Privacy Policy
- Last Updated:
- July 18, 2026
- Effective Date:
- July 18, 2026
Privacy Policy
Last Updated: July 18, 2026 Effective Date: July 18, 2026
This Privacy Policy ("Privacy Policy") describes how My Opus, Inc. ("Opus," "Company," "we," "us," or "our") collects, uses, discloses, and otherwise processes information about you ("you," "your," or "User") in connection with the Opus services (collectively, the "Services"), as defined in our Terms of Use.
This Privacy Policy applies to information we collect through the Opus mobile application, the Opus website (including any subdomains), the Opus web application, our marketing site, and any other digital property that links to or references this Privacy Policy.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. Please review this Privacy Policy carefully. If you do not agree with our policies and practices, do not access or use the Services.
1. Scope and Application
This Privacy Policy applies to personal information we collect, use, or disclose in connection with the Services. It does not apply to information collected by third parties, including through any third-party websites or services that you access through the Services. Your use of any third-party services is governed by the privacy policies of those third parties.
For purposes of this Privacy Policy, "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as that term is further defined under applicable law.
Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in our Terms of Use. Without limitation, the following terms used in this Privacy Policy have the meanings set forth below or in our Terms of Use:
(a) "Outputs" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use, and refers generally to insights, interpretations, lessons, quests, summaries, recommendations, content, and other materials generated, produced, or delivered to you by or through the Services.
(b) "Services" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use.
(c) "subprocessor" means a third-party service provider that processes personal information on our behalf, as further described in Section 6.1 (Service Providers and Subprocessors).
(d) "User Content" has the meaning set forth in Section 1.2 (Definitions) of our Terms of Use.
(e) Other terms used in this Privacy Policy that have specific meanings under applicable privacy laws (such as "controller," "processor," "personal data," "sensitive personal information," "sale," and "share") have the meanings given to them under the applicable law in the jurisdiction in which you reside.
2. Information We Collect
We collect personal information from and about you in the following categories:
2.1 Information You Provide to Us
(a) Account Information: When you create an account or update your account, we collect information such as your name, email address, password (in hashed form), date of birth (for age verification), authentication credentials, and (where you provide them) other contact details such as mailing address and phone number that you choose to provide for purposes such as receiving marketing communications, account verification, or transactional notifications. If you sign in using a third-party authentication provider (such as Apple, Google, or another social login), we receive certain information from that provider in accordance with your authorization. We may, from time to time, request additional account information that we determine, in our reasonable judgment, is necessary to provide, secure, or improve the Services.
(b) Profile Information: Information you provide in connection with your user profile, such as display name, profile photo, time zone, language, and stated preferences.
(c) Onboarding and Assessment Inputs: Responses you provide during the onboarding process, including answers to questions used to determine your cognitive function profile (sometimes referred to as your "type") under the cognitive function model developed by John Beebe.
(d) User Content: Written responses, journal entries, reflections, goal statements, quest reports, and other content you submit to or through the Services.
(e) Communications: Information you provide when you contact us for support, respond to surveys, participate in user research, or otherwise communicate with us, including the content of your communications.
(f) Payment Information: If and when paid features become available, payment information will be collected and processed by our third-party payment processors (such as Apple, Google, or Stripe). We do not store full payment card numbers on our servers.
2.2 Information We Generate About You
(a) Type and Function Profile: Based on your onboarding inputs, we generate a personality type designation and an associated cognitive function stack used to personalize your experience. The type and function profile is exploratory and educational in nature and is not, and should not be relied upon as, a diagnostic assessment. The profile may be updated, refined, or revised from time to time as you provide additional inputs to the Services, as you complete additional assessments, or as our systems develop a more refined representation of your cognitive function preferences based on your interactions. We do not represent that any type designation or function profile is accurate, complete, definitive, or invariant, and you should not rely on it as such.
(b) Lessons, Quests, and Other Outputs: Outputs (as defined above) personalized to you based on your inputs and interactions.
(c) AI-Generated Representations of Your Inputs: To enable our memory and personalization systems, we generate mathematical representations (sometimes referred to as "embeddings") of your User Content. These representations allow our Services to retrieve relevant past content and tailor your experience over time. These representations are derived from your User Content and are treated as personal information.
(d) Inferences and Themes: Patterns, themes, key phrases, and inferences derived from your interactions with the Services and used to inform personalization, including importance scores and decay weights for memory retrieval.
(e) Progress and Engagement Data: Information about your progress through lessons, quests, and other features, including completion status, timestamps, and engagement metrics.
