skip to content
✿ the small print

legal & policies

these describe how opia actually works today. if anything reads as unclear or wrong, please email us.

Privacy Policy

Last updated: 26th September 2026

Opia is a small social wishlist app run by Abbas Alibhai, based in London, United Kingdom (hereafter "we", "us", "Opia"). This page explains what data we collect, why, and what we do with it. The short version: only what the product needs to work, and we don't sell any of it.

If anything here is unclear, email abbasalibhai.business@gmail.com.


1. Who's the data controller?

Abbas Alibhai, a sole trader trading as Opia, is the controller.

Email: abbasalibhai.business@gmail.com

UK GDPR and the Data Protection Act 2018 apply.

EU users: Opia does not currently have a designated EU representative. If usage from the EU grows materially, this will be revisited.

Wherever you live, the rights in section 6 are honoured for anyone who asks.

2. What we collect

2.1 Account data

When you sign in:

  • Email address (always)
  • Display name and profile image (when you sign in with Google)
  • A handle you pick (e.g. @abbas)
  • Handles you've changed away from, so old links still find you
  • Your birthday (required at sign-up, see below)
  • Per-occasion dates you optionally provide (e.g. an anniversary)

Your birthday is mandatory to create an account. We ask for it for two reasons: (a) to check you are at least 13, which is Opia's minimum age (see section 8), and (b) so friends who follow you can see an upcoming birthday countdown if you choose to share it.

We never show your birthday year to anyone else. It is used only to check your age. You separately choose, from /settings, whether your month/day appears on your list page and in your friends' upcoming-occasion feeds. This is off by default. You can toggle it at any time.

2.2 Content data

The items you add to your wishlist: the link, title, photo, price, currency, category, priority and any note you write. A photo you upload is stored with the item. Items you take off your list are kept, marked as removed, so you can put them back.

When you paste a link, our servers fetch that shop page to read the product's name, photo and price. Some pages are fetched for us by a scraping service (see section 4). They get only the product's plain address, with anything extra taken off, and never a link that looks private. Nothing about you is sent with it. What we read is kept in a cache shared by everyone who pastes the same link, and read again when someone pastes it more than 7 days later.

To pick a background colour for each photo, our servers download the photo once and keep the colour's name. For a shop's photo, other than Amazon's, we also keep a copy, with its details stripped out, and show that instead (see section 2.4).

2.3 Relationship data

Who follows whom, and which items have been claimed by which user.

Opia never tells a list's owner who claimed what, or how much is claimed. Friends who are signed in can see that an item is claimed, and the first letter of the name of the first person who claimed it. Nothing about claims is shown to anyone who isn't signed in.

Following someone isn't secret. They're told who started following them, on Opia and, if they've turned it on, by email or notification.

Pooling money for a gift isn't ready yet. If you tap "pool it with friends" on something on a friend's list, we keep your account email against that item so we can tell you when it is. The list's owner never sees this.

2.4 Technical data

  • Sign-in cookies (see section 7). Each session is also stored on our side with the IP address and browser details (user agent) it started from.
  • Cookieless product analytics and error reports via PostHog. Nothing is stored on your device, IP addresses are discarded, and there are no advertising identifiers. It records which buttons and links are used, with their text hidden. It records when things happen, like an item being added or a list being shared, without saying whose or which. When something breaks, it records what failed and on which page, with email addresses taken out. None of it is linked to your account.
  • Request logs kept by our host, Netlify: IP address, browser details, the page requested and the time. We use them for security and fixing faults.
  • A record each time a scraping service fetches a page for your account, with the shop's web address, so we stay within the services' limits.
  • To stop abuse, we count how often each IP address and each account does things like ask for sign-in links or add items. We keep the count against a one-way code rather than the address itself, and delete it after a day.
  • Product photos on a list are copies we keep on Cloudflare, so the shop doesn't see who looks at them. Amazon's photos are the exception: they load straight from Amazon, which sees your IP address and browser details when you view a list.

2.5 What we don't collect

  • We never read your phone book / contacts.
  • We don't share or sell email lists.
  • We don't show ads, and we don't load anyone else's tracking script on our pages. Links to shops only carry affiliate tracking if you agree to it (see section 7).

2.6 Search engines and personal wishlists

Personal wishlist pages (e.g. opia.social/your-handle) are unlisted by design. Anyone with the link can view them, signed in or not. They see your name, your profile photo, your list with its items and notes, and your birthday's day and month if you share it. Every list page tells search engines not to index, archive or quote it, with a noindex tag and an X-Robots-Tag header. Marketing and legal pages remain crawlable. Handing the link to a friend won't put your list in a Google search.

Note: Opia cannot force a misbehaving bot to honour these directives, and we cannot retroactively remove your URL from a search engine that ignored them. If you ever discover your list indexed somewhere it shouldn't be, email abbasalibhai.business@gmail.com and we'll help you file the relevant removal request.

