Reelly — Privacy Policy
Version 1.0 · Last updated: 2026‑09‑21
Reelly is built and operated by Benjamin Ollomo (“I”, “me”), an individual. Reelly is an iOS app for saving public links from Instagram, TikTok, X, and Reddit into a private, searchable library. This policy explains what the Service collects, how it is used and shared, how long it is kept, and the choices you have. It applies to the Reelly app and the backend it connects to.
The short version: your library is yours. It is not sold, not rented, not used for advertising, and not used to train AI models. Reelly is a small, self-funded beta, and I collect as little as I can get away with while still making saves searchable.
1. Who this policy covers
- It covers individuals who use the Reelly iOS app (“you”).
- Reelly is an invitation-only beta. Accounts are limited to email addresses on an approval list.
- The backend and its database are hosted with third-party cloud providers. No data-residency guarantees are offered, and the Service is not designed for use under the EU/UK GDPR.
2. What is collected
2.1 Information you provide
- Account. Your email address and a password, which is stored only as a salted hash. Email verification is required before an account becomes usable. If Google sign-in is enabled for your account, an account identifier and email address from Google are received instead of a password. Session and token records are kept so you stay signed in.
- Saved links. The canonical public URL of each post you save, whether you save it in the app, through the iOS share sheet, or by sending it to Reelly on Instagram.
- Things you write. Notes, tags, favourites, item status, and the collections you create.
- Instagram DM linking. If you use the DM-saving feature, a one-time code is generated in the app and you send it by direct message to the configured Reelly account. The link between your Reelly account and that Instagram sender is stored so later links you send land in your library.
2.2 Information generated when you save something
When you save a link, the Service fetches what the platform makes publicly available at that URL and stores the result against your account. Depending on the post, that can include:
- the post’s available text (caption, title, body) and author fields;
- a transcript of spoken audio in a video;
- text sampled from what is visible on screen in a video;
- a short generated summary;
- a JPEG preview image;
- a numeric embedding of the item’s text, used for semantic search, and job records describing whether extraction succeeded, was partial, or failed.
Extraction is public-link-only. Reelly does not accept file uploads, does not sign in to any platform or use platform login cookies, and does not read comments or replies.
2.3 Technical data
The backend and the hosting providers keep ordinary operational records: request timestamps, IP addresses, error codes, and job status. These exist to run and debug the Service.
2.4 What is not collected
- No advertising identifiers, no third-party ad SDKs, no cross-app or cross-site tracking.
- No sale or rental of personal information, and no sharing for behavioural advertising.
- No location data, contacts, camera roll, or microphone access.
- No payment details — Reelly is free during the beta and has no billing flow.
3. How information is used
- Run the Service — store your library, extract and index saves, serve previews, and run keyword and semantic search.
- Account email — verification messages, password resets, security notices, and occasional beta announcements about the Service itself. No marketing email without your opt-in.
- Security and abuse prevention — authenticate requests, enforce the approval list and rate limits, and investigate abuse.
- Debugging and improvement — diagnose failures, especially extraction failures, and improve the product.
- Legal — comply with applicable law and enforce the Terms.
Your saves are not used to train AI models, and no automated decisions with legal or similarly significant effects are made about you.
4. How AI is used
- OpenAI is the AI provider. Audio from saved videos is sent to OpenAI for transcription, frames or text are sent for visual-text extraction, item text is sent for summarization, and item text is sent to the
text-embedding-3-smallmodel to produce search embeddings. - Content is sent to OpenAI only to produce these results and return them to your library.
- Transcripts, extracted text, and summaries are automated output and can be incomplete or wrong. They are aids for finding a post again, not a substitute for the post itself.
- If embeddings are unavailable, search falls back to keyword matching and says so in the app.
5. How information is shared
Information is shared only as described here:
- Infrastructure providers. A managed MongoDB database stores your items, collections, and account records; Google Cloud Storage holds preview images in a private bucket; hosting and email-delivery providers run the services and send account email. They process data on my instructions to operate the Service.
- OpenAI receives the content described in Section 4 to produce transcripts, extracted text, summaries, and embeddings.
- The platforms you save from. Fetching a public URL is a request to that platform, which will see it as ordinary traffic. Your identity is not sent to them.
- Apple provides App Store distribution and the device platform under its own terms.
- Legal and safety. Information may be disclosed if required by law or valid legal process, or where necessary to protect the rights, safety, or property of users, the public, or me. Where lawful and practical, affected users will be notified.
- Transfer of the project. If Reelly is transferred to another operator or entity, data may transfer with it, subject to this policy or a successor policy with comparable protections.
Your information is never sold, and never shared with advertisers.
6. Who can see your library
Every backend request must carry your own authentication, and items and collections are scoped to their owner, so one account cannot read another account’s library. Preview images live in a private bucket and are served only through short-lived signed URLs.
I am the sole operator and therefore hold administrative access to the database and storage. I do not read your library, and would only access individual records where strictly necessary to fix a fault you reported, investigate abuse, or comply with a legal obligation. Being candid about the limits: this is a one-person beta, and that restraint is a commitment and an access-control practice rather than something enforced by a third-party auditor.
7. How long information is kept
- Library data — saved items, notes, tags, collections, transcripts, summaries, embeddings, and previews are kept until you delete them or your account is closed.
- Account records — kept while the account exists.
- Operational logs — kept for a short period for debugging and security, then aged out by the hosting providers under their own retention settings.
- Backups — routine database backups may hold deleted records for a short window before they expire.
There is no immutable or legally mandated long-term retention: nothing is deliberately kept beyond what is described here.
8. Your choices and rights
- Delete individual saves at any time in the app.
- Delete your account and library. There is no self-serve account deletion in this beta build. Email benji.ollomo@gmail.com from your account address and your account and its data will be deleted, normally within 30 days.
- Get a copy of your data. Ask at the same address and you will receive an export of your library.
- Correct your information. Notes, tags, and collections are editable in the app; email me to change your account email address.
- Stop Instagram DM saving by no longer sending links to the Reelly account; ask me to unlink the connection entirely.
- Depending on where you live, you may have additional rights over your personal information. Email me and I will honour them as far as applicable law requires.
9. Children
Reelly is not directed to children under 13, and accounts are not knowingly created for them. If you believe a child has created an account, email me and it will be removed.
10. Security
Traffic is encrypted in transit, credentials are hashed, sessions are token-based, requests are owner-scoped, and previews are private by default. The Security Overview sets out what is actually in place — and what is not.
11. Changes to this policy
This policy may be updated. Material changes will be announced with reasonable notice in the app or by email, and the version and date at the top of this page will change.
12. Contact
Benjamin Ollomo
Email: benji.ollomo@gmail.com