Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how Opti (“Opti”, “we”, “us”) collects, uses, and protects your personal data when you use optieducation.app (the “Service”). We handle your data in line with the EU General Data Protection Regulation (GDPR).
Who we are (data controller)
Opti is an independent ESAT study tool operated by Enzo Horps, an individual based in Belgium. For the purposes of the GDPR, Enzo Horps is the “data controller” for the personal data described here. You can contact us about privacy at optiapp.business@gmail.com.
What data we collect
- Account data: your email address and a securely hashed password. If you choose “Continue with Google”, we receive your name and email from your Google account.
- Age verification: your date of birth, collected once at onboarding to confirm you meet our minimum age. If you are under 16, we also record that a parent or guardian gave permission. We do not send your date of birth to our analytics provider.
- Onboarding data: your self-reported preparation stage, the study methods you currently use, and how you heard about Opti.
- Study & practice data: the subjects you study; your practice session settings; the questions you attempt, the answers you select, whether they were correct, and how long you took; optional self-diagnosis tags and short notes you add when reviewing; and spaced-repetition data we derive to schedule your practice.
- Session diagnosis: when you request an end-of-session read, we send your wrong answers, the relevant question text, your self-diagnosis tags and optional notes, and timing information to an AI model to generate a short study summary for you. The result is stored so you can view it again (see “Automated processing & third parties”).
- Feedback: messages you send via the in-app feedback or question-report forms, plus the page you were on and (for reports) the question and session involved.
- Technical data: your IP address, device and browser information, and standard server logs, used for security, rate-limiting, and keeping the Service running.
We do not intentionally collect special-category data (such as health or political data). Please don’t put such information into free-text fields.
Cookies & storage
We use strictly-necessary cookies and similar storage for things the Service cannot work without: keeping you signed in, binding your browser to the practice sessions you start, and remembering your analytics consent choice. Because these are essential to a service you’ve asked for, they don’t require consent.
Specifically, this includes your authentication session (Supabase), a signed session-access cookie that lets your browser reach the practice sessions it created, your analytics consent preference, and (optionally) a flag that you dismissed a release-notes banner.
Product analytics (optional)
We also use privacy-friendly product analytics (PostHog, EU Cloud) to understand how Opti is used and improve it — for example which steps people complete and where they drop off. These analytics load only if you agree via the consent banner. If you decline, no analytics cookies are set and no optional usage events are collected.
When enabled, we record events such as page views and key actions (for example, starting or finishing a session), linked to your account identifier once you are signed in. We do not send your answers, question text, diagnosis content, name, email, or date of birth to this analytics layer. You can change or withdraw your choice at any time using ; withdrawing stops optional analytics immediately and clears the link to your account.
Operational telemetry (not optional)
Separately from optional product analytics, we record coarse operational data so we can run the Service safely and sustainably. This is not gated on your analytics consent because it is necessary to prevent abuse, enforce rate limits, and account for paid AI usage — not to profile you for marketing.
When you use AI-powered features (such as the end-of-session diagnosis), we log metadata about each model call to our monitoring system (PostHog, EU Cloud): the model used, token counts, latency, and your account or session identifier so we can attribute cost and spot runaway usage. We never log the prompt or the model’s response text in this telemetry.
Why we use your data and our legal basis
- To create and run your account and deliver the practice Service: performance of a contract with you.
- To verify your age and, where required, parental permission: performance of a contract and our legitimate interest in protecting minors.
- To personalise your practice (spaced repetition, resurfacing questions you got wrong, and similar): performance of a contract and our legitimate interest in making the Service effective.
- To generate your session diagnosis when you request it: performance of a contract (a feature you request).
- To handle feedback and question reports you send us: performance of a contract and our legitimate interest in maintaining quality.
- To keep the Service secure, prevent abuse, enforce rate limits, account for AI costs, and moderate access: our legitimate interest in protecting the Service and its users.
- To measure how the Service is used so we can improve it (optional product analytics): your consent, which you can withdraw at any time.
- To comply with our legal obligations: legal obligation.
We do not make decisions producing legal or similarly significant effects about you by solely automated means.
Automated processing & third parties (sub-processors)
To run the Service we share the minimum data necessary with carefully chosen providers who process it on our behalf, under data-processing agreements:
- Supabase: database hosting, authentication, and file storage.
- Cloudflare: application hosting and content delivery.
- PostHog (EU Cloud): optional product analytics (only with your consent) and operational telemetry (AI cost and usage metadata, always on). We send coarse events and your account or session identifier — never your answers, question text, diagnosis content, or other study material.
- Anthropic: when you request a session diagnosis, your wrong answers, the relevant question text, your self-diagnosis tags and optional notes, and timing context are sent to Anthropic’s language model to generate your summary. Anthropic processes it to return the result and does not use it to train its models.
- Voyage AI: generates mathematical embeddings of our question-bank content during internal authoring and ingestion workflows. This does not process your personal study data during normal use of the Service.
- Upstash: temporary storage of identifiers used for rate-limiting and abuse prevention.
- Slack: when you submit feedback or report a question, a notification (including your email and message) may be sent to our internal team workspace so we can review it.
- Google: only if you choose to sign in with Google.
We do not sell your personal data, and we do not share it for advertising.
International transfers
Some of our providers (including Anthropic and Voyage AI) are based in the United States, so your data may be transferred outside the European Economic Area. Where it is, the transfer is protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework. You can ask us for more detail.
How long we keep your data
We keep your data for as long as your account is active. If you delete your account or ask us to erase your data, we will delete your account data, practice history, session diagnoses, onboarding answers, and feedback within 30 days, except where we must keep certain records to comply with the law. Backups are overwritten on a rolling basis. Copies of feedback notifications already delivered to our team tools (such as Slack) may persist in those systems until manually cleared.
Your rights
Under the GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it at any time. To exercise any of these, email optiapp.business@gmail.com and we’ll respond within one month.
You also have the right to lodge a complaint with your local data-protection authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels: autoriteprotectiondonnees.be.
Children
You must be at least 13 to use Opti. The age at which you can consent to online services on your own varies by country (between 13 and 16). If you are under 16, you confirm that a parent or guardian has given permission for you to use Opti and for us to process your data as described here. If we learn that we have collected data from a child below the applicable age without the required permission, we will delete it. Parents or guardians can contact us at optiapp.business@gmail.com.
Security
We protect your data with measures including hashed passwords, encryption in transit, and restricted access. No online service can be guaranteed 100% secure, but we work to protect your information and will notify you and the relevant authority of a data breach where the law requires.
Changes to this policy
We may update this policy from time to time. We’ll change the “Last updated” date above and, for significant changes, take reasonable steps to let you know.
Contact
Questions or requests: optiapp.business@gmail.com.