Privacy
The short version. Overs runs in your browser, your key goes only to OpenRouter, and your work stays on your device unless you sign in to share it.
What we store
By default, nothing. Your brands, campaigns, prompts and generated images are written to this browser using IndexedDB, and your API key is written to local storage on this device. Clearing your browser data deletes all of it, and we cannot recover it for you. If you choose to sign in, your email address and the brands, campaigns and images in your workspaces are stored in a database so they can open on your other devices and be shared with people you invite. Your API key is never stored there.
Where your API key goes
Only to OpenRouter, from your browser, over HTTPS, on the calls you trigger. It is never sent to this site’s own servers, because the model calls are made client side. You can confirm this in your browser’s network inspector.
Where your images go
The reference images you upload are sent to the model provider you selected, through OpenRouter, as part of a generation request. That is the only place they travel. They are also stored locally so a campaign survives a reload.
Analytics
Page views and where they came from, counted by Vercel Web Analytics. There is no cookie, no advertising identifier and nothing that follows you to another site. The address is stripped before it is sent: a campaign is counted as /studio/campaign/[campaignId] rather than by its id, and query strings are dropped whole, so nothing carried in a link you followed goes with it. Your brands, images, prompts and key are no part of it, and the fonts are still self-hosted, so a page load calls no font provider either.
Your responsibilities
You are responsible for holding the rights to the reference images you upload, and for the usage terms of the models you choose. Overs does not review or moderate the work you generate.