Oh My Kink

Privacy policy

Last updated Oct 3, 2026

The short version: this app is private and invite-only. We collect only what the app needs to work, we never sell or share it for advertising, and you can see, change and delete it yourself under Us.

Who we are

The app is run by its admins, private individuals in Canada, not a company. The lead admin is the person responsible for your personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

To ask a question, see your data, correct it, or complain, sign in and use Report a concern in the app, which only the admins read.

What we collect

Everything below is given by you or by your partner, in the app. We don't buy data about you and we don't collect anything from other websites.

  • Your account. Email address, first name, a password (stored only as a one-way hash), a PIN (hashed too), and the invite code you signed up with. Optionally a nickname, pronouns, a short bio, an avatar and a country flag, and your choices about which name each audience sees. The invite codes you make for friends, and whether each is waiting, used or expired.
  • Your couple. Its name, safeword, aftercare note, bio, avatar and settings, and who its members are.
  • What you play. Leagues you're in, the challenges your couple writes (including the stories you type), what you mark done or skipped, scores and modifiers, bonus challenges, comments, afterglow stories, ladder rungs you tick or log (on your solo ticks, whether you were the giver or the receiver), your inventory and wishlist, and app events you take part in. Much of this is about your sex life, which the law treats as highly sensitive. That's why the app exists only behind an invite, a sign-in and a PIN.
  • Photos and videos. Proof you send to another couple, photos and videos you add to the library, inventory photos, and a screenshot if you attach one to a bug report. Every one is stripped of camera details and location, re-encoded, and stored encrypted.
  • Your devices. A signed-in session per device (a random token, when it was last used, and whether it's locked), passkeys you add (the public key and a device name), and notification subscriptions (the address your browser gives us, its keys, and the browser's name).
  • Shop pages you suggest. Under Where to get one, the shop page's address (with the tracking parameters we recognise removed), the title and note you type, and that you suggested it, which only the admins see. Members see the page without your name.
  • Reports. What you write in Report a concern or Report a bug, who it's about if you say, replies, and for a bug the page, app version, browser, screen size, time zone and recent error messages, which the sheet shows you before you send.
  • Technical. Your IP address is used in the moment to limit sign-in, sign-up and password-reset attempts, and isn't saved by the app. The app keeps one row per person per day saying you used it, for its activity counts. Error logs record the page's address and a request id, never your name, and never the contents of challenges, comments or reports.

Why, and your consent

  • To run the game: show your couple its challenges, score them, and show leagues their totals.
  • To keep your account safe: sign-in, the PIN lock, passkeys, and limits on guessing.
  • To send the notifications you turn on, and the password-reset email you ask for.
  • To handle reports, keep the app safe, and fix bugs.
  • To see, in counts only, how much the app is used and whether it's healthy.

You agree to this when you create your account and tick the box, and whenever you choose to add something optional, such as a photo, a nickname or a notification device. Because what you share here is sensitive, we ask for that consent plainly and up front, and we use your information for nothing else: no advertising, no analytics trackers, no selling, and no profiling. You can take your consent back at any time by turning a feature off or deleting your account (see Your rights).

Who can see what

  • Your partner sees everything your couple does, your solo ladder ticks (giver or receiver), and the name you chose for them.
  • Couples in your leagues see your couple's name, avatar and bio, your profile (your name, avatar, pronouns, bio and country flag), the challenges you wrote once the season starts, your totals (never your modifiers), your comments on the league board, and, unless you switch it off in couple settings, your ladders and inventory. Your solo ladder ticks, giver and receiver, show to them only if you tick Couples in my leagues can see my solo ticks (giver or receiver) in Us → Profile. They see the name you chose for leagues.
  • Every member can read afterglow stories and library photos and videos that your couple chose to publish and an admin approved. Anonymous lines such as "Someone ticked a rung" never say who.
  • The couple you send proof to can view it once, within 48 hours, and then it's deleted. Admins never see proof.
  • The admins see names and emails, reports and replies, library and afterglow submissions waiting for review, and usage counts. They run the server, so in principle they could read anything that isn't encrypted; they don't, except to handle a report or a bug you sent.
  • Anyone with an invite link you made can open it, even signed out, and sees your name on it: the one your leagues see, or on a couple code the one your partner sees, with the couple or league it's for.
  • Nobody else. We never sell, rent or give your information to anyone. We use no analytics services and show no ads. The one commercial arrangement is the shop links under Where to get one, described below.

