Privacy Notice
Version 2026-08-28. Covers the Oarly app and this website.
Oarly rings your phone and speaks a reminder out loud. To do that we hold a small amount of information about you, and for Family check-ins we may hold a recording of your reply and your location. This notice says exactly what we keep, why, and for how long. It is written to be read, not to be survived.
Who we are
Oarly (“we”), the operator of oarly.app, is the data controller for everything described here. The fastest way to reach us about anything on this page, and the address our privacy requests go to, is privacy@oarly.app. We answer within one month, and usually much sooner. If you need our full registered details for a formal request or a complaint to a regulator, email that address and we will provide them.
What we collect, and why
Your account
Your email address, a hash of your password (never the password), your name if you give one, your chosen email alias, and your language and timezone. We need these to give you an account and to ring you at the right moment. Legal basis: performance of our contract with you.
Your age, but not your date of birth
Signup asks your date of birth so we can apply a minimum age of 13. We check it and then throw it away. What we store is a timestamp recording that you asserted an eligible date, and nothing else. We do not keep the date, and we cannot reconstruct your age from what we hold. Legal basis: compliance with a legal obligation.
Your reminders
The title, time, recurrence and any notes of anything you ask us to remind you about, plus the tags you file them under. These are the content of the service. Legal basis: contract.
Calendar invitations sent to your alias
If you add your Oarly alias to a calendar event, we receive the invitation and read it: the event title, its times, and the organiser’s name and email address. We use this only to create the reminder you asked for by adding the alias. The first invitation from an organiser we have not seen before is held until you approve that sender. Legal basis: contract with you, and our legitimate interest in delivering a reminder you requested. See also “People who did not sign up” below.
Your device
A push token so we can wake your phone, which platform it runs, and diagnostic readings about whether the operating system is allowing our notifications through: battery restriction state, standby bucket, manufacturer, and the reasons the system last stopped our app. We collect these because Android delivery is genuinely unreliable on some devices and this is the only way we can tell a phone that never rang from a phone that rang and was ignored. Legal basis: contract, and our legitimate interest in the service actually working.
Calls
For each call: whether it was answered, missed or never attempted, how long it lasted, when it started and ended, and why it ended. Legal basis: contract.
Family check-in replies (only with your consent)
If you are set up for conversational check-ins and you have agreed to it, answering a check-in records your spoken reply on your phone, uploads it to us, and transcribes it so the person organising your check-ins can read it. If you have separately agreed to location sharing, we also record where you are when you answer, and, if you agreed to that separately again, when you miss a check-in. It is your actual location and not a rough area, because the reason for keeping it is that someone can come and find you. We only ever take it around a check-in call, never when you decline one, and never in between. Your phone can give us an approximate area instead if you prefer, and we will use that.
We treat this as health-adjacent information about you, and we rely on your explicit consent for it (Article 9(2)(a) GDPR). Each of these is a separate switch you control, each one is recorded with the version and language of the wording you agreed to, and each can be withdrawn on its own at any time, from the phone you actually hold. If you have not agreed to recording, the check-in still rings but your microphone is never opened: answering is itself the check-in.
The website
If you join the beta list, we keep the email address you type and the fact that you asked to join, on the basis of your consent. That is all. This site sets no cookies, runs no analytics and has no advertising or tracking of any kind, which is why you were not asked to dismiss a banner.
Automated voice
The voice on a Oarly call is synthetic. It is generated by text-to-speech from the reminder you wrote, and there is no person on the line and no artificial intelligence deciding what to say to you. Conversational check-in replies are transcribed into text by an automated speech recognition model. Nothing you say is used to train anyone’s models, and no decision with a legal or similarly significant effect is made about you automatically.
People who did not sign up
Two groups of people can end up in our systems without ever visiting us, and Article 14 GDPR says we owe them this notice.
- Managed profiles. Someone can set up a Oarly phone for another person, typically a partner, a child or an older parent. That person is shown who set them up, what is collected and what their choices are, on their own device, and holds their own privacy switches and their own delete button. They are not dependent on the organiser to exercise their rights.
- Calendar organisers. If you add your alias to someone else’s invitation, we receive that organiser’s name and email as part of the invitation. We use it to identify the sender and to let you approve or block them. We do not contact organisers, market to them, or build any profile of them.
