Privacy Policy
A plain-language explanation of what Opplic processes, why it is needed, and the control you keep.
Effective and last updated: July 26, 2026
At a glance
- We collect only the account, workspace, integration, and usage data needed to run Opplic.
- Your repositories and client materials remain your content.
- We do not sell personal information.
- You can request access, correction, or deletion by contacting support.
Scope
This Privacy Policy explains how Opplic handles personal information when you visit our website, request a demo, communicate with us, or use an Opplic workspace. It also explains the choices available to you.
When an agency customer uploads or connects information about its own clients, that agency controls the business purpose for that information and Opplic processes it to provide the service.
Information we collect
- Account and session information, such as your work email, Supabase user identifier, authentication provider, and session data.
- Connected-service information, including GitHub identity, installation metadata, repository metadata, access tokens, commits, diffs, pull-request data, and the bounded repository content needed for requested features.
- Workspace content, including public website copy, client profiles, instructions, selected brand assets, briefs, analyses, campaign drafts, approvals, generated images, reports, and other generated materials.
- Ordinary request and security information made available by our hosting and authentication providers, such as timestamps, IP address, user agent, errors, and authentication events.
- Communications and scheduling information that you provide when requesting support, responding to us, or booking a meeting.
How we use information
- Provide, personalize, maintain, and secure Opplic.
- Authenticate users, enforce workspace permissions, and prevent fraud or abuse.
- Connect authorized repositories and integrations and perform the actions you request.
- Prepare analyses, recommendations, drafts, approvals, and reports.
- Respond to support requests and communicate service or security information.
- Understand performance and improve product reliability and usability.
- Comply with law and enforce our agreements.
AI-assisted processing
When you use an AI-assisted feature, Opplic may send prompts, business context, selected repository excerpts, patches, commit messages, drafts, or brand materials to OpenRouter and the model providers it routes requests to. When configured, image workflows may send prompts and selected brand images to ComfyUI. Provider handling may be governed by those providers’ own terms and policies.
Do not submit credentials, secrets, regulated data, sensitive personal information, or other information that is unnecessary for the task. AI output may be stored with the workspace when needed to support editing, approval, and reporting.
Retention and deletion
We retain information while needed to provide and secure Opplic, preserve requested workspace history, and satisfy legal obligations. Retention varies by the type of information and the applicable customer arrangement.
Opplic does not currently provide self-service account or workspace deletion. Disconnecting GitHub stops future authorized access but does not automatically delete previously imported data. Contact support@opplic.com to request deletion. Backup and deletion timelines depend on the applicable customer arrangement and our documented retention process.
Security
We use access controls, private storage, server-only credentials, signed webhook validation, encrypted network transport, and other reasonable safeguards designed to protect information.
No security program can eliminate every risk. Please use strong credentials, protect connected accounts, limit repository permissions, and contact us promptly if you suspect unauthorized activity.
Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to appeal or complain to a data-protection authority. Some rights are subject to legal exceptions.
To make a request, email support@opplic.com from the address associated with your account. We may need to verify your identity and your authority to act for an organization or another person. Agency end clients should normally contact the agency that controls their information first.
International processing
Opplic and its providers may process information in countries other than where you live. We handle cross-border processing as required by applicable law. Contact us if you need more information about where a particular provider processes information.
Children
Opplic is a business service and is not directed to children. We do not knowingly collect personal information from children through account registration. Contact us if you believe a child has provided personal information to Opplic.
Changes and contact
We may update this Policy as Opplic, our providers, or legal requirements change. We will post the new effective date and provide additional notice when appropriate.
For privacy questions or requests, contact support@opplic.com.