Privacy Policy for Logogram
Last updated: 12 March 2026
1 Controller (Art. 4 No. 7 GDPR)
Company / Owner: Obey24com (sole proprietorship) – Owner: Orhan Yilmaz
Postal address: Bussardweg 3, 75223 Niefern, Germany
Telephone: +49 176 62915092
E-mail: info@obey24.com
VAT ID: DE269627535
Commercial register: Not applicable (sole proprietorship)
A formal data-protection officer is not required under Art. 37 GDPR. For all privacy-related enquiries, please use the contact details above.
2 What data we process – and why
| Purpose | Typical data | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|
| Website delivery (hosting on Vercel) | IP address, user-agent, timestamps, requested URL, HTTP status code | Legitimate interest (f) – IT security & delivery | Server logs ≤ 30 days |
| Server security & error logging | IP address, user-agent, request path, HTTP method, error message, trace ID, authenticated user ID (if logged in) | Legitimate interest (f) – IT security & debugging | Logs ≤ 30 days |
| Rate limiting & abuse prevention | Hashed IP address or authenticated user ID, request counters | Legitimate interest (f) – security | Rolling window ≤ 1 hour (Redis / in-memory), then automatically purged |
| User account creation & management (Supabase Auth) | Name, e-mail address, password hash, profile photo URL, sign-in method (email/password, Google, magic link), session ID, device type, browser, last-login timestamp | Contract (b) | Until account deletion, which also erases the authentication record and every active session. A pseudonymised account stub (internal ID only, with name, e-mail, photo, bio and social links removed) is kept solely to keep billing records traceable – see "Payment processing" below |
| Logo generation via AI (concept generation & image rendering) | Brand name, industry, product description, target audience, tagline, style keywords, colour preferences, logo-type selection, free-text prompt, optional reference image (uploaded file or external URL), AI-generated concept prompt | Contract (b) | Prompt inputs: forwarded to AI providers and not retained beyond the job; reference images: stored as a public CDN URL until the logo is deleted; generated SVG: until logo or account deletion |
| Logo & asset storage (Vercel Blob CDN) | SVG file content, public CDN URL, user-ID-scoped storage path | Contract (b) | Until logo deletion or account deletion |
| Design Story generation (AI writing) — free, included with every logo | Rendered logo image (converted to a PNG on the fly), brand brief and logo description, interface language | Contract (b) | Story, email copy and one-liner text stored until deleted by user or on account deletion; the rendered PNG is not stored |
| Web analytics & performance measurement (Google Analytics 4, Vercel Web Analytics) | Pseudonymous client ID, device type, browser, city-level geolocation, session events (page views, feature interactions, logo-generation and credit-purchase events) | Consent (a) – via cookie banner (analytics category) | GA4: up to 14 months; configurable in the GA4 property settings |
| Aggregate traffic analysis (Vercel Web Analytics) | Anonymised page-view count, referrer URL, country (no cookies set, no fingerprinting, no cross-site tracking) | Consent (a) – via cookie banner (analytics category) | Rolling 24-hour aggregation; no persistent user identifiers stored |
| Marketing & conversion tracking (Meta Pixel / Facebook Pixel) | Pseudonymous browser identifiers (_fbp / _fbc), page-view events, credit-purchase conversion events | Consent (a) – via cookie banner (marketing category) | Meta: up to 180 days (configurable in Meta Business Manager); we do not retain raw Pixel data ourselves |