2.7 Notifications

Notifications on a device are off until you turn them on, when you sign up or in /settings, and allow them when your browser asks. Once you do, claim reminders are on for that device. Friends' occasions, new followers and the weekly digest stay off until you turn each one on. Your browser gives us an address and keys for sending to that device. The address belongs to your browser's push service (Google, Apple, Mozilla or Microsoft). We store those, a name for the device (like "iphone · safari") and when you added it. Remove a device from /settings at any time.

The emails about friends' occasions, new followers and the weekly digest are off until you turn each one on. Each of those emails has a link that turns it off. Turning one back on means signing in.

Each time you turn one of these on or off, we record when, where you did it (sign-up, settings or an email link) and what you were shown.

2.8 Your choice about shop links

When you sign up, we ask whether the shop links you open can be affiliate links. We record your answer, when you gave it and where. You can change it any time in /settings. Section 7 and the Affiliate Disclosure explain what each answer means.

3. How we use it

PurposeLawful basis (UK GDPR Art. 6)
Run Opia: your account, list and profile page, sign-in, following, claimsContract (Art. 6(1)(b))
Read product details from links you paste, including through a scraping service, download a photo once to pick the background colour behind it, and keep copies of shop photosContract (Art. 6(1)(b))
Sign-in emails, and claim reminders by email and notificationContract (Art. 6(1)(b))
Emails and notifications about friends' occasions, new followers and the weekly digestConsent (Art. 6(1)(a)). Withdraw it any time in settings or from the email.
Earn commission on links to shopsConsent (Art. 6(1)(a)), given in the shop links choice. Say no and links go straight to the shop.
Measure how Opia is used, in aggregate, and find what breaks (PostHog)Legitimate interests (Art. 6(1)(f)): learning which parts of Opia work, without identifying anyone. Object by email.
Keep Opia secure: session records, request logs, limits on scraping, sign-in and other actionsLegitimate interests (Art. 6(1)(f)): stopping abuse and fixing faults.
Check you are 13 or overLegitimate interests (Art. 6(1)(f)): keeping under-13s off a service not built for them.
Answer requests about your data, and keep records of consentLegal obligation (Art. 6(1)(c))

We do not engage in automated decision-making or profiling with legal effect.

4. Who receives your data

Processors handle data for us, on our instructions, under a data processing agreement:

ProviderWhat they doWhere, and the safeguard for data leaving the UK
NetlifyHosts the site, runs its code, keeps request logsUS (Ohio). The UK Extension to the EU-US Data Privacy Framework
NeonDatabase for your account and listsUS (Ohio). The UK Extension to the EU-US Data Privacy Framework, and the UK Addendum to the EU standard contractual clauses
ResendSends every emailUS. The EU standard contractual clauses with the UK Addendum, and the UK Extension to the EU-US Data Privacy Framework
PostHogCookieless analytics and error reportsEU (Frankfurt). The UK's adequacy regulations for the EEA
CloudflareStores and serves copies of product photosUS, or where Cloudflare's network serves you. The UK Extension to the EU-US Data Privacy Framework, and the UK Addendum to the EU standard contractual clauses

Scraping services fetch shop pages for links you paste. They get a plain product link with anything extra taken off, never who pasted it, and never a link that looks private:

ProviderWhere
ZenRowsSpain
Scrape.doUS

Others receive some data and decide themselves how to use it, under their own privacy policies:

WhoWhat they receive
GoogleYour sign-in, if you use Sign in with Google. Your browser loads your Google profile photo from Google.
SkimlinksIf you've agreed to affiliate links: the shop links you open, and the page you opened them from.
AmazonIf you've agreed to affiliate links: that you arrived from Opia, when you open an Amazon UK link.
Shops (including Etsy, eBay and Steam's product APIs)Requests from our servers for product pages, details and photos. Your IP address, when your browser loads a product photo from Amazon.
Browser push services (Google, Apple, Mozilla, Microsoft)Encrypted notifications for devices you turn on.

