Privacy Policy for Logogram

Last updated: 12 March 2026

1 Controller (Art. 4 No. 7 GDPR)

Company / Owner: Obey24com (sole proprietorship) – Owner: Orhan Yilmaz
Postal address: Bussardweg 3, 75223 Niefern, Germany
Telephone: +49 176 62915092
E-mail: info@obey24.com
VAT ID: DE269627535
Commercial register: Not applicable (sole proprietorship)

A formal data-protection officer is not required under Art. 37 GDPR. For all privacy-related enquiries, please use the contact details above.

2 What data we process – and why

PurposeTypical dataLegal basis (Art. 6 GDPR)Retention
Website delivery (hosting on Vercel)IP address, user-agent, timestamps, requested URL, HTTP status codeLegitimate interest (f) – IT security & deliveryServer logs ≤ 30 days
Server security & error loggingIP address, user-agent, request path, HTTP method, error message, trace ID, authenticated user ID (if logged in)Legitimate interest (f) – IT security & debuggingLogs ≤ 30 days
Rate limiting & abuse preventionHashed IP address or authenticated user ID, request countersLegitimate interest (f) – securityRolling window ≤ 1 hour (Redis / in-memory), then automatically purged
User account creation & management (Supabase Auth)Name, e-mail address, password hash, profile photo URL, sign-in method (email/password, Google, magic link), session ID, device type, browser, last-login timestampContract (b)Until account deletion, which also erases the authentication record and every active session. A pseudonymised account stub (internal ID only, with name, e-mail, photo, bio and social links removed) is kept solely to keep billing records traceable – see "Payment processing" below
Logo generation via AI (concept generation & image rendering)Brand name, industry, product description, target audience, tagline, style keywords, colour preferences, logo-type selection, free-text prompt, optional reference image (uploaded file or external URL), AI-generated concept promptContract (b)Prompt inputs: forwarded to AI providers and not retained beyond the job; reference images: stored as a public CDN URL until the logo is deleted; generated SVG: until logo or account deletion
Logo & asset storage (Vercel Blob CDN)SVG file content, public CDN URL, user-ID-scoped storage pathContract (b)Until logo deletion or account deletion
Design Story generation (AI writing) — free, included with every logoRendered logo image (converted to a PNG on the fly), brand brief and logo description, interface languageContract (b)Story, email copy and one-liner text stored until deleted by user or on account deletion; the rendered PNG is not stored
Web analytics & performance measurement (Google Analytics 4, Vercel Web Analytics)Pseudonymous client ID, device type, browser, city-level geolocation, session events (page views, feature interactions, logo-generation and credit-purchase events)Consent (a) – via cookie banner (analytics category)GA4: up to 14 months; configurable in the GA4 property settings
Aggregate traffic analysis (Vercel Web Analytics)Anonymised page-view count, referrer URL, country (no cookies set, no fingerprinting, no cross-site tracking)Consent (a) – via cookie banner (analytics category)Rolling 24-hour aggregation; no persistent user identifiers stored
Marketing & conversion tracking (Meta Pixel / Facebook Pixel)Pseudonymous browser identifiers (_fbp / _fbc), page-view events, credit-purchase conversion eventsConsent (a) – via cookie banner (marketing category)Meta: up to 180 days (configurable in Meta Business Manager); we do not retain raw Pixel data ourselves
Payment processing & subscription management (Stripe)Stripe checkout-session ID, Stripe customer ID, Stripe subscription ID, payment status, amount paid, currency, credits purchased, billing e-mail address; card data is processed exclusively by Stripe and never reaches our serversContract (b) / Legal obligation (c)Kept for 10 years for invoicing and tax purposes (§ 147 AO, § 257 HGB Germany) and therefore not deleted when you delete your account; erasure is excluded for these records under Art. 17 (3) (b) GDPR. They remain linked to a pseudonymised internal account ID, while your name, e-mail and profile data are erased
Transactional e-mails (welcome, purchase confirmation, low-credits notification, presentation-activity notifications)Recipient e-mail address, display name, relevant event details (e.g. purchase amount, credit balance, presentation URL)Contract (b) – necessary for service fulfilmentE-mail delivery metadata retained by Postmark per their retention policy; we do not store e-mail body content long-term
Newsletter (opt-in only)E-mail address, display name, opt-in timestampConsent (a)Until unsubscribe request or account deletion
Support & feedback (via the in-app feedback form)E-mail address, name, free-text message, feedback type (feedback / help)Legitimate interest (f)12 months after ticket is closed
Public client presentations – interactions by non-authenticated visitorsSelf-entered reviewer name, comment text, vote / approval status, review note, IP address (used for view-count deduplication, stored as event metadata)Legitimate interest (f) – enabling designer–client collaboration workflowsComment, vote and approval data: until the designer deletes the presentation; IP in event records: ≤ 30 days
Fraud prevention & legal complianceAbove data; internal audit logs; credit-event log (generation, refund, purchase)Legal obligation (c) / Legitimate interest (f)Statutory minimum (6–10 years in Germany, depending on category); see payment-data note above

