Privacy Policy
This policy explains exactly what Opis App Hub collects, why it is collected, who else processes it, how long it is kept and what you can ask us to do with it. It describes what the service actually does today, not what it might do one day.
Last updated: 30 August 2026
Who we are
Opis App Hub is a strategic intelligence suite operated as a sole trader business based in the United Kingdom. For the purposes of UK GDPR we are the data controller for the personal data described in this policy.
For any privacy question, or to exercise any of the rights described below, contact support@opis-app-hub.com. We aim to respond within five working days and are required to respond within one month.
What we collect
Account and authentication. Your email address and an encrypted representation of your password, handled by our authentication provider. We never see your password in readable form.
Subscription state. Your plan tier, subscription status, trial start and conversion dates, and an identifier linking your account to your payment record.
Content you create. The inputs you submit, the analyses and results generated from them, saved workflows, brand presets, colour palettes and any files you upload. This content belongs to you; we store it so you can return to it.
Your AI provider keys. If you supply your own API key, it is encrypted before it is stored and decrypted only at the moment it is needed to run your request. We keep an access log recording when a key was used, so that unexpected use is detectable.
Usage records. A record of analyses run against the platform key, used to enforce fair-use limits. Once you are on a paid plan your work runs on your own key, so these records generally stop accruing.
A payment card fingerprint. When you start a trial, our payment provider gives us a one-way fingerprint of the card. We store that fingerprint to prevent the same card being used for repeated free trials. It is not the card number, it cannot be reversed into one, and we never receive or store your full card details.
Uploaded logos are publicly readable
Brand logos you upload are stored in a public storage bucket so that they can be embedded in reports and shared documents. Anyone who has the file URL can view that image, even without an Opis account.
The URLs are not listed or indexed anywhere, but you should treat an uploaded logo as publicly accessible rather than private, and should not upload anything confidential as a brand asset.
What happens when you run an analysis
When you run an app, the text you submit and the instructions we build around it are sent to an AI provider for processing, and search queries may be sent to a search provider to gather evidence.
On a paid plan this happens using your own API key, under your own agreement with that provider. Your relationship with them is direct: their terms and privacy policy govern what they do with the content, and any charges are billed by them to you. We do not add a margin to that cost.
Do not paste information into an analysis that you are not permitted to share with a third-party AI provider.
Why we are allowed to process it
- To perform our contract with you — providing the service, your account, and the analyses you ask for.
- To meet legal obligations — retaining financial records for the periods UK tax law requires.
- For our legitimate interests — keeping the service secure, preventing repeated abuse of free trials, and diagnosing faults. We consider these limited and proportionate, and you may object at any time.
Who else processes your data
We use a small number of established providers. Each processes data only to deliver its part of the service:
- Supabase — database, authentication and file storage, hosted in the EU.
- Vercel — application hosting and content delivery.
- Stripe — payment processing. Stripe handles card details directly; we never receive them.
- Google — the Gemini AI models used to generate analyses and content.
- Tavily — web search used to gather evidence for grounded analyses.
- Microsoft — the mailbox behind our support address.
- Resend — delivery of service emails such as sending a report to a destination you choose.
Some of these providers are based outside the UK, principally in the United States. Where data is transferred internationally it is done under the safeguards those providers offer, such as standard contractual clauses. We do not sell your data, and we do not share it for advertising.
Cookies and tracking
Opis App Hub currently sets only two kinds of cookie, both strictly necessary: a session cookie that keeps you signed in, and a preference cookie remembering your chosen interface language.
We do not currently use Google Analytics, advertising pixels, session recording or any third-party tracking. That is why you are not being asked to accept cookies.
If that changes, we will update this policy and put proper consent controls in place before any analytics or advertising technology is loaded, rather than switching it on quietly and describing it afterwards.
How long we keep it
Account data and the content you create are kept while your account is open, so that your saved work remains available to you.
Records of payments and invoices are kept for six years after the end of the relevant tax year, because UK law requires it.
Card fingerprints used for trial-abuse prevention are kept for as long as that control remains necessary.
Deleting your account
There is not yet a self-service delete button in the product. Until there is, email support@opis-app-hub.com from the address on your account and we will delete your account and its associated content within 30 days, and confirm when it is done.
Financial records we are legally required to retain are the exception, and we will tell you what has been kept and why.
Your rights
Under UK GDPR you have the right to ask for a copy of your data, to have inaccurate data corrected, to have your data erased, to restrict or object to how we use it, and to receive it in a portable format. You will never be charged or penalised for exercising these rights.
Email support@opis-app-hub.com to make any of these requests. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first so we can put it right.
How we protect it
Traffic is encrypted in transit. Database access is restricted per-account at the database level, so one account cannot read another account’s rows. AI provider keys are encrypted at rest with a versioned scheme that allows the encryption key to be rotated without exposing stored credentials.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify the Information Commissioner’s Office within 72 hours where required, and tell you directly where there is a high risk to you.
Changes to this policy
If we change how we handle your data, we will update this page and change the date at the top. Where a change materially affects you — new tracking technology, a new category of data, or a new purpose — we will tell you rather than rely on you noticing.