The four legal documents, together
Privacy, terms, subprocessors and data retention, on one page: what each document covers, with its full authored text beneath.
Privacy Policy
Last revised: 20 August 2026.
This policy describes how personal data is processed in the Operifex service at operifex.com. It is written to be read, not filed: where the service does not yet do what it should, the text says so rather than leaving it out.
1. Data controller
The controller is the individual identified below, who runs the service as a sole trader. No company has been incorporated.
- Name
- [[NOME LEGAL COMPLETO PENDENTE]] — sole trader (empresário em nome individual)
- Tax number (NIF)
- [[NIF PENDENTE]]
- Registered address
- [[MORADA FISCAL PENDENTE]]
- Privacy contact
- privacidade@operifex.com
No data protection officer has been appointed, because none of the conditions in Article 37 GDPR applies. Any question about personal data should go to the address above.
2. What data is processed
The following list was derived from the service’s own code and database structure, not from a generic description.
- Email address, preferred language and the date the account was created. Account signup is open to anyone and is passwordless, through an email link.
- The state of access to artificial-intelligence features associated with the account.
- Conversation content: every question you write and every answer generated are stored in our database, linked to your account.
- The knowledge files and preferences you save, with a record of each change.
- The Experts and apps you create, including instructions, specifications and published versions. It also covers work you saved under the previous structure before 8 August 2026, which was archived rather than destroyed.
- Per-session usage records: start, end, and the number of text units processed. Neither your IP address nor your browser identifier is stored.
- Email the service sends on your instruction, with recipient and subject, and mail received at addresses on the domain.
- Approvals for sensitive operations, together with the request that raised them.
- The record of shares other accounts granted to your address, with what was shared and when. It is an audit record belonging to the account that granted the share, so it outlives the erasure of your own account; at that point your address is replaced by a pseudonym. It is covered in section 9 and in the Retention Periods document.
Your IP address is used only in memory, during the request itself, to limit repeated access attempts. It is written to no table. Your email address may, however, appear in the server’s technical logs.
3. Purposes and legal bases
Performance of the contract, Article 6(1)(b): creating and maintaining the account, authenticating access, carrying out the requests you make, keeping the work produced, and answering support requests.
Legitimate interests, Article 6(1)(f): keeping the service secure, limiting abusive authentication attempts, and keeping minimal technical records.
Compliance with legal obligations, Article 6(1)(c), where applicable, in particular when responding to lawful requests from public authorities.
No processing is carried out for advertising, for profiling, or to sell or otherwise transfer data to third parties. No analytics or tracking cookies are used: the service stores only a session identifier and your language and theme preferences, in your own browser.
4. Legitimate interests assessment
Where legitimate interests are relied on, the three-step assessment described in Opinion 28/2024 of the European Data Protection Board was carried out.
- Purpose: to keep the service available and sound, and to stop passwordless-link authentication being abused. These are specific, present and lawful interests, not a justification written after the fact.
- Necessity: the data processed on this basis is limited to the email address and to technical counters. Rate limiting uses the IP address only during the request and does not retain it. There is no less intrusive way to reach the same result.
- Balancing: the processing is what somebody creating and using an account would expect, it covers no special categories of data, it produces no automated decisions with legal effect, and it is not used to evaluate the person. Weighing against it is the prolonged retention described in the Retention Periods document, which is an acknowledged shortcoming and not a purpose.
You may object to any processing based on legitimate interests, under Article 21, by writing to the address in section 1.
5. Artificial intelligence: what happens to what you write
You are interacting with an artificial-intelligence system. That disclosure is required by Article 50 of Regulation (EU) 2024/1689, and it is also the reason to review any result before using it.
Model access is switched off on every account by default and is switched on individually, account by account, by a decision of the operator. While it is off, nothing you write reaches a model provider: requests are refused on the server, at a single checkpoint.
On accounts where it is switched on, the text you write is sent by our server to the model provider, Scaleway, a French company, through its Generative APIs, and the model used is GLM. The access key belongs to the service and never to your browser, so the provider does not receive your identity, only the text of the request.
Under Scaleway’s AI Specific Conditions, version 07/04/2026, article 4.4, the provider does not retain request content and does not use it to train models. That is a contractual statement by the provider, which we invoke and rely on; it is not an independent verification carried out by us.
Separately from answer generation by Scaleway, a web-search query may be sent to Perplexity through Sonar / Chat Completions. Only the query text is sent, without the account identity; the full terms of that processing are in the Subprocessors document.
Whatever the provider retains, Operifex keeps the conversation in its own database, as described in section 2. It is wise not to write into the service anything you would not want kept.
No decision is taken solely by automated means that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22.
6. Who else processes your data
The service relies on subprocessors for infrastructure, email, name resolution and answer generation. They are all identified, with their purpose and location, in the Subprocessors document.
Data is not sold, transferred or shared with third parties for those parties’ own purposes.
7. Transfers outside the European Economic Area
Cloudflare is a United States company with a globally distributed network, so processing may occur outside the European Economic Area, under the European Commission’s standard contractual clauses and the applicable adequacy framework.
