← Back to Opti

Privacy Policy

Last updated: 15 July 2026

This Privacy Policy explains how Opti (“Opti”, “we”, “us”) collects, uses, and protects your personal data when you use optieducation.app (the “Service”). We handle your data in line with the EU General Data Protection Regulation (GDPR).

Who we are (data controller)

Opti is an independent ESAT study tool operated by Enzo Horps, an individual based in Belgium. For the purposes of the GDPR, Enzo Horps is the “data controller” for the personal data described here. You can contact us about privacy at optiapp.business@gmail.com.

What data we collect

We do not intentionally collect special-category data (such as health or political data). Please don’t put such information into free-text fields.

Cookies & storage

We use strictly-necessary cookies and similar storage for things the Service cannot work without: keeping you signed in, binding your browser to the practice sessions you start, and remembering your analytics consent choice. Because these are essential to a service you’ve asked for, they don’t require consent.

Specifically, this includes your authentication session (Supabase), a signed session-access cookie that lets your browser reach the practice sessions it created, your analytics consent preference, and (optionally) a flag that you dismissed a release-notes banner.

Product analytics (optional)

We also use privacy-friendly product analytics (PostHog, EU Cloud) to understand how Opti is used and improve it — for example which steps people complete and where they drop off. These analytics load only if you agree via the consent banner. If you decline, no analytics cookies are set and no optional usage events are collected.

When enabled, we record events such as page views and key actions (for example, starting or finishing a session), linked to your account identifier once you are signed in. We do not send your answers, question text, diagnosis content, name, email, or date of birth to this analytics layer. You can change or withdraw your choice at any time using ; withdrawing stops optional analytics immediately and clears the link to your account.

Operational telemetry (not optional)

Separately from optional product analytics, we record coarse operational data so we can run the Service safely and sustainably. This is not gated on your analytics consent because it is necessary to prevent abuse, enforce rate limits, and account for paid AI usage — not to profile you for marketing.

When you use AI-powered features (such as the end-of-session diagnosis), we log metadata about each model call to our monitoring system (PostHog, EU Cloud): the model used, token counts, latency, and your account or session identifier so we can attribute cost and spot runaway usage. We never log the prompt or the model’s response text in this telemetry.

Why we use your data and our legal basis

We do not make decisions producing legal or similarly significant effects about you by solely automated means.

Automated processing & third parties (sub-processors)

To run the Service we share the minimum data necessary with carefully chosen providers who process it on our behalf, under data-processing agreements:

We do not sell your personal data, and we do not share it for advertising.

International transfers

Some of our providers (including Anthropic and Voyage AI) are based in the United States, so your data may be transferred outside the European Economic Area. Where it is, the transfer is protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework. You can ask us for more detail.

How long we keep your data

We keep your data for as long as your account is active. If you delete your account or ask us to erase your data, we will delete your account data, practice history, session diagnoses, onboarding answers, and feedback within 30 days, except where we must keep certain records to comply with the law. Backups are overwritten on a rolling basis. Copies of feedback notifications already delivered to our team tools (such as Slack) may persist in those systems until manually cleared.

Your rights

Under the GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it at any time. To exercise any of these, email optiapp.business@gmail.com and we’ll respond within one month.

You also have the right to lodge a complaint with your local data-protection authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels: autoriteprotectiondonnees.be.

Children

You must be at least 13 to use Opti. The age at which you can consent to online services on your own varies by country (between 13 and 16). If you are under 16, you confirm that a parent or guardian has given permission for you to use Opti and for us to process your data as described here. If we learn that we have collected data from a child below the applicable age without the required permission, we will delete it. Parents or guardians can contact us at optiapp.business@gmail.com.

Security

We protect your data with measures including hashed passwords, encryption in transit, and restricted access. No online service can be guaranteed 100% secure, but we work to protect your information and will notify you and the relevant authority of a data breach where the law requires.

Changes to this policy

We may update this policy from time to time. We’ll change the “Last updated” date above and, for significant changes, take reasonable steps to let you know.

Contact

Questions or requests: optiapp.business@gmail.com.