Who we share it with
We do not sell your data, and we do not share it for anyone’s advertising. We use a small number of suppliers who process data on our instructions:
- Cloudflare runs our servers, stores the recorded audio, receives the incoming mail for your alias, and performs the speech recognition that produces check-in transcripts.
- Supabase hosts our database, which holds your account, your reminders, your call records and your check-in transcripts. It is located in Ireland.
- Google delivers our notifications (Firebase Cloud Messaging), generates the spoken voice (Cloud Text-to-Speech), receives crash reports, and, through Google Play, handles your subscription and payment.
- Apple delivers notifications and handles subscriptions on iPhone, if and when we ship there.
- Resend sends our account emails, such as verification and password reset.
Our database is located in Ireland, inside the EEA. We may also disclose information where the law requires it. Some of these suppliers process data outside the EEA. Where they do, we rely on the European Commission’s Standard Contractual Clauses, or on the supplier’s certification under an approved adequacy framework, as the safeguard for that transfer.
Payment
Subscriptions are bought inside the app through Google Play or the App Store. They are the merchant, not us. We never see your card number: the store tells us only that a subscription is active.
How long we keep things
These are the actual periods our systems enforce, not aspirations:
- The recording of your check-in reply: 30 days. The audio is transcribed once and never played back by us, so the recording itself is deleted well before the text of it is.
- Check-in transcripts and locations: 120 days, then erased from the call record while the outcome survives. This is set by what the app can display, not by what is convenient for us to store.
- Call outcomes (answered, missed, duration): 180 days.
- Completed reminders: 90 days, so we can answer “why did it not ring”.
- Superseded sign-in tokens: 30 days. Each time your app refreshes its session the previous token is retired and erased a month later. Signing out of a device ends its session immediately.
- The beta list: until the beta ends, or until you ask us to remove you, and in any case no longer than 24 months.
- Emailed codes (verification, password reset, deletion): erased within a day of expiring. The codes themselves expire in 15 to 30 minutes.
- Abandoned signups: 7 days. If you start an account and never confirm your email, we delete it and release the alias.
- Your account and reminders: for as long as you have an account.
- Record that a deletion happened: 12 months. See below.
Deleting your account
You can delete your account in the app under Settings, or from oarly.app/delete-account. A managed profile can delete itself from its own device.
Deletion is real deletion, not a hidden flag. There is a 14 day window in which you can change your mind and restore the account, after which everything is physically removed: your account, your reminders, your call history, any stored recordings, and your consent records. Managed profiles that exist only because of you are removed with you.
Our database keeps rolling backups so it can be restored after a failure, and those go back up to 7 days. For that period a backup taken before you deleted your account will still contain your data. We do not use backups to look anything up, and if we ever had to restore one we would re-apply every deletion afterwards.
One other thing survives, and you should know about it. We keep a record that a deletion happened for 12 months: an internal identifier, when it was requested, and how the request was verified. Where the account had an email address, we keep a one-way cryptographic fingerprint of it rather than the address itself, so we can recognise a repeat request without being able to read who it was. We keep this to prove we honoured your request and so a database restore cannot quietly bring you back.
Your rights
You can ask us for a copy of your data, correct it, delete it, restrict or object to what we do with it, or receive it in a portable form. Where we rely on your consent, you can withdraw it at any time without giving a reason, and withdrawing it does not affect what we did before you withdrew it. The recording and location switches can be turned off in the app without contacting us at all.
Email privacy@oarly.app and we will respond within one month. If you think we have got this wrong you can complain to your national data protection authority.
Children
Oarly is not for children under 13, and signup refuses an ineligible date of birth. A parent or guardian can set up a managed profile for a younger child, in which case their consent is what permits it, and they can delete that profile at any time. If you believe a child has an account of their own, email privacy@oarly.app and we will remove it.
Security
Passwords are hashed. The credential your phone holds so it can ring you is stored in the device’s hardware-backed keystore. Everything is encrypted in transit. No system is perfect, and we will tell you and the regulator if something goes wrong in a way that affects you.
Changes
We will update this notice as Oarly changes and move the version date at the top. If a change materially affects something you consented to, we will ask you again rather than rely on the old agreement.