Perplexity processes Sonar queries on AWS infrastructure in North America, in the United States, outside the European Economic Area. The transfer relies on the European Commission’s standard contractual clauses. We have not confirmed the exact region of Scaleway model inference, so we do not assert a specific location for that processing.
8. Retention
The periods, and what the service actually does today, are set out in the Retention Periods document. In short: apart from the fifteen-minute validity of the access link and the seven-day session, nothing is deleted automatically today.
9. Your rights
You have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21).
To exercise any of them, write to the address in section 1. A reply is given within one month, extendable by two further months in complex cases, with prior notice.
An honest note about erasure. An account-erasure procedure exists, it runs as a single database transaction and it also removes the account’s workspace on the server, but no button in this interface invokes it yet: a request sent to the address in section 1 is carried out by hand by the operator. Copies also exist in technical logs whose complete removal needs case-by-case checking.
Two things deliberately survive erasure, and both are described in the last two rows of the Retention Periods document. The first: the entries you published to the catalog stay published. Before an entry is published it goes through a process that makes it generic and strips private information from it, and it is credited only to a creator name that is not linked to your account; on erasure the link to the account is severed and the entry stays in the catalog. The second: the rows of the record of shares other accounts granted to your address are kept, with the address replaced by a pseudonym, so that the share stays provable without identifying anybody. The right is honoured and the deadline in the previous paragraph applies; what survives is named, not left out.
On portability: any published app exports as a single file that works with no account and no connection to the service.
If you consider the processing unlawful, you may complain to the Comissão Nacional de Proteção de Dados, the supervisory authority in Portugal, or to the authority of the Member State where you live.
10. Security
Access uses a single-use link valid for fifteen minutes, with no password. Connections are encrypted in transit. Provider keys stay on the server and are never sent to the browser.
No claims are made about certifications, external audits or isolation between accounts, because none of them is demonstrated today. Where the service improves on this, this document will be updated and the revision date changed.
11. Changes
Material changes are announced thirty days in advance, by message to the account address. The date of the last revision is at the top of this page.
Terms of Use
Last revised: 20 August 2026.
These terms govern use of the Operifex service. By creating an account and using the service, you accept them.
1. Who provides the service
The service is provided by the person identified in section 1 of the Privacy Policy, acting as a sole trader.
2. Access and price
Account signup is open to anyone and is automatic: the account is created without a password, through an email link. The only decision taken by a person is switching artificial intelligence on for the account.
At launch the service is free. There is no published pricing, no subscription and no payment method is asked for. If a price is introduced it will be announced in advance and will never apply retroactively to use already made.
Artificial intelligence is switched on individually, account by account, by a decision of the operator, and may not be available from the first day.
3. Your account
The account is personal. Access is by a link sent to your email, so the security of the account depends on the security of that mailbox. Tell us at once if you suspect misuse.
4. Acceptable use
The service may not be used for unlawful purposes, to process other people’s data without a valid basis, to attempt to circumvent technical limits or reach other accounts’ data, or to generate content that infringes third-party rights.
You are responsible for the content you enter and the instructions you give the service, including where they contain other people’s personal data. In that case you are the controller of that data towards the people it concerns.
5. AI-generated code and content
This is the most important section of these terms and it is written plainly.
The apps, calculations, text and code the service produces are generated by a language model from the description you supply. A language model produces the most likely result, not the correct one. The result may contain arithmetic errors, undeclared assumptions, invented references, security flaws or legal non-compliance, and it may do so while looking entirely convincing.
The result is provided as it stands, with no warranty of accuracy, of fitness for any particular purpose, of legal compliance, or of freedom from defects. No professional advice of any kind is given, in particular no engineering, legal, tax or accounting advice.
It is for you to review and validate the result before using it, publishing it, delivering it to a client, or running it against real data. That review is a condition of using the service, not a recommendation.
No liability is accepted for decisions taken on the basis of a generated result, or for harm caused by using it without review. What the service produces is a proposal for a piece of work; professional responsibility for the work you deliver remains yours.
On ownership: the content you enter remains yours, and the result generated from it is attributed to you so far as the applicable law allows. Note that in several jurisdictions a result generated entirely by machine may attract no copyright at all, and nothing here can change that.
No licence over your content is claimed beyond what is strictly needed to provide the service you asked for.
6. Availability
No service level is promised. This is a free service in an early phase, run by one person, and there may be outages, changes or removed features. Material changes are announced in advance wherever possible.
Do not treat backups of your data as guaranteed. Export what matters.
7. Limitation of liability
To the fullest extent permitted by Portuguese law, no liability is accepted for lost profits, lost data, lost opportunity or indirect damage arising from use of the service.
Nothing in these terms excludes liability for wilful misconduct or gross negligence, or displaces rights the law confers mandatorily, in particular consumer rights.
8. Suspension and termination
Access may be suspended or ended for breach of these terms, or on reasonable notice if the service is discontinued. You may stop using it whenever you wish and ask for the account to be erased, at the address in the Privacy Policy.
