The fine print
Privacy Policy
Last updated · July 6, 2026
This Privacy Policy describes how Opsis ("we", "us") collects, uses, and protects personal data when you use our Service, and explains the rights you have under applicable data protection laws (including the EU/UK GDPR, and similar regulations that apply where you operate). It should be read together with our Cookie Policy and Data Processing Terms.
1. About Opsis
Opsis watches your real users, finds broken flows, reproduces bugs with automated checks, and hands developers actionable fixes. You connect your analytics source with OAuth; Opsis then analyzes real user sessions. The controller of the end-user session data inside your connected project is you (the customer); Opsis acts as a processor for that data. For the account data you give us directly (your email), Opsis is the controller.
2. Data we collect
- Account data: your email address and password (stored by our authentication provider; we never see your password in plain text).
- Read-only OAuth tokens: when you connect your analytics source, we receive read-only OAuth tokens scoped to organization, project, session recording, and query access. Tokens are encrypted at rest (AES-256-GCM), are never sent to your browser, and are never logged.
- Session replay data from your project: events, console and network errors, click behavior (such as rage and dead clicks), and the routes users visited. This data is imported only after you connect your project and choose to import sessions. You are responsible for having a legal basis (consent) to record these sessions in your own app.
- Usage and diagnostic data: aggregated, pseudonymized analytics about how the public marketing site performs (only when you opt in via our cookie banner — see our Cookie Policy), and service logs needed to keep Opsis secure and reliable.
3. Pseudonymization and redaction
- End-user distinct IDs are pseudonymized with SHA-256 at import time. We do not store raw identifiers.
- Personal data patterns — email addresses, phone numbers, national ID numbers, card numbers, and tokens — are redacted before storage, before any data is sent to an AI provider, and in generated reports.
4. Legal basis for processing (GDPR)
For end-user session data we process on behalf of a customer, the legal basis is the contract between Opsis and that customer (GDPR Article 6(1)(b)). For the personal data we handle as a controller (your account email, your consent choices), the legal bases are:
- Performance of a contract — creating and running your account.
- Consent — when you opt in to optional cookies or optional communications. You can withdraw consent at any time.
- Legitimate interests — keeping the Service secure, preventing abuse, and diagnosing reliability issues, where those interests are not overridden by your privacy rights.
- Legal obligation — where we are required to retain or disclose data by law.
5. How we use the data
- To provide the Service: detecting signals of broken flows (rage and dead clicks, console errors, network failures, checkout abandonment), clustering related findings, AI analysis of redacted snippets, reproducing issues with automated checks, and generating reports with suggested fixes.
- To operate, secure, and improve the Service: reliability monitoring, abuse prevention, and aggregate product analytics.
- To communicate with you about your account, security, and (with your consent) product updates.
AI findings must cite real sessions — the AI is never permitted to invent evidence.
6. Our role regarding session data
For end-user data inside your connected project, you are the Personal Data Controller and Opsis acts as the Personal Data Processor. Your analytics source remains your own data source, connected by you via OAuth. See our Data Processing Terms for details.
7. Storage, security, and international transfers
- Data is stored in our database infrastructure with deny-all row-level security on secret tables.
- OAuth tokens are encrypted at rest with AES-256-GCM and never exposed to the browser or written to logs.
- Verification artifacts (videos, traces, screenshots, logs) are private and served only through an authenticated gateway that checks your organization membership.
- Unused pending OAuth grants expire after 30 minutes and are revoked and deleted.
- International transfers: your data may be processed by our sub-processors in regions different from your own. Where that involves a transfer out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, and require our sub-processors to do the same.
8. Sub-processors
We use a small set of third-party sub-processors to run the service. We list their function rather than name specific vendors; a current list is available on request:
- Database & authentication sub-processor — stores encrypted OAuth tokens and account data.
- AI analysis provider — used only on redacted data snippets; no unredacted personal data is sent.
- Cloud hosting sub-processor — runs the Opsis application and stores verification artifacts.
- Merchant of record — processes payments; receives only the billing details you provide at checkout.
9. Retention
- Imported sessions and findings are kept while your workspace is active.
- Verification artifacts are kept according to your plan and then deleted automatically — from 3 days on Free up to 365 days on Enterprise (see the Pricing page).
- When you disconnect your analytics source, we revoke the tokens upstream (best-effort) and always delete our stored copies.
- Service logs are retained only as long as needed for security and reliability, and then deleted.
10. Your rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data (the "right to be forgotten"), subject to legal retention obligations.
- Restriction / objection — ask us to limit processing or object to processing based on legitimate interests.
- Data portability — receive your personal data in a structured, machine-readable format.
- Withdraw consent — at any time, for processing based on consent (including optional cookies).
Send requests to admin@heyopsis.com and we will respond promptly, generally within 30 days.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act gives you additional rights:
- Know — the categories and specific pieces of personal information we collect, and how we use and share them.
- Delete — request deletion of your personal information, subject to exceptions.
- Correct — request correction of inaccurate personal information.
- Opt-out — of the "sale" or "sharing" of personal information for cross-context behavioral advertising. Opsis does not sell personal information and does not share it for cross-context advertising.
- Limit — the use of sensitive personal information.
- Non-discrimination — we will not treat you differently for exercising these rights.
To exercise these rights, email admin@heyopsis.com. Authorized agents may submit requests on your behalf with proof of permission.
12. Minors
Opsis is intended for use by developers and businesses, and is not directed to children. We do not knowingly collect personal information from children under 16 (or the age of digital consent in your country). If you believe a minor has provided us with personal data, contact us and we will delete it.
13. Revoking access
You can disconnect your analytics source at any time from the Opsis dashboard — we revoke both the refresh and access tokens upstream (best-effort) and always delete the tokens we hold. You can also revoke the Opsis authorization directly in your source's settings.
14. No sale of data
We do not sell personal data, and we do not share session data with third parties except the sub-processors listed above, strictly to provide the Service.
15. Cookies
Opsis uses essential cookies to keep you signed in. With your consent, we may also set pseudonymized performance cookies (Google Analytics 4) on public pages. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list of cookies, what each does, and how to change your preferences at any time.
16. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent change. If we make material changes to how we process personal data, we will notify you through the Service or by email before the change takes effect.
17. Contact
Privacy questions and requests: admin@heyopsis.com.