Privacy Policy
What data is processed, for what purposes, on what legal basis, and what your rights are.
Last revised: 20 August 2026.
This policy describes how personal data is processed in the Operifex service at operifex.com. It is written to be read, not filed: where the service does not yet do what it should, the text says so rather than leaving it out.
1. Data controller
The controller is the individual identified below, who runs the service as a sole trader. No company has been incorporated.
- Name
- [[NOME LEGAL COMPLETO PENDENTE]] — sole trader (empresário em nome individual)
- Tax number (NIF)
- [[NIF PENDENTE]]
- Registered address
- [[MORADA FISCAL PENDENTE]]
- Privacy contact
- privacidade@operifex.com
No data protection officer has been appointed, because none of the conditions in Article 37 GDPR applies. Any question about personal data should go to the address above.
2. What data is processed
The following list was derived from the service’s own code and database structure, not from a generic description.
- Email address, preferred language and the date the account was created. Account signup is open to anyone and is passwordless, through an email link.
- The state of access to artificial-intelligence features associated with the account.
- Conversation content: every question you write and every answer generated are stored in our database, linked to your account.
- The knowledge files and preferences you save, with a record of each change.
- The Experts and apps you create, including instructions, specifications and published versions. It also covers work you saved under the previous structure before 8 August 2026, which was archived rather than destroyed.
- Per-session usage records: start, end, and the number of text units processed. Neither your IP address nor your browser identifier is stored.
- Email the service sends on your instruction, with recipient and subject, and mail received at addresses on the domain.
- Approvals for sensitive operations, together with the request that raised them.
- The record of shares other accounts granted to your address, with what was shared and when. It is an audit record belonging to the account that granted the share, so it outlives the erasure of your own account; at that point your address is replaced by a pseudonym. It is covered in section 9 and in the Retention Periods document.
Your IP address is used only in memory, during the request itself, to limit repeated access attempts. It is written to no table. Your email address may, however, appear in the server’s technical logs.
3. Purposes and legal bases
Performance of the contract, Article 6(1)(b): creating and maintaining the account, authenticating access, carrying out the requests you make, keeping the work produced, and answering support requests.
Legitimate interests, Article 6(1)(f): keeping the service secure, limiting abusive authentication attempts, and keeping minimal technical records.
Compliance with legal obligations, Article 6(1)(c), where applicable, in particular when responding to lawful requests from public authorities.
No processing is carried out for advertising, for profiling, or to sell or otherwise transfer data to third parties. No analytics or tracking cookies are used: the service stores only a session identifier and your language and theme preferences, in your own browser.
4. Legitimate interests assessment
Where legitimate interests are relied on, the three-step assessment described in Opinion 28/2024 of the European Data Protection Board was carried out.
- Purpose: to keep the service available and sound, and to stop passwordless-link authentication being abused. These are specific, present and lawful interests, not a justification written after the fact.
- Necessity: the data processed on this basis is limited to the email address and to technical counters. Rate limiting uses the IP address only during the request and does not retain it. There is no less intrusive way to reach the same result.
- Balancing: the processing is what somebody creating and using an account would expect, it covers no special categories of data, it produces no automated decisions with legal effect, and it is not used to evaluate the person. Weighing against it is the prolonged retention described in the Retention Periods document, which is an acknowledged shortcoming and not a purpose.
You may object to any processing based on legitimate interests, under Article 21, by writing to the address in section 1.
5. Artificial intelligence: what happens to what you write
You are interacting with an artificial-intelligence system. That disclosure is required by Article 50 of Regulation (EU) 2024/1689, and it is also the reason to review any result before using it.
Model access is switched off on every account by default and is switched on individually, account by account, by a decision of the operator. While it is off, nothing you write reaches a model provider: requests are refused on the server, at a single checkpoint.
On accounts where it is switched on, the text you write is sent by our server to the model provider, Scaleway, a French company, through its Generative APIs, and the model used is GLM. The access key belongs to the service and never to your browser, so the provider does not receive your identity, only the text of the request.
Under Scaleway’s AI Specific Conditions, version 07/04/2026, article 4.4, the provider does not retain request content and does not use it to train models. That is a contractual statement by the provider, which we invoke and rely on; it is not an independent verification carried out by us.
Separately from answer generation by Scaleway, a web-search query may be sent to Perplexity through Sonar / Chat Completions. Only the query text is sent, without the account identity; the full terms of that processing are in the Subprocessors document.
Whatever the provider retains, Operifex keeps the conversation in its own database, as described in section 2. It is wise not to write into the service anything you would not want kept.
No decision is taken solely by automated means that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22.
6. Who else processes your data
The service relies on subprocessors for infrastructure, email, name resolution and answer generation. They are all identified, with their purpose and location, in the Subprocessors document.
Data is not sold, transferred or shared with third parties for those parties’ own purposes.
7. Transfers outside the European Economic Area
Cloudflare is a United States company with a globally distributed network, so processing may occur outside the European Economic Area, under the European Commission’s standard contractual clauses and the applicable adequacy framework.
Perplexity processes Sonar queries on AWS infrastructure in North America, in the United States, outside the European Economic Area. The transfer relies on the European Commission’s standard contractual clauses. We have not confirmed the exact region of Scaleway model inference, so we do not assert a specific location for that processing.
8. Retention
The periods, and what the service actually does today, are set out in the Retention Periods document. In short: apart from the fifteen-minute validity of the access link and the seven-day session, nothing is deleted automatically today.
9. Your rights
You have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21).
To exercise any of them, write to the address in section 1. A reply is given within one month, extendable by two further months in complex cases, with prior notice.
An honest note about erasure. An account-erasure procedure exists, it runs as a single database transaction and it also removes the account’s workspace on the server, but no button in this interface invokes it yet: a request sent to the address in section 1 is carried out by hand by the operator. Copies also exist in technical logs whose complete removal needs case-by-case checking.
Two things deliberately survive erasure, and both are described in the last two rows of the Retention Periods document. The first: the entries you published to the catalog stay published. Before an entry is published it goes through a process that makes it generic and strips private information from it, and it is credited only to a creator name that is not linked to your account; on erasure the link to the account is severed and the entry stays in the catalog. The second: the rows of the record of shares other accounts granted to your address are kept, with the address replaced by a pseudonym, so that the share stays provable without identifying anybody. The right is honoured and the deadline in the previous paragraph applies; what survives is named, not left out.
On portability: any published app exports as a single file that works with no account and no connection to the service.
If you consider the processing unlawful, you may complain to the Comissão Nacional de Proteção de Dados, the supervisory authority in Portugal, or to the authority of the Member State where you live.
10. Security
Access uses a single-use link valid for fifteen minutes, with no password. Connections are encrypted in transit. Provider keys stay on the server and are never sent to the browser.
No claims are made about certifications, external audits or isolation between accounts, because none of them is demonstrated today. Where the service improves on this, this document will be updated and the revision date changed.
11. Changes
Material changes are announced thirty days in advance, by message to the account address. The date of the last revision is at the top of this page.
Continue to Terms