Privacy Policy

Your data, without the legalese.

This policy covers what Operelio collects, why we collect it, and what control you have.

Last updated 6 August 2026

At a glance

What matters most

What we collect: Your account details, the files you upload, how you use the product, and payment information handled by Stripe.

What we don't do: We don't sell your data, use it to train AI models, serve ads, or share it with marketing partners.

Where it lives: Your files are processed and stored in the UK and the EU.

How long we keep files: 24 hours on Free, 30 days on Starter and Pro, 90 days on Agency. After that we delete them.

Your rights: You can ask us for a copy of your data, ask us to correct it, or ask us to delete it.

Questions: Email hello@operelio.com. We answer data requests within 30 days.

Two kinds of data

Your account and your files are different things

Data about you. Your name, email address, billing details and how you use the product. We decide how that data is handled, which makes us the controller for it. This policy is about exactly that.

Data inside the files you upload. Your contacts, your prospects, other people's details. You decide what to upload and what happens to it, which makes you the controller and Operelio your processor. We only do what you ask.

Our obligations as your processor

They are set out in our Data Processing Agreement. It applies automatically when you accept our Terms of Service, so there is nothing to request and nothing to sign.

Data collection

What we collect and why

Account information. Your name and email address, used to run your account, send service messages and answer you when you contact support. These are the only details you must provide to use Operelio (a paid plan also needs billing details, entered with Stripe); without them we cannot run your account. Clerk handles sign-in for us. When you first sign in we also ask three optional setup questions; your answers help us decide what to build next and are shared with our analytics provider.

Files you upload. Spreadsheets, typically containing business contact data. We process them to run the tools you choose and delete them at the end of your plan's retention window. The section below covers them fully.

What you type into Bridgeant. Bridgeant is the assistant on our paid plans. We store your messages and its replies so you can pick a conversation back up, and delete a conversation 30 days after its last message. To answer you, we send your message, the names of your files, sheets and saved workflows, and a structural summary of the file (column headers, fill rates and counts, never your cell values) to OpenAI. You can see exactly what was sent under any reply. On the Free plan the assistant answers from a built-in help guide instead: nothing goes to OpenAI and nothing is stored.

Email verification results. When you run the Email Verifier & Finder, the addresses in your file are checked by our EU-based verification providers. We keep each result for 7 days, stored against a one-way hash rather than the address itself, with no link to you, your file or your account. That lets us reuse a recent result, whichever customer ran the check, instead of paying to check the same address twice. Because the cache is shared, we operate it as a controller in our own right, relying on our legitimate interest in keeping verification costs down; the addresses it is built from come from files our customers upload, and the rights described below apply to it. The address itself is deleted with the rest of your file.

CRM credentials. If you connect HubSpot, Salesforce or Pipedrive, we store the access tokens needed to push data on your behalf. They are encrypted, never written to logs, and deleted the moment you disconnect.

Usage and technical data. Job history, file sizes, processing times and which tools you use, so we know what people actually use and where things break. Your IP address, browser type and the pages you visit are collected by PostHog, our analytics provider, and by Vercel, which hosts the site.

Payment data. Billing runs through Stripe. You enter card details directly into Stripe's own forms and they never reach our servers. We receive your billing email, your plan, and card metadata such as the card type, last four digits and expiry date.

Messages you send us. Anything you send through the contact form or to support. We keep these so we have the context if you write again.

Our legal basis for using your data

To provide the service (Article 6(1)(b), contract): running your files through the tools you choose, managing your account, taking payment, and pushing data to a CRM you connect.

Our legitimate interests (Article 6(1)(f)): improving the product, monitoring for security problems, preventing fraud, and sending you occasional product updates. You can object to any of this, and product update emails can be turned off in Settings.

Legal obligations (Article 6(1)(c)): tax records, financial regulations, and lawful requests from authorities.

File handling

How we handle your files

Your files are processed and stored in the UK and the EU, and are not sent outside them; the one payload derived from a file that goes further is the structural summary Bridgeant sends to OpenAI, described above, never your rows or cell values. Files are encrypted in transit and at rest, and every file is scoped to your workspace, so it is not reachable from another account. How the platform is built and protected is on our security page.

We never use the contents of your files for analytics or to train a model.

Files are deleted 24 hours after processing on Free, after 30 days on Starter and Pro, and after 90 days on Agency. Deletion is permanent. One exception: if you star a file in your library, we keep it until you delete it yourself.

What survives closing your account. Two things. Records the law requires us to hold, such as invoices for tax. And a stripped record of each job you ran: which tool, when, how long it took and how many rows warned or errored, with everything taken from your file removed. We keep that for 2 years, because if a payment is disputed it is the only evidence we have that the service was delivered. Everything else, including your files and anything quoted from them, is deleted when you close your account.

