Privacy Policy
Last Updated: [DATE]
Provided by: [YOUR FULL LEGAL NAME]
This Privacy Policy explains how OperaCore ("OperaCore," "we," "us," or "our") collects, uses, discloses, and protects information when you use our business operations platform at operacore.app (the "Service").
By using the Service, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Account & Business Information
When you sign up, we collect:
- Name, email address, business name, industry, team size
- Login credentials (handled securely via Supabase Authentication — we do not store raw passwords)
- Billing information (processed by Stripe — see Section 4)
1.2 Business Data You Provide
As you use OperaCore, we store the data you enter or upload to run your business, including:
- Job records (client names, addresses, quotes, costs, margins, notes)
- Client contact information
- Invoices and payment status
- Employee records (names, roles, contact info, hours, assigned jobs)
- Files, photos, and documents you upload (e.g., via Smart Inbox)
1.3 Information from Connected Third-Party Accounts
If you choose to connect integrations, we access limited data from those accounts as authorized by you:
- Google (Gmail, Calendar, Drive): inbox previews, calendar events, and file metadata you authorize
- Slack: messages and notifications you authorize us to send or read
You can revoke these connections at any time in Settings; we stop accessing the connected account immediately upon revocation.
1.4 Usage & Device Data
We automatically collect standard technical data — IP address, browser type, pages visited, and timestamps — to operate and secure the Service.
2. How We Use Your Information
We use the information above to:
- Provide, operate, and maintain the Service
- Process payments and manage subscriptions
- Power the AI assistant and automation features (see Section 3)
- Send transactional emails (e.g., invoice reminders, welcome emails, notifications)
- Respond to support requests
- Detect, prevent, and address technical issues, fraud, or abuse
- Improve and develop the Service
We do not sell your personal information or your business data to third parties.
3. AI Features — How We Use Artificial Intelligence
OperaCore uses Anthropic's Claude API to power certain features, including the AI assistant, AI-generated quotes, and Smart Inbox document classification.
What this means in practice:
- When you use these features, relevant data (such as job details, uploaded documents, or your questions) is sent to Anthropic's API to generate a response.
- Anthropic processes this data solely to return the AI-generated output to you and, per Anthropic's API terms, does not use API business data to train its models by default.
- We do not use your business data to train any AI models ourselves.
You can see Anthropic's own data handling terms at anthropic.com/legal.
4. Third-Party Service Providers (Subprocessors)
We share information with the following service providers, each of which processes data on our behalf under their own security and privacy commitments:
| Provider | Purpose | Data Involved |
|---|---|---|
| Supabase | Authentication, database, file storage | Login credentials, session data, uploaded files |
| Airtable | Core business data storage | Jobs, clients, invoices, employee records |
| Stripe | Payment processing, billing | Payment method, billing address, transaction history |
| Resend | Transactional/outbound email delivery | Email address, email content |
| Make.com | Workflow automation | Data relevant to the automation being run (e.g., invoice or job data) |
| Anthropic (Claude API) | AI assistant and AI-generated content | Data relevant to the specific AI feature used |
| OAuth integrations (Gmail, Calendar, Drive) — only if you connect them | Data you explicitly authorize | |
| Slack | OAuth integration — only if you connect it | Data you explicitly authorize |
| Vercel | Application hosting | Standard technical/log data |
We do not permit these providers to use your data for their own purposes beyond providing their service to us.
5. Data Retention & Deletion
- We retain your business data for as long as your account is active.
- Uploaded files (photos, documents) are retained until you delete them or close your account.
- Upon account cancellation, we delete or anonymize your business data within [X DAYS], except where retention is required by law (e.g., financial records tied to Stripe transactions).
- You may request deletion of your account and associated data at any time by contacting us (Section 9).
6. Data Security
We use industry-standard security measures to protect your information, including:
- Encryption in transit (HTTPS/TLS) across all services
- Encryption at rest for data stored in Supabase
- Role-based access controls (Owner, Manager, Employee tiers) that restrict what each user can view or modify
- Fail-closed access logic — access is denied by default unless explicitly authorized
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights & Choices
Depending on your location, you may have rights to:
- Access, correct, or delete your personal information
- Export your business data
- Object to or restrict certain processing
- Withdraw consent for connected integrations at any time
To exercise these rights, contact us at [SUPPORT EMAIL].
8. Children's Privacy
OperaCore is intended for business use by adults. We do not knowingly collect information from anyone under 18.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. Continued use of the Service after changes take effect constitutes acceptance.
10. Contact Us
Questions about this Privacy Policy or your data?
Email: [SUPPORT EMAIL]
Business: OperaCore
This document is a working draft prepared for OperaCore and is not a substitute for review by a licensed attorney. Before publishing, have this reviewed by counsel familiar with your state and any states where your customers are located, particularly the data retention window (Section 5) and your specific compliance obligations (e.g., CCPA if you have California users, GDPR if you have EU users).