Privacy Policy
- Last Updated:
- August 28, 2026
- Effective Date:
- August 28, 2026
Privacy Policy
Last Updated: August 28, 2026 Effective Date: August 28, 2026
This Privacy Policy ("Privacy Policy") describes how My Opus, Inc. ("Opus," "Company," "we," "us," or "our") collects, uses, discloses, and otherwise processes information about you ("you," "your," or "User") in connection with the Opus services (collectively, the "Services"), as defined in our Terms of Use.
This Privacy Policy applies to information we collect through the Opus mobile application, the Opus website (including any subdomains), the Opus web application, our marketing site, and any other digital property that links to or references this Privacy Policy.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. Please review this Privacy Policy carefully. If you do not agree with our policies and practices, do not access or use the Services.
1. Scope and Application
This Privacy Policy applies to personal information we collect, use, or disclose in connection with the Services. It does not apply to information collected by third parties, including through any third-party websites or services that you access through the Services. Your use of any third-party services is governed by the privacy policies of those third parties.
For purposes of this Privacy Policy, "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as that term is further defined under applicable law.
Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in our Terms of Use. Without limitation, the following terms used in this Privacy Policy have the meanings set forth below or in our Terms of Use:
(a) "Outputs" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use, and refers generally to insights, interpretations, lessons, quests, summaries, recommendations, content, and other materials generated, produced, or delivered to you by or through the Services.
(b) "Services" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use.
(c) "subprocessor" means a third-party service provider that processes personal information on our behalf, as further described in Section 6.1 (Service Providers and Subprocessors).
(d) "User Content" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use.
(e) Other terms used in this Privacy Policy that have specific meanings under applicable privacy laws (such as "controller," "processor," "personal data," "sensitive personal information," "sale," and "share") have the meanings given to them under the applicable law in the jurisdiction in which you reside.
2. Information We Collect
We collect personal information from and about you in the following categories:
2.1 Information You Provide to Us
(a) Account Information: When you create, claim, or access an account, we collect information such as your email address, account identifiers, verification and session records, and any name or other profile information you choose to provide. Where required for a feature, we may also record eligibility attestations such as confirmation that you are at least eighteen years old and located in the United States. The current launch uses emailed verification or sign-in codes and does not require you to create a password. We do not currently offer third-party social-login methods in the launch configuration.
(b) Profile Information: Information you provide in connection with your user profile, such as display name, profile photo, time zone, language, and stated preferences.
(c) Onboarding and Assessment Inputs: Responses you provide during the onboarding process, including answers to questions used to determine your cognitive function profile (sometimes referred to as your "type") under the cognitive function model developed by John Beebe.
(d) User Content: Written responses, journal entries, reflections, goal statements, quest reports, and other content you submit to or through the Services.
(e) Communications: Information you provide when you contact us for support, submit a privacy request, respond to surveys, participate in user research, or otherwise communicate with us, including your contact information, account identifiers, the contents of your communication, attachments, and our responses. Please do not include sensitive personal information unless it is necessary for your request. Information you choose to send through a support channel is processed as a support communication and is not automatically treated as User Content submitted through an in-product feature. Support and chat-access reconsideration email may be processed and stored through Google Workspace, including a restricted Google Group accessible only to authorized Opus reviewers, as identified in our Subprocessor List.
(f) Payment Information: Paid features are not currently active in the launch configuration. Before paid processing begins, we will update this Privacy Policy and the applicable provider disclosures to describe the payment arrangement then in use. Opus does not intend to store full payment-card numbers on its own servers.
2.2 Information We Generate About You
(a) Type and Function Profile: Based on your onboarding inputs, we generate a personality type designation and an associated cognitive function stack used to personalize your experience. The type and function profile is exploratory and educational in nature and is not, and should not be relied upon as, a diagnostic assessment. The profile may be updated, refined, or revised from time to time as you provide additional inputs to the Services, as you complete additional assessments, or as our systems develop a more refined representation of your cognitive function preferences based on your interactions. We do not represent that any type designation or function profile is accurate, complete, definitive, or invariant, and you should not rely on it as such.
(b) Lessons, Quests, and Other Outputs: Outputs (as defined above) personalized to you based on your inputs and interactions.
(c) AI-Generated Representations of Your Inputs: To enable our memory and personalization systems, we generate mathematical representations (sometimes referred to as "embeddings") of your User Content. These representations allow our Services to retrieve relevant past content and tailor your experience over time. These representations are derived from your User Content and are treated as personal information.
(d) Inferences and Themes: Patterns, themes, key phrases, and inferences derived from your interactions with the Services and used to inform personalization, including importance scores and decay weights for memory retrieval.
(e) Progress and Engagement Data: Information about your progress through lessons, quests, and other features, including completion status, timestamps, and engagement metrics.
(f) Other Generated Information: Other information that we may generate from your use of the Services for the purposes described in Section 4 (How We Use Your Information), including without limitation analytics, security signals, and quality metrics.
