Pricing

Opaline Privacy

Effective date: 21 September 2026

This Privacy notice explains how Opaline Labs, Inc. collects, uses and discloses personal information in connection with the hosted Opaline service.

1. Who we are

Opaline Labs, Inc. is a San Francisco-based company that provides analytics for coding-agent sessions.

Opaline Labs, Inc.
2261 Market Street
San Francisco, CA 94114
United States

Email: evren@opaline.so

2. Scope

This notice applies to Opaline's website, hosted application, API, command-line integration, support and related hosted features.

It does not apply to a self-hosted deployment operated entirely by a Customer. If a self-hosted deployment sends information to Opaline's hosted services, this notice applies to the information Opaline receives.

The Service is intended for business use and is not directed to children.

3. Our role

Customers decide which coding-agent sessions are uploaded, who can access a workspace and how session analytics are used. For personal information contained in Customer-submitted session content and the analytics derived from it, Opaline acts as a service provider or processor for the Customer. The Customer's instructions and Opaline's obligations are described in the Data Processing Agreement.

Opaline acts as the business or controller for account administration, authentication, Service operation and security, support, communications, billing and product analytics.

4. Information we collect

Account and organization information

We collect names, email addresses, profile images, account and organization identifiers, workspace memberships and roles, invitations, authentication provider, login records, preferences, subscription information and protected API or CLI credentials.

Coding-agent session content

When a Customer submits a session, it can contain prompts, model responses, system messages, source code, files and file paths, terminal commands and output, tool calls, repository and version-control information, URLs, timestamps, model and token information, errors, and personal or confidential information appearing in those materials.

Workspace analytics

We create Customer-directed analytics from submitted sessions, such as session and interaction counts, timing, token and model usage, repository and project information, skill and agent activity, errors, classifications, reports and User-, project- or workspace-level comparisons.

Device, usage and log information

We collect IP address, browser and operating-system information, application and CLI version, requested pages and features, timestamps, request identifiers, authentication events, upload status, error codes, approximate location derived from IP address and information used to prevent abuse or investigate incidents.

Communications

When someone contacts us, joins a sales conversation or uses support, we collect contact details, the communication and attachments, and relevant account or technical information.

5. Sources of information

We receive information directly from Users and Customers; automatically from browsers, the CLI, integrations and use of the Service; from a Customer's workspace administrators; from identity providers such as Google or GitHub when selected; and from service providers that help us operate Opaline.

6. How we use information

We use personal information to:

  • create accounts, authenticate Users and manage organizations, invitations and permissions;
  • receive, store, display and analyze coding-agent sessions at the Customer's direction;
  • provide dashboards, reports, workspace analytics, exports and public shares requested by a User;
  • operate, maintain, troubleshoot and secure the Service;
  • respond to support, sales and other communications;
  • send authentication, operational and administrative messages;
  • manage subscriptions, transactions and business records;
  • understand feature adoption and improve reliability and usability;
  • prevent fraud, abuse and unauthorized access; and
  • comply with law and establish, exercise or defend legal claims.

We do not use substantive coding-agent session content to train general-purpose AI models, create advertising profiles or build cross-customer benchmarks. We do not use workspace analytics to evaluate a Customer's personnel for Opaline's own purposes.

7. AI processing

When a Customer uses an AI-assisted analysis feature, Opaline may send the content needed for that request to OpenAI or Anthropic. The relevant provider processes that content to return the requested analysis. Opaline does not authorize those providers to use Customer content to train their general-purpose models.

AI-generated analysis can be incomplete or inaccurate. Customers decide whether and how to use it and should not treat it as the sole basis for employment or other legally significant decisions about an individual.

8. How we disclose information

We may disclose personal information:

  • to infrastructure, database, analytics, AI, email, authentication and support providers that help deliver Opaline;
  • within a Customer's workspace according to its settings and permissions;
  • to the public when an authorized User intentionally creates a public share;
  • to professional advisers and auditors under appropriate confidentiality obligations;
  • to comply with law, legal process or valid government requests, or to protect rights, safety and the Service; and
  • in connection with a merger, financing, acquisition, reorganization or sale of assets, subject to customary protections.

Our current providers and their functions are listed on the Subprocessors page.

9. Cookies and analytics

Opaline uses cookies, local storage and similar technologies to maintain sessions, authenticate Users, remember settings, prevent abuse and measure product use.

