Privacy Policy
Last updated: April 2026
Who We Are
Opalo is a private social app for sharing moments with close friends. This policy explains what data we collect, why, and how you can control it. If you have questions, contact us at support@opaloapp.com.
What We Collect
Account information: Your email address, username, display name, date of birth, and profile/cover pictures. Collected when you sign up via email, Google, or Apple Sign-In. Your date of birth is used only to verify you meet our minimum age requirement and is not stored on our servers. Messages and media: Text messages, photos, videos, and voice notes you send to friends are stored on our servers (Firebase) so they can be delivered to recipients. View-once media is deleted from our servers after viewing. Journal entries: Photos, videos, and journal entries you save to your journal are stored locally on your device and synced to your personal iCloud account. We do not have access to your journal data. Device information: We store a push notification token (FCM token) on your device so we can deliver notifications. Firebase infrastructure may collect IP addresses and basic device information for service operation. Analytics data: We use Firebase Analytics to understand how the app is used. This includes events such as sign-ups, messages sent, features used, and screen views. Analytics data is linked to your user ID so we can measure engagement, but is never used for advertising or sold to third parties. You cannot opt out of analytics separately from using the app. Crash data: We use Firebase Crashlytics to collect crash reports, including device model, OS version, and stack traces. This helps us identify and fix bugs. Crash data is linked to your user ID to help diagnose issues.
Website Analytics (opaloapp.com)
This website uses Google Analytics 4 to understand how visitors find and use opaloapp.com. We only load Google Analytics if you click "Accept" on our cookie banner — if you click "Reject" or ignore it, no analytics data is collected from your visit. When you accept, Google Analytics collects: pages you view, time on each page, which site or platform referred you (e.g. TikTok, search engines, direct), approximate location based on IP address (anonymized — we only see country/region), and device type (mobile vs desktop). This data is used purely to improve the site and understand which marketing channels work. We have IP anonymization enabled. We do not use Google Analytics for advertising or remarketing. Analytics data is retained by Google for up to 14 months, then automatically deleted. You can review Google's data practices in their privacy policy. To change your choice later, clear your browser's site data for opaloapp.com — the cookie banner will appear again on your next visit.
Why We Collect It
We collect data to make the app work and to improve it: • Account info — so your friends can find and message you • Messages and media — so they reach the people you send them to • Push notification tokens — so you know when someone messages you • Analytics — so we can understand which features are used, measure growth, and make the app better • Crash data — so we can find and fix bugs We do not collect data for advertising or profiling. We do not sell your data. Analytics data is used to improve the product and to understand how the app is growing (for example, aggregate user counts and engagement trends for internal business reporting). Individual user data is never shared with third parties for these purposes.
Legal Basis for Processing (UK GDPR)
We process your data under the following lawful bases: • Contract — account data, messages, and media are necessary to provide the service you signed up for • Legitimate interest — analytics and crash reporting help us maintain, secure, and improve the app, and aggregate metrics (such as total user counts and engagement trends) are used for internal business reporting. We have assessed that this does not override your rights, as individual data is never shared with advertisers or third parties • Consent — optional email communications (product updates, surveys) are only sent if you opt in during onboarding
Who We Share With
We do not sell, rent, or share your personal data with advertisers or data brokers. We use Google Firebase as our infrastructure provider. Firebase processes your data on our behalf under Google's Data Processing Terms. This includes Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase Analytics, and Firebase Crashlytics. Data is stored on servers in the United States. Messages and media you send are delivered to the friends you choose. We do not share your data with anyone else.
How Long We Keep It
Account data: Kept until you delete your account. Messages and media: Kept until you or the other participant deletes them, or until you delete your account. View-once media: Deleted from our servers after the recipient views it (60-second replay window, then permanently deleted). Journal data: Stored on your device and iCloud — we never have access to it. Analytics data: Retained by Firebase for up to 14 months, then automatically deleted. Crash data: Retained by Firebase for 90 days.
Your Rights
You can: • Delete your account and all associated data at any time from Settings. This removes your messages, media, friend connections, and profile from our servers. • Export your data in a machine-readable format directly from the app. • Correct your information by editing your profile. If you are in the UK or EU, you also have the right to: restrict processing, object to processing, and lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local data protection authority in the EU. To exercise any of these rights, email support@opaloapp.com.
Children
Opalo is not intended for anyone under 13. All users must provide their date of birth during sign-up, and we do not allow accounts for anyone under 13. If you are under 16 and in the EU, you must have a parent or guardian's consent to use the app. If we learn that a user is under 13, we will delete their account and data.
Changes
If we make significant changes to this policy, we will notify you in the app before the changes take effect.