2.3 Information We Collect Automatically
(a) Device and Technical Information: Device identifiers, device type, operating system, browser type and version, mobile network information, language settings, screen resolution, and similar technical information.
(b) Usage Data: Information about your use of the Services, including pages or screens viewed, features used, buttons clicked, time spent on the Services, dates and times of access, and referring URLs.
(c) Log Data: Server logs, including IP address, access times, error reports, performance data, and crash data.
(d) Location Information: We do not intentionally collect precise GPS or device-level location. We may derive approximate location from your IP address (e.g., country, region, or city) for service operation, security, and analytics purposes. Third-party services that you authorize separately (such as authentication providers, mapping services, or platform-level features that you enable) may collect more precise location information subject to their own privacy practices, and we encourage you to review those practices.
(e) Cookies and Similar Technologies: As described in Section 8 (Cookies and Tracking Technologies) and our Cookie Policy.
(f) Push Notification Tokens: Opus does not currently collect mobile or browser push-notification tokens in the launch configuration. If we introduce push notifications, we will update this Privacy Policy and our provider disclosures before beginning that processing.
(g) Other Automatically Collected Information: Additional technical, diagnostic, performance, and usage information that may be collected by us or by our service providers operating on our behalf in connection with your use of the Services.
2.4 Information from Third Parties
(a) Authentication Services: Our current launch uses Supabase for account authentication and session management and Opus-delivered email verification or sign-in codes. We receive the account and authentication information necessary to establish and maintain your session.
(b) Analytics Providers: We receive aggregated information about how Users interact with the Services from our analytics providers.
(c) Service Providers: Information provided to us by service providers we use to operate the Services.
2.5 Sensitive Information and Consumer Health Data
Opus is an educational typology and self-reflection service. It is not a healthcare provider and does not provide medical, psychiatric, psychological, therapeutic, diagnostic, crisis-response, or emergency services.
Information We Do Not Request
We do not request government identification numbers, financial-account credentials, full payment-card information, precise geolocation, biometric identifiers used to identify you, genetic information, or information about minors. Please do not submit this information through the Services.
Opus is intended only for adults aged eighteen or older. You should not submit sensitive information about a minor.
Sensitive Information You May Choose to Provide
Because Opus allows personal reflection and conversation, information you choose to provide may include or reveal sensitive personal information. Depending on the content and applicable law, this may include information concerning:
- physical or mental health, symptoms, diagnoses, disabilities, medications, or medical history;
- emotional distress, self-harm, suicidality, or immediate safety;
- relationship violence, abuse, coercion, or other traumatic experiences;
- religious or philosophical beliefs;
- racial or ethnic origin;
- sexual orientation, sex life, or gender identity;
- immigration or citizenship status; or
- other information treated as sensitive or protected under applicable U.S. law.
Opus may also generate limited inferences or automated routing signals from information you provide. For example, an automated safety system may determine that a message should receive fixed safety information or that access to chat should be paused. These signals are automated product-routing decisions. They are not diagnoses, medical records, clinical assessments, findings about your credibility, or evidence that you currently present a danger to yourself or anyone else.
HIPAA and Other Health-Privacy Laws
Opus does not currently provide the Services as a healthcare provider, health plan, healthcare clearinghouse, or business associate acting for one of those entities. The Services are not designed to receive or maintain protected health information on behalf of a HIPAA-covered entity.
This does not mean that health-related information you provide is non-sensitive or excluded from every health-privacy law. Information submitted to or generated by Opus may qualify as consumer health data, health information, or sensitive personal information under other applicable U.S. laws. Where such a law applies, Opus will process the information in accordance with that law and our applicable state consumer health data privacy policy, including our Washington Consumer Health Data Privacy Policy or Nevada Consumer Health Data Privacy Policy.
How We Use Sensitive Information
We process sensitive information only as reasonably necessary for the purposes described in this Privacy Policy, which may include:
(a) providing the feature or response you requested; (b) generating and personalizing educational Opus content; (c) operating the automated safety-routing system and displaying fixed, reviewed safety information; (d) enforcing a temporary or continuing restriction on chat access; (e) conducting a non-clinical product-access review when you request one; (f) receiving, authenticating, routing, and responding to support communications; (g) protecting the security and integrity of Opus and its users; (h) complying with applicable law; and (i) establishing, exercising, or defending legal claims.
An Opus product-access review determines only whether chat access will be restored. It is not a review of your safety, diagnosis, credibility, character, or fitness.
Opus will not use sensitive information contained in chat, a safety event, a reconsideration request, or an unsolicited support disclosure for targeted advertising, sale, model training, classifier evaluation, product research, or unrelated product improvement unless we provide a separate notice and obtain any affirmative permission required for that specific use.
Notice and Consent
Voluntarily submitting sensitive information does not give Opus unlimited permission to use that information for unrelated purposes. Where applicable law requires consent for a particular collection, use, or disclosure, Opus will present a separate notice and consent choice appropriate to that processing.
You may decline to provide sensitive information, although Opus may be unable to provide a feature that depends on the information you choose not to provide. Declining to share a conversation for a product-access review will not subject that review to a less favorable decision standard.
