Oplos is operated by Deodatum Inc., a company incorporated federally in Canada under the Canada Business Corporations Act, with its registered office at 205 Macdonnell Street, Kingston, Ontario, Canada.
In this policy, "Oplos", "we", "us" and "our" mean Deodatum Inc. "You" means the person using Oplos, including someone who joins a mediated session without an account.
1. The short version
- Oplos is for adults only. You must be 18 or older.
- We collect what you write in sessions, basic account details, and technical logs. That is close to all of it.
- Session content is sent to our AI provider so the assistant can respond. It is not used to train anyone's AI models.
- We do not sell your personal information. We do not share it for advertising. We do not run third-party ad tracking anywhere in Oplos.
- Your data is stored outside Canada, in the United States. That means it is subject to the laws of that country.
- You can see your data, correct it, take it with you, or delete it. Deleting your account takes effect immediately and is permanent. Write to privacy@oplos.co and we will answer within 30 days.
- After you delete an account we keep one thing: a scrambled, one way version of your email address, so that a free session or free trial already used cannot be reset by deleting the account and signing up again. It holds no readable address and nothing you wrote.
- We use only the cookies needed to keep you signed in and keep a session running. There is no advertising or analytics tracking to opt into or out of.
The rest of this document is the detail behind those points.
2. Who is responsible for your information
We have designated a Privacy Officer, who is accountable for our compliance with this policy and with applicable privacy law, and who handles your access, correction, portability and deletion requests.
Privacy Officer
Deodatum Inc.
205 Macdonnell Street, Kingston, Ontario, Canada
privacy@oplos.co
The name of the individual currently holding this role is available on request, by writing to privacy@oplos.co.
3. What we collect
3.1 Information you give us directly
| What | When | Why |
|---|---|---|
| Email address | Account creation | To identify your account, send service messages, and let you recover access |
| Display name or first name | Account creation or first session | So the other person in a room knows who they are talking to |
| Password, stored only as a cryptographic hash | Account creation | Authentication |
| Session content: everything you type in a solo or mediated session | Whenever you use Oplos | To generate the assistant's responses and to show you your own history |
| Room and relationship labels you create | When you set up a room | To organise your sessions |
| Resolution card content, including what each person agreed to | End of a mediated session | To produce and store the resolution record |
| Check-in responses | After a resolution | To track whether an agreement held |
| Support messages | When you contact us | To answer you |
3.2 Information we generate about you
| What | How | Why |
|---|---|---|
| Relationship Arc | Automated analysis of the emotional tone of your sessions over time | To show you a trend view of the relationship |
| Recall themes | Automated extraction of recurring themes across sessions in a room | To surface patterns you may not have noticed |
| Entitlement and billing status | From your plan and payment processor | To determine what features you can use |
| A one way hash of your email address | Generated when you create an account, using a secret key held only on our servers | To apply the free session and free trial limits fairly, and to stop those limits being reset by deleting an account and signing up again on the same address |
About that hash. It is produced by a one way function, so it cannot be turned back into your email address. It is not readable by anyone using Oplos, it is never shared, and it is not used to contact you, profile you, or link you to anything else. It records only two things: whether that address has used its free mediated session, and whether it has used the 7 day Resolve trial. We keep it after an account is deleted, which is the one exception to section 4, and we explain why in section 11.
This is automated processing. The Relationship Arc and Recall are produced by software analysing what you wrote, without a human reading it first. They are descriptive features, not decisions about you: they do not affect your access to Oplos, your pricing, or anything outside the product. You can ask us how a particular output was produced, and you can ask us to delete these outputs or stop generating them, by writing to privacy@oplos.co. We will act on that within 30 days. There is not yet a switch for this inside the product; until there is, the request route above is how it is done, and it works.
3.3 Information collected automatically
- IP address, browser type, device type, operating system, and approximate region derived from IP
- Timestamps of logins, session starts, session ends, and invite claims
- Error and performance logs
- Essential cookies and local storage needed to keep you signed in and to keep a session running
We do not use analytics or advertising tracking. There is no optional tracking category, because we do not collect any.