(f) Other Generated Information: Other information that we may generate from your use of the Services for the purposes described in Section 4 (How We Use Your Information), including without limitation analytics, security signals, and quality metrics.
2.3 Information We Collect Automatically
(a) Device and Technical Information: Device identifiers, device type, operating system, browser type and version, mobile network information, language settings, screen resolution, and similar technical information.
(b) Usage Data: Information about your use of the Services, including pages or screens viewed, features used, buttons clicked, time spent on the Services, dates and times of access, and referring URLs.
(c) Log Data: Server logs, including IP address, access times, error reports, performance data, and crash data.
(d) Location Information: We do not intentionally collect precise GPS or device-level location. We may derive approximate location from your IP address (e.g., country, region, or city) for service operation, security, and analytics purposes. Third-party services that you authorize separately (such as authentication providers, mapping services, or platform-level features that you enable) may collect more precise location information subject to their own privacy practices, and we encourage you to review those practices.
(e) Cookies and Similar Technologies: As described in Section 8 (Cookies and Tracking Technologies) and our Cookie Policy.
(f) Push Notification Tokens: If you enable push notifications, we collect device tokens or browser registration information from your platform's push notification service (such as the Apple Push Notification service, Firebase Cloud Messaging, or browser-based Web Push) for the purpose of delivering notifications to you.
(g) Other Automatically Collected Information: Additional technical, diagnostic, performance, and usage information that may be collected by us or by our service providers operating on our behalf in connection with your use of the Services.
2.4 Information from Third Parties
(a) Authentication Providers: When you sign in via a third-party identity provider, we receive basic profile information (such as name and email) in accordance with your authorization to that provider.
(b) Analytics Providers: We receive aggregated information about how Users interact with the Services from our analytics providers.
(c) Service Providers: Information provided to us by service providers we use to operate the Services.
2.5 Sensitive Information
We do not request, and do not intend to use the Services to systematically collect, the following categories of sensitive personal information: (a) Social Security numbers, driver's license numbers, or other government-issued identification numbers; (b) financial account numbers or payment card credentials (other than as collected by our payment processors); (c) precise geolocation; (d) genetic or biometric data used for the purpose of uniquely identifying an individual; (e) information regarding sexual orientation; (f) information regarding citizenship or immigration status; (g) information about minors; or (h) information about racial or ethnic origin, trade union membership, or political opinions.
We may, in connection with onboarding and the operation of the Services, ask questions about general life circumstances and personal context (such as your relationship status, family relationships, life goals, or self-described personal experiences). These questions are intended to provide context for personalized coaching content and are not designed to elicit special-category data. You should not interpret a question as a request for any particular sensitive category of information, and you should not provide information you are not comfortable sharing.
You acknowledge that User Content you voluntarily submit (such as journal entries, reflections, or quest reports) may, at your option, contain information that could be characterized as sensitive personal information under applicable law, including (without limitation) information revealing religious or philosophical beliefs, health-related information, or information about your sex life or sexual orientation. By voluntarily submitting such information through the Services, you understand that it will be processed as User Content in accordance with this Privacy Policy and our Terms of Use, and, where applicable, you provide your explicit consent under Article 9(2)(a) of the EU General Data Protection Regulation, the analogous provisions of the UK GDPR and the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws (including, without limitation, the California Consumer Privacy Act, as amended) to such processing. You may withdraw such consent at any time by deleting the relevant User Content or your account, although withdrawal will not affect the lawfulness of processing prior to withdrawal. Any sensitive personal information voluntarily included in User Content will be subject to the same protections as other personal information described in this Privacy Policy and will not be used for purposes of inferring characteristics about you that would trigger additional notice or limit-of-use requirements under California Civil Code § 1798.121.
If you choose to include such information in User Content, you do so at your own risk and you authorize us to process it as described in this Privacy Policy.
Position on Health Data and Special Category Data. Opus is a non-clinical coaching application that draws on the writings of Carl Jung and the cognitive function model developed by John Beebe. Opus does not provide medical, psychiatric, psychological, or therapeutic services and does not employ licensed mental health professionals to deliver such services through the Services. The personality-type designations, cognitive function profiles, and related inferences generated by the Services are not "protected health information" under the Health Insurance Portability and Accountability Act ("HIPAA"), are not "personal health record identifiable health information" under the FTC Health Breach Notification Rule, and are not "data concerning health" within the meaning of Article 4(15) of the GDPR. They are educational and self-reflective in nature.
