Skip to content
OPTOPUS
  • Home
  • Marketing
  • Design & Advertising
  • Web Design
  • OPTOPUS AI
  • About
  • Contact
|
  • Home
  • Marketing & Digital
  • Design & Advertising
  • Web Design
  • OPTOPUS AI
  • About
  • Contact

Legal

Privacy Policy

Last updated: September 2026

Who this policy covers

This policy explains how OPTOPUS handles personal information on optopus.space, including the OPTOPUS AI workspace at /ai. It describes what the system does today, not what we might do in future; if that changes, we will update this page first.

The official channel for any privacy question or request is info@optopus.space.

This policy governs the processing of personal data and our privacy practices. Our Terms of Service govern use of the website, OPTOPUS services and the contractual relationships that arise from them. Each document regulates different matters, and they should be read together.

Using the public site

You can visit optopus.space without an account. Browsing the public pages does not require you to give us any personal information, and the site does not use analytics, advertising or marketing cookies or scripts. The exact cookies and browser storage in use are listed in our Cookie Policy.

Some pages load fonts or a graphics library from other services (Google Fonts, jsDelivr); loading them sends your IP address to those services, as with any web resource. Our application code does not record page visits.

Contact and “Start a Project” forms

The “Start a Project” forms (in the header menu and on the Contact page) send what you type — your name, email, company, area of interest, project description, goals, budget, timeline and how you found us — to our server, which emails it to info@optopus.space through our email service. OPTOPUS does not store the submission in its own database or use it for anything else; it is kept like any email in that mailbox, and your email address is set as the reply address so we can answer you. Our server logs record only that a form was sent (never its content). To limit spam and abuse, each IP address can submit only a few times per hour and per day (counted in memory), and the forms include a hidden anti-spam field. You can also write to us directly at info@optopus.space.

If you email us, we receive the address and the content you send, and use them to reply to you.

Your OPTOPUS AI account

OPTOPUS AI requires an account to send messages or create, change or delete anything; without one you can only look around a read-only demo. When you create an account we store:

  • your email address;
  • your password, only as a salted one-way hash (we cannot read it);
  • the time the account was created and the time you confirmed you are 18 or older;
  • your marketing choice (off unless you turned it on — see “Marketing”).

Logging in sets a session cookie (optopus_session) that keeps you signed in for up to 30 days or until you log out.

Age: 18 and older

OPTOPUS AI is available to users 18 and older. While OPTOPUS AI uses the Gemini API, we do not allow anyone under 18 to use the AI chat. When you create an account you must confirm that you are 18 or older, and accounts created before this rule must confirm it before using OPTOPUS AI; the chat does not work until then. The rest of the site remains open to everyone.

This is a confirmation you give us, not a check against an identity document. If you believe someone under 18 has an account, email info@optopus.space and we will delete it.

What OPTOPUS AI stores

Everything below is stored on our server, tied to your account, and stays until you delete it (see “Retention and deletion”). It does not disappear when you close the tab or log out.

  • Conversations (“Recents”): the messages you and OPTOPUS AI exchange in standalone chats, up to the latest 40 messages per conversation.
  • Projects: the project name; its memory (notes and fields, including anything you ask OPTOPUS AI to “remember”); the project’s chat history; the artifacts OPTOPUS AI creates for you (every version); and its task history.
  • Files: files you upload (up to 15 MB; text, Markdown, CSV, JSON, PDF, DOCX, PNG, JPEG, WebP) are kept on our server together with the text we extract from documents. Images are stored but their content is not read.
  • Usage records: for each AI request, technical details only — time, capability, provider name and mode, duration, token counts and related ids. They contain no message text.

If our server is briefly unreachable, your browser may keep a working copy of your projects and conversations in local storage (optopus-ai:projects, optopus-ai:conversations, optopus-ai:user). These are cleared when you log in, log out or delete your account.

AI providers: what is sent

When you send a message, our server (never your browser, and never with your account credentials) sends this to the AI provider so it can reply:

  • your message, and up to the last 12 messages of that chat;
  • your site language (English or Spanish);
  • if you are working in a project: the project name, its saved memory fields, the titles of recent artifacts, and — only when your message reads like a follow-up — the text of one relevant earlier artifact (up to about 2,000 characters);
  • only when your message refers to a file you uploaded: that file’s name and the first ~2,000 characters of its extracted text.