3.4 What we deliberately do not collect
- We do not ask for your date of birth, your address, your phone number, or government identification.
- We do not collect health information, and Oplos is not a health service. If you choose to write about your health in a session, that content is treated as session content and is subject to the same protections and the same deletion rights as anything else you write.
- We never see or store your full payment card number. That goes directly to Stripe.
4. Mediated sessions: two people, one record
This is the part of Oplos that needs the most careful explanation, because a mediated session contains two people's personal information in a single conversation.
If you start a room and invite someone, you are choosing to share the content of that mediated session with them. We cannot un-share it later on your behalf.
If you join by invite code, you are joining with your existing Oplos account. The session is saved to your account and appears in your own mediated sessions list.
If you join by invite link without signing in, you join anonymously. We do not create an account for you. We collect only what you write in the session, a temporary session identifier, and basic technical logs. You get access to the session and to the resolution card for 7 days after the session resolves, and you can download the resolution card as a PDF as your permanent copy. After that 7 day window your access ends and your temporary identifier is deleted.
What the other person can see. Both participants in a mediated session can read the full session transcript and the resolution card. Neither participant can read the other's solo sessions, ever. Solo sessions are private to the person who wrote them, with no exceptions.
Deleting a shared session. If you delete your Oplos account, your solo content becomes inaccessible immediately and is permanently erased within 30 days. For mediated sessions, we cannot simply erase half a conversation and leave the other person with a record that no longer makes sense. So we do this instead:
- Your name and account identifiers are removed from the session and replaced with a neutral label. The other person sees a former participant, with no name, no picture, and nothing to click through to.
- The other participant keeps their copy of the conversation, with your contributions still present but no longer attributed to an identified account. We do not delete their copy and we do not alter what was said in it, because it is their conversation as much as yours.
- The other person is not told that you deleted your account. They see only that the room is no longer active.
- If both participants request deletion, the entire session, including its content, is permanently deleted.
- You can ask us to fully delete a specific mediated session at any time. We will contact the other participant, and if they agree, we delete it entirely.
If you are uncomfortable with that arrangement, use solo mode.
What deleting your account does, in order. The moment you confirm, we cancel any paid subscription, sign you out on every device, release your email address so it can be used for a new account, and make your rooms and solo sessions invisible to everyone including you. There is no waiting period you have to sit through and no way to undo it, so please be sure before you confirm. The permanent erasure of the underlying records completes within 30 days, which is the window in section 11 and the same window our backups roll on. We do not offer a restore, and support cannot reverse a deletion for you.
5. Why we use your information
We use personal information only for these purposes:
- To run the service. Authenticating you, keeping sessions alive, generating assistant responses, producing resolution cards, delivering invites.
- To provide the memory features. Relationship Arc and Recall, where you have those features enabled.
- To handle billing. Determining your plan, processing subscriptions, issuing refunds.
- To keep Oplos safe. Detecting abuse, fraud, and misuse of invite links, and responding to safety situations as described in our Safety Policy.
- To support you. Answering your messages.
- To meet legal obligations. Responding to lawful requests and preserving records where the law requires it.
- To improve Oplos, using aggregated or de-identified information only, meaning information from which you cannot reasonably be re-identified.
- To send you marketing, but only if you have separately opted in. This is never bundled with account creation, and every message has a working unsubscribe link.
We will not use your information for a new purpose without telling you and, where the law requires, asking your consent again.
6. How the AI works, and what happens to your words
The Oplos assistant is artificial intelligence. You are not talking to a human being. Sometimes it will be wrong, and it is never a substitute for professional advice or care.
To generate a response, the text of your session is transmitted to our AI provider, Anthropic PBC, and processed on their infrastructure. Under our commercial agreement with Anthropic:
- Your content is not used to train Anthropic's models.
- Content is retained by Anthropic only as long as needed to return a response and to meet their trust and safety obligations.
We send only what the assistant needs in order to respond. We do not send your email address, your billing details, or your account identifiers to the AI provider.
We do not use your session content to train any model of our own.