We use PostHog for website and product analytics. On our public website, PostHog operates in cookieless mode without creating persistent visitor profiles. In the authenticated product, analytics may include User and organization identifiers, pages and features used, onboarding and authentication actions, upload results, application version, device category, broad content-size categories, normalized error codes, installation identifiers and hashed project identifiers. We configure analytics not to collect raw prompts, model responses, source code, file contents or terminal output.

Where required by law, we request consent or provide an opt-out for non-essential browser storage. Browser settings can also block or delete cookies, although doing so may affect the Service. Opaline does not currently respond to browser “Do Not Track” signals. We honor legally recognized opt-out preference signals, such as Global Privacy Control, where required.

10. Retention

We keep personal information only as long as reasonably necessary for the purposes described here, including providing the Service, maintaining business and transaction records, resolving disputes, enforcing agreements and complying with law.

  • Account and organization information is generally retained while the account is active and for a limited period afterward.
  • Customer session content and workspace analytics are retained until the Customer deletes the relevant session, account or workspace, the agreement ends, or another valid instruction requires deletion.
  • Public shares remain available until deleted, replaced or automatically expired.
  • Operational logs, analytics and support records are retained according to their purpose and configured retention periods.
  • Residual copies may remain in protected backups until overwritten through ordinary backup cycles.

11. Privacy choices and rights

Depending on where a person lives and subject to legal exceptions, they may have the right to request access to, correction of, deletion of or a portable copy of personal information; learn about its collection and disclosure; opt out of sale, sharing or targeted advertising; limit certain uses of sensitive personal information; withdraw consent; object to or restrict processing; and appeal a denied request.

Opaline does not sell personal information or share it for cross-context behavioral advertising, and does not use sensitive personal information to infer characteristics about individuals.

To exercise a right, email evren@opaline.so. We may verify a request using account or contact information. An authorized agent may submit a request where permitted by law, but we may require proof of authority and verification of the individual. We will not discriminate against anyone for exercising a privacy right.

If personal information is part of Customer-controlled session content, the individual should normally contact that Customer first. We will assist the Customer as required by law.

12. California disclosures

During the preceding 12 months, Opaline collected the following categories of personal information, depending on how the Service was used:

CategoryExamplesCategories of recipients
IdentifiersName, email, account, organization, IP and device identifiersInfrastructure, authentication, email, analytics and support providers
Customer records and commercial informationContact, subscription, plan and transaction informationInfrastructure, communications and business-service providers
Internet or network activityUsage, interaction, device, log and diagnostic informationInfrastructure, database, analytics and support providers
Professional informationOrganization, role, projects, repositories and coding-agent activityInfrastructure, database, analytics and AI providers
Contents and inferencesSession content, communications, classifications and workspace analyticsInfrastructure, database, AI and support providers
Sensitive personal informationAccount credentials and sensitive information incidentally included in session contentInfrastructure, database and AI providers as needed to deliver requested features

The sources and business purposes for these categories are described in Sections 5 and 6. We disclosed these categories for the business purposes described above. We did not sell them or share them for cross-context behavioral advertising, and we do not knowingly sell or share personal information of anyone under 16.

13. International transfers

Opaline is based in the United States. Personal information may be processed in the United States and other countries where our providers operate. Those countries may have different privacy laws from a person's home jurisdiction.

For people in the European Economic Area, United Kingdom or Switzerland, our legal bases for controller processing are performance of a contract, compliance with legal obligations, legitimate interests in operating and improving a secure business service, and consent where required. Where required for an international transfer, we use an adequacy decision, certification, contractual clauses or another lawful mechanism.

Individuals in those jurisdictions may have rights to access, correct, erase, restrict, object, receive a portable copy, withdraw consent and complain to their local supervisory authority.

14. Security

We use administrative, technical and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Users should protect their credentials and promptly notify us of suspected unauthorized access.

15. Children

Opaline is a business service not directed to anyone under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us, contact us so we can review and delete it where appropriate.

16. Changes

We may update this notice as the Service, providers or legal requirements change. We will post the current version here and update its effective date. If a change materially affects privacy rights, we will provide additional notice where required.

17. Contact

Questions, complaints and privacy requests can be sent to evren@opaline.so or:

Opaline Labs, Inc.
2261 Market Street
San Francisco, CA 94114
United States

Table of Contents

Copyright © 2026 Opaline Labs, Inc. All rights reserved.

PricingPrivacyTerms of ServiceDPASubprocessors

Table of Contents