You may exercise applicable access, deletion, withdrawal, or other privacy rights as described in Section 13 and, where applicable, our applicable state consumer health data privacy policy, including our Washington Consumer Health Data Privacy Policy or Nevada Consumer Health Data Privacy Policy. Withdrawal or deletion does not reverse processing that lawfully occurred before the request. Information may also remain temporarily in restricted backups or service-provider security, abuse-prevention, or legally required records as described in Section 9 and the applicable notice.
Sensitive Information in Support Communications
Most support requests do not require sensitive information. Please avoid including crisis, medical, abuse, or other sensitive details unless they are necessary to explain your request.
If you voluntarily include sensitive information in a support communication, Opus will use it only as reasonably necessary to receive, authenticate, route, respond to, secure, retain, or delete the communication; comply with applicable law; or establish, exercise, or defend legal claims.
A support communication is not monitored continuously and cannot provide crisis support or emergency assistance. Sending sensitive information to support does not automatically enroll it in the formal chat-review process and does not authorize Opus to use it for model training, classifier evaluation, product research, or unrelated product improvement.
Information About Other People
You may provide ordinary relationship context when using Opus, but you should not submit another person's medical records, diagnoses, private communications, account credentials, or other sensitive information unless you are legally authorized to do so. Opus-generated descriptions of another person are educational interpretations, not verified facts or clinical assessments.
3. Sources of Information
We collect personal information from the following sources:
(a) Directly from you, when you create an account, complete onboarding, submit User Content, communicate with us, or otherwise interact with the Services;
(b) Automatically, when you access or use the Services, including through cookies, log files, and similar technologies;
(c) From service providers, including authentication, hosting, analytics, transactional-email, and other providers that operate on our behalf; and
(d) Generated by our systems, including AI-generated content, embeddings, inferences, and Outputs.
4. How We Use Your Information
We use the personal information we collect for the following purposes:
4.1 To Provide the Services
(a) Create and manage your account; (b) Authenticate you and authorize access to features; (c) Generate personalized lessons, quests, reflections, and other Outputs; (d) Maintain your profile, preferences, progress, and history; (e) Operate our memory and personalization systems, including AI-generated representations of your inputs; (f) Process payments (when applicable); (g) Send transactional and service-related communications, including notifications, updates, and security alerts; (h) Provide customer support and respond to your inquiries, including authenticating and routing requests, investigating reported issues, maintaining limited records of our response, and protecting the security and integrity of our support channels.
4.2 To Improve and Develop the Services
(a) Conduct internal research, testing, and analysis; (b) Develop new features, products, and services; (c) Refine, fine-tune, and improve our prompts, models, methodologies, and AI systems, as further described in Section 5 (How AI Processing Works at Opus); (d) Diagnose and resolve technical issues; (e) Conduct user research, usability testing, and surveys (with appropriate consent where required).
4.3 To Communicate with You
(a) Send you updates, newsletters, marketing communications, and information about features that may interest you, in accordance with Section 7 and your communication preferences; (b) Notify you about changes to the Services, this Privacy Policy, or our other terms; (c) Solicit feedback and conduct surveys.
4.4 To Maintain Safety, Security, and Integrity
(a) Verify accounts and activity; (b) Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms; (c) Enforce our Terms of Use and other policies; (d) Maintain the security and integrity of the Services and our systems.
4.5 To Comply with Legal Obligations
(a) Comply with applicable laws, regulations, court orders, subpoenas, and other legal processes; (b) Establish, exercise, or defend legal claims; (c) Cooperate with law enforcement and governmental authorities.
4.6 With Your Consent
We may use personal information for any other purpose for which you provide your consent.
4.7 Aggregated and De-Identified Data
We may aggregate, anonymize, or de-identify personal information so that it can no longer reasonably be used to identify you. We may use and disclose such aggregated or de-identified data for any lawful business purpose, including in perpetuity, without further notice to you.
4.8 Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the EU General Data Protection Regulation, UK GDPR, and Swiss Federal Act on Data Protection (as applicable):
(a) Performance of a Contract: To provide the Services you have requested and to fulfill our obligations under our Terms of Use; (b) Legitimate Interests: For our legitimate interests in operating, securing, and improving the Services, conducting research and analytics, marketing our services, and protecting our rights, where those interests are not overridden by your rights and freedoms; (c) Consent: For purposes for which we have obtained your consent (such as certain marketing communications and use of certain cookies), which you may withdraw at any time; (d) Legal Obligation: To comply with our legal obligations.
You have the right to object to processing based on legitimate interests, as further described in Section 15.
5. How AI Processing Works at Opus
Because Opus is an AI-powered service, we believe transparency about our AI practices is important. This Section describes, in plain terms, how we process your information using artificial intelligence.