You should not submit through the Services any information about other individuals (other than information about your own personal relationships, where you provide context for your own coaching experience) without their authorization, and you are solely responsible for ensuring that any such information you choose to include is shared lawfully.
3. Sources of Information
We collect personal information from the following sources:
(a) Directly from you, when you create an account, complete onboarding, submit User Content, communicate with us, or otherwise interact with the Services;
(b) Automatically, when you access or use the Services, including through cookies, log files, and similar technologies;
(c) From third parties, including authentication providers, analytics providers, payment processors, and other service providers; and
(d) Generated by our systems, including AI-generated content, embeddings, inferences, and Outputs.
4. How We Use Your Information
We use the personal information we collect for the following purposes:
4.1 To Provide the Services
(a) Create and manage your account; (b) Authenticate you and authorize access to features; (c) Generate personalized lessons, quests, reflections, and other Outputs; (d) Maintain your profile, preferences, progress, and history; (e) Operate our memory and personalization systems, including AI-generated representations of your inputs; (f) Process payments (when applicable); (g) Send transactional and service-related communications, including notifications, updates, and security alerts; (h) Provide customer support and respond to your inquiries.
4.2 To Improve and Develop the Services
(a) Conduct internal research, testing, and analysis; (b) Develop new features, products, and services; (c) Refine, fine-tune, and improve our prompts, models, methodologies, and AI systems, as further described in Section 5 (How AI Processing Works at Opus); (d) Diagnose and resolve technical issues; (e) Conduct user research, usability testing, and surveys (with appropriate consent where required).
4.3 To Communicate with You
(a) Send you updates, newsletters, marketing communications, and information about features that may interest you, in accordance with Section 7 and your communication preferences; (b) Notify you about changes to the Services, this Privacy Policy, or our other terms; (c) Solicit feedback and conduct surveys.
4.4 To Maintain Safety, Security, and Integrity
(a) Verify accounts and activity; (b) Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms; (c) Enforce our Terms of Use and other policies; (d) Maintain the security and integrity of the Services and our systems.
4.5 To Comply with Legal Obligations
(a) Comply with applicable laws, regulations, court orders, subpoenas, and other legal processes; (b) Establish, exercise, or defend legal claims; (c) Cooperate with law enforcement and governmental authorities.
4.6 With Your Consent
We may use personal information for any other purpose for which you provide your consent.
4.7 Aggregated and De-Identified Data
We may aggregate, anonymize, or de-identify personal information so that it can no longer reasonably be used to identify you. We may use and disclose such aggregated or de-identified data for any lawful business purpose, including in perpetuity, without further notice to you.
4.8 Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the EU General Data Protection Regulation, UK GDPR, and Swiss Federal Act on Data Protection (as applicable):
(a) Performance of a Contract: To provide the Services you have requested and to fulfill our obligations under our Terms of Use; (b) Legitimate Interests: For our legitimate interests in operating, securing, and improving the Services, conducting research and analytics, marketing our services, and protecting our rights, where those interests are not overridden by your rights and freedoms; (c) Consent: For purposes for which we have obtained your consent (such as certain marketing communications and use of certain cookies), which you may withdraw at any time; (d) Legal Obligation: To comply with our legal obligations.
You have the right to object to processing based on legitimate interests, as further described in Section 15.
5. How AI Processing Works at Opus
Because Opus is an AI-powered service, we believe transparency about our AI practices is important. This Section describes, in plain terms, how we process your information using artificial intelligence.
5.1 How AI Generates Your Experience
When you submit User Content (such as a journal entry, onboarding response, or quest reflection), our systems may:
(a) transmit your input to third-party AI service providers (currently including Anthropic and OpenAI) under contractual confidentiality and data processing obligations, for the purpose of generating responses or analyses; (b) generate mathematical representations (embeddings) of your input to enable our memory and retrieval systems to identify thematically related past content and personalize future Outputs; (c) extract themes, key phrases, and inferences to inform personalization; (d) generate Outputs (such as lessons, quests, reflections, and insights) that are returned to you within the Services.
5.2 Personalized AI Learning
Our Services personalize your experience over time, including by adjusting Outputs and recommendations based on your User Content, your stated goals, your reported experiences, and your engagement patterns. This personalization is specific to your account.
5.3 Use of Aggregated Data to Improve the Services
We use aggregated, de-identified, or statistical data derived from User Content and interactions across all Users to evaluate, refine, and improve our prompts, our methodologies, our AI systems, and the Services generally. For example, we may analyze aggregated data to determine which prompts produce the most helpful Outputs, to identify common patterns of engagement, or to refine our content for particular cognitive function profiles.
