Privacy Policy
Last updated: August 2026
Who We Are
Opalo is a private social app for sharing moments with close friends. This policy explains what data we collect, why, and how you can control it. The data controller is [LEGAL ENTITY NAME], [a company registered in England and Wales under company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]]. We are registered with the UK Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER]. For anything about your data, contact support@opaloapp.com.
What We Collect
Account information: Your email address, username, display name, and profile/cover pictures. Collected when you sign up via email, Google, or Apple Sign-In. Date of birth: We ask for your date of birth at sign-up solely to check that you meet our minimum age requirement. It is checked on your device and is not sent to or stored on our servers. Messages and media: Text messages, photos, videos, and voice notes you send to friends are stored on our servers (Firebase) so they can be delivered to recipients. View-once media is deleted from our servers after viewing. Personal journal entries and Moments: Photos, videos, and entries you save to your own private journal, or keep as Moments, are stored locally on your device and, when iCloud backup is on, backed up to your personal iCloud account. We do not have access to them. Shared journals: If you create or join a shared journal, the photos, videos, and entries added to it are stored on our servers so that everyone in that journal can see them. Unlike your personal journal, this material is on our infrastructure, and other members of the journal can view and save it. Friend connections: Who you are connected to, and who you have blocked, so the app can work and so blocks are enforced. Reports you make: If you report a user or something they shared, we keep a record of the report and the material reported so we can act on it and handle repeat offenders. Device information: We store a push notification token (FCM token) so we can deliver notifications. Firebase infrastructure may collect IP addresses and basic device information for service operation and security. Analytics data: We use Firebase Analytics to understand how the app is used — events such as sign-ups, messages sent, features used, and screen views. Analytics data is linked to your user ID so we can measure engagement, but is never used for advertising and never sold. You cannot opt out of analytics separately from using the app. Crash data: We use Firebase Crashlytics to collect crash reports, including device model, OS version, and stack traces. Crash data is linked to your user ID to help diagnose issues. We do not collect location data, we do not use tracking for advertising, and we do not use your photos, videos, or messages to train artificial intelligence models.
Website Analytics (opaloapp.com)
This website uses Google Analytics 4 to understand how visitors find and use opaloapp.com. We only load Google Analytics if you click "Accept" on our cookie banner — if you click "Reject" or ignore it, no analytics data is collected from your visit. When you accept, Google Analytics collects: pages you view, time on each page, which site or platform referred you (e.g. TikTok, search engines, direct), approximate location based on IP address (anonymized — we only see country/region), and device type (mobile vs desktop). This data is used purely to improve the site and understand which marketing channels work. We have IP anonymization enabled. We do not use Google Analytics for advertising or remarketing. Analytics data is retained by Google for up to 14 months, then automatically deleted. You can review Google's data practices in their privacy policy. To change your choice later, clear your browser's site data for opaloapp.com — the cookie banner will appear again on your next visit.
Why We Collect It
We collect data to make the app work, to keep it safe, and to improve it: • Account info — so your friends can find and message you • Messages and media — so they reach the people you send them to • Shared journal material — so everyone in that journal can see it • Push notification tokens — so you know when someone messages you • Blocks and reports — so we can enforce blocks, act on abuse, and meet our safety obligations • Analytics — so we can understand which features are used, measure growth, and make the app better • Crash data — so we can find and fix bugs We do not collect data for advertising or profiling. We do not sell your data. Aggregate metrics such as total user counts and engagement trends are used for internal business reporting. Individual user data is never shared with third parties for these purposes. We do not make decisions about you by automated means that produce legal or similarly significant effects.
Legal Basis for Processing (UK GDPR)
We process your data under the following lawful bases: • Contract — account data, messages, media, and shared journal material are necessary to provide the service you signed up for • Legitimate interest — analytics and crash reporting help us maintain, secure, and improve the app, and aggregate metrics are used for internal business reporting. We have assessed that this does not override your rights, as individual data is never shared with advertisers or third parties • Legitimate interest — keeping records of blocks, reports, and terminated accounts so that we can protect users, enforce our terms, and prevent banned users from returning • Legal obligation — retaining and reporting material where the law requires it, including reporting child sexual abuse material to the appropriate authorities • Consent — optional email communications (product updates, surveys) are only sent if you opt in, and website analytics cookies are only set if you accept them. You can withdraw consent at any time
Who We Share With
We do not sell, rent, or share your personal data with advertisers or data brokers. We use Google Firebase as our infrastructure provider. Firebase processes your data on our behalf under Google's Data Processing Terms. This includes Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase Analytics, and Firebase Crashlytics. We use Resend to send transactional and (where you have opted in) product emails. Messages and media you send are delivered to the friends you choose, and shared journal material is visible to the members of that journal. We do not share your data with anyone else, except where we are required to by law, or where it is necessary to investigate abuse, enforce our terms, or protect someone's safety.
Where Your Data Is Stored
Our infrastructure runs on Google Cloud servers located in the United States, which means your data is transferred outside the UK and the European Economic Area. These transfers are covered by the safeguards required under UK and EU data protection law: Google's Data Processing Terms incorporate the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and Google LLC is certified under the EU-US and UK-US Data Privacy Framework. You can request more information about these safeguards at support@opaloapp.com.
How We Protect It
Data is encrypted in transit and at rest by our infrastructure provider. Access to production data is restricted, protected by multi-factor authentication, and limited to what is needed to run and support the app. Server-side security rules control which users can read and write which records. No service can promise perfect security, and we do not. If a breach occurs that is likely to put your rights and freedoms at risk, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly where the law requires it.
How Long We Keep It
Account data: Kept until you delete your account. Messages and media: Kept until you or the other participant deletes them, or until you delete your account. Shared journal material: Kept until it is deleted from the journal, or the journal is deleted. Note that if you leave a shared journal, material you already added remains visible to the other members unless you delete it first. View-once media: Deleted from our servers after the recipient views it (60-second replay window, then permanently deleted). Personal journal and Moments data: Stored on your device and, when iCloud backup is on, backed up to your iCloud — we never have access to it. Blocks, reports, and records of terminated accounts: Kept for as long as needed to enforce our terms and keep users safe, and longer where the law requires it. Analytics data: Retained by Firebase for up to 14 months, then automatically deleted. Crash data: Retained by Firebase for 90 days. When you delete your account, your data is removed from our live systems promptly. Residual copies may persist in encrypted infrastructure backups for a short period before being overwritten in the ordinary course.
Your Rights
Under UK and EU data protection law you have the right to: • Access the personal data we hold about you • Correct it if it is wrong — you can edit most of it directly in your profile • Delete it — you can delete your account and its associated data at any time from Settings, which removes your messages, media, friend connections, and profile from our servers • Receive a copy of your data in a portable, machine-readable format — email support@opaloapp.com and we will provide it • Restrict or object to processing, including processing based on legitimate interests • Withdraw consent at any time, where we rely on consent To exercise any of these rights, email support@opaloapp.com. We will respond within one month. We will not charge you, and we will not treat you differently for asking. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or to your local data protection authority if you are in the EU. We would rather hear from you first so we can put it right.
Children
Opalo is not intended for anyone under 13. We ask for date of birth during sign-up and do not create accounts for anyone below that age. If you are under 16 and in the EU, you must have a parent or guardian's consent to use the app. If we learn that a user is under 13, we will delete their account and data. If you are a parent or guardian and believe your child has created an account, email support@opaloapp.com and we will remove it.
Changes
If we make significant changes to this policy, we will notify you in the app before the changes take effect. The date at the top of this page shows when it was last updated.