Privacy Policy
Last updated: 2026-06-17
This Privacy Policy explains how Opora collects, uses, stores, and shares personal information in connection with the Opora platform at oporasupply.com. It covers AI tool usage, account data, anonymous sessions, and the third-party services that process your data on our behalf.
By using the platform, you acknowledge that you have read and understood this policy. If you have questions, contact us at [email protected].
Effective date: 2026-06-17
1. What data we collect
We collect only what we need to operate the platform. Here is what that includes.
1.1 Account data (authenticated users)
- Email address — provided at registration, used for magic-link authentication and transactional email. Managed by Clerk.
- Display name — optional, provided during profile setup. Stored in our database (Cloudflare D1).
- Authentication metadata — session tokens, login timestamps, last-active timestamp. Managed by Clerk; audit events logged in our D1 database.
- Account preferences — default settings, notification preferences. Stored in D1.
1.2 Tool inputs and outputs (Artifacts)
- Tool prompts and inputs — the text, data, and other content you submit to any Opora tool. Transmitted to our AI sub-processors for generation (see Section 5), then stored in D1 as part of your Artifact history.
- Artifacts — generated outputs saved to your library. Stored in Cloudflare D1. You control their deletion via your account settings.
- Vector embeddings — semantic representations of your saved Artifacts, stored in Cloudflare Vectorize to power semantic search in your library. Embeddings do not contain raw text — they are mathematical representations used only for search relevance.
- Voice audio — recordings submitted to the Voice Walkthrough tool. Stored in Cloudflare R2 with a 30-day automatic expiration. Not shared with third-party AI models beyond transcription.
1.3 Usage analytics
- Tool run events — which tools you run, timestamps, success/error status. Stored in D1. Used for your personal analytics dashboard and for platform monitoring.
- Session activity — page views, feature interactions. Collected by Google Analytics 4 if you have accepted analytics cookies (see Section 8).
1.4 Anonymous session data
- Rate-limit fingerprint — a short-lived identifier derived from technical signals (IP address range, browser characteristics) used solely to enforce per-session tool limits. Not stored beyond 90 days in operational logs. Not linked to your identity. Not shared with any third party.
- No other data is persistently collected from Anonymous Sessions.
1.5 Communications
- Transactional email — emails we send you about your account, tool activity, and platform updates. Routed through Klaviyo.
- Marketing email — newsletters and product updates. Sent only if you opt in. You can opt out at any time via the unsubscribe link in any marketing email or through your account notification settings.
- Feedback and support — messages you send us directly. Stored in our D1 feedback table.
2. How we use your data
We use your data to run the platform, communicate with you, and keep things secure.
- Provide the platform — authenticate you, run tools, save Artifacts, power semantic search via vector embeddings.
- AI generation — transmit your prompts to the AI sub-processor handling the relevant tool (Anthropic, OpenAI, or Cohere) to generate outputs. See Section 3 and Section 5 for details.
- Transactional email — send you account confirmations, magic links, limit warnings, and artifact-saved notifications via Klaviyo.
- Optional marketing email — send newsletters and product updates if you opt in. Each marketing email includes a one-click unsubscribe.
- Product analytics — understand how tools are used in aggregate to improve the platform.
- Security and rate limiting — enforce per-user and per-session limits, detect abuse, prevent unauthorized access.
- Legal compliance — comply with applicable law and respond to lawful requests from authorities.
3. AI-specific disclosures
Our AI tools transmit your prompts to third-party AI model providers. Here is what you need to know.
3.1 Which providers handle your prompts. Depending on the tool you use, your input may be processed by Anthropic (Claude), OpenAI, or Cohere. The specific sub-processor for each tool is identified in the tool's description page.
3.2 No model training on your data. Under the default terms of the APIs we use, your prompts and outputs are not used to train the underlying third-party AI models. If those providers ever change their default terms in a way that affects this, we will update this policy and notify you.
3.3 Vector embeddings. Artifacts in your library are converted to vector embeddings by Cohere and stored in Cloudflare Vectorize. These embeddings are used solely for semantic search within your own library. Embeddings are deleted when you delete the associated Artifact or your Account.
3.4 Voice audio. Recordings submitted to the Voice Walkthrough tool are stored in Cloudflare R2. Audio files are automatically deleted after 30 days. They are used only to produce the walkthrough transcript and output — not for any other purpose.
3.5 Magic link authentication. Your email address is your only credential. We do not store passwords. Clerk manages authentication — see the sub-processors table in Section 5.
4. Anonymous tracking disclosure
If you use the platform without an account, we use a fingerprint-based rate-limit signal to enforce tool limits. This signal:
- Is derived from technical characteristics of your request (IP range, browser signals), not from any personally identifying account data.
- Is not a persistent identifier — it is not stored in a user profile and does not survive session boundaries.
- Is not used for cross-site tracking, advertising profiling, or any purpose beyond abuse prevention on oporasupply.com.
- Is retained in operational logs for up to 90 days, then purged.