5.4 No Sale of Personal Information for AI Training; Position on Third-Party Model Training
(a) We do not sell your personal information.
(b) We do not authorize our third-party AI service providers to use your User Content to train, fine-tune, or otherwise improve their general-purpose models. Our agreements with such providers contractually restrict such use, consistent with their published enterprise data policies.
(c) We may use your User Content and Outputs to develop, refine, and improve Opus's own AI systems, prompts, and methodologies, as described in Section 5.3 (Use of Aggregated Data to Improve the Services).
5.5 AI Outputs Are Not Professional Advice
AI-generated Outputs are produced through probabilistic systems and may be inaccurate, incomplete, biased, or otherwise problematic. Outputs are provided for informational and self-reflection purposes only and are not professional, medical, psychological, therapeutic, financial, or legal advice. See Section 11 of our Terms of Use for important disclaimers.
5.6 No Solely Automated Decisions with Legal or Similarly Significant Effects
We do not use the Services to make solely automated decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of Article 22 of the GDPR.
5.7 Your Choices Regarding AI Processing
If you do not wish to have your information processed by our AI systems, you should not use the Services, as such processing is integral to the operation of the Services. You may delete your account at any time as described in Section 13.
6. How We Share Your Information
We share personal information in the following circumstances:
6.1 Service Providers and Subprocessors
We share information with third-party service providers (also referred to as "subprocessors") that perform services on our behalf and that are contractually obligated to protect your information and to use it only for the purposes for which we engage them. We share information with subprocessors that fall within the following categories:
(a) Cloud Infrastructure, Database, and Storage: providers that host our applications and data and provide authentication and storage services;
(b) Artificial Intelligence and Machine Learning: providers that supply large language model, embedding, and related AI processing services that we use to deliver and personalize the Services;
(c) Mobile Application Distribution and Build Services: providers that support the building, distribution, and over-the-air updating of our mobile applications;
(d) Push Notification, Messaging, and Communications: providers that enable us to deliver push notifications, transactional emails, and (where applicable and where you have provided express consent) text messages;
(e) Analytics and Product Telemetry: providers that help us understand how the Services are used and how they perform;
(f) Error Monitoring and Performance: providers that help us detect, diagnose, and resolve technical issues;
(g) Customer Support: providers that help us provide support to you and respond to your inquiries;
(h) Payment Processing: providers that process payments when paid features become available;
(i) Authentication and Identity: providers (including Apple, Google, and similar identity providers) that authenticate you to the Services if you choose to use such methods;
(j) Security and Fraud Prevention: providers that help us protect the integrity and security of the Services and detect, prevent, and respond to fraud and abuse;
(k) Legal, Compliance, and Audit: outside counsel, accountants, auditors, and other professional advisors;
(l) Other Service Providers: other vendors and contractors performing services on our behalf in connection with the operation of the Services.
A current list of our specific subprocessors, the function each performs, and the location of processing is available at our Subprocessor List. We update the Subprocessor List from time to time as we engage, change, or discontinue subprocessors. By referring to the Subprocessor List rather than maintaining a list within this Privacy Policy, we are able to update our subprocessor relationships without requiring an amendment to this Privacy Policy. Material changes to subprocessors that affect categories of personal information shared will be reflected in updates to the Subprocessor List, and where we determine an update to be material, we will provide notice through the Services or by other reasonable means.
6.2 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, asset sale, or other similar transaction, your personal information may be transferred to or shared with the relevant third party as part of that transaction. We will notify you of any change in ownership or use of your personal information, as well as any choices you may have, by providing notice through the Services or by other appropriate means.
6.3 Legal Requirements and Protection of Rights
We may disclose personal information when we believe in good faith that disclosure is necessary to:
(a) comply with applicable laws, regulations, court orders, subpoenas, or other legal process; (b) respond to lawful requests from public authorities, including for national security or law enforcement purposes; (c) establish, exercise, or defend legal claims; (d) protect our rights, property, or safety, or the rights, property, or safety of our Users or others; (e) detect, prevent, or investigate fraud, security, or technical issues; or (f) enforce our Terms of Use or other agreements.
6.4 With Your Consent or at Your Direction
We may share personal information with third parties when you direct us to do so or with your consent.
6.5 Aggregated and De-Identified Information
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for any lawful business purpose, including with research partners, marketing partners, and the public.
