Privacy Policy

Last updated: 11 October 2026

In short: Most of what you store in OBLIVIO stays on your phone. If you create an optional cloud account, your messages and files are encrypted on your phone before upload (end-to-end). We cannot read them. The free version shows non-personalised ads (Premium has none). We never sell data.

1. Who is responsible

OBLIVIO is developed by Hüseyin Fikri Özbay, Rotterdam, the Netherlands (the "controller" under the GDPR). Contact: privacy@oblivioapp.com

2. Data that stays on your phone

The following is stored only on your device and is never sent to us unless you use the cloud account described below: your PIN, will messages, final instructions, vault notes, photo vault, trusted contacts, settings and reset/trigger configuration.

3. Optional cloud account

If you create a cloud account, so that your messages can be delivered even when your phone is off, we process:

Delivery starts when your check-in period and grace period have passed, when a confirmation by your trusted contacts is not cancelled within the waiting period, or when your phone starts a reset. You then receive a warning email where applicable. Recipients receive an email with a link. They open the content in their browser with the password you gave them; decryption happens only on their device.

4. Phone permissions

OBLIVIO does not collect your location.

4a. Advertising and purchases

Ads (free version only): OBLIVIO shows non-personalised ads from Google AdMob on a few general screens, never on the vault, will or countdown screens. In the EEA, the UK and Switzerland, Google’s consent form is shown first. Even non-personalised ads use limited data such as your device’s IP address and a device identifier for frequency capping, fraud prevention and measurement. Premium users see no ads.

Premium purchase: payments are handled by Google Play or the App Store; we never see your card details. We use RevenueCat to check whether your subscription is active; it processes an anonymous app user ID, your purchase history for OBLIVIO and basic device and store information.

5. Purpose and legal basis

We process this data only to provide the service you asked for (Art. 6(1)(b) GDPR). Ads are based on your consent where the law requires it (Art. 6(1)(a) GDPR). Recipient names and email addresses are processed so that your messages can reach them, based on your and their legitimate interest (Art. 6(1)(f) GDPR).

6. Service providers

Some of these companies are based in the United States. Where data is transferred outside the EEA, this is covered by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

7. How long we keep data

Cloud data is kept until you delete your account. Links sent to recipients are valid for 30 days. Data on your phone is kept until you delete it or uninstall the app.

8. Deleting your account

You can delete your cloud account and all server data at any time in the app: Settings → Cloud Account → Delete my account and cloud data. Deletion is immediate and permanent. You can also request deletion by email: how to request deletion.

9. Your rights

You have the right to access, correct, delete, restrict, object to and receive a copy of your data. Contact privacy@oblivioapp.com. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the authority in your country.

10. Security

Content is encrypted end-to-end (PBKDF2-SHA256 key derivation, AES-256-GCM). All connections use TLS. Because we do not have your recipients' passwords, lost passwords cannot be recovered.

11. Children

OBLIVIO is not intended for children under 16.

12. Changes

We will publish any changes to this policy on this page and update the date above.