Worth knowing before you publish: entries you publish to the catalog are not withdrawn with the account. They stay published, credited to a creator name with no link to the account, so that the work of everyone who installed them is not undone. The Retention Periods document sets out the full regime.
9. Third-party software
The Operifex software is distributed under the MIT licence and uses third-party components under permissive licences. The corresponding attribution notices are on the site’s licences page.
10. Governing law
Portuguese law applies. For disputes where the law so permits, the courts of the provider’s domicile have jurisdiction, without prejudice to any forum the law mandatorily grants a consumer.
Subprocessors
Last revised: 20 August 2026.
The parties below process personal data on our behalf and on our instructions. The list was derived from the service’s own configuration.
| Party | What it is for | What data it reaches | Where |
|---|---|---|---|
| Scaleway — Generative APIs | Generating answers and apps with the GLM model. | The text of requests and the context sent with them, on accounts with artificial intelligence switched on. It does not receive the account holder’s identity. | A French company. We do not assert the exact inference region. |
| Scaleway — Transactional Email | Sending access messages and the messages the service sends on your instruction. | Recipient address, subject and message body. | France, region fr-par, per the service configuration. |
| Cloudflare | Domain name resolution and routing of mail received at addresses on the domain. | Mail received on the domain, including sender, subject and body. Requests to the site do not pass through this network. | A United States company, with a globally distributed network. |
| Hetzner | The server that runs the service, the database and the accounts’ workspaces. | All the data described in the Privacy Policy, for as long as it is kept. | A German company. We do not assert the specific data centre. |
| Let's Encrypt (ISRG) | Issuing the certificates that encrypt the connection to the site. | No user data. Only the domain name and an administrative contact address. | A United States non-profit organisation. |
| Perplexity — Sonar / Chat Completions | Web search through Sonar using Chat Completions. The Search API is not used and the Search Addendum does not apply. | Only the search-query text is sent, with no account identity. Under Perplexity’s contractual confirmation, zero data retention applies to Sonar / Chat Completions requests; we have not independently verified this. | Processing on AWS in North America, in the United States; no region in the EU is available. The transfer relies on the European Commission’s standard contractual clauses (SCCs). |
Any addition to this list is announced on this page before it goes into service. A distributed map component fetches its imagery from public OpenStreetMap servers, which reveals your browser’s IP address to those servers; that happens only in apps that use that component.
Retention Periods
Last revised: 20 August 2026.
This document states what the service does today, not what it is meant to do one day. The table covers only Operifex storage: its own database and file storage. Provider-side retention terms are in the Subprocessors document. Where there is no automatic deletion, it says there is none.
| Data | Today | Intended period |
|---|---|---|
| Single-use access link | Valid for fifteen minutes and usable once. The record stays in the database after it expires. | The record is deleted thirty days after expiry. |
| Signed-in session | The session credential expires after seven days. It can be revoked sooner. | Unchanged. |
| Account and email address | Kept for as long as the account exists. | Erased within thirty days of an erasure request. |
| Conversations and generated answers | Kept indefinitely. There is no automatic cleanup and no history limit. | Twelve months after the session was last used, or erasure on request, whichever comes first. |
| Experts, apps and published versions | Kept for as long as the account exists. Published versions are immutable by design: none is ever rewritten. The owner of an app may delete a version they do not want kept, and that deletion is immediate and final. Work saved under the previous structure before 8 August 2026 was archived rather than destroyed, and is still kept on the same terms. | Erased with the account, except for anything you published to the catalog, which is dealt with in the second-to-last row of this table. |
| Knowledge files and their change history | Kept for as long as the account exists, with the history of changes. | Erased with the account. |
| Workspace on the server | Kept on disk. Some workspaces outlive the account that created them, which is a known defect. | Erased with the account, within the same thirty days. |
| Mail sent and received | Recipient, subject and a delivery identifier are recorded. Received mail is kept on disk. | Twenty-four months, to be able to evidence delivery. |
| Approvals and run records | Kept indefinitely. Nothing prunes them. | Twenty-four months. |
| Server technical logs | Rotated by the operating system. They may contain email addresses. | Thirty days. |
| Entries you published to the catalog | They survive the erasure of the account, by decision. Before an entry is published it goes through a process that makes it generic and strips private information from it, and it is credited only to a creator name that is not linked to your account. On erasure the link to the account is severed and the entry stays published. | Unchanged: the entry is not withdrawn. If the creator name contains your address it is replaced by a pseudonym at the moment of erasure. |
| Record of shares other accounts granted to your address | Kept indefinitely. It is another account’s audit record: it shows who was given access, to which resource, and when. | The row is kept and your address is replaced, at the moment of erasure, by a pseudonym computed with a keyed hash function. The share stays provable and countable; it no longer identifies anybody. The pseudonym cannot be turned back into the address. |
An erasure request sent to the privacy address is carried out against the database and against the account’s workspace, and it reaches every row of this table except the last two: the entries you published to the catalog stay published, and the rows of other accounts’ sharing records stay, with your address replaced. Both exceptions are described in their own rows; they are decisions taken openly, not omissions.