6.6 No Sale or Sharing for Cross-Context Behavioral Advertising
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. We do not currently use advertising-related cookies or pixels (such as Meta Pixel or Google Ads conversion tracking) on the marketing site or within the Services. If we begin to use such technologies in the future, we will update this Privacy Policy and our Cookie Policy accordingly and will provide a "Do Not Sell or Share My Personal Information" or analogous opt-out mechanism to the extent required by applicable law.
6.7 Social, Community, and Comparison Features
Where the Services offer social, community, or comparison features (such as features that allow you to add another User to your network and to receive AI-generated comparisons of your respective type designations and cognitive function profiles), the use of those features involves sharing certain information between participating Users.
(a) Information shared by default: When you and another User both elect to participate in a comparison or community feature, certain information about each of you (which may include, depending on the feature, your display name or chosen identifier, your type designation, and aggregated or generalized analyses generated by our AI Systems) will be made available to the other.
(b) Information shared only with your express consent: We will not share specific examples drawn from your User Content (such as quotations or summaries of your journal entries or reflections) with another User unless you have provided your express consent for such sharing for that purpose. Absent your express consent, AI-generated comparisons are limited to generalized observations based on type designation alone.
(c) Your role as a participant: By choosing to participate in a social, community, or comparison feature with another User, you authorize us to share the categories of information described in subsections (a) and (b) above with that other User in accordance with the feature's design and your consent. You may withdraw from any social, community, or comparison feature at any time, in which case we will discontinue further sharing on a prospective basis (although we cannot retract information already shared with another User).
(d) Information you provide about other individuals: If you provide information about other individuals (for example, the name of a friend or family member you wish to discuss in your reflections), you represent that you have the right to provide that information and that providing it does not violate the rights or expectations of those individuals. You should not provide information about other individuals that is sensitive, that those individuals would reasonably expect to remain private, or that you are not authorized to share.
7. Marketing Communications
7.1 Email Newsletters and Marketing
We may send you marketing communications by email, including newsletters, content about cognition, cognitive functions, the writings of Carl Jung, product updates, and promotional offers. You may opt in to receive these communications when you create an account, subscribe to our mailing list, or otherwise provide your information to us.
7.2 Text Messages
We may, from time to time and only with your prior express consent (and, where required for marketing messages, your prior express written consent in accordance with the U.S. Telephone Consumer Protection Act, 47 U.S.C. § 227, and the implementing regulations of the Federal Communications Commission), send you text messages, including (a) transactional messages (such as account verification codes, security alerts, and other service-related notices) where you have provided a mobile telephone number for such purposes; and (b) marketing messages where you have separately opted in to receive marketing text messages.
If you have opted in to receive marketing text messages, you may opt out at any time by replying "STOP" (or such other keyword as we may indicate) to any marketing text message, or by contacting us at the address in Section 19 (Contact Us). Even after opting out of marketing messages, we may continue to send you transactional messages as necessary to operate the Services. Message and data rates may apply. Message frequency varies. We will not sell or share mobile telephone numbers collected for the purpose of receiving messages with third parties for their independent marketing purposes.
7.3 Your Choices
You can unsubscribe from marketing emails at any time by:
(a) clicking the "unsubscribe" link in any marketing email; (b) updating your communication preferences in your account settings; or (c) contacting us at the address in Section 19 (Contact Us).
You can opt out of marketing text messages by following the instructions in Section 7.2 (Text Messages).
Even if you opt out of marketing communications, we may still send you transactional and service-related communications, such as account notifications, security alerts, and updates to this Privacy Policy or our Terms.
7.4 Social Media
We maintain accounts on social media platforms and may share content, including educational material about cognitive functions, on those platforms. Your interactions with our social media presence are governed by the privacy policies of the applicable platforms. We may receive aggregated information about engagement with our social media content from those platforms.
7.5 Push Notifications
If you have opted in to push notifications on your mobile device or to web/browser-based push notifications, you may opt out at any time through your device or browser settings or, where available, through your account settings within the Services.
8. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, software development kits, and similar tracking technologies on the Services. For more information about the specific technologies we use and your choices regarding them, please refer to our Cookie Policy.
You can also control cookies through your browser settings. Please note that disabling certain cookies may limit your ability to use certain features of the Services.
9. Data Retention and Account Lifecycle
9.1 General Retention Principles
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The criteria we use to determine retention periods include:
(a) the duration of your relationship with us and your use of the Services; (b) whether retention is required to comply with a legal obligation, regulatory requirement, contractual commitment, or to defend against legal claims; (c) whether retention is advisable in light of our legal position (such as in connection with applicable statutes of limitations, litigation, or regulatory investigations).
