvil.rowu.workers.dev. If you prefer, you can also open an issue at github.com/rowb53/oganvil-mcp/issues.
If this policy changes materially we will update the date at the top of this page. Continued use of the service after a change means you accept the updated policy.