Overio
Privacy Policy
This Privacy Policy explains how Overio ("we", "us", or "our") collects, uses, stores, and protects information when you use Stikoo (the "App"). Please read it carefully before using the App.
1. Overview
- Stikoo is a visual sticker journal. You can take a photo or select one from your photo library, turn its main subject into a sticker, add a title, category, tags, note, and date, and browse saved stickers by day.
- No account or sign-in is required in the current version.
- Saved journal entries are stored locally on your device and are not synced to a Stikoo account.
- Stikoo offers two recognition modes:
- Quick Recognition processes recognition on your device and can work offline.
- Enhanced Recognition sends a processed recognition image to our recognition service and an AI service provider to generate suggestions.
2. Information We Process
2.1 Photos, camera access, and local journal content
- Camera access is used only when you choose to take a photo in the App.
- When you select an existing photo, Stikoo uses Apple's system photo picker or related system photo-library interface. Stikoo receives only the photo you choose, subject to the permissions provided by iOS.
- A selected photo may contain its capture location. When available, Stikoo reads it and stores it locally with the sticker for future map features. The current version does not display the location or a location status in the product interface.
- When you take a photo in the App, Stikoo attempts to record the device location available when you press the shutter only after you grant While Using the App access. Taking a photo and creating a sticker remain available if location is unavailable or permission is denied.
- When you explicitly choose to save a sticker to Photos, Stikoo requests add-only access and writes that sticker image to your photo library. This does not give Stikoo access to browse your other photos.
- Subject separation and sticker rendering are performed on your device.
- Saved sticker images, titles, notes, categories, tags, recognition labels, confidence values, dates, and optional source-photo locations are stored locally using Apple platform storage mechanisms such as SwiftData. Location is not embedded in exported sticker images.
2.2 Enhanced Recognition data
When you use Enhanced Recognition:
- Stikoo sends a processed JPEG recognition image, with a maximum dimension of 768 pixels, over HTTPS to the Stikoo recognition service. This image normally contains the separated subject. If on-device subject separation cannot be completed, it may contain a compressed version of the selected image.
- The request may also include your selected App language, a random request identifier, App Attest security data, and other technical metadata needed to authenticate the request and enforce usage limits.
- Our server processes the uploaded image in memory and does not save the uploaded image as an image file.
- To produce recognition suggestions, our server sends the processed image and a task prompt to the GLM API provided by Beijing Zhipu Huazhang Technology Co., Ltd. (智谱). The provider returns suggested content such as a title, category, tags, short description, journal note, and confidence value.
- Do not use Enhanced Recognition for images containing information that you do not want transmitted to a cloud service. Avoid submitting highly sensitive personal information or images of another person without an appropriate legal basis or permission.
2.3 Face data and images containing people
- A photo that you intentionally capture or select may contain a visible human face. Stikoo does not perform facial recognition, identity verification, facial landmark extraction, biometric profiling, or other face-specific analysis. We do not generate or store face templates, face embeddings, facial coordinates, biometric identifiers, or identity records.
- Foreground subject separation is performed on your device using Apple's Vision framework. This general-purpose process treats people, pets, plants, food, objects, and other subjects in the same manner and does not identify an individual.
- When you use Enhanced Recognition, the processed recognition image may contain visible face pixels if the photo you selected contains a person. The image is sent over HTTPS to the Stikoo recognition service and then to the GLM API operated by Beijing Zhipu Huazhang Technology Co., Ltd. solely to generate a suggested title, category, labels or tags, short description, journal note, and confidence value.
- Images containing visible faces are not used for facial recognition, authentication, identity verification, advertising, marketing, user tracking, or biometric profiling. The Stikoo server processes the image in memory and does not retain it as an image file after the recognition request is serviced.
- We may retain the non-image operational records described below, including an image hash, generated textual recognition result, request identifier, status, security information, error information, and timestamps. These records do not contain face templates, facial landmarks, or biometric identifiers.
- The resulting sticker and journal content are stored locally on your device until you delete the related journal entry or remove the App, subject to iOS backup, restore, and device-management behavior.
2.4 Anonymous installation, security, quota, and service records
Enhanced Recognition uses anonymous installation records rather than a user account. We may process and store:
- Apple App Attest key identifiers, public-key and attestation receipt data, assertion counters, App environment, distribution category, App version, risk status, and related timestamps;
- anonymous installation identifiers and short-lived access-session information;
- daily quota date, successful and reserved usage counts, and quota reset information;
- idempotency request identifiers, image SHA-256 hashes, recognition results, provider request identifiers, stable error codes, and request timestamps.
These records are used to authenticate genuine App installations, prevent replay and abuse, provide up to the configured daily recognition quota, return idempotent results, investigate failures, and protect the service. They are not used to create a named Stikoo account.
2.5 Network and diagnostic information
- Internet Protocol (IP) addresses are processed temporarily by network infrastructure and an in-memory rate limiter to secure the service and limit abusive traffic. Stikoo's application database does not store IP addresses for this purpose.
- Server logs may include a random request ID, request method and path, response status, duration, and a safe error description. We do not intentionally log uploaded images, request bodies, access tokens, App Attest objects, App Attest key IDs, or image hashes.