5. How long we keep it

  • Account data: while your account is active. When you ask to delete it, it's hidden from everyone at once and you're signed out everywhere. Your notification devices are deleted then too. Nothing else is erased for 30 days, and signing in and confirming stops the deletion. After 30 days we delete your profile, lists, items (including ones you took off), every claim you made, follows in both directions, occasions, your notification and shop link choices with their records, and the log of what we sent you. Your handle is then free for someone else.
  • What stays after deletion: the records of scraping-service fetches. Your account is removed from them at once. After 30 days no record links to anyone, and each holds only a shop's web address and how the fetch went. We delete them after 12 months.
  • Backups: our database keeps a restore history for 6 hours. Deleted data drops out of it after that, and we never restore a backup over a deleted account.
  • Claims: kept while the claimer's account exists, including claims that ended.
  • Asking to hear about pooling: your email against the item is kept while your account exists, or until pooling launches and we've told you.
  • Items you take off your list: kept, marked as removed, until you delete your account.
  • Handles you've changed away from: kept for 30 days, so old links still find you and nobody else can take the name in the meantime. After that the record is deleted. Changing your handle again, or deleting your account, removes it sooner.
  • Sessions: a session lasts until you sign out, or 7 days after you last used it. Its record, with the IP address and browser details, is deleted when it ends.
  • Sign-ups: if sign-up stops someone for being under 13, the account they started is deleted straight away. A sign-up that isn't finished is deleted after 30 days.
  • Request logs: kept by Netlify for 1 day.
  • Emails we sent you: our email provider, Resend, keeps a copy of each one, with your address, for 30 days, then deletes it. Deleting your account doesn't reach those copies sooner.
  • Abuse counters (see section 2.4): a day.
  • Sign-in links: deleted when you use one, or within a day of it expiring.
  • Analytics: PostHog keeps usage events and error reports under its retention for our plan, currently a year of history. They carry no IP address, no cookie and no account, so they can't be linked back to you.
  • Copies of product photos: kept while any list uses them. They are photos of products, not of anyone.
  • Link preview cache: kept for 30 days after a page was last fetched. It holds what shop pages show publicly, read from a plain product link. Email us to remove an entry sooner.
  • Affiliate click data: handled by Skimlinks and Amazon under their own retention terms.
  • Notification devices: until you remove one, the browser stops accepting notifications, or you ask to delete your account.
  • A note of each notification we sent you, so the same one is never sent twice: while your account exists.

6. Your rights

Under UK GDPR you can ask us to:

  • Access the data we hold about you
  • Correct anything that's wrong
  • Delete your account and associated data
  • Export your data in a portable format
  • Object to or restrict specific processing, including analytics
  • Withdraw consent for any email, notification or affiliate link you agreed to, from /settings or the link in the email

From the danger zone in /settings you can delete your account and download a copy of your data. The download leaves out a few things you can still ask for, like your session records and the log of notifications we sent. For anything else, email abbasalibhai.business@gmail.com. We'll answer within one month, or tell you within that month if a complex request needs up to two more.

Neither the download nor an emailed request includes who claimed things from your list. That's information about the people who claimed, and handing it over would affect their rights.

If you're unhappy with how we've handled your data, tell us first and we'll try to put it right. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

7. Cookies

CookiePurposeLastsType
__Secure-better-auth.session_tokenKeeps you signed in7 days from last useStrictly necessary
__Secure-better-auth.session_dataSaves a database check on each page60 secondsStrictly necessary
__Secure-better-auth.stateProtects Sign in with Google against forged requests5 minutesStrictly necessary
Skimlinks cookie, on Skimlinks' own site after you click a shop linkLets the shop tell the sale came from OpiaSet by Skimlinks' policyAffiliate tracking, only if you agree
Amazon cookie, on amazon.co.uk after you click an Amazon UK linkLets Amazon tell the sale came from OpiaSet by Amazon's policyAffiliate tracking, only if you agree

The cookies Opia sets itself are only the three sign-in cookies above. Analytics stores nothing on your device.

When you sign up, we ask whether the shop links you open can be affiliate links. Say yes and a link goes through Skimlinks, or to Amazon with our tag, and that network may save a cookie on its own site so the shop knows the sale came from Opia. Say no and links go straight to the shop. Either way the price is the same. Change your mind any time in /settings.

Our website contains affiliate links, which means we earn a commission on some purchases made through them. We use Skimlinks and its affiliates (the "Skimlinks Group"), and more about how they collect and use data is in their privacy policy: https://skimlinks.com/privacy-policies/end-users/

Turning on notifications installs a small script in your browser, a service worker, whose only job is to show them. It keeps nothing about you. Your browser holds the notification address it gave us.

8. Children

Opia is not for under-13s. Sign-up asks for your birthday and stops anyone under 13. When it does, the account they started is deleted. If you believe a child under 13 has signed up anyway, email abbasalibhai.business@gmail.com and we'll delete the account.

9. Security

Opia has no passwords. You sign in with a one-time email link or with Google. Your browser holds only a random session token, in a cookie page scripts can't read, and we check the session on our side. Before our servers fetch a link you paste, they check it points at a public website. Neon, our database host, encrypts the data it stores, and connections to it are encrypted too. On top of that, your email address, birthday, sign-in links and the IP address and browser details of your sessions are encrypted by Opia before they reach the database, with keys the database never sees.

No service is unbreachable. If a breach puts people's data at risk, we'll report it to the ICO within 72 hours of finding out (UK GDPR Art. 33). If it's likely to put you at high risk, we'll tell you directly, without undue delay (Art. 34).

10. Changes

If we change this policy in a way that matters, we'll email registered users before the change takes effect, and update the date at the top. This policy tells you what we do. It isn't something you agree to. Where a change needs your consent, we'll ask for it.

11. Contact

Abbas Alibhai · London, UK
Email: abbasalibhai.business@gmail.com