| Payment processing & subscription management (Stripe) | Stripe checkout-session ID, Stripe customer ID, Stripe subscription ID, payment status, amount paid, currency, credits purchased, billing e-mail address; card data is processed exclusively by Stripe and never reaches our servers | Contract (b) / Legal obligation (c) | Kept for 10 years for invoicing and tax purposes (§ 147 AO, § 257 HGB Germany) and therefore not deleted when you delete your account; erasure is excluded for these records under Art. 17 (3) (b) GDPR. They remain linked to a pseudonymised internal account ID, while your name, e-mail and profile data are erased |
| Transactional e-mails (welcome, purchase confirmation, low-credits notification, presentation-activity notifications) | Recipient e-mail address, display name, relevant event details (e.g. purchase amount, credit balance, presentation URL) | Contract (b) – necessary for service fulfilment | E-mail delivery metadata retained by Postmark per their retention policy; we do not store e-mail body content long-term |
| Newsletter (opt-in only) | E-mail address, display name, opt-in timestamp | Consent (a) | Until unsubscribe request or account deletion |
| Support & feedback (via the in-app feedback form) | E-mail address, name, free-text message, feedback type (feedback / help) | Legitimate interest (f) | 12 months after ticket is closed |
| Public client presentations – interactions by non-authenticated visitors | Self-entered reviewer name, comment text, vote / approval status, review note, IP address (used for view-count deduplication, stored as event metadata) | Legitimate interest (f) – enabling designer–client collaboration workflows | Comment, vote and approval data: until the designer deletes the presentation; IP in event records: ≤ 30 days |
| Fraud prevention & legal compliance | Above data; internal audit logs; credit-event log (generation, refund, purchase) | Legal obligation (c) / Legitimate interest (f) | Statutory minimum (6–10 years in Germany, depending on category); see payment-data note above |
No automated decision-making with legal or similarly significant effects (Art. 22 GDPR) is performed. Uploads or reference images that you provide for logo generation may be stored as publicly accessible CDN URLs for the purpose of AI processing. Please do not upload images containing sensitive personal data of third parties.
3 Cookies & browser storage
We use cookies (small text files stored by your browser) and browser storage (localStorage / sessionStorage) as described below. You can grant or withdraw optional-category consent at any time via the "Cookie settings" link at the bottom of any page.
3a HTTP Cookies
| Name | Category | Purpose | Lifetime | Set by |
|---|---|---|---|---|
| authToken | Essential | Supabase access token used as a fallback for mobile browsers where the Authorization header may be unreliable | 1 hour | First-party |
| presentation_token | Essential | HMAC-signed access token granting entry to a password-protected presentation link without re-entering the password on every page load | 24 hours | First-party |
| pv_{slug} | Essential | Prevents the same browser from incrementing a presentation's view counter more than once per hour (deduplication) | 1 hour | First-party |
| _ga, _ga_* | Analytics | Google Analytics 4 – distinguishes unique users and sessions for traffic analysis; only set after analytics consent | 2 years | Google LLC |
| _fbp | Marketing | Meta Pixel – identifies the browser for conversion tracking and Facebook/Instagram ad attribution; only set after marketing consent | 90 days | Meta Platforms Ireland Ltd. |
| _fbc | Marketing | Meta Pixel – stores a click identifier from a Facebook ad link for attribution; only set after marketing consent and only if you arrived via a Facebook ad | 90 days | Meta Platforms Ireland Ltd. |
3b localStorage & sessionStorage
These are stored in your browser only, never transmitted to third parties, and can be cleared at any time through your browser's storage settings.
