Privacy Policy
Effective Date: March 31, 2026
The operator of Overwall ("Overwall," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you use our website, applications, and services (collectively, the "Service").
By using the Service, you consent to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.
1. What We Do NOT Collect (Strict No-Activity-Logs Policy)
Overwall is architected with privacy as a foundational principle. We do not monitor, record, log, or store your internet activity. Specifically, we do not collect or retain:
- Browsing history or the content of websites you visit.
- DNS queries or domain name lookups.
- The content or payload of your internet traffic.
- The destination IP addresses or URLs of your traffic.
- Connection timestamps linking you to specific online activity.
Our infrastructure is designed so that we have no technical ability to associate a specific user with specific browsing activity, web content, or DNS resolution occurring through the Service. We do not modify, redirect, or inject data into your traffic.
2. Information We Do Collect
To operate the Service, manage subscriptions, enforce usage limits, and maintain service quality, we collect the following limited categories of data:
2.1 Account Data
When you create an account, we collect:
- Email Address: Required for account creation, authentication, payment receipts, and customer support communications.
2.2 Payment Data
Payments are processed entirely by our third-party payment processor. We do not store or have access to your full credit card number or payment method details. We retain only:
- Transaction records (date, amount, currency, and payment status) for billing and accounting purposes.
- Payment processor identifiers to manage your subscription lifecycle.
2.3 Device Data
When you connect to the Service from a device, we collect:
- Device Identifier: A cryptographically hashed identifier unique to your device, used solely to enforce the device limit on your subscription plan. The original device identifier cannot be recovered from the hash.
- Device Name and Platform: (e.g., "iPhone," "macOS") for display in your account dashboard.
- Application Version: To ensure compatibility and provide support.
2.4 Operational Data
To enforce bandwidth limits and maintain service quality, we collect:
- Bandwidth Consumed: The total bytes transferred per session and per billing period, used solely for plan enforcement.
- Server Assignment: Which server node your device connected to, retained only during the active session.
This operational data is used solely for service delivery and plan enforcement. It is never used to monitor, profile, or track your browsing activity, the content of your traffic, or the websites you visit.
2.5 Aggregate Performance Data
We collect anonymous, aggregate statistics about server load and network performance to maintain and improve service quality. This data cannot be tied to individual users.
3. How We Use Your Information
We use the information we collect strictly for the following purposes:
- Service Delivery: To provide, operate, and maintain the Service.
- Billing and Subscription Management: To process payments, manage your subscription, and enforce plan limits.
- Account Administration: To authenticate your identity, manage your account, and provide customer support.
- Abuse Prevention: To detect and prevent fraud, unauthorized access, and violations of our Acceptable Use Policy.
- Service Improvement: To analyze aggregate usage patterns and improve the reliability and performance of the Service.
- Transactional Communications: To send you essential emails (e.g., payment confirmations, security alerts, account notifications). We do not send marketing emails unless you opt in.
4. Data Sharing and Disclosure
We do not sell, rent, trade, or share your personal information with any third party for marketing or advertising purposes.
We may share your information only in the following limited circumstances:
- Payment Processor: We share necessary billing information with our payment processor to process your payments. Their use of your data is governed by their own privacy policy.
- Legal Compliance: We may disclose limited account information (email address, payment records) if we are compelled to do so by a valid court order or other binding legal process issued by a court of competent jurisdiction. Because we do not log browsing activity, traffic content, or connection metadata, we are unable to provide such data even if requested.
- Protection of Rights: We may disclose information if we believe in good faith that it is necessary to protect the rights, property, or safety of Overwall, our users, or the public.
- Business Transfer: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction. We will notify you via email or a prominent notice on our website before any such transfer occurs.
5. Data Retention
- Account Data: Retained for as long as your account is active. Upon account deletion, personal data is permanently deleted or anonymized within thirty (30) days.
- Payment Records: Transaction records necessary for tax and accounting compliance are retained for the period required by applicable law, after which they are permanently deleted.
- Operational Data: Bandwidth and session data is retained only for the duration of the current billing period and is automatically purged thereafter.
- Support Communications: Emails to our support team are permanently deleted within ninety (90) days of resolution.
- Aggregate Data: Anonymous, aggregate statistics may be retained indefinitely as they cannot identify individual users.
6. Data Security
We implement industry-standard technical and organizational security measures to protect your data, including encryption in transit, secure infrastructure, and strict access controls. Payment data is handled entirely by our payment processor and is never stored on our systems. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
7. International Data Transfers
By using the Service, you acknowledge and consent to the transfer, storage, and processing of your data in the countries where our infrastructure is located. These countries may have data protection laws that differ from those in your jurisdiction.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request correction of inaccurate data.
- Deletion: You may request deletion of your account and associated data.
- Data Portability: You may request a copy of your data in a portable format.
- Restriction: You may request restriction of processing of your personal data.
- Objection: You may object to the processing of your personal data.
To exercise any of these rights, please contact us at support@overwall.app. We will respond to your request within thirty (30) days.
9. Cookies and Tracking
Our website uses only essential cookies necessary for authentication and session management. We do not use third-party advertising cookies, tracking pixels, or behavioral analytics. We do not participate in cross-site tracking or behavioral advertising. We respect Do Not Track browser signals.
10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party websites you visit.
11. Children's Privacy
The Service is not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@overwall.app.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will provide at least thirty (30) days' advance notice of material changes by updating the "Effective Date" at the top of this page and, where practicable, by notifying you via email. Your continued use of the Service after any changes take effect constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at:
Email: support@overwall.app