NamingOwl is run by Blue Mango Ventures Inc., which is the data controller for everything described here. We collect the least we can get away with and we have never sold data to anybody.
What we collect
- Your account: your email address, a securely hashed password, and the name you choose to be greeted by. We store the hash, never the password itself.
- Your projects: the description you write, the settings you pick, the names we generated for you, their scores, which ones you starred, and any appraisals you asked for.
- Billing: your plan, a monthly count of how much you have used, and a reference to your Stripe customer and subscription. Card details go straight to Stripe and never touch our servers.
- Usage analytics:our own, not a third party’s. Which pages you visit, which steps you complete, where you first arrived from, and when. See the cookie section below.
- Messages you send us: the name, email address, and message from the contact form, which we store so we can reply and keep track of the conversation. Questions you put to the help assistant are passed to our AI provider to answer and are not stored by us.
- Technical logs: our web server records IP addresses, timestamps, and which page was requested, which we use for security and troubleshooting and for nothing else.
We do not use advertising trackers, we do not run third party analytics scripts, and there are no social media pixels on this site.
Why we are allowed to use it
- To give you what you signed up for (your account, your projects, generating and checking names, taking payment). This is the contract between us.
- To keep the service working and honest (bot checks, rate limits, fraud and abuse prevention, security logs, understanding which parts of the product people actually use). These are our legitimate interests, and we have kept the data involved as thin as we could.
- To meet legal obligations, mainly keeping records of payments for the period tax law requires.
Cookies
We set three cookies and they are all first party and strictly functional. There is no advertising cookie to consent to, which is why you are not being asked to dismiss a banner.
- A sign-in cookie, so you stay signed in. It goes away when you sign out.
- An anonymous visitor id, kept for up to 400 days, so we can count one returning person as one person instead of five. It is a random identifier and holds no personal data. Once you create an account, it gets linked to that account so we can see how people move from a first visit to signing up.
- A source marker, kept for 90 days, recording how you first found us, for example a search result or an ad.
Cloudflare also sets a short lived cookie as part of the “are you human” check on our sign-up and contact forms.
Who else sees your data
A handful of companies process data on our behalf, each only for their own part of the job, and none of them may use it for anything else:
- Google (Gemini API), which receives your project description and the candidate names in order to generate, score, and assess them, and the questions you put to the help assistant. Under the paid API terms we use, Google does not use this data to train its models.
- Stripe, which handles payments and holds your card details directly.
- Cloudflare, which sits in front of the site as a network and security layer and runs the bot check.
- SMTP2GO, which delivers our transactional emails, such as your confirmation link and password resets.
- Hetzner, which provides the server NamingOwl runs on, in a data centre in Germany. They supply the hardware and the network; they have no reason to look at what is on it and no part in running the service.
Checking whether a domain is free involves public DNS and public registry lookups. Those queries carry the domain name being checked and nothing about you.
Your account and your projects live on a server in Germany. That is where the database is, so the description you write and the names we find for you stay in the EU at rest.
We are a Canadian company, and some of the providers above operate in the United States, so parts of what we do reach them: payments through Stripe, generation through Google, email through SMTP2GO, and traffic through Cloudflare’s network. Where personal data leaves the EU or the UK it travels under the standard contractual clauses those providers offer, and Canada is recognised by the European Commission as providing an adequate level of protection for commercial organisations.
The only other time we would hand anything over is if the law genuinely required it, or if the business were sold, in which case this policy would travel with it.
What we never do
- We do not sell your data, and we do not share it for advertising.
- We do not use your project descriptions to train AI models, and nor does our provider.
- We do not read your projects except when you ask us for support and it is necessary to help.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop a particular use of it. If you are in the EU or the UK, those are your rights under the GDPR; if you are in California, they are your rights under the CCPA. We do not charge for any of this and we will answer within 30 days.
Deletion is self-service. Open Billing, choose Delete account, and confirm by typing your email address. That removes your projects, every name and appraisal in them, your sign-in details and your account record, cancels any paid plan, and deletes your customer record at our payment processor. It happens immediately and we cannot undo it.
A copy of your data is self-service too. Open Billing and choose Download my data. You get one JSON file with your account, your projects, every name and appraisal in them, the activity we have recorded, and any messages you have sent us. Your password hash and session tokens are left out on purpose, because handing those to a downloads folder makes your account less safe rather than more transparent.
For anything else, such as a correction or deleting a message you sent us, use the contact form. You may also complain to your local data protection authority if you think we have got it wrong.
How long we keep things
- Your account and projects: while your account exists, and then removed the moment you delete it.
- Payment records: kept as long as tax and accounting law requires, even after you leave.
- Analytics events: kept so we can see long term trends. While your account exists they are linked to it; when you delete it, that link is removed and what is left is an anonymous visitor id with no way back to you.
- Contact messages: kept while they are useful for support history, and deleted on request.
- Server logs: rotated and deleted on a short cycle.
Security
Passwords are hashed with argon2id, everything travels over HTTPS, payment card data never reaches us, and access to the production database is limited to the people who run the service. No system is perfect, but we do not cut corners here.
Children
NamingOwl is not for people under 16. We do not knowingly collect their data, and if we find we have, we delete it.
Changes
If we change this policy we will update the date at the top, and if the change is significant we will tell you by email rather than hoping you notice.
Contact
Data questions go through our contact form, or by post to the controller:
Blue Mango Ventures Inc.
112-970 Burrard St, Office #1618
Vancouver, BC V6Z 2R4
Canada
See also our Terms of Service.