No automated decision-making with legal or similarly significant effects (Art. 22 GDPR) is performed. Uploads or reference images that you provide for logo generation may be stored as publicly accessible CDN URLs for the purpose of AI processing. Please do not upload images containing sensitive personal data of third parties.

3 Cookies & browser storage

We use cookies (small text files stored by your browser) and browser storage (localStorage / sessionStorage) as described below. You can grant or withdraw optional-category consent at any time via the "Cookie settings" link at the bottom of any page.

3a HTTP Cookies

NameCategoryPurposeLifetimeSet by
authTokenEssentialSupabase access token used as a fallback for mobile browsers where the Authorization header may be unreliable1 hourFirst-party
presentation_tokenEssentialHMAC-signed access token granting entry to a password-protected presentation link without re-entering the password on every page load24 hoursFirst-party
pv_{slug}EssentialPrevents the same browser from incrementing a presentation's view counter more than once per hour (deduplication)1 hourFirst-party
_ga, _ga_*AnalyticsGoogle Analytics 4 – distinguishes unique users and sessions for traffic analysis; only set after analytics consent2 yearsGoogle LLC
_fbpMarketingMeta Pixel – identifies the browser for conversion tracking and Facebook/Instagram ad attribution; only set after marketing consent90 daysMeta Platforms Ireland Ltd.
_fbcMarketingMeta Pixel – stores a click identifier from a Facebook ad link for attribution; only set after marketing consent and only if you arrived via a Facebook ad90 daysMeta Platforms Ireland Ltd.

3b localStorage & sessionStorage

These are stored in your browser only, never transmitted to third parties, and can be cleared at any time through your browser's storage settings.

KeyStorage typeCategoryPurposeLifetime
cookieConsentlocalStorageEssentialRecords whether the user has interacted with the cookie consent bannerUntil cleared by user
cookiePreferenceslocalStorageEssentialStores granular consent choices (analytics on/off, marketing on/off) to avoid re-asking on every page loadUntil cleared by user
emailForSignInlocalStorageEssentialTemporarily holds the e-mail address you entered, so it can be verified when you return from a magic-link sign-in e-mail in the same browserCleared immediately after sign-in completes
logogram_voter_tokenlocalStorageEssentialRandomly generated UUID (anonymous, never linked to a user account) that prevents duplicate votes on a public presentationUntil cleared by user
logogram_client_namelocalStorageEssentialStores the name a client typed when commenting on or voting on a public presentation, so they do not need to re-enter it on the same deviceUntil cleared by user
logogram_votes_{slug}localStorageEssentialRecords which logos the visitor has voted for in a specific presentation, so vote buttons show the correct state on return visitsUntil cleared by user
api_cache_*sessionStorageEssentialShort-lived client-side cache of API responses (logos, credits) to reduce redundant server requests; scoped by user ID to prevent cross-user data leakage≤ 5 minutes; cleared when the tab is closed

