What we collect
When you join the waitlist, sign up, or use the mobile app, we collect things you give us directly: your email, your name, the username you pick, your hometown (so we can match you to a city), the category of places you care about, your phone platform (iOS or Android), the optional social handles or website you share, profile photos you choose to upload, and any free-text ideas you send us about the app.
We also automatically log basic technical details, like your IP address, browser or device details, and pages and app screens you visit, so we can run the Service, prevent abuse, and fix bugs. If you click a referral link, we record that attribution so we can credit the right person. If you enable location in the mobile app, we use it to show nearby venues, search near you, estimate travel time, and (if you turn them on) send you notifications when you’re near a place you saved.
What we do with it
We use your data to run the Service, send you transactional emails (magic-link sign-in, account notices), keep your spot in line on the waitlist, prevent fraud and abuse, and improve the product. If you opt in, we may also send you marketing emails with updates about new features and spots. Every one of those has an unsubscribe link, and you can opt out any time.
We use AI providers to help write and enrich the venue listings and articles in the catalog. We do not send your personal data to those providers to train their models.
What we do NOT do
We do not sell your data. We do not rent it, trade it, or share it with advertisers or data brokers. Full stop.
Who we share with
Only the service providers we need to run Opulist:
- Supabase: hosts our database and authentication.
- Resend: sends our transactional emails (sign-in links, etc.).
- Flodesk: manages our marketing email list, if you opt in. You can unsubscribe any time.
- Cloudflare R2: stores images you or we upload.
- Google Places: powers the city/hometown and venue search. Your typed query is sent to Google so it can return suggestions.
- Google and Apple Sign-In: if you choose to sign in with them in the mobile app, they confirm your identity to us.
- Vercel: hosts the website, and its analytics measures page performance (load times, web vitals).
- PostHog: product analytics so we can see which features people actually use and improve the app.
- Sentry: collects crash and error reports so we can fix bugs. Any session replays are masked so we don’t see your text or images.
- Apple and Google push services: deliver mobile push notifications, if you turn them on.
Each of these providers is bound by their own privacy terms and only sees what they need to do their job.
Importing your places
If you import your saved places from Google Maps, you upload an export file to us. We use it once to match those places against our catalog and add them to your account. We don’t share that file with anyone, and you can delete the imported places any time.
Cookies
We use a small number of cookies: one to remember your session when you sign in, one to keep your referral attribution if a friend sent you our way, one to protect forms from cross-site abuse, and first-party analytics cookies for the product-usage and performance data above (PostHog, served through our own domain, and Vercel Analytics). We don’t use third-party advertising cookies and we don’t track you across other websites.
Your rights
You can ask us to:
- Show you the data we hold about you.
- Correct anything that’s wrong.
- Delete your account and everything tied to it. Some logs may stick around for a short time for security and abuse-prevention reasons, then drop off.
- Export your data so you can take it elsewhere.
Email support@opulist.co and we’ll handle it.
How long we keep data
We keep your account data while your account is active. If you delete your account, we remove your personal data from our live systems within 30 days. Backups roll off within 90 days. We may keep aggregated, non-identifying statistics indefinitely.
Security
Data in transit is encrypted with TLS. Data at rest is encrypted in our database and storage providers. Sensitive operations require a fresh sign-in. We follow the principle of least access for our team.
Kids
Opulist isn’t for children under 13. We don’t knowingly collect data from anyone in that age range; if you think we have, email us and we’ll remove it.
International transfers
Our providers may process data in the United States and the European Union. By using Opulist you’re fine with that transfer.
Changes to this policy
We’ll update this page when things change. Material changes will be flagged by email or in-product banner before they take effect.
Read the Terms of Service for the rules of using Opulist.