Closed-beta draft for the Ownedgaze product. English only. This is not legal advice,
not a “GDPR compliant” stamp, and may change as the beta evolves.
Who is responsible
Ownedgaze is the product name for this invite-only closed beta.
A formal legal entity / named controller is not published yet
and will be added before a wider release. Until then, contact
beta@ownedgaze.com.
The service is hosted in the EU (currently an OVH VPS in the EU).
For monitoring, the paired Dom decides who is watched and can decrypt evidence on
their phone. We treat that as a split of roles (operator vs Dom) that we will
formalise when a company exists. It is not a finished joint-controller contract.
Why we process data
- Create and authenticate invite-only accounts (Dom or Sub).
- Pair a Sub with a Dom and run consensual screen monitoring.
- Store sealed evidence and day summaries for the Dom, and Dom allowlist media for matching.
- Relay end-to-end encrypted chat.
- Receive beta feedback and crash reports so we can keep the app running.
Legal bases (beta draft)
- Accounts, pairing, sync metadata, chat ciphertext: operating the service you asked to join (invite + terms).
- Sexual-life data (Art. 9): explicit consent at registration (and a blocking prompt for older testers). You can withdraw by deleting the account and stopping capture. Withdrawal does not undo copies already decrypted onto a Dom device.
- Crash reports: running a closed beta (stacks and app version only).
Special-category data (Art. 9)
Ownedgaze processes data concerning sex life and sexual orientation context:
NSFW screen evidence, on-device sexual classifications, day summaries of that activity,
and Dom allowlist images/videos. That is why registration has a dedicated consent
checkbox, separate from 18+ and the in-app “I understand” disclaimer.
What we process
- Account: username, display name, role (Dom/Sub), invite redemption records, Art. 9 consent timestamp, 18+ flag.
- Operational: last sync / health-style flags, Dom web library session records, peer notices (export / account deleted).
- Monitoring: day summaries and NSFW evidence packages stored as ciphertext sealed to the Dom. Operators are not meant to casually read plaintext frames or intimate breakdowns.
- Chat: end-to-end ciphertext between Dom and Sub. Operators cannot read message bodies by design.
- Allowlist library: Dom-uploaded images/videos (originals) so we can build fingerprint indexes for the paired Sub device. Originals sit unencrypted on our disk; staff with server access could open them.
- On the Sub device: screen capture, on-device classification, fingerprint matching, and a local encrypted queue before sync.
Who else receives data
- OVH (EU): VPS, Postgres, allowlist files.
- Sentry.io (US SaaS): Android crash reports: stack traces, device/app version. No evidence frames, seal ciphertext, chat plaintext, invite codes, or Dom private keys.
- Resend (email send): in-app feedback, including username and user id, to our inbox.
- Proton (Switzerland): operator mailbox beta@ownedgaze.com.
- Let’s Encrypt / GitHub: TLS and CI. Not a store of user monitoring data.
Sending crash reports and feedback email to US processors is an international transfer.
For closed beta we accept that and disclose it. We may self-host crash reporting later.
Dom allowlist media stays on our servers
When a Dom uploads allowlist media, the original files stay on Ownedgaze servers for that Dom’s library and re-indexing.
They are not redistributed to other Doms, not published as a content platform, and the media contents themselves do not leave our servers to Sub phones or third parties for browsing.
Paired Sub devices receive a compact fingerprint / embedding pack derived from that media so matching can run on-device, not a copy of the originals.
Delete an asset in the library when you want it gone from indexing; treat Dom uploads as high-sensitivity personal media.
Retention
- Evidence and summaries: about a 14-day sliding window.
- Chat ciphertext: until the contract is cleared or either account is deleted. Not on the 14-day evidence window.
- Allowlist originals: until the Dom deletes them or deletes the account (no automatic 14-day purge in beta).
- Account / operational records: for as long as the account is active.
- Sentry / mail / database backups: follow those systems. A delete in the app does not instantly wipe backups, crash events, or emails.
Your rights
You can access, export, and erase data we hold, and withdraw Art. 9 consent by deleting
the account and stopping capture. You can complain to a supervisory authority
(in France: the CNIL).
- Access / portability: in the app, You → Download my data. This is a zip of what the operator holds (including ciphertext we cannot read). It is not a live stats dashboard on Sub Home. If you are a Sub, your Dom is notified that you downloaded your data.
- Erasure: You → Delete account (type your username). Immediate. Shared chat for your pairing(s) is deleted for both people. If you are a Dom, every paired Sub loses that pair’s server-side history and your library files. The other party is notified, then the data is removed.
- You can also email beta@ownedgaze.com during beta.
Evidence and summaries are sealed to the Dom. An export includes those blobs as ciphertext.
Copies the Dom already decrypted on their phone are outside our control;
deleting your account here cannot wipe their device.
Cookies and local storage
Browsing the public pages (home, How it works, Screen ownership, Consent, Privacy, Terms) does not set cookies for normal use.
We do not use advertising or analytics cookies in closed beta.
The Dom library browser link stores a scoped session token in the browser’s localStorage (sent as a Bearer token to the API), not as a cookie.
Django may set session or CSRF cookies for admin tools or future cookie-backed forms; if public pages start relying on cookies, we will update this section.
Consent and age
Ownedgaze is for adults (18+) in a consensual Dom/sub dynamic. The Sub must knowingly install the app and grant screen-capture permission.
This is not designed as covert stalkerware. Registration also requires explicit consent to process sexual-life data described above.
How to stop
- Sub: uninstall the app and/or revoke screen-capture permission; ask the Dom to cancel the contract; or delete the account in You.
- Dom: cancel contracts, revoke linked library browsers in the app, delete allowlist assets, or delete the account in You.