Privacy Policy

Last updated: 1 September 2026  ·  Effective: 1 September 2026

This policy explains what personal information Opteva 360 ("Opteva", "we", "us") collects through the Opteva platform and website (the "Service"), why we collect it, who we share it with, and the choices you have.

It forms part of our Terms and Conditions.

1. Two different roles

Opteva is used both directly by businesses and by agencies managing brands on behalf of their own clients. Which role we play depends on the information:

  • We decide how it is handled (we are the "controller") for account and billing information, and for information about how you use the Service.
  • We handle it on your instructions (we are the "processor") for the brand information and content you put into the Service, including information about your clients. You remain responsible for having a lawful basis to give it to us.

If you are an agency: you decide what client information enters the Service and how long it stays. If one of your clients asks about their information, that request goes to you, and we will support you in answering it.

2. Information we collect

2.1 You give us directly

WhatExamples
AccountEmail address, password (stored only as a cryptographic hash), your role and which agency you belong to
Brand informationBusiness name, contact first and last name, contact email, website, industry, target audience, brand voice, brand colours, typefaces, logo, goals, posting frequency
Social handlesInstagram, Facebook, TikTok, LinkedIn, YouTube, X, Pinterest, Google Business identifiers you supply
Onboarding submissionsEverything submitted through our intake form, including uploaded logo files
ContentCaptions, scripts, calendars, images you upload, scheduling instructions, approvals and overrides
BillingThe name, email, and billing address needed to raise and reconcile invoices. Card details are entered directly with Stripe and are not stored by us: we may see only the card type and last four digits.
CorrespondenceMessages you send us for support

2.2 Created when you use the Service

  • Generation records: which model was used, approximate input and output sizes, and timestamps, so we can meter usage and diagnose faults.
  • Publishing records: attempts to publish, which accounts were targeted, and the responses received.
  • Technical logs: IP address, browser type, pages requested, and error details, retained for security and troubleshooting.

2.3 Credentials for connected accounts

When you connect a marketing or social account, we store the access credential needed to act on your behalf, together with the identifier of the account it applies to. We do not receive or store your password for those platforms. Credentials are held so that only server-side processes can read them, and you can disconnect at any time.

2.4 From connected platforms

Where you have connected an account, we retrieve the list of connected profiles and their performance figures (such as reach, engagement, and follower counts) in order to display analytics to you. We retrieve only what is needed for that purpose.

2.5 What we ask you not to send

The Service is not designed to hold patient records or clinical information. Do not submit protected health information or identifiable patient imagery unless you hold all consents the law requires, and note that we are not a HIPAA business associate unless we have signed a separate agreement with you. See the Terms for detail.

3. Why we use it

PurposeLegal basis (UK/EU)
Providing the Service (generating content, publishing it, showing analytics)Performance of a contract
Authenticating you and keeping accounts separate and securePerformance of a contract; legitimate interests
Metering usage against your plan, and billingPerformance of a contract; legal obligation
Diagnosing faults and improving reliabilityLegitimate interests
Preventing abuse, fraud, and security incidentsLegitimate interests; legal obligation
Responding to support requestsPerformance of a contract; legitimate interests
Sending service notices about your accountPerformance of a contract
Sending marketing emailsConsent, which you may withdraw at any time

4. We do not sell your information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other United States privacy laws. We do not use your brand information or content to advertise to you or to anyone else.

5. Training of AI models

We do not use your content to train our own models, and we do not permit our AI providers to use it to train theirs. Your inputs are sent to those providers only to generate the Output you asked for, under commercial terms that exclude training use.

If that ever changes, we will tell you before it takes effect and give you a way to object.

6. Who we share it with

We share personal information only with service providers who help us operate the Service, and only as needed for their role. They are bound to protect it and may not use it for their own purposes.

ProviderWhat it does for us
SupabaseDatabase, authentication, and file storage
VercelWebsite and application hosting
AnthropicGenerating written content from your brand information
GoogleGenerating images; and, where you use our intake form, Google Workspace services that receive and hold submissions
OpenAIGenerating images, where configured as the image provider
GoHighLevel (LeadConnector)Publishing content to your connected accounts and retrieving performance data
StripeProcessing payments and managing billing

We may also disclose information where we are legally required to, to enforce our Terms, to protect our rights or someone's safety, or in connection with a merger or acquisition, in which case we will tell you before your information becomes subject to a different policy.

7. International transfers

We and our providers operate in the United States and elsewhere. If you are in the United Kingdom or European Economic Area, this means your information may be transferred outside it. Where that happens we rely on appropriate safeguards, such as the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses. You may ask us for details of the safeguards used.

8. How long we keep it

  • Account information: for as long as your account is open, and for a reasonable period afterwards.
  • Brand information and content: until you delete it, or until a reasonable period after your account closes.
  • Connection credentials: until you disconnect the account or close your account, whichever comes first.
  • Usage and publishing records: retained on a rolling basis for metering, troubleshooting, and security.
  • Billing records: for as long as tax and accounting law requires.

Backups are kept for a limited period and are overwritten in the ordinary course. Do not treat the Service as your only copy of anything you need.

9. Security

We take measures intended to protect personal information, including encryption in transit, restricting credential access to server-side processes, and enforcing database-level separation so one customer's records cannot be read by another. Access by our personnel is limited to what their role requires.

No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur. Where a breach affecting personal information occurs, we will notify affected customers and regulators as the law requires.

10. Your rights

Depending on where you live, you may have the right to:

  • know what personal information we hold and get a copy of it;
  • have inaccurate information corrected;
  • have information deleted;
  • restrict or object to certain uses;
  • receive information in a portable format;
  • withdraw consent where we rely on it;
  • not be discriminated against for exercising these rights.

To exercise any of these, email hello@opteva.ai. We will verify your identity before acting, and respond within the period the law allows. You may use an authorised agent where the law permits.

If your information was given to us by an agency using the Service, we will refer your request to them, as they decide how it is used.

If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority. If you are in the UK, that is the Information Commissioner's Office.

11. Deleting your data

You can delete individual brands and content from within the Service at any time. To delete your account and the information associated with it, email hello@opteva.ai. We will action it within 30 days, other than information we must retain by law or for the limited backup period described above.

Disconnecting a social account removes the stored credential for it. It does not delete anything already published to that platform. You control that on the platform itself.

12. Cookies and similar technologies

We use browser storage and cookies that are necessary for the Service to work, principally to keep you signed in and to remember your preferences. We do not use advertising cookies or third-party tracking pixels in the application.

13. Children

The Service is for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.

14. Changes to this policy

We may update this policy. Where a change is material, we will give notice by email or in-product before it takes effect, and update the date at the top. Continuing to use the Service after that date means you accept the updated policy.

15. Contact

Questions, requests, or complaints about privacy:

Opteva 360
520 5th Street
Catasauqua, Pennsylvania 18032
United States
hello@opteva.ai