Privacy Policy
Last updated: 1 September 2026 · Effective: 1 September 2026
This policy explains what personal information Opteva 360 ("Opteva", "we", "us") collects through the Opteva platform and website (the "Service"), why we collect it, who we share it with, and the choices you have.
It forms part of our Terms and Conditions.
1. Two different roles
Opteva is used both directly by businesses and by agencies managing brands on behalf of their own clients. Which role we play depends on the information:
- We decide how it is handled (we are the "controller") for account and billing information, and for information about how you use the Service.
- We handle it on your instructions (we are the "processor") for the brand information and content you put into the Service, including information about your clients. You remain responsible for having a lawful basis to give it to us.
If you are an agency: you decide what client information enters the Service and how long it stays. If one of your clients asks about their information, that request goes to you, and we will support you in answering it.
2. Information we collect
2.1 You give us directly
| What | Examples |
|---|---|
| Account | Email address, password (stored only as a cryptographic hash), your role and which agency you belong to |
| Brand information | Business name, contact first and last name, contact email, website, industry, target audience, brand voice, brand colours, typefaces, logo, goals, posting frequency |
| Social handles | Instagram, Facebook, TikTok, LinkedIn, YouTube, X, Pinterest, Google Business identifiers you supply |
| Onboarding submissions | Everything submitted through our intake form, including uploaded logo files |
| Content | Captions, scripts, calendars, images you upload, scheduling instructions, approvals and overrides |
| Billing | The name, email, and billing address needed to raise and reconcile invoices. Card details are entered directly with Stripe and are not stored by us: we may see only the card type and last four digits. |
| Correspondence | Messages you send us for support |
2.2 Created when you use the Service
- Generation records: which model was used, approximate input and output sizes, and timestamps, so we can meter usage and diagnose faults.
- Publishing records: attempts to publish, which accounts were targeted, and the responses received.
- Technical logs: IP address, browser type, pages requested, and error details, retained for security and troubleshooting.
2.3 Credentials for connected accounts
When you connect a marketing or social account, we store the access credential needed to act on your behalf, together with the identifier of the account it applies to. We do not receive or store your password for those platforms. Credentials are held so that only server-side processes can read them, and you can disconnect at any time.
2.4 From connected platforms
Where you have connected an account, we retrieve the list of connected profiles and their performance figures (such as reach, engagement, and follower counts) in order to display analytics to you. We retrieve only what is needed for that purpose.
2.5 What we ask you not to send
The Service is not designed to hold patient records or clinical information. Do not submit protected health information or identifiable patient imagery unless you hold all consents the law requires, and note that we are not a HIPAA business associate unless we have signed a separate agreement with you. See the Terms for detail.
3. Why we use it
| Purpose | Legal basis (UK/EU) |
|---|---|
| Providing the Service (generating content, publishing it, showing analytics) | Performance of a contract |
| Authenticating you and keeping accounts separate and secure | Performance of a contract; legitimate interests |
| Metering usage against your plan, and billing | Performance of a contract; legal obligation |
| Diagnosing faults and improving reliability | Legitimate interests |
| Preventing abuse, fraud, and security incidents | Legitimate interests; legal obligation |
| Responding to support requests | Performance of a contract; legitimate interests |
| Sending service notices about your account | Performance of a contract |
| Sending marketing emails | Consent, which you may withdraw at any time |
4. We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other United States privacy laws. We do not use your brand information or content to advertise to you or to anyone else.
5. Training of AI models
We do not use your content to train our own models, and we do not permit our AI providers to use it to train theirs. Your inputs are sent to those providers only to generate the Output you asked for, under commercial terms that exclude training use.
If that ever changes, we will tell you before it takes effect and give you a way to object.
6. Who we share it with
We share personal information only with service providers who help us operate the Service, and only as needed for their role. They are bound to protect it and may not use it for their own purposes.
| Provider | What it does for us |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Website and application hosting |
| Anthropic | Generating written content from your brand information |
| Generating images; and, where you use our intake form, Google Workspace services that receive and hold submissions | |
| OpenAI | Generating images, where configured as the image provider |
| GoHighLevel (LeadConnector) | Publishing content to your connected accounts and retrieving performance data |
| Stripe | Processing payments and managing billing |
We may also disclose information where we are legally required to, to enforce our Terms, to protect our rights or someone's safety, or in connection with a merger or acquisition, in which case we will tell you before your information becomes subject to a different policy.
7. International transfers
We and our providers operate in the United States and elsewhere. If you are in the United Kingdom or European Economic Area, this means your information may be transferred outside it. Where that happens we rely on appropriate safeguards, such as the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses. You may ask us for details of the safeguards used.
8. How long we keep it
- Account information: for as long as your account is open, and for a reasonable period afterwards.
- Brand information and content: until you delete it, or until a reasonable period after your account closes.
- Connection credentials: until you disconnect the account or close your account, whichever comes first.
- Usage and publishing records: retained on a rolling basis for metering, troubleshooting, and security.
- Billing records: for as long as tax and accounting law requires.
Backups are kept for a limited period and are overwritten in the ordinary course. Do not treat the Service as your only copy of anything you need.
9. Security
We take measures intended to protect personal information, including encryption in transit, restricting credential access to server-side processes, and enforcing database-level separation so one customer's records cannot be read by another. Access by our personnel is limited to what their role requires.
No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur. Where a breach affecting personal information occurs, we will notify affected customers and regulators as the law requires.
10. Your rights
Depending on where you live, you may have the right to:
- know what personal information we hold and get a copy of it;
- have inaccurate information corrected;
- have information deleted;
- restrict or object to certain uses;
- receive information in a portable format;
- withdraw consent where we rely on it;
- not be discriminated against for exercising these rights.
To exercise any of these, email hello@opteva.ai. We will verify your identity before acting, and respond within the period the law allows. You may use an authorised agent where the law permits.
If your information was given to us by an agency using the Service, we will refer your request to them, as they decide how it is used.
If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority. If you are in the UK, that is the Information Commissioner's Office.
11. Deleting your data
You can delete individual brands and content from within the Service at any time. To delete your account and the information associated with it, email hello@opteva.ai. We will action it within 30 days, other than information we must retain by law or for the limited backup period described above.
Disconnecting a social account removes the stored credential for it. It does not delete anything already published to that platform. You control that on the platform itself.
12. Cookies and similar technologies
We use browser storage and cookies that are necessary for the Service to work, principally to keep you signed in and to remember your preferences. We do not use advertising cookies or third-party tracking pixels in the application.
13. Children
The Service is for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy. Where a change is material, we will give notice by email or in-product before it takes effect, and update the date at the top. Continuing to use the Service after that date means you accept the updated policy.
15. Contact
Questions, requests, or complaints about privacy:
Opteva 360
520 5th Street
Catasauqua, Pennsylvania 18032
United States
hello@opteva.ai