4 Processors & data transfers

ServiceRole / PurposeData categories transferredHosting region(s)Third-country safeguard
Vercel Inc.Hosting, CDN, serverless functions, Blob storage, Web AnalyticsAll user requests (IP, UA, path), SVG asset files, anonymised analytics eventsEU, USA, global CDNSCC (2021/914/EU) + DPA on file
Supabase, Inc.Authentication, primary database (Postgres) and file storageUser profile (name, e-mail, UID), session data, saved logos and uploaded reference imagesEU (project region)DPA on file; SCC where support access originates outside the EU
Google LLC (Google Analytics 4)Web analytics – active only after analytics consentPseudonymous client ID, event data, page paths, city-level geoEU & USASCC + EU-US DPF; anonymize_ip: true configured
Meta Platforms Ireland Ltd. (Meta Pixel)Marketing & conversion tracking – active only after marketing consent. Meta acts as an independent (joint) controller for data received via the Pixel.Pseudonymous browser ID (_fbp / _fbc), page-view and conversion eventsEU & USASCC + EU-US DPF; Meta's own privacy policy applies to data it receives
Replicate, Inc.AI image generation (openai/gpt-image-2, google/nano-banana-pro) and SVG vectorisation (recraft-ai/recraft-vectorize)Render prompt text, reference image URL (if provided)USASCC + EU-US DPF
Recraft AI, Inc.SVG vectorisation of generated and uploaded raster imagesThe raster image being vectorisedUSASCC + EU-US DPF
OpenAI, Inc.Concept / prompt generation (GPT-5.2 via Responses API); reference image analysis (GPT-4o Vision API); Design Story generation (fallback only, used when OPENROUTER_API_KEY is not configured)Brand facts, style inputs, logo description, reference image URL or base64 PNG (for vision analysis); Design Story (fallback path): rendered logo image (as a PNG), brand brief and logo description, interface languageUSASCC + EU-US DPF; OpenAI's API zero-retention data-usage policy applies to API traffic
OpenRouterAI model routing for Design Story generation (primary path; used whenever OPENROUTER_API_KEY is configured)Rendered logo image (as a PNG), brand brief and logo description, interface languageUSASCC; OpenAI used as fallback only when OPENROUTER_API_KEY is not configured
Stripe, Inc.Payment processing (one-time credit purchases) and subscription management (Pro / Agency plans); webhook event deliveryBilling e-mail, Stripe session / customer / subscription IDs, payment amount and currency, subscription status; card data is processed exclusively by Stripe (PCI DSS Level 1) and never transmitted to our serversEU & USASCC + EU-US DPF; Stripe GDPR DPA on file
Postmark (ActiveCampaign, LLC)Transactional e-mail delivery (welcome, purchase confirmation, low-credits alert, presentation-activity notifications)Recipient e-mail address, display name, e-mail content, delivery metadataUSASCC; Postmark GDPR DPA available
Supabase (PostgreSQL, Auth, Storage)Primary relational database (users, logos, credits, payments, sessions, presentations, rationales), account authentication, and generated file storageAll structured application data, authentication credentials, generated logo filesEU (eu-central-1, Frankfurt)DPA on file; data stored within EU
Redis / Vercel KV (optional)Short-lived rate-limit counters, generation idempotency keys, and response cachesHashed IP or user ID (rate-limit keys), generation idempotency tokens (no personal content)EU or USA depending on configurationSCC (if applicable)

Processors acting under Art. 28 GDPR operate strictly on our documented instructions. Data-processing agreements have been or will be concluded with each qualifying processor. Meta Platforms Ireland Ltd. acts as an independent joint controller for data it receives via the Meta Pixel after transmission; Meta's own Privacy Policy governs that processing.

5 International data transfers

Where personal data leaves the EEA / UK / Switzerland (e.g. to the USA), we rely on one or more of the following mechanisms:

  • EU Standard Contractual Clauses (Decision 2021/914/EU), and/or
  • the provider's certification under the EU-US Data Privacy Framework (DPF), where applicable,
  • plus technical safeguards: TLS 1.2+ in transit, AES-256 at rest where supported by the provider.