5.1 How AI Generates Your Experience
When you submit User Content (such as a journal entry, onboarding response, or quest reflection), our systems may:
(a) transmit information needed for AI responses, analyses, and applicable automated chat classification to Anthropic through its commercial API path; (b) transmit onboarding-derived user-memory text to the OpenAI API to generate mathematical representations (embeddings) used for memory retrieval and personalization. This OpenAI embedding path is not used to process ordinary Opus chat or chat-safety content; (c) extract themes, key phrases, and inferences to inform personalization; (d) generate Outputs (such as lessons, quests, reflections, and insights) that are returned to you within the Services.
5.2 Personalized AI Learning
Our Services personalize your experience over time, including by adjusting Outputs and recommendations based on your User Content, your stated goals, your reported experiences, and your engagement patterns. This personalization is specific to your account.
5.3 Use of Aggregated Data to Improve the Services
We use aggregated, de-identified, or statistical data derived from User Content and interactions across all Users to evaluate, refine, and improve our prompts, our methodologies, our AI systems, and the Services generally. For example, we may analyze aggregated data to determine which prompts produce the most helpful Outputs, to identify common patterns of engagement, or to refine our content for particular cognitive function profiles.
5.4 No Sale of Personal Information for AI Training; Position on Third-Party Model Training
(a) We do not sell your personal information.
(b) We do not authorize our third-party AI service providers to use your User Content to train, fine-tune, or otherwise improve their general-purpose models. We use the providers' commercial/API services, under which customer API content is not used for general model training by default unless the customer separately opts in.
(c) We may use your User Content and Outputs to develop, refine, and improve Opus's own AI systems, prompts, and methodologies, as described in Section 5.3 (Use of Aggregated Data to Improve the Services).
5.5 AI Outputs Are Not Professional Advice
AI-generated Outputs are produced through probabilistic systems and may be inaccurate, incomplete, biased, or otherwise problematic. Outputs are provided for informational and self-reflection purposes only and are not professional, medical, psychological, therapeutic, financial, or legal advice. See Section 11 of our Terms of Use for important disclaimers.
5.6 No Solely Automated Decisions with Legal or Similarly Significant Effects
We do not use the Services to make solely automated decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of Article 22 of the GDPR.
5.7 Your Choices Regarding AI Processing
If you do not wish to have your information processed by our AI systems, you should not use the Services, as such processing is integral to the operation of the Services. You may delete your account at any time as described in Section 13.
5.8 Conversational Chat and Voluntary Submissions
Conversational chat messages are processed to generate responses but are not ordinarily retained by Opus as part of your account, converted into embeddings, or used for cross-session memory or personalization. Chat history remains locally available in your browser during the session.
If Opus restricts your access to chat and you choose the formal reconsideration process, you may voluntarily submit the relevant chat exchange, including both your messages and the corresponding Opus responses. Opus may retain and review that submitted exchange only for the purposes disclosed when you make the submission. The applicable notice will describe the review and retention terms. Submitting a support email that happens to quote or describe a chat does not enroll you in the formal reconsideration process or authorize Opus to retrieve browser-held chat history.
5.9 Generic Chat-Access State and Temporary Review Evidence
When Opus's automated safety systems apply a chat-access restriction, Opus creates a minimized, account-linked access-control record. The record contains only the identifiers and administrative metadata needed to apply and maintain the current state, such as the account identifier, generic access state, state date, content-free reference code, and applicable copy or state version. The life-of-account access-control record does not contain a safety category, route, user message, surrounding conversation, or Opus response.
Limited routing-category and event-linkage information, where created, is maintained separately as temporary review or short-audit evidence and is generalized or removed under the approved retention schedule. A transcript is stored only when the user affirmatively chooses review with the conversation. Review without the conversation does not collect a transcript.
The generic chat-access state may be retained for the life of the account because it keeps a restriction effective across sessions and supports access-related requests without reconstructing what the user disclosed. It is deleted from active systems with account deletion, subject to backup expiration, lawful exceptions, and legal holds. Temporary review evidence and any affirmatively submitted transcript remain subject to the shorter withdrawal, seven-day post-review, and forty-five-day maximum periods described below.
6. How We Share Your Information
We share personal information in the following circumstances:
6.1 Service Providers and Subprocessors
We share information with third-party service providers (also referred to as "subprocessors") that perform services on our behalf and that are contractually obligated to protect your information and to use it only for the purposes for which we engage them. We share information with subprocessors that fall within the following categories:
(a) Cloud Infrastructure, Database, Authentication, and Storage: providers that host application data, manage account authentication, and provide storage and access-control services;
(b) Web Hosting and Delivery: providers that host and deliver our web application and public website;
(c) Artificial Intelligence and Machine Learning: providers that supply large-language-model and embedding processing used to deliver and personalize the Services;
(d) Transactional Email and Communications: providers that deliver login, access, and other service-related email;
(e) Analytics and Product Telemetry: providers that help us understand how the Services are used and how they perform;
(f) Error Monitoring and Performance: providers that help us detect, diagnose, and resolve technical issues; and
(g) Customer Support Communications: providers that host restricted support and reconsideration email communications.