Retention at a glance

Uploaded files: 24 hours (Free), 30 days (Starter and Pro), 90 days (Agency)

Starred files: kept until you delete them

Account data: kept while your account is open

Job and usage history: kept while your account is open; a stripped record of each job is kept for 2 years after closure as proof of service

Bridgeant conversations: 30 days after the last message in that conversation

Email verification results: 7 days, as a one-way hash with no link to you

Support and chat messages: kept so we have the context if you contact us again

Analytics and request logs: kept while we need them to understand usage and keep the service secure

Payment records: kept as long as tax and financial law requires, usually six to seven years

CRM tokens: deleted the moment you disconnect

Sub-processors

Who else touches your data

We use a small number of outside services to run Operelio: hosting, storage and processing infrastructure, sign-in (Clerk), payments (Stripe), email and support chat, product analytics, the language model behind Bridgeant (OpenAI), and EU-based email verification providers. Each one has one job and receives only what that job needs.

The complete list, with what each service receives, where it is based, and the legal basis for any transfer outside the UK and the EEA, is at operelio.com/subprocessors. We will email you before we add or replace one, with time to object; the notice period is set out there and in the DPA.

When you push data to HubSpot, Salesforce or Pipedrive, that CRM becomes an independent controller of the data you sent it, under its own privacy policy.

Your rights

What you can ask us to do

The UK GDPR and the EU GDPR give you rights over your personal data, and we honor them for everyone, wherever you live. California residents have similar rights under the CPRA.

See your data. Ask us for a copy of what we hold about you.

Correct it. Tell us what is wrong and we will fix it. You can change most of your account details yourself in Settings.

Delete it. Ask us to delete your account and your data. We will do it unless the law requires us to keep something, such as invoices for tax.

Restrict or object. If you dispute the accuracy of your data you can ask us to pause using it. You can also object to anything we do on the basis of legitimate interests, including product update emails.

Take it elsewhere. Ask us for your data in a structured format you can give to another provider.

If your details are in someone else's file. These rights cover the data Operelio holds about you as a customer or visitor. If your details appear in a file another customer uploaded, that customer controls the file, so we will pass your request to them rather than acting on it ourselves.

We do not make automated decisions about you that have legal or similarly significant effects.

If you are in California

We do not sell your personal information and we do not share it for cross-context behavioral advertising.

Using any of these rights will never affect your price or your service. If we refuse a request you can appeal, and you can appoint someone to make requests for you.

To use any of these, email hello@operelio.com from the address on your account. We reply within 30 days. If a request is complicated we may need longer, and we will tell you if that happens. You can also complain to the Information Commissioner's Office in the UK, or to your local data protection authority in the EU.

Cookies

Cookies and tracking

The only cookies we set by default are the authentication cookies from Clerk, our sign-in provider. Because signing in has to work from any page, Clerk runs across the whole site, so a small authentication cookie can be set before you ever sign in. It is strictly necessary for sign-in to work and it identifies nobody until you actually do.

We do not use advertising cookies, retargeting scripts, or social media tracking pixels. There are none on any Operelio page.

Our analytics provider, PostHog, is configured to store nothing on your device. It keeps no cookie and writes nothing to local storage. We chose that deliberately, so that browsing operelio.com does not require a cookie banner.

Our live chat sets its own cookies, so we do not load it until you click to open a chat. If you never open it, nothing from the chat provider is loaded and no cookie is set.

Data transfers

Where your data goes

Operelio runs in the UK and the EU, and your files are not sent outside them to be processed or stored.

Some of the services that support Operelio, such as sign-in and payments, are US companies. Where personal data reaches one of them, the transfer is covered either by the company's certification under the EU-US Data Privacy Framework and its UK Extension, or by Standard Contractual Clauses with the UK Addendum. Our sub-processor page says which applies to each one, and the transfer terms are carried by our Data Processing Agreement. If you would like a copy of the clauses that apply to a particular provider, email hello@operelio.com and we will send them.

Other details

Other things worth knowing

If there is a breach. If someone gets access to personal data they should not have, we tell the relevant authority within 72 hours where the law requires it, and we tell you without undue delay. We will say what happened, what data was involved, and what we are doing about it.

Children. Operelio is not for anyone under 16. We do not knowingly collect data about children. If you think we have, email security@operelio.com and we will delete it.

Changes to this policy. If we change something that matters, we will email you or tell you in the product at least 30 days before it takes effect.

Contact

Privacy questions and data requests

For data questions or requests, email hello@operelio.com. For security issues, email security@operelio.com.

Operelio Ltd is registered in England and Wales, company number 17343466. Registered office: 66 Paul Street, London EC2A 4NA. We are registered with the Information Commissioner's Office, registration number ZC214944.