For Meta Pixel data, Meta Platforms Ireland Ltd. (Dublin, Ireland) is the primary EU/EEA controller. US transfers are covered by Meta's DPF certification and SCCs. You can object to this processing by withdrawing marketing consent via the "Cookie settings" link at the bottom of any page.

6 Your rights (Art. 15–22 GDPR)

  • Access (Art. 15) – obtain a copy of your personal data
  • Rectification (Art. 16) – correct inaccurate data
  • Erasure (Art. 17) – request deletion ("right to be forgotten"). Deleting your account removes your logos, projects, folders, presentations and profile data, and erases your authentication record. Payment and credit records are exempt under Art. 17 (3) (b) GDPR because German tax and accounting law requires us to keep them; they are kept under a pseudonymised internal ID with your identifying data removed
  • Restriction (Art. 18) – restrict how your data is processed
  • Data portability (Art. 20) – receive your data in a structured format
  • Object (Art. 21) – object to processing based on legitimate interest or to direct marketing at any time
  • Withdraw consent (Art. 7 (3)) – withdraw any consent at any time with future effect; withdrawal does not affect the lawfulness of prior processing
  • Lodge a complaint (Art. 77) with the competent supervisory authority:
    Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
    Königstraße 10a, 70173 Stuttgart, Germany
    www.baden-wuerttemberg.datenschutz.de

To exercise any of the above rights, e-mail info@obey24.com. We will respond within one month; in complex cases the deadline may be extended by a further two months (we will inform you within the first month).

To unsubscribe from the newsletter, use the unsubscribe link in any newsletter e-mail or go to account settings. To withdraw analytics or marketing consent (including Meta Pixel), click "Cookie settings" at the bottom of any page.

7 Data security

  • TLS 1.3 encryption for all client-server traffic
  • AES-256 encryption at rest in Supabase and Vercel Blob storage
  • Multi-factor authentication for admin accounts
  • Strict role-based access control on all API endpoints
  • Rate limiting on all API endpoints to prevent brute-force and abuse
  • Idempotency guards on payment and logo-generation endpoints to prevent duplicate processing
  • Regular vulnerability scans
  • Daily backups and disaster-recovery plan (RPO ≤ 24 h)

8 Children

Logogram is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a minor has provided personal data, please contact us and we will delete it promptly.

9 Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or business changes. The current version is always available at logogram.io/privacy. For material changes, registered users will be notified by e-mail or via a prominent notice on the site.

10 Contact

Obey24com – Owner: Orhan Yilmaz
Bussardweg 3
75223 Niefern, Germany

Phone: +49 176 62915092
E-mail: info@obey24.com

Annex – Cookie banner consent categories

The cookie banner offers the following three consent categories. This section documents the exact categories and what they cover, ensuring alignment between the banner UI and this policy.

We value your privacy

Cookies help us keep Logogram secure and improve your experience.

Click "Accept all" to allow Analytics & Marketing cookies, "Reject all" to refuse them, or "Settings" for granular control.

Wir respektieren Ihre Privatsphäre

Cookies unterstützen die Sicherheit und verbessern Ihr Nutzererlebnis.

Klicken Sie auf „Alle akzeptieren", um Analyse- und Marketing-Cookies zuzulassen, auf „Ablehnen", um sie zu verweigern, oder auf „Einstellungen" für eine individuelle Auswahl.

Consent-category details (shown in the settings dialog):

  • Essential (always active, cannot be disabled) – authentication tokens, session management, consent preference storage, presentation access tokens, view-deduplication cookies, anonymous voter token, presentation client name, API response cache (sessionStorage).
  • Analytics (opt-in) – Google Analytics 4 (GA4), Vercel Web Analytics. Used to understand how users interact with the product so we can improve it.
  • Marketing (opt-in) – Meta Pixel (Facebook Pixel) for conversion tracking and Facebook/Instagram ad retargeting.