Our current providers in these categories are identified in the Subprocessor List. Providers for future payment, push-notification, social-login, SMS, mobile-distribution, or similar features are not treated as current subprocessors merely because Opus may consider or build those features later.
A current list of our specific subprocessors, the function each performs, and the location of processing is available at our Subprocessor List. We update the Subprocessor List from time to time as we engage, change, or discontinue subprocessors. By referring to the Subprocessor List rather than maintaining a list within this Privacy Policy, we are able to update our subprocessor relationships without requiring an amendment to this Privacy Policy. Material changes to subprocessors that affect categories of personal information shared will be reflected in updates to the Subprocessor List, and where we determine an update to be material, we will provide notice through the Services or by other reasonable means.
6.2 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, asset sale, or other similar transaction, your personal information may be transferred to or shared with the relevant third party as part of that transaction. We will notify you of any change in ownership or use of your personal information, as well as any choices you may have, by providing notice through the Services or by other appropriate means.
6.3 Legal Requirements and Protection of Rights
We may disclose personal information when we believe in good faith that disclosure is necessary to:
(a) comply with applicable laws, regulations, court orders, subpoenas, or other legal process; (b) respond to lawful requests from public authorities, including for national security or law enforcement purposes; (c) establish, exercise, or defend legal claims; (d) protect our rights, property, or safety, or the rights, property, or safety of our Users or others; (e) detect, prevent, or investigate fraud, security, or technical issues; or (f) enforce our Terms of Use or other agreements.
6.4 With Your Consent or at Your Direction
We may share personal information with third parties when you direct us to do so or with your consent.
6.5 Aggregated and De-Identified Information
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for any lawful business purpose, including with research partners, marketing partners, and the public.
6.6 No Sale or Sharing for Cross-Context Behavioral Advertising
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. We do not currently use advertising-related cookies or pixels (such as Meta Pixel or Google Ads conversion tracking) on the marketing site or within the Services. If we begin to use such technologies in the future, we will update this Privacy Policy and our Cookie Policy accordingly and will provide a "Do Not Sell or Share My Personal Information" or analogous opt-out mechanism to the extent required by applicable law.
6.7 Social, Community, and Comparison Features
Where the Services offer social, community, or comparison features (such as features that allow you to add another User to your network and to receive AI-generated comparisons of your respective type designations and cognitive function profiles), the use of those features involves sharing certain information between participating Users.
(a) Information shared by default: When you and another User both elect to participate in a comparison or community feature, certain information about each of you (which may include, depending on the feature, your display name or chosen identifier, your type designation, and aggregated or generalized analyses generated by our AI Systems) will be made available to the other.
(b) Information shared only with your express consent: We will not share specific examples drawn from your User Content (such as quotations or summaries of your journal entries or reflections) with another User unless you have provided your express consent for such sharing for that purpose. Absent your express consent, AI-generated comparisons are limited to generalized observations based on type designation alone.
(c) Your role as a participant: By choosing to participate in a social, community, or comparison feature with another User, you authorize us to share the categories of information described in subsections (a) and (b) above with that other User in accordance with the feature's design and your consent. You may withdraw from any social, community, or comparison feature at any time, in which case we will discontinue further sharing on a prospective basis (although we cannot retract information already shared with another User).
(d) Information you provide about other individuals: If you provide information about other individuals (for example, the name of a friend or family member you wish to discuss in your reflections), you represent that you have the right to provide that information and that providing it does not violate the rights or expectations of those individuals. You should not provide information about other individuals that is sensitive, that those individuals would reasonably expect to remain private, or that you are not authorized to share.
7. Marketing Communications
7.1 Email Newsletters and Marketing
We may send you marketing communications by email, including newsletters, content about cognition, cognitive functions, the writings of Carl Jung, product updates, and promotional offers. You may opt in to receive these communications when you create an account, subscribe to our mailing list, or otherwise provide your information to us.
7.2 Text Messages
We may, from time to time and only with your prior express consent (and, where required for marketing messages, your prior express written consent in accordance with the U.S. Telephone Consumer Protection Act, 47 U.S.C. § 227, and the implementing regulations of the Federal Communications Commission), send you text messages, including (a) transactional messages (such as account verification codes, security alerts, and other service-related notices) where you have provided a mobile telephone number for such purposes; and (b) marketing messages where you have separately opted in to receive marketing text messages.
If you have opted in to receive marketing text messages, you may opt out at any time by replying "STOP" (or such other keyword as we may indicate) to any marketing text message, or by contacting us at the address in Section 19 (Contact Us). Even after opting out of marketing messages, we may continue to send you transactional messages as necessary to operate the Services. Message and data rates may apply. Message frequency varies. We will not sell or share mobile telephone numbers collected for the purpose of receiving messages with third parties for their independent marketing purposes.
7.3 Your Choices
You can unsubscribe from marketing emails at any time by:
(a) clicking the "unsubscribe" link in any marketing email; (b) updating your communication preferences in your account settings; or (c) contacting us at the address in Section 19 (Contact Us).