- Release builds may record limited client-side error information, such as an error code, HTTP status, path, and request ID, to help diagnose failures. Diagnostic information excludes photos, journal text, authentication tokens, and request bodies.
2.6 Product analytics
Stikoo uses Firebase Analytics to understand basic product usage and improve reliability. Analytics events may include:
- screens viewed and feature entry points;
- whether sticker creation, recognition, saving to Photos, or deletion succeeded or failed;
- recognition mode and source, broad sticker category, fallback-processing status, and selected settings;
- App version, build number, operating-system version, locale, device or App-instance information, and other technical information automatically processed by Firebase Analytics.
Analytics events are designed not to include your photos, sticker titles, journal notes, custom text, recognition labels, location, coordinates, location accuracy, access tokens, or App Attest material. We do not use Stikoo for personalized advertising, do not use analytics for cross-app tracking, and do not intentionally collect IDFA.
3. How We Use Information
We use information only as reasonably necessary to:
- capture or import a selected photo and create a sticker;
- store and display your journal locally;
- automatically keep the source photo's location locally for future map features;
- provide on-device or Enhanced Recognition suggestions;
- authenticate anonymous App installations and maintain daily usage quotas;
- prevent fraud, replay, automated abuse, and attacks;
- diagnose errors, operate the service, and improve App performance and usability;
- comply with applicable law and respond to valid legal requests.
We do not sell or rent your personal information.
4. Storage and Retention
- Local journal data: including an optional source-photo location, remains on your device until you delete the entry or remove the App, subject to iOS backup, restore, and device-management behavior. Location is not sent to Enhanced Recognition, analytics, or diagnostic logs.
- Stickers saved to Photos: remain in your photo library until you delete them there. Deleting a journal entry or removing Stikoo does not delete copies already saved to Photos.
- Enhanced Recognition images: are processed in memory by the Stikoo server and are not retained by us as image files after the request is serviced. The processed image is transmitted to the AI service provider as described above and is subject to that provider's processing terms and privacy policy.
- Attestation challenges: are short-lived and are deleted by a scheduled cleanup process after expiration.
- Installation, quota, request, recognition-result, and security records: are retained for as long as reasonably necessary to operate quotas, provide idempotent responses, prevent abuse, maintain security and audit records, resolve disputes, and comply with legal obligations. We delete or anonymize such records when they are no longer reasonably necessary, subject to technical and legal requirements.
- Analytics data: is retained according to our Firebase configuration and Google's applicable retention controls and policies.
- Support communications: if you contact us, we may retain your email address and message for as long as needed to respond, keep support records, prevent abuse, or meet legal obligations.
5. Third-Party and Platform Services
Stikoo relies on the following services where relevant:
- Apple: iOS camera, photo, and location services, App Attest, device security, App distribution, backup, and related platform services. Apple's handling of data is governed by Apple's terms and privacy policy.
- Google Firebase Analytics: limited product analytics and technical information. Google's handling of data is governed by its applicable privacy and Firebase terms.
- Beijing Zhipu Huazhang Technology Co., Ltd. (智谱 / GLM API): cloud image analysis for Enhanced Recognition. Its handling of transmitted data is governed by its applicable service terms and privacy policy.
- Hosting and network providers: infrastructure used to operate the Stikoo recognition service and securely deliver requests.
We disclose information to service providers only as needed to provide, secure, and maintain the relevant feature, or where required by law.
6. Your Choices and Rights
- You can use Quick Recognition to keep recognition processing on your device and avoid sending an image to the Enhanced Recognition service.
- You can manage camera, photo, and location permissions in iOS Settings. Disabling location does not prevent photo selection or sticker creation.
- You can view, edit, and delete saved sticker entries in the App.
- You can remove local App data by deleting entries or uninstalling Stikoo, subject to iOS backups and Keychain or system-security behavior.
- You may contact us to request access to, correction of, or deletion of server-side data associated with your anonymous installation. Because Stikoo does not use named accounts, we may need technical information from your device or a recent request to verify and locate the relevant record. Some records may need to be retained for security, fraud prevention, dispute resolution, or legal compliance.
- You may exercise any additional rights available under applicable data-protection law by contacting us.
7. Data Security
We use reasonable technical and organizational safeguards, including HTTPS transport, App Attest verification, access controls, input limits, rate limiting, and restricted diagnostic logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Children and Minors
Stikoo is not directed to young children. Minors should use the App only with the involvement and consent of a parent or legal guardian where required by applicable law. Do not submit a child's image or personal information to Enhanced Recognition unless you are authorized to do so and have considered the related privacy risks.
9. International Processing
Stikoo's own backend infrastructure at api.stikoo.overio.space is hosted in mainland China. Depending on your location and the infrastructure used by Apple, Google, the AI service provider, and hosting providers, information may be processed in mainland China or in other countries or regions outside where you live. Where required, we will use appropriate safeguards and comply with applicable data-transfer requirements.
10. Changes to This Policy
We may update this Privacy Policy when features, service providers, legal requirements, or data practices change. Material changes will be communicated through the App or our official website where reasonably practicable. The date at the top of this page shows the current version.
11. Contact Us
If you have questions, requests, or concerns about privacy or data handling, contact:
Email: over.io@icloud.com
Last Updated: July 31, 2026