5. Sub-processors
These are the third-party services that process data on our behalf. We have agreements with each that require them to protect your data.
| Sub-processor | Data processed | Purpose | Jurisdiction | Policy |
|---|---|---|---|---|
|
Cloudflare (Workers, D1, KV, R2, Vectorize) |
All user content, account data, embeddings, voice audio | Compute, database, key-value store, file storage, vector index (CDN and edge infrastructure) | US | Cloudflare Privacy Policy |
| Clerk | Email address, display name, authentication metadata | Authentication, magic link delivery, session management | US | Clerk Privacy Policy |
| Anthropic | User prompts and tool inputs | AI generation (Claude models) for Handbook Drafter, Ask Opora, and other tools | US | Anthropic Privacy Policy |
| OpenAI | User prompts and tool inputs | AI generation and embeddings for Bid Drafter, RFP Decoder, and other tools | US | OpenAI Privacy Policy |
| Cohere | Text from saved Artifacts | Embedding and reranking for semantic search (Vectorize index) | Canada / US | Cohere Privacy Policy |
| Klaviyo | Email address, display name, behavioral events | Transactional and marketing email delivery | US | Klaviyo Privacy Notice |
| Google (Workspace) | Email (operator-side only — not user data) | Internal operator email and support communications | US | Google Privacy Policy |
| SAM.gov | Federal contracting search queries (no PII) | Win history overlay and RFP search (no personal data transmitted) | US | SAM.gov Privacy |
| Shopify | Page rendering, customer accounts (e-commerce) | E-commerce platform (storefront, checkout, customer accounts) | Canada / US | Shopify Privacy Policy |
We will provide at least 15 days' advance notice before adding a new sub-processor that processes personal data. Notification is delivered via your account email and a platform banner.
6. International data transfers
Opora Supply is operated from the United States. The sub-processors listed above are primarily US-based, with Cohere operating from Canada as well as the US and Shopify from Canada.
If you access the platform from the EU, UK, or EEA, your data may be transferred to and processed in the United States. For such transfers, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms where SCCs are not the applicable mechanism (such as the UK International Data Transfer Agreement for UK transfers).
Cohere's cross-border transfers between Canada and the US fall within adequacy decisions or equivalent safeguards applicable to Canada.
7. Data retention
We keep your data for as long as your Account is active, and purge it on deletion.
- Active accounts — account data, Artifacts, embeddings, and usage logs are retained for as long as your Account exists.
-
Deleted accounts — on account deletion, a 30-day purge cycle begins. Account data, Artifacts, embeddings, and associated records are permanently deleted within 30 days of the deletion request. The API response to your deletion request includes a
retention_noticefield confirming this timeline. - Voice audio — automatically deleted from R2 storage after 30 days, regardless of account status.
- Anonymous sessions — rate-limit fingerprint signals are retained in operational logs for up to 90 days, then purged as part of standard log rotation.
- Audit log — account-action audit events (account creation, deletion, export) are retained for up to 2 years to support security investigations and legal compliance, even after account deletion.
8. Cookies
We use three categories of cookies. You can manage your preferences at any time using the "Cookie preferences" link in the site footer.
- Essential — required for the platform to function (session management, authentication, rate-limit fingerprint, consent record). Cannot be disabled.
- Analytics — Google Analytics 4 cookies that help us understand how the platform is used. Default OFF — enabled only with your consent.
- Marketing — Klaviyo web-tracking cookie used for email list matching. Default OFF — enabled only with your consent.
Full cookie inventory, third-party cookie details, and opt-out instructions are in our Cookie Policy.
9. Your rights
You have rights over your data. Here is how to exercise them.
9.1 GDPR rights (EU / UK / EEA residents)
- Access — request a copy of the data we hold about you.
- Rectification — request correction of inaccurate data.
- Deletion (right to erasure) — delete your Account and all associated data via /account/settings/data.
- Portability — export your data as a JSON package via /account/settings/data.
- Opt-out of marketing — use the unsubscribe link in any marketing email, or adjust notification settings in your account.
- Withdraw consent — where we rely on consent (marketing email, analytics cookies), you may withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — if you believe we have not handled your data lawfully, you may lodge a complaint with your local supervisory authority.
9.2 CCPA rights (California residents)
- Know / access — the right to know what personal information we collect, use, and share.
- Delete — as above (account deletion initiates a 30-day purge).
- Correct — the right to correct inaccurate personal information.
- Opt-out of "sale" or "sharing" — to the extent any advertising cookies or cross-context behavioral tracking constitutes a "sale" or "sharing" under the CCPA/CPRA, you can opt out via our Your Privacy Choices page or by enabling a Global Privacy Control (GPC) signal in your browser. We do not sell personal information for monetary consideration.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
9.3 Other US state rights
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar access, deletion, correction, and opt-out rights. Contact us to exercise them.
9.4 How to contact us
Email [email protected] with the subject line "Privacy Request." We will verify your identity and respond within 30 days (or as required by applicable law).
10. Children's privacy
The platform is intended for users 18 and older. Account creation requires confirming you are at least 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has created an account, contact us and we will delete it promptly.
11. Security
We apply technical and organizational measures appropriate to the sensitivity of the data we handle.
- Encryption in transit — all connections to the platform use TLS 1.3.
- Secrets management — API keys and credentials are stored as encrypted secrets in Cloudflare Workers, never in source code.
- Audit logging — account lifecycle events (creation, deletion, export) are recorded in a tamper-resistant audit log.
- Rate limiting — per-user and per-session limits prevent abuse and protect platform availability.
- Branded error handling — API errors return structured envelopes with a request ID for tracing; raw stack traces are never exposed to end users.
No system is perfectly secure. You are responsible for maintaining access to the email address associated with your Account.
12. Breach notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach, consistent with GDPR Article 33 obligations. Notification will be sent to the email address associated with your Account and, where required, to the relevant supervisory authority.
13. Changes to this policy
We may update this Privacy Policy when we change our data practices or to reflect new legal requirements. When we do:
- The "Last updated" date at the top of this page will change.
- For material changes, we will send notice to your Account email and display a banner on the platform at least 30 days before the change takes effect.
14. Contact
For privacy questions, data subject requests, or breach reports:
Opora
Atlanta, Georgia
Email: [email protected]
Website: oporasupply.com
Effective date: 2026-06-17. This version supersedes all prior Privacy Policies.
