Last updated: 19 September 2026
Short version. We collect your email address (if you sign up or pay), a Stripe customer ID, and usage counters. We do not run third-party analytics, we do not run advertising trackers, we do not set cookies in your browser, and we do not sell or share your data with anyone for marketing.
oganvil ("we", "us") is an OG (Open Graph) image generation API operated as an independent project. The service is reachable at https://oganvil.rowu.workers.dev. For any privacy question or request, contact us at the address in section 8.
| Data | Why | Where / how long |
|---|---|---|
| Email address | To issue your free API key, send quota notifications (50% / 90% / 100% of your monthly limit) and account-related notices. | Database row tied to your account. Kept while the account exists. |
| Billing identifiers — Stripe customer ID, subscription ID, plan, status | To apply the correct monthly quota to your account and to reflect upgrades, cancellations and payment failures. | Database row. Kept while the account exists. |
| API key (derived value) | To authenticate your renders. | Stored on your account row. |
| Usage counters — unique images used this month, anonymous renders today | Quota accounting and abuse/rate limiting. | Key-value store; monthly counter kept for 30 days, per-IP counters for 48 hours. |
| IP address (as a counter key only) | Anonymous tier limit (10 renders/day per IP) and signup rate limiting. We do not build profiles from it and we do not log it with your identity. | Key-value store, 48 hours. |
Render inputs — the title, tag and format you send |
To generate the image and to serve repeats from cache instead of billing you twice. | Rendered image cached for up to 1 hour, then discarded. Inputs are not used for anything else. |
Card numbers, CVCs and full payment details never reach us. Payments are processed by Stripe, Inc.; we only receive the resulting customer and subscription identifiers.
localStorage for tracking.We use a small number of processors, each for one purpose only: Cloudflare (hosting, edge compute, key-value store and database), Stripe (payment processing and subscription billing), and Resend (transactional email delivery). Each processes data on our instructions and under its own terms.
Where the GDPR applies: we process your email and account data to perform our contract with you (providing the service you signed up for), and we process usage counters and IP keys on the basis of our legitimate interest in keeping the service available and free from abuse.
You can ask us to access, correct, export or delete the data we hold about you, and you can object to processing based on legitimate interest. Write to the contact address below and we will respond within 30 days. Deleting your account revokes your API key and removes your account row; anonymised usage counters expire on their own.
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.
Privacy questions and data requests: privacy@oganvil.rowu.workers.dev. If you prefer, you can also open an issue at github.com/rowb53/oganvil-mcp/issues.
If this policy changes materially we will update the date at the top of this page. Continued use of the service after a change means you accept the updated policy.