9.2 Retention Schedule
| Category of Information | Retention Period |
|---|---|
| Account information | During active account; through 12-month Deactivation Period; then deletion within 30 days from active systems and 90 days from backups (as described in Section 9.3) |
| User Content (journal entries, reflections, etc.) | Same as Account information |
| Generated Outputs | Same as Account information |
| Embeddings and AI-generated representations | Same as Account information |
| Type assessment history | Same as Account information |
| Communications and support records | 3 years from date of communication |
| Payment records (when applicable) | 7 years (to comply with tax and accounting laws) |
| Technical logs (IP, device data, etc.) | Up to 18 months |
| Analytics data (de-identified or aggregated) | Indefinitely |
| Aggregated and de-identified data | Indefinitely |
| Backup copies | Up to 90 days, then deleted in the ordinary course of backup rotation |
| User research data (interviews, surveys, usability sessions) | As specified in the applicable research consent or participation agreement; aggregated, de-identified, or summary findings may be retained indefinitely |
| Recordings of user research sessions | As specified in the applicable recording consent; if no consent specifies otherwise, deleted within 24 months following the session unless retained as part of a study record |
Beta and User Research Data. Information you provide in connection with beta participation, user research interviews, surveys, and similar activities (collectively, "Research Data") may be retained outside of your account record and aggregated with information from other research participants. Research Data, including responses to surveys and interview transcripts, may be retained for a period specified in the applicable consent form or research participation agreement. We may retain aggregated, de-identified, or summary findings derived from Research Data indefinitely for the purposes described in Section 4 (How We Use Your Information). Where Research Data has been included in a research study or publication, we may retain it for the purpose of preserving the integrity of that study or publication.
9.3 Account Lifecycle and Deletion
When you no longer wish to use the Services, you have two options that result in different treatment of your personal information.
9.3.1 Account Closure (Deactivation)
You may close your account at any time through your account settings. When you close your account:
(a) Your access to the Services ceases immediately.
(b) Your account enters a deactivated state.
(c) Your account information, User Content, and personalization data (including AI-generated representations of your inputs and your type and function profile history) are retained in a recoverable state for twelve (12) months from the date of account closure (the "Deactivation Period"). This allows you to reactivate your account during the Deactivation Period by logging in or by contacting us at privacy@opuswithin.com.
(d) During the Deactivation Period, your information is not used to provide the Services to you and is segregated from active production use, but is retained on our systems and in our backups so that reactivation is possible.
(e) During the Deactivation Period, we do not send you marketing communications or use your information for personalization, but we may continue to use de-identified, aggregated, or statistical data derived from your prior interactions for the purposes described in Section 4 (How We Use Your Information).
(f) At the end of the Deactivation Period, your personal information will be transitioned to permanent deletion as described in Section 9.3.3 (Deletion Cascade), unless you have reactivated your account.
9.3.2 Permanent Deletion (Erasure)
You may, at any time and including during the Deactivation Period, request the permanent deletion of your personal information by:
(a) using any in-product permanent deletion option that we may make available; or
(b) submitting a deletion request to privacy@opuswithin.com (which we treat as an exercise of your right to deletion under applicable law — see Section 13 (Your Privacy Rights)).
A request for permanent deletion bypasses the Deactivation Period. Following receipt of a verified permanent deletion request, the procedures in Section 9.3.3 (Deletion Cascade) apply.
A request for permanent deletion is irreversible. We are unable to recover personal information that has been permanently deleted.
9.3.3 Deletion Cascade
Following the triggering event for permanent deletion — which is either (i) expiration of the Deactivation Period without reactivation, or (ii) receipt of a verified permanent deletion request — we will:
(a) remove your personal information from our active production systems within thirty (30) days following the triggering event;
(b) cascade deletion to subprocessors that hold copies of your personal information on our behalf, in accordance with our agreements with those subprocessors;
(c) allow remaining copies of your personal information in routine system backups to be deleted in the ordinary course of backup rotation, which we complete within an additional ninety (90) days following the triggering event; and
(d) retain only such information as we are permitted or required to retain under applicable law (such as records reasonably necessary for tax, accounting, fraud prevention, security, or legal-defense purposes; aggregated or de-identified data; and records relating to your prior exercise of privacy rights), and only for the duration permitted or required.
9.3.4 Statutory Timelines
Where applicable law requires us to respond to a deletion request within a specified timeframe (such as the forty-five (45) day response window under the California Consumer Privacy Act, as amended, or the one (1) month response window under the EU/UK General Data Protection Regulation), we comply with that timeframe. The thirty (30) day cascade described in Section 9.3.3 (Deletion Cascade) falls within all such statutory windows.
10. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, and destruction. These safeguards include:
(a) encryption of personal information in transit using industry-standard transport layer security (TLS); (b) encryption of personal information at rest in our databases and storage systems; (c) access controls and authentication requirements (including multi-factor authentication for personnel with access to sensitive systems); (d) least-privilege access policies and regular access reviews; (e) logging and monitoring of system access and activity; (f) employee and contractor security training; (g) vendor security review processes; and (h) incident response procedures.
Despite our efforts, no security measure is perfect, and we cannot guarantee the absolute security of your personal information. You are responsible for safeguarding your account credentials and for promptly notifying us if you suspect unauthorized use of your account.
11. Security Incident Notification
In the event of a security incident affecting your personal information, we will notify you and applicable regulators in accordance with the requirements of applicable law, including the breach notification provisions of state privacy and data breach laws and Articles 33 and 34 of the GDPR (where applicable). Notifications will be made without undue delay following our determination that a notifiable incident has occurred.
12. International Data Transfers
The Services are operated from the United States and are currently available only to residents of the fifty (50) United States and the District of Columbia, as described in Section 2.3 (Geographic Availability) of our Terms of Use. The Public Pages (such as our marketing website and blog) remain accessible globally; however, we do not currently offer the account-required features of the Services to residents of jurisdictions outside the United States.
Even within the United States, your personal information will be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate. The data protection laws of these jurisdictions may differ from those of your state of residence and may provide a different level of protection.
The provisions of Section 15 (European Economic Area, United Kingdom, and Switzerland Rights) and the international-transfer mechanisms described therein (including the European Commission's Standard Contractual Clauses and the UK Addendum thereto) apply to international transfers of personal information of residents of the European Economic Area, the United Kingdom, or Switzerland. While such transfers do not occur in the ordinary course during the period of US-only availability, we have included those provisions in this Privacy Policy to describe our practices upon expansion of the Services to additional jurisdictions, and to provide transparency to visitors to our Public Pages who reside in those jurisdictions.
13. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights with respect to your personal information. We honor verifiable requests in accordance with applicable law. Common rights include:
(a) Right to Access: The right to request access to and a copy of the personal information we hold about you; (b) Right to Correct: The right to request correction of inaccurate or incomplete personal information; (c) Right to Delete: The right to request the permanent deletion of your personal information, subject to certain exceptions. This right is distinct from closing your account: closing your account places it in a recoverable deactivated state for the Deactivation Period described in Section 9.3.1 (Account Closure (Deactivation)), while exercising your right to delete results in permanent erasure as described in Section 9.3.2 (Permanent Deletion (Erasure)) and Section 9.3.3 (Deletion Cascade). Where you wish to permanently delete your personal information rather than retain the option to reactivate, please use the in-product permanent deletion option (if available) or submit a deletion request as described in Section 13.1 (How to Exercise Your Rights); (d) Right to Opt Out of Sale or Sharing: The right to opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); (e) Right to Limit Use of Sensitive Personal Information: The right to limit our use of sensitive personal information to that which is necessary to provide the Services; (f) Right to Data Portability: The right to receive your personal information in a portable format; (g) Right to Withdraw Consent: The right to withdraw any consent you have provided; (h) Right to Non-Discrimination: The right not to be discriminated against for exercising your privacy rights.
13.1 How to Exercise Your Rights
You may exercise your rights by:
(a) accessing your account settings, where you can review, update, and delete certain personal information directly; (b) emailing us at privacy@opuswithin.com with the subject line "Privacy Rights Request"; or (c) contacting us at the address in Section 19 (Contact Us).
13.2 Verification
We will take reasonable steps to verify your identity before responding to your request, which may include asking you to confirm information associated with your account. We may require additional verification for sensitive requests (such as deletion).
13.3 Response Time
We will respond to verifiable requests within the time periods required by applicable law. Under most U.S. state privacy laws, we will respond within 45 days, with the possibility of a 45-day extension where reasonably necessary. Under GDPR and UK GDPR, we will respond within one (1) month, with the possibility of a two (2) month extension where reasonably necessary.
13.4 Authorized Agents
You may designate an authorized agent to make a request on your behalf. We will require written documentation of the agent's authority and may require additional verification of your identity.
13.5 Appeals
If we deny your request, you may appeal our decision by contacting us at privacy@opuswithin.com with the subject line "Privacy Rights Appeal." We will respond to your appeal within the time period required by applicable law.
14. United States State Privacy Rights
This Section applies to residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Utah, Virginia, and other states with similar laws as they come into effect.