You can opt out of marketing text messages by following the instructions in Section 7.2 (Text Messages).
Even if you opt out of marketing communications, we may still send you transactional and service-related communications, such as account notifications, security alerts, and updates to this Privacy Policy or our Terms.
7.4 Social Media
We maintain accounts on social media platforms and may share content, including educational material about cognitive functions, on those platforms. Your interactions with our social media presence are governed by the privacy policies of the applicable platforms. We may receive aggregated information about engagement with our social media content from those platforms.
7.5 Push Notifications
If you have opted in to push notifications on your mobile device or to web/browser-based push notifications, you may opt out at any time through your device or browser settings or, where available, through your account settings within the Services.
8. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, software development kits, and similar tracking technologies on the Services. For more information about the specific technologies we use and your choices regarding them, please refer to our Cookie Policy.
You can also control cookies through your browser settings. Please note that disabling certain cookies may limit your ability to use certain features of the Services.
9. Data Retention and Account Lifecycle
9.1 General Retention Principles
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The criteria we use to determine retention periods include:
(a) the duration of your relationship with us and your use of the Services;
(b) whether retention is required to comply with a legal obligation, regulatory requirement, contractual commitment, or to defend against legal claims;
(c) whether retention is advisable in light of our legal position (such as in connection with applicable statutes of limitations, litigation, or regulatory investigations).
9.2 Retention Schedule
| Category of Information | Retention Period |
|---|---|
| Account information | While the account remains active and as otherwise necessary for the purposes described in this Policy. Following a valid deletion request, deleted or de-identified as required by applicable law, subject to limited lawful exceptions and temporary restricted backup or provider-retention copies described in Section 9.3. |
| User Content (journal entries, reflections, etc.) | Same as Account information |
| Generated Outputs | Same as Account information |
| Embeddings and AI-generated representations | Same as Account information |
| Type assessment history | Same as Account information |
| Generic account-linked chat-access state | Life of the account; contains no safety category, route, or chat content; deleted from active systems with account deletion, subject to backup expiration, lawful exceptions, and legal holds |
| Ordinary support communications | Generally up to 12 months. Unsolicited sensitive information that is not needed for the request is targeted for deletion or redaction on a shorter schedule, generally within 30 days after it is identified as unnecessary. |
| Chat-access reconsideration email | Generally deleted 7 days after a final decision, or within 30 days if no decision is reached, subject to lawful security, legal-hold, or provider-retention exceptions. |
| Formal reconsideration conversation submission | If withdrawn before review, the submitted conversation is deleted and not reviewed. Otherwise it is retained only for the review purpose, generally 7 days after the review decision and no longer than 45 days while a decision remains pending, subject to lawful exceptions. |
| Payment records (when applicable) | 7 years (to comply with tax and accounting laws) |
| Technical logs (IP, device data, etc.) | Up to 18 months |
| Analytics data (de-identified or aggregated) | Indefinitely |
| Aggregated and de-identified data | Indefinitely |
| Backup and provider recovery copies | Deleted information may remain temporarily in restricted backup, security, or recovery systems until the applicable provider rotation or retention cycle expires. Such copies are not restored to ordinary active use after deletion. Where a specific law imposes a maximum backup-deletion period, we comply with that requirement. |
| User research data (interviews, surveys, usability sessions) | As specified in the applicable research consent or participation agreement; aggregated, de-identified, or summary findings may be retained indefinitely |
| Recordings of user research sessions | As specified in the applicable recording consent; if no consent specifies otherwise, deleted within 24 months following the session unless retained as part of a study record |
Beta and User Research Data. Information you provide in connection with beta participation, user research interviews, surveys, and similar activities (collectively, "Research Data") may be retained outside of your account record and aggregated with information from other research participants. Research Data, including responses to surveys and interview transcripts, may be retained for a period specified in the applicable consent form or research participation agreement. We may retain aggregated, de-identified, or summary findings derived from Research Data indefinitely for the purposes described in Section 4 (How We Use Your Information). Where Research Data has been included in a research study or publication, we may retain it for the purpose of preserving the integrity of that study or publication.
9.3 Account Deletion and Privacy Requests
The current launch does not rely on a separate recoverable account-deactivation period or promise an in-product deletion control that has not yet been built.
You may request deletion of your account or personal information at any time by emailing privacy@opuswithin.com with the subject line Privacy Rights Request. We may take reasonable steps to verify that the request relates to your account before acting on it.
When a valid deletion request applies, Opus will delete or de-identify personal information from active systems as required by applicable law and will direct applicable service providers to do the same. We may retain limited information where permitted or required for security, fraud prevention, legal compliance, legal claims, or records of the privacy request itself.
Deleted information may remain temporarily in restricted backup, recovery, security, or legally required provider records until the applicable retention cycle expires. Those copies are not restored to ordinary active use after deletion.
Different statutory timelines apply depending on the law governing a request. Opus responds and completes required actions within the periods required by the applicable law. Additional consumer-health-data deletion rules are described in the applicable Washington or Nevada consumer health data privacy policy.
