Last updated: August 13, 2026
1. Who We Are
OpsPanel is operated by App Ranch. If you have any questions about this policy, contact us at hello@opspanel.app.
2. What We Collect
We collect the minimum data needed to run the service:
- Your email address (for authentication)
- Your display name and panel name (optional, set by you)
- Your tasks and related data (titles, subtitles, notes, completion status, dates, priorities)
- Optional context you write for connected assistants (role, goals, working style, avoid list)
- Records of which chatbots you connected, the permissions you granted, and each time they accessed your data
- Payment information (processed by Stripe — we never see or store card numbers)
3. How We Use Your Data
Your data is used solely to provide the OpsPanel service. We do not sell, rent, share, or analyse your data for advertising. We do not use analytics trackers, advertising pixels, or third-party scripts that monitor your behaviour.
4. Data Storage and Security
- All data is stored on Supabase infrastructure with TLS encryption in transit and AES-256 encryption at rest.
- Row Level Security (RLS) ensures your data is isolated at the database level — no other user or admin can access your tasks.
- Authentication is passwordless via magic links and one-time codes. We never store passwords.
5. Connected assistants (OpsPanel Connect)
If you connect a chatbot (Claude, ChatGPT, Perplexity, Cursor, VS Code or similar) via the MCP URL, that assistant can read or change your OpsPanel data only through https://opspanel.app/api/mcp, and only with the permissions you ticked. An OAuth token issued for that connection cannot read your database any other way.
- Connections are per-user. Nobody else's bot can see your list.
- You choose the scopes. You can widen or narrow them in Settings; the change applies on the next request, without connecting again.
- You can revoke a connection at any time. The next tool call is refused immediately.
- Every tool call is logged and visible to you in Settings. We do not send your tasks to any other party, and we do not log access tokens.
- The assistant you connected is a third party you chose. Their handling of the data they receive is governed by their own policy, not ours.
6. Payment Processing
Payments are handled by Stripe. We store your Stripe customer ID and subscription status but never your card details. Stripe's privacy policy applies to payment data: stripe.com/privacy.
7. Your Rights (GDPR)
If you are in the UK or EEA, you have the right to:
- Access a copy of all data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict processing
- Withdraw consent at any time
To exercise any of these rights, email hello@opspanel.app. We will respond within 30 days.
8. Data Retention
Your data is retained for as long as your account is active. You can delete individual tasks at any time. If you cancel your subscription and request account deletion, we will permanently erase all your data within 30 days.
9. Cookies
OpsPanel uses only essential cookies required for authentication (session tokens). We do not use tracking cookies, analytics cookies, or advertising cookies. See our Cookie Policy for details.
10. Third-Party Services
- Supabase — database and authentication
- Stripe — payment processing
- Resend — transactional email delivery
- Vercel — application hosting
No other third-party services have access to your data unless you explicitly connect an assistant via OpsPanel Connect.
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email. Continued use of OpsPanel after changes constitutes acceptance.