We do not send your email address, password, account id, IP address, uploaded files as files, images, or content from projects you are not using. Our provider keys are held only on the server.

Provider today: Google Gemini API, unpaid (free) tier. We cannot promise that data sent to Gemini is private. Google’s published terms for its unpaid Gemini API service say that submitted content may be used to improve Google’s products and may be reviewed by people; see Google’s Gemini API terms. Please do not send passwords, financial or health information, or other people’s confidential information to OPTOPUS AI.

The software can also use the OpenAI API (the developer API, not the ChatGPT app) in place of Gemini if it is configured; it is not the provider in use today. If we change or add a provider, we will update this page. Data already sent to a provider is governed by that provider’s terms and we cannot delete it from their systems.

If the provider returns an error or does not respond within the time limit, you see a plain error message and can try again; no substitute answer is generated, and the message may already have reached the provider, so a retry sends it again. Built-in demo responses, produced on our own server with nothing sent to a provider, are used only when no provider is configured. OPTOPUS does not sell your data and does not train its own AI models on it.

How we use your information

We use it to run your account and OPTOPUS AI (showing your conversations, projects and files back to you and generating replies), to keep the service secure and prevent abuse (login protection and request rate limits), and to answer the requests you send us. We do not use it for advertising.

Server logs and security

Our server writes operational logs to its standard output. They record technical details — a browser identifier, account and project/conversation ids, durations, token counts and errors — and never message text, file contents or keys. Failed login attempts are logged with the email that was typed and the IP address. OPTOPUS does not keep its own log files; how long the hosting platform retains its output is up to that platform. Request rate limits are counted in memory by browser identifier and by IP address. As platform and security limits (not guarantees, and they may change), an account can make up to 300 OPTOPUS AI requests in any 24-hour period and can have up to 10 active login sessions at once; signing in beyond that ends the oldest session. The 24-hour count is taken from the usage records described above.

Passwords are stored as salted hashes, the session cookie is HttpOnly and SameSite=Lax (and Secure over HTTPS), and each account can only read and change its own data. No system is perfectly secure, so we cannot guarantee absolute security.

Retention and deletion

We keep your data until you delete it; we do not set a fixed expiry for account content.

  • Delete a conversation — removes its messages.
  • Delete a project — removes its memory, chat history, artifacts (all versions), tasks and files, including the stored file bytes.
  • Delete an artifact — removes every version of it.
  • Delete a file — removes the record, the extracted text and the stored file.
  • Delete a memory item — erases its content from the project’s memory.
  • Delete your account (OPTOPUS AI → Settings → Privacy & data → Delete my account; your password is required) — permanently removes the account, all your projects, conversations, files, memory, artifacts, tasks, usage records and login sessions.

You can also send a valid deletion request to info@optopus.space; we may ask you to confirm you control the account email, and we will delete the same data. Usage records (technical details only) are kept until the account is deleted.

Login sessions last 30 days at most; expired sessions are deleted automatically. When your browser first uses OPTOPUS AI, a random identifier and its creation time are stored on our server; it holds no personal data and is not linked to your account. Emails you send us are kept like any email until you ask us to delete them. Data already sent to an AI provider stays under that provider’s terms.

Marketing

OPTOPUS does not currently send marketing emails. Creating an account, using OPTOPUS AI or contacting us does not subscribe you to anything. When you create an account there is an optional box, unticked by default, to say you would like news and offers by email. You can turn that choice on or off at any time in OPTOPUS AI → Settings → Privacy & data, or by emailing info@optopus.space. We will only send marketing to accounts that have opted in, and we stop when you withdraw.

Your choices and rights

You can look at, change and delete your OPTOPUS AI data yourself, as described above. Depending on where you live you may have additional rights over your personal information, such as access, correction or portability. To exercise any right, or to make any privacy request, write to info@optopus.space.

Other countries

The AI providers named above may process the data we send them in countries other than yours.

Changes to this policy

When how OPTOPUS handles data changes, we update this page and its “Last updated” date. Questions: info@optopus.space.

OPTOPUS

Try something great.

  • Marketing & Digital
  • Design & Advertising
  • Web Design
  • OPTOPUS AI
  • About
  • Contact

© OPTOPUS. All rights reserved.

Start a Project

Tell us about your idea.
Let’s make it real.

Budget range

Project received

Thank you. We’ve received your project information.

We’ll be in touch with you soon.