9.4 Support Communications and Reconsideration Records
We retain support communications only for as long as reasonably necessary to respond to the request, maintain appropriate business and security records, comply with law, and establish, exercise, or defend legal claims. Retention may vary depending on the nature of the request. We seek to delete or redact unsolicited sensitive information that is not needed for the support request on a shorter schedule. Information retained in secure backups or service-provider systems may remain until the applicable provider deletion or backup cycle expires and will not be restored for ordinary use after deletion.
Messages sent to chat-access@opuswithin.com are stored in a restricted Google Workspace group rather than routinely delivered as full copies to individual reviewer inboxes. Access is limited to authorized Opus reviewers. Opus applies the active-system deletion and redaction schedule described in its Support Communications Policy, uses available provider deletion controls, and discloses that limited provider copies may remain temporarily under provider backup, security, legal, or retention processes.
Chat exchanges voluntarily submitted through the formal in-product reconsideration process are retained under the separate period disclosed at the time of submission. Chat content sent through email or ordinary support without using that process remains a support record and is not copied into the reconsideration system unless you separately agree.
10. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, and destruction. These safeguards include:
(a) encryption of personal information in transit using industry-standard transport layer security (TLS); (b) encryption of personal information at rest in our databases and storage systems; (c) access controls and authentication requirements (including multi-factor authentication for personnel with access to sensitive systems); (d) least-privilege access policies and regular access reviews; (e) logging and monitoring of system access and activity; (f) employee and contractor security training; (g) vendor security review processes; and (h) incident response procedures.
Despite our efforts, no security measure is perfect, and we cannot guarantee the absolute security of your personal information. You are responsible for safeguarding your account credentials and for promptly notifying us if you suspect unauthorized use of your account.
11. Security Incident Notification
In the event of a security incident affecting your personal information, we will notify you and applicable regulators in accordance with the requirements of applicable law, including the breach notification provisions of state privacy and data breach laws and Articles 33 and 34 of the GDPR (where applicable). Notifications will be made without undue delay following our determination that a notifiable incident has occurred.
12. International Data Transfers
The Services are operated from the United States and are currently available only to residents of the fifty (50) United States and the District of Columbia, as described in Section 2.3 (Geographic Availability) of our Terms of Use. The Public Pages (such as our marketing website and blog) remain accessible globally; however, we do not currently offer the account-required features of the Services to residents of jurisdictions outside the United States.
Even within the United States, your personal information will be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate. The data protection laws of these jurisdictions may differ from those of your state of residence and may provide a different level of protection.
The provisions of Section 15 (European Economic Area, United Kingdom, and Switzerland Rights) and the international-transfer mechanisms described therein (including the European Commission's Standard Contractual Clauses and the UK Addendum thereto) apply to international transfers of personal information of residents of the European Economic Area, the United Kingdom, or Switzerland. While such transfers do not occur in the ordinary course during the period of US-only availability, we have included those provisions in this Privacy Policy to describe our practices upon expansion of the Services to additional jurisdictions, and to provide transparency to visitors to our Public Pages who reside in those jurisdictions.
13. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights with respect to your personal information. We honor verifiable requests in accordance with applicable law. Common rights include:
(a) Right to Access: The right to request access to and a copy of the personal information we hold about you; (b) Right to Correct: The right to request correction of inaccurate or incomplete personal information; (c) Right to Delete: The right to request deletion of your personal information, subject to applicable exceptions. You may submit a deletion request as described in Section 13.1 (How to Exercise Your Rights). Opus handles valid deletion requests as described in Section 9.3 (Account Deletion and Privacy Requests) and within the timelines required by applicable law; (d) Right to Opt Out of Sale or Sharing: The right to opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); (e) Right to Limit Use of Sensitive Personal Information: The right to limit our use of sensitive personal information to that which is necessary to provide the Services; (f) Right to Data Portability: The right to receive your personal information in a portable format; (g) Right to Withdraw Consent: The right to withdraw any consent you have provided; (h) Right to Non-Discrimination: The right not to be discriminated against for exercising your privacy rights.
13.1 How to Exercise Your Rights
You may exercise your rights by:
(a) emailing us at privacy@opuswithin.com with the subject line "Privacy Rights Request"; or (b) using another privacy-request method that we expressly make available in the Services in the future.
13.2 Verification
We will take reasonable steps to verify your identity before responding to your request, which may include asking you to confirm information associated with your account. We may require additional verification for sensitive requests (such as deletion).
13.3 Response Time
We will respond to verifiable requests within the time periods required by applicable law. Under most U.S. state privacy laws, we will respond within 45 days, with the possibility of a 45-day extension where reasonably necessary. Under GDPR and UK GDPR, we will respond within one (1) month, with the possibility of a two (2) month extension where reasonably necessary.
13.4 Authorized Agents
You may designate an authorized agent to make a request on your behalf. We will require written documentation of the agent's authority and may require additional verification of your identity.
