Legal

Privacy policy

Last updated: July 31, 2026

This policy explains what information Opustock collects, how it is used, who receives it, how long it is kept, and the choices you have. It covers the Opustock website, tools, Memory store, and connected AI clients.

Information we collect

  • Account information you provide: your name, username, and email address.
  • AI provider keys you add. These are stored encrypted on our servers and are never shown in full again or exposed to your browser.
  • Usage records created when you run a tool: the tool used, provider and model, request and token counts, status, and timestamps.
  • Memory documents that you or an authorized AI client choose to store: document paths, Markdown content, versions, sizes, and update times. We keep up to 20 prior versions per document.
  • Connected-client records: the client name, granted scope, and the expiry or revocation status of its authorization.
  • Payment records when you subscribe or buy credits, processed through our payment gateway. We do not store full card details.

How we use information

We use this information to operate your account, run the tools you request, synchronize Memory documents with clients you authorize, preserve document history, enforce plan limits and credit balances, process payments, provide support, and keep the service secure.

Storage and security

Provider keys are held in an encrypted, server-side vault and injected into requests by a server-side proxy, so your key stays out of the browser. Memory access uses revocable personal access tokens or OAuth authorization. We apply reasonable safeguards to protect data, though no method of storage or transmission is perfectly secure.

Third parties

When you run inference with your own key, requests go to the AI provider you connected, under that provider's terms and privacy policy. Payments are handled by our payment gateways.

When you authorize an AI client such as ChatGPT or Codex, that client may send content you explicitly ask it to store and may receive the Memory documents or snippets needed for your request. Opustock does not request or reconstruct your full chat history. The connected client may keep or use its copy under its own terms, privacy policy, account settings, and data controls. Revoking the connection stops future access but does not remove copies the client already processed.

We do not sell your personal information.

Analytics

We use first-party, cookieless analytics to understand site traffic and improve the product. We do not use third-party analytics services, advertising trackers, or cross-site cookies, and no analytics data leaves our servers. To count visitors without a cookie, we derive a daily fingerprint from your IP address and browser user agent using a salt that rotates every day. This fingerprint is a one-way hash: we do not store your raw IP address, and the daily salt means the fingerprint cannot be linked across days. We also record which pages are viewed, the referring site and campaign parameters in a link, an approximate country, and a device type. If your browser sends a "Do Not Track" signal, we skip this tracking. Raw analytics records are kept for a limited window (page views about 90 days, authentication events about a year) and then deleted; only aggregated daily totals are retained longer.

Advertising measurement (Meta)

With your consent, we measure how our ads on Meta (Facebook and Instagram) perform, using the Meta Pixel in your browser and the Meta Conversions API on our server. These report a limited set of events to Meta, such as viewing a page, creating an account, starting checkout, and completing a purchase. For a purchase we include the amount and currency.

To help Meta match an event to an account, we send a hashed, non-reversible version of your email address and your account id, and we may include your IP address and browser user agent. The pixel also uses Meta's own cookies (_fbp and _fbc). Meta processes this data as an independent controller under its own data policy.

None of this loads or is sent until you accept the cookie banner, and nothing is sent if your browser signals "Do Not Track". You can decline and still use everything: declining sets no Meta cookies and shares no data. To change your choice later, clear the opustock_consent cookie in your browser and reload.

Data retention and your choices

Active and soft-deleted Memory documents remain recoverable until you delete your account. Each document keeps up to 20 prior versions, and older versions are removed as later writes create new history. OAuth access tokens expire after one hour and refresh tokens after one year unless you revoke them sooner. Revoked and expired authorization records may remain until account deletion so they cannot be reused.

You can inspect, edit, restore, or soft-delete Memory documents from your account and disconnect an AI client at any time. Do not store passwords, API keys, payment-card information, health information, government identifiers, or other sensitive personal data in Memory.

We keep account and usage data while your account is active, subject to the analytics windows described above. Deleting your account removes your account, provider keys, Memory documents and revisions, client authorizations, credits, and usage logs. Billing records may be retained without a user-account link for the applicable accounting, tax, fraud-prevention, and dispute periods.

Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected by the "last updated" date above.

Contact

Questions about privacy? Reach us from the contact page.