Three outside services touch a little of your data because the app can't work without them, and one more only when you choose it:

  • Push notifications go through your browser's push service (Apple, Google or Mozilla, depending on your device). It sees the subscription address and an encrypted message; the message is a fixed, generic sentence that never names a person or a challenge.
  • Email is sent only when you ask to reset your password, through our own mail server.
  • Hosting. The app runs on one rented server (see below). The hosting company stores the machine and never has the keys to the encrypted media.
  • Shops, only when you tap Open shop under Where to get one. The link opens the shop in a new tab, sometimes by way of the affiliate network the shop uses. The shop, and any affiliate network it uses, see your visit as they see any visitor (your IP address, your browser) and may set their own cookies. They learn from the link that the visit came from this app's affiliate account. The link carries no name, id or session, your browser sends no referrer, and nothing from any shop loads until you tap. If you sign in or buy there, the shop knows that customer came from this app. Some shop links earn this app a small commission; it never changes what you pay. The app keeps one count per shop page per day of how often it was opened, and nothing about who opened it.

We disclose information without your consent only where Canadian law requires it, such as a court order, or to protect someone's safety.

Where it's kept

Your data is stored on one rented server; the admins can tell you which country it's in. Photos and videos are encrypted at rest with keys that stay on that server. Passwords and PINs are stored only as hashes. Everything travels over HTTPS.

The database and the encrypted library, inventory and report pictures are backed up nightly. Proof media is never backed up. Something you delete can stay in a backup until that backup is replaced.

How long we keep it

  • Your account and what your couple made: until you delete it, or an admin removes it for breaking the terms.
  • Proof: deleted when viewed, 48 hours after it was sent, or 24 hours after upload if it was never sent.
  • Library uploads: until a partner takes them down or an admin rejects them; a rejected or never-submitted upload is deleted after 7 days.
  • Sessions: stop working 30 days after the last use. Signing out ends one now; Sign out everywhere (Us → Settings → Account) ends all of them.
  • Password-reset links: stop working after 30 minutes, or once used.
  • Reports: kept so admins can follow up, even after an account is deleted (it then shows as "deleted account"). A bug screenshot is deleted 90 days after the report is resolved.
  • Bans: a banned email address is kept with the ban, so the account can't be recreated while it lasts. When the ban ends it no longer blocks anyone, but the record, with the email, stays as the ban's history.
  • Shop pages you suggest: one still waiting for an admin is kept until you remove it, an admin decides, or you delete your account. One an admin has looked at is kept; an approved page stays for other members.
  • Shop page opens: the daily counts are deleted after 400 days.
  • Usage days: 400 days.
  • Raw uploads: the original file, with its camera details, is processed in a temporary folder and gone within 30 minutes.

Your rights

  • See and correct. Your account, names, profile, couple and settings are all under Us, and you can change them there any time.
  • Get a copy. Ask (above) and we'll send you what we hold about you, within 30 days, as PIPEDA requires. We'll say if any of it can't be released, and why.
  • Delete. Delete my account (Us → Settings → Account) removes your account at once: your names, email, password, PIN, devices, comments, inventory, ladders and solo ladder ticks. What you approved for the library or afterglow goes with you. Shop pages you suggested that are still waiting for an admin are deleted. Ones an admin already looked at stay, an approved page for other members, with no record of who suggested them. If you were one of a couple of two, everything the couple made goes too; if others remain in it, the couple and what it made stay with them. Reports you sent, and a ban if there is one, stay as described above.
  • Withdraw consent. Turn off notifications, ladders, solo tick sharing, inventory sharing or announcements in their settings, or delete your account.
  • Complain. Tell us first (above). If you're not satisfied, you can complain to the Office of the Privacy Commissioner of Canada.

How we protect it

Sign-in and an invite are required for everything. Your device locks after 5 minutes idle and five wrong PINs sign it out. Passwords use argon2id hashing; sessions are random tokens stored hashed. Photos and videos are encrypted with AES-256-GCM before they touch the disk, and proof is deleted after one view. The app loads no scripts, fonts or images from any other site. Nothing is perfect, though: this is a small app run by volunteers, and we can't promise it will never fail.

If something goes wrong

If we learn that your information has been lost, stolen or seen by someone who shouldn't have, we will tell you as soon as we can, say what happened and what to do, and report it to the Office of the Privacy Commissioner of Canada where the law requires. We keep a record of every such incident.

A few more things

  • Adults only. Everyone here is 18 or older. If we learn an account belongs to someone younger, we delete it.
  • Emails and notifications. We send no marketing, newsletters or promotional messages of any kind. The only email is the password reset you ask for. Notifications are off until you turn them on, and you can turn them off per device in Us → Settings → Notifications.
  • Cookies. The app uses five small, necessary cookies and no trackers. The cookie policy lists each one.
  • Changes. When this policy changes we update the date at the top. If a change matters to what you agreed to, you'll be asked to accept the terms again, which point here.

Terms · Cookie policy· Create an account · Sign in