14.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the rights described in Section 13 under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and additional rights described below.
14.1.1 Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information, as defined in the CCPA/CPRA:
| CCPA/CPRA Category | Examples | Sources | Business Purposes | Categories of Recipients |
|---|---|---|---|---|
| Identifiers | Name, email, account ID, IP address, device identifiers | You; automatic collection; auth providers | Provide Services; security; communications | Service providers (Sec. 6.1) |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email, payment information | You | Provide Services; payments | Service providers; payment processors |
| Internet/network activity | Usage data, log data, device data | Automatic collection | Provide Services; analytics; security | Service providers; analytics providers |
| Geolocation (approximate) | IP-derived approximate location | Automatic collection | Service operation; security | Service providers |
| Inferences | Type designation; cognitive function profile; themes; embeddings | Generated by us | Personalization; Service operation | Service providers |
| Audio/visual (if any) | Profile photo (if uploaded) | You | Profile display | Service providers |
| Other personal information | User Content (journal entries, reflections) | You | Provide Services; personalization | Service providers (including AI processors) |
14.1.2 Sensitive Personal Information
We do not collect sensitive personal information (as defined under CCPA/CPRA) for the purpose of inferring characteristics about you. Where User Content may contain information that could be characterized as sensitive (such as voluntarily disclosed health, religious, or political information), we use it solely to provide the Services you have requested and not for purposes that would require notice and a right to limit under CCPA/CPRA § 1798.121.
14.1.3 No Sale or Sharing
We do not sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under the age of 16.
14.1.4 Retention
We retain personal information in accordance with the retention schedule in Section 9.
14.1.5 Shine the Light
California Civil Code § 1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
14.2 Utah Residents (UCPA)
If you are a Utah resident, you have the rights described in Section 13 under the Utah Consumer Privacy Act ("UCPA"), including the rights to confirm processing, access, delete, and obtain a portable copy of your personal data, and to opt out of the sale of personal data and the processing of personal data for targeted advertising. We do not engage in the sale of personal data or targeted advertising as defined under UCPA.
14.3 Colorado, Connecticut, and Virginia Residents
If you are a resident of Colorado, Connecticut, or Virginia, you have the rights described in Section 13 under the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Virginia Consumer Data Protection Act, respectively, including the rights to access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal data, and the right to appeal any denial of a privacy rights request.
14.4 Other U.S. States
Residents of other U.S. states with comprehensive privacy laws (including, as those laws come into effect, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and others) may have similar rights, which we will honor to the extent required by applicable law.
15. European Economic Area, United Kingdom, and Switzerland Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following additional information applies:
15.1 Controller
The controller of your personal information is My Opus, Inc., contactable at the addresses in Section 19.
15.2 Legal Bases
We process personal information on the legal bases set forth in Section 4.8.
15.3 Your Rights
In addition to the rights described in Section 13, you have the right to:
(a) lodge a complaint with a supervisory authority in the country of your habitual residence, place of work, or place of an alleged infringement; (b) object to processing based on our legitimate interests, including for direct marketing purposes; (c) request information about the safeguards we use for international data transfers.
15.4 EU/UK Supervisory Authorities
You can find a list of EU supervisory authorities at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK supervisory authority is the Information Commissioner's Office (https://ico.org.uk). The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch).
15.5 EU/UK Representative
We have not yet designated an EU or UK representative. We will appoint one and update this Privacy Policy before making the Services available to users in the EU or UK.
16. Children's Privacy
The Services are intended for users who are at least eighteen (18) years of age. We do not knowingly collect personal information from individuals under eighteen (18). If you are under eighteen (18), please do not access or use the Services or provide any personal information.
If we learn that we have collected personal information from an individual under eighteen (18), we will delete that information promptly. If you believe that an individual under eighteen (18) has provided personal information to us, please contact us at the address in Section 19 (Contact Us).
We comply with the Children's Online Privacy Protection Act ("COPPA") and applicable state laws regarding the privacy of minors.
17. Third-Party Links and Services
The Services may contain links to or integrations with third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to such third-party services. We are not responsible for the content, privacy practices, or terms of any third-party services, and we recommend that you review the privacy policies of any third-party services you use.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email, by posting a notice within the Services, or by other reasonable means at least thirty (30) days before the changes take effect, except where applicable law requires more immediate notice. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
My Opus, Inc. Attention: Privacy Email: privacy@opuswithin.com General Legal: legal@opuswithin.com
This Privacy Policy is © My Opus, Inc. All rights reserved.