13.5 Appeals
If we deny your request, you may appeal our decision by contacting us at privacy@opuswithin.com with the subject line "Privacy Rights Appeal." We will respond to your appeal within the time period required by applicable law.
14. United States State Privacy Rights
This Section applies to residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Utah, Virginia, and other states with similar laws as they come into effect.
14.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the rights described in Section 13 under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and additional rights described below.
14.1.1 Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information, as defined in the CCPA/CPRA:
| CCPA/CPRA Category | Examples | Sources | Business Purposes | Categories of Recipients |
|---|---|---|---|---|
| Identifiers | Name, email, account ID, IP address, device identifiers | You; automatic collection; auth providers | Provide Services; security; communications | Service providers (Sec. 6.1) |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email, payment information | You | Provide Services; payments | Service providers; payment processors |
| Internet/network activity | Usage data, log data, device data | Automatic collection | Provide Services; analytics; security | Service providers; analytics providers |
| Geolocation (approximate) | IP-derived approximate location | Automatic collection | Service operation; security | Service providers |
| Inferences | Type designation; cognitive function profile; themes; embeddings | Generated by us | Personalization; Service operation | Service providers |
| Audio/visual (if any) | Profile photo (if uploaded) | You | Profile display | Service providers |
| Other personal information | User Content (journal entries, reflections) | You | Provide Services; personalization | Service providers (including AI processors) |
14.1.2 Sensitive Personal Information
We do not collect sensitive personal information (as defined under CCPA/CPRA) for the purpose of inferring characteristics about you. Where User Content may contain information that could be characterized as sensitive (such as voluntarily disclosed health, religious, or political information), we use it solely to provide the Services you have requested and not for purposes that would require notice and a right to limit under CCPA/CPRA § 1798.121.
14.1.3 No Sale or Sharing
We do not sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under the age of 16.
14.1.4 Retention
We retain personal information in accordance with the retention schedule in Section 9.
14.1.5 Shine the Light
California Civil Code § 1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
14.2 Utah Residents (UCPA)
If you are a Utah resident, you have the rights described in Section 13 under the Utah Consumer Privacy Act ("UCPA"), including the rights to confirm processing, access, delete, and obtain a portable copy of your personal data, and to opt out of the sale of personal data and the processing of personal data for targeted advertising. We do not engage in the sale of personal data or targeted advertising as defined under UCPA.
14.3 Colorado, Connecticut, and Virginia Residents
If you are a resident of Colorado, Connecticut, or Virginia, you have the rights described in Section 13 under the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Virginia Consumer Data Protection Act, respectively, including the rights to access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal data, and the right to appeal any denial of a privacy rights request.
14.4 Other U.S. States
Residents of other U.S. states with comprehensive privacy laws (including, as those laws come into effect, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and others) may have similar rights, which we will honor to the extent required by applicable law.
15. European Economic Area, United Kingdom, and Switzerland Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following additional information applies:
15.1 Controller
The controller of your personal information is My Opus, Inc., contactable at the addresses in Section 19.
15.2 Legal Bases
We process personal information on the legal bases set forth in Section 4.8.
15.3 Your Rights
In addition to the rights described in Section 13, you have the right to:
(a) lodge a complaint with a supervisory authority in the country of your habitual residence, place of work, or place of an alleged infringement; (b) object to processing based on our legitimate interests, including for direct marketing purposes; (c) request information about the safeguards we use for international data transfers.
15.4 EU/UK Supervisory Authorities
You can find a list of EU supervisory authorities at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK supervisory authority is the Information Commissioner's Office (https://ico.org.uk). The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch).
15.5 EU/UK Representative
We have not yet designated an EU or UK representative. We will appoint one and update this Privacy Policy before making the Services available to users in the EU or UK.
16. Children's Privacy
The Services are intended for users who are at least eighteen (18) years of age. We do not knowingly collect personal information from individuals under eighteen (18). If you are under eighteen (18), please do not access or use the Services or provide any personal information.
If we learn that we have collected personal information from an individual under eighteen (18), we will delete that information promptly. If you believe that an individual under eighteen (18) has provided personal information to us, please contact us at the address in Section 19 (Contact Us).
We comply with the Children's Online Privacy Protection Act ("COPPA") and applicable state laws regarding the privacy of minors.
17. Third-Party Links and Services
The Services may contain links to or integrations with third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to such third-party services. We are not responsible for the content, privacy practices, or terms of any third-party services, and we recommend that you review the privacy policies of any third-party services you use.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email, by posting a notice within the Services, or by other reasonable means at least thirty (30) days before the changes take effect, except where applicable law requires more immediate notice. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised.
19. Contact Us
Opus support channels are not monitored continuously and cannot provide emergency or crisis assistance. Do not use email or a support form if you or another person may be in immediate danger. Contact emergency services or an appropriate crisis resource. Please do not include sensitive personal information unless it is necessary for your request.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
My Opus, Inc. Attention: Privacy Email: privacy@opuswithin.com General Legal: legal@opuswithin.com
This Privacy Policy is © My Opus, Inc. All rights reserved.