| Key | Storage type | Category | Purpose | Lifetime |
|---|---|---|---|---|
| cookieConsent | localStorage | Essential | Records whether the user has interacted with the cookie consent banner | Until cleared by user |
| cookiePreferences | localStorage | Essential | Stores granular consent choices (analytics on/off, marketing on/off) to avoid re-asking on every page load | Until cleared by user |
| emailForSignIn | localStorage | Essential | Temporarily holds the e-mail address you entered, so it can be verified when you return from a magic-link sign-in e-mail in the same browser | Cleared immediately after sign-in completes |
| logogram_voter_token | localStorage | Essential | Randomly generated UUID (anonymous, never linked to a user account) that prevents duplicate votes on a public presentation | Until cleared by user |
| logogram_client_name | localStorage | Essential | Stores the name a client typed when commenting on or voting on a public presentation, so they do not need to re-enter it on the same device | Until cleared by user |
| logogram_votes_{slug} | localStorage | Essential | Records which logos the visitor has voted for in a specific presentation, so vote buttons show the correct state on return visits | Until cleared by user |
| api_cache_* | sessionStorage | Essential | Short-lived client-side cache of API responses (logos, credits) to reduce redundant server requests; scoped by user ID to prevent cross-user data leakage | ≤ 5 minutes; cleared when the tab is closed |
4 Processors & data transfers
| Service | Role / Purpose | Data categories transferred | Hosting region(s) | Third-country safeguard |
|---|---|---|---|---|
| Vercel Inc. | Hosting, CDN, serverless functions, Blob storage, Web Analytics | All user requests (IP, UA, path), SVG asset files, anonymised analytics events | EU, USA, global CDN | SCC (2021/914/EU) + DPA on file |
| Supabase, Inc. | Authentication, primary database (Postgres) and file storage | User profile (name, e-mail, UID), session data, saved logos and uploaded reference images | EU (project region) | DPA on file; SCC where support access originates outside the EU |
| Google LLC (Google Analytics 4) | Web analytics – active only after analytics consent | Pseudonymous client ID, event data, page paths, city-level geo | EU & USA | SCC + EU-US DPF; anonymize_ip: true configured |
| Meta Platforms Ireland Ltd. (Meta Pixel) | Marketing & conversion tracking – active only after marketing consent. Meta acts as an independent (joint) controller for data received via the Pixel. | Pseudonymous browser ID (_fbp / _fbc), page-view and conversion events | EU & USA | SCC + EU-US DPF; Meta's own privacy policy applies to data it receives |
| Replicate, Inc. | AI image generation (openai/gpt-image-2, google/nano-banana-pro) and SVG vectorisation (recraft-ai/recraft-vectorize) | Render prompt text, reference image URL (if provided) | USA | SCC + EU-US DPF |
| Recraft AI, Inc. | SVG vectorisation of generated and uploaded raster images | The raster image being vectorised | USA | SCC + EU-US DPF |
| OpenAI, Inc. | Concept / prompt generation (GPT-5.2 via Responses API); reference image analysis (GPT-4o Vision API); Design Story generation (fallback only, used when OPENROUTER_API_KEY is not configured) | Brand facts, style inputs, logo description, reference image URL or base64 PNG (for vision analysis); Design Story (fallback path): rendered logo image (as a PNG), brand brief and logo description, interface language | USA | SCC + EU-US DPF; OpenAI's API zero-retention data-usage policy applies to API traffic |
| OpenRouter | AI model routing for Design Story generation (primary path; used whenever OPENROUTER_API_KEY is configured) | Rendered logo image (as a PNG), brand brief and logo description, interface language | USA | SCC; OpenAI used as fallback only when OPENROUTER_API_KEY is not configured |
| Stripe, Inc. | Payment processing (one-time credit purchases) and subscription management (Pro / Agency plans); webhook event delivery | Billing e-mail, Stripe session / customer / subscription IDs, payment amount and currency, subscription status; card data is processed exclusively by Stripe (PCI DSS Level 1) and never transmitted to our servers | EU & USA | SCC + EU-US DPF; Stripe GDPR DPA on file |
| Postmark (ActiveCampaign, LLC) | Transactional e-mail delivery (welcome, purchase confirmation, low-credits alert, presentation-activity notifications) | Recipient e-mail address, display name, e-mail content, delivery metadata | USA | SCC; Postmark GDPR DPA available |
| Supabase (PostgreSQL, Auth, Storage) | Primary relational database (users, logos, credits, payments, sessions, presentations, rationales), account authentication, and generated file storage | All structured application data, authentication credentials, generated logo files | EU (eu-central-1, Frankfurt) | DPA on file; data stored within EU |
| Redis / Vercel KV (optional) | Short-lived rate-limit counters, generation idempotency keys, and response caches | Hashed IP or user ID (rate-limit keys), generation idempotency tokens (no personal content) | EU or USA depending on configuration | SCC (if applicable) |
Processors acting under Art. 28 GDPR operate strictly on our documented instructions. Data-processing agreements have been or will be concluded with each qualifying processor. Meta Platforms Ireland Ltd. acts as an independent joint controller for data it receives via the Meta Pixel after transmission; Meta's own Privacy Policy governs that processing.