7. Who else touches your data
We use a small number of service providers. Each is bound by contract to protect your information, to use it only on our instructions, and to apply security safeguards comparable to our own.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, and transactional email for sign-in and password reset | United States, us-west-1, California |
| Vercel | Application hosting and delivery | Global edge network, primarily United States |
| Anthropic PBC | AI processing of session content | United States |
| Stripe | Payment processing and subscription billing | United States, with global processing |
We keep this list current. The live version is at oplos.co/privacy-policy, and it is also linked from the safety and legal hub. We will post there at least 30 days before adding a new provider that handles personal information.
We do not sell personal information. We do not disclose personal information to advertisers or data brokers. We do not share your session content with anyone outside this list except where section 9 applies.
8. Cookies
Oplos uses only strictly necessary cookies and local storage: the items that keep you signed in and keep a live session from breaking when you refresh. These cannot be switched off, because the product does not function without them, and they are not used to profile you or track you across other sites.
We do not use advertising cookies, analytics cookies, cross-site tracking pixels, or third party ad networks anywhere in Oplos. Because we collect no optional tracking, there is nothing here for you to consent to or opt out of. If that ever changes, we will add a consent control and ask you first.
9. When we would disclose your information
We disclose personal information outside the list in section 7 only in these situations:
- Where you tell us to, including by inviting someone into a mediated session.
- Where the law compels us, such as a valid court order, warrant, or lawful demand from a regulator. We will tell you unless we are legally prohibited from doing so.
- Where there is an imminent risk of serious harm to you or to another identifiable person, and disclosure to emergency services or an appropriate authority is necessary to reduce that risk. This is described in more detail in our Safety Policy.
- Where we are required to report content involving the sexual exploitation of a child, which we are obliged to do by law.
- In a business transaction, such as a sale or merger of Deodatum Inc. or the Oplos product. In that case the recipient would be bound to use the information only for the purpose of evaluating and completing the transaction, and would have to continue to protect it under this policy. We would notify you before any transfer of your information became effective.
10. Where your data lives, and what that means
Oplos is operated from Canada, but your personal information is stored and processed outside Canada, in the United States, including in the us-west-1 region in California.
This means that while your information is in another country, it is subject to the laws of that country, and may be accessible to the courts, law enforcement and national security authorities of that country under their own legal processes. That is true regardless of the protections we and our providers put in place.
We have assessed this transfer, we contractually require comparable protection from each provider, and we remain accountable to you for your information no matter where it sits. If you are not comfortable with your information being stored outside Canada, please do not use Oplos.
11. How long we keep things
| Data | Retention |
|---|---|
| Account record | While your account is open. On deletion, access ends immediately and the record is permanently erased within 30 days |
| Solo session content | While your account is open, then deleted within 30 days of account deletion, including from backups |
| Mediated session content | While at least one participant's account is open, then handled as described in section 4 |
| Anonymous guest session access | 7 days after the session resolves, then the temporary identifier is deleted |
| Relationship Arc and Recall outputs | While your account is open, deleted within 30 days of you asking us to stop generating them or deleting the account |
| Resolution cards | With the session they belong to |
| Billing records | 7 years, because tax law requires it |
| Technical and security logs | 12 months |
| Support correspondence | 24 months |
| Marketing consent records | For as long as you are subscribed, plus 3 years after you unsubscribe, so we can prove we had consent |
| Backups | Rolling, retained no longer than 30 days |
| One way hash of an email address, with whether that address has used its free session or free trial | Kept indefinitely, including after account deletion |
When a retention period ends, we delete the information or irreversibly de-identify it.
The one thing that outlives deletion, and why. The last row above is the single exception to everything else in this policy, so we would rather state it plainly than bury it. The free mediated session and the 7 day Resolve trial are offered once per person. Without a record that survives deletion, anyone could take the free session, delete the account, sign up again on the same address, and repeat that indefinitely, and the free tier would not survive it. So we keep a scrambled, one way version of the address and two yes or no flags about what it has used.
We keep as little as it is possible to keep and still have this work. It is not your email address and cannot be turned back into it. It does not record your name, your sessions, anything you wrote, what you paid, or when you left. If you never used the free session, nothing is carried over and a new account gets it in full: only actual use carries, never the fact that you deleted. We rely on our legitimate interest in preventing fraud and abuse of the service for this, we do not use it for any other purpose, and we will not start doing so without changing this policy first.
12. How we protect it
- Encryption in transit and at rest
- Row level access controls so that one account cannot read another account's data
- Passwords stored only as salted hashes, never in readable form
- Access to production data limited to those who need it, currently a single administrator, with access logged
- Regular dependency and vulnerability review
No system is perfectly secure and we will not pretend otherwise. If a breach occurs that creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada, notify you directly and promptly, and record it in our breach register.
13. Your rights
Whatever province or country you are in, you can:
- Know what personal information we hold about you and why
- Access a copy of it
- Correct anything inaccurate or incomplete
- Withdraw consent at any time, including consent to marketing, subject to legal or contractual limits which we will explain to you
- Delete your account and your information, subject to section 4 for shared sessions, to the fraud prevention record described in section 11, and to legal retention obligations such as the 7 year tax requirement on billing records
- Take your data with you, in a structured, commonly used, machine readable format
- Complain, first to us and then to a regulator
To exercise any of these, email privacy@oplos.co. We will verify who you are, and we will respond within 30 days. We do not charge for this.
If we say no, we will tell you why in writing and tell you how to challenge it.
If you are still not satisfied, you can complain to:
- The Office of the Privacy Commissioner of Canada, at priv.gc.ca
- If you are in Quebec, the Commission d'accès à l'information du Québec, at cai.gouv.qc.ca
- If you are in Alberta or British Columbia, your provincial Information and Privacy Commissioner
14. Quebec residents
If you live in Quebec, additional protections apply to you and we apply them:
- Our Privacy Officer's role and contact details are published in section 2, and the individual's name is available on request.
- We do not use technology that identifies, locates or profiles you. If we ever introduce any, it will be deactivated by default and we will tell you how to activate it.
- We conduct a privacy impact assessment before transferring personal information outside Quebec and before deploying any new technology that processes it.
- You have the right to data portability, described in section 13.
- Section 3.2 explains where automated processing is used and how to ask about it.
- This policy is currently available in English only. We will provide a French version before we actively market Oplos to Quebec residents.
15. United States residents
Oplos is available to users in the United States. Depending on your state, you may have specific rights and we honour them:
- The automated AI features of Oplos are covered by our Safety Policy, which describes how the assistant discloses that it is AI and how it responds to signs of crisis, consistent with emerging state laws governing AI companion and chatbot services.
- If your state grants rights to access, delete, correct, or port your personal information, or to opt out of sale or targeted advertising, you can exercise them at privacy@oplos.co. We do not sell personal information or use it for targeted advertising in any state.
- We treat relationship and emotional content you write as sensitive, and apply the protections in this policy to it regardless of your state of residence.
16. Age
Oplos is for adults. You must be at least 18 years old to create an account or to join a mediated session.
You confirm your age by self-declaration when you create an account. Someone joining a mediated session through an invite link makes the same declaration, and agrees to this policy and to the Terms, before they can join.
We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe a minor is using Oplos, tell us at privacy@oplos.co.
17. International users and where Oplos is aimed
Oplos is operated from Canada and offered to users in Canada, the United States, and other countries in English. It is not specifically directed at, or marketed to, residents of the European Economic Area or the United Kingdom, and prices are shown in Canadian dollars. If you access Oplos from outside Canada, you do so on your own initiative and are responsible for compliance with your local laws.
18. Changes to this policy
If we make a material change, we will tell you by email and by notice inside the product at least 14 days before the change takes effect, and we will not apply a materially different use of information you have already given us without asking you first.
The date at the top of this page always shows the current version. We keep previous versions and will provide one on request.
19. Contact
Privacy and data requests: privacy@oplos.co
Safety concerns: safety@oplos.co
Everything else: support@oplos.co
By post:
Privacy Officer, Deodatum Inc.
205 Macdonnell Street
Kingston, Ontario, Canada