5 International data transfers
Where personal data leaves the EEA / UK / Switzerland (e.g. to the USA), we rely on one or more of the following mechanisms:
- EU Standard Contractual Clauses (Decision 2021/914/EU), and/or
- the provider's certification under the EU-US Data Privacy Framework (DPF), where applicable,
- plus technical safeguards: TLS 1.2+ in transit, AES-256 at rest where supported by the provider.
For Meta Pixel data, Meta Platforms Ireland Ltd. (Dublin, Ireland) is the primary EU/EEA controller. US transfers are covered by Meta's DPF certification and SCCs. You can object to this processing by withdrawing marketing consent via the "Cookie settings" link at the bottom of any page.
6 Your rights (Art. 15–22 GDPR)
- Access (Art. 15) – obtain a copy of your personal data
- Rectification (Art. 16) – correct inaccurate data
- Erasure (Art. 17) – request deletion ("right to be forgotten"). Deleting your account removes your logos, projects, folders, presentations and profile data, and erases your authentication record. Payment and credit records are exempt under Art. 17 (3) (b) GDPR because German tax and accounting law requires us to keep them; they are kept under a pseudonymised internal ID with your identifying data removed
- Restriction (Art. 18) – restrict how your data is processed
- Data portability (Art. 20) – receive your data in a structured format
- Object (Art. 21) – object to processing based on legitimate interest or to direct marketing at any time
- Withdraw consent (Art. 7 (3)) – withdraw any consent at any time with future effect; withdrawal does not affect the lawfulness of prior processing
- Lodge a complaint (Art. 77) with the competent supervisory authority:
Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
To exercise any of the above rights, e-mail info@obey24.com. We will respond within one month; in complex cases the deadline may be extended by a further two months (we will inform you within the first month).
To unsubscribe from the newsletter, use the unsubscribe link in any newsletter e-mail or go to account settings. To withdraw analytics or marketing consent (including Meta Pixel), click "Cookie settings" at the bottom of any page.
7 Data security
- TLS 1.3 encryption for all client-server traffic
- AES-256 encryption at rest in Supabase and Vercel Blob storage
- Multi-factor authentication for admin accounts
- Strict role-based access control on all API endpoints
- Rate limiting on all API endpoints to prevent brute-force and abuse
- Idempotency guards on payment and logo-generation endpoints to prevent duplicate processing
- Regular vulnerability scans
- Daily backups and disaster-recovery plan (RPO ≤ 24 h)
8 Children
Logogram is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a minor has provided personal data, please contact us and we will delete it promptly.
9 Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or business changes. The current version is always available at logogram.io/privacy. For material changes, registered users will be notified by e-mail or via a prominent notice on the site.
10 Contact
Obey24com – Owner: Orhan Yilmaz
Bussardweg 3
75223 Niefern, Germany
Phone: +49 176 62915092
E-mail: info@obey24.com
Annex – Cookie banner consent categories
The cookie banner offers the following three consent categories. This section documents the exact categories and what they cover, ensuring alignment between the banner UI and this policy.
We value your privacy
Cookies help us keep Logogram secure and improve your experience.
Click "Accept all" to allow Analytics & Marketing cookies, "Reject all" to refuse them, or "Settings" for granular control.
Wir respektieren Ihre Privatsphäre
Cookies unterstützen die Sicherheit und verbessern Ihr Nutzererlebnis.
Klicken Sie auf „Alle akzeptieren", um Analyse- und Marketing-Cookies zuzulassen, auf „Ablehnen", um sie zu verweigern, oder auf „Einstellungen" für eine individuelle Auswahl.
Consent-category details (shown in the settings dialog):
- Essential (always active, cannot be disabled) – authentication tokens, session management, consent preference storage, presentation access tokens, view-deduplication cookies, anonymous voter token, presentation client name, API response cache (sessionStorage).
- Analytics (opt-in) – Google Analytics 4 (GA4), Vercel Web Analytics. Used to understand how users interact with the product so we can improve it.
- Marketing (opt-in) – Meta Pixel (Facebook Pixel) for conversion tracking and Facebook/Instagram ad retargeting.