Short version: your report runs in your browser. Your Instagram data never touches our servers. We collect the minimum we need to run a business. This page explains exactly what, why, and how you opt out.
Opt2In is built client-side. When you upload your data export, it is unzipped, parsed, and rendered into the report entirely on your device. The file is never uploaded to Opt2In servers, never stored in a database, and never shared with a third party. You can verify this yourself in DevTools → Network tab while the report generates. This is the single most important fact about our product and it is the reason this policy is short.
OPT2IN LLC (“Opt2In,” “we,” “us,” “our”) is a Florida limited liability company that operates opt2in.com. We are the controller of any personal information described in this policy.
This policy applies to visitors and users of opt2in.com and any subdomains or pages we operate. It does not apply to third-party websites that our site may link to.
We want to be explicit about what we never see, because most data-related services exist by collecting exactly these things:
We use the data listed above for these specific purposes and no others:
We use a small number of well-known service providers. Each is contractually required to handle data appropriately. Providers listed here are sub-processors under our agreement with them.
Netlify hosts the opt2in.com site and runs a small number of serverless functions (see below). Server access logs include IP address and browser user-agent. Netlify Analytics is aggregate and cookie-free. Netlify’s privacy policy is at netlify.com/privacy.
When you use the AI analyst chat, your typed question and a summary of your report numbers are sent to Anthropic’s Claude API to generate a response. Anthropic does not use API data to train models and deletes it within a short retention window. Anthropic’s privacy policy is at anthropic.com/privacy. If you do not want your question sent to a third party, do not use the chat input.
If you submit your email via the capture form, it is added to a list managed by Kit (formerly ConvertKit). Kit sends the single launch-notification email and stores your address until you unsubscribe. You can unsubscribe with one click from any email we send, or email us to remove it manually. Kit’s privacy policy is at kit.com/privacy.
The “Locations of interest” section of your report uses OpenStreetMap map tiles and Nominatim (OSM’s geocoder) to display the place names Meta inferred about you on a map. The place names (e.g. “Miami, Florida”) are sent to Nominatim to look up coordinates. No other personal data is sent. OSM’s privacy notice is at osmfoundation.org.
Brand logos on the monetize and report pages are loaded from DuckDuckGo’s public favicon service, which receives the domain name of the logo being requested. This is a standard practice and does not transfer personal data.
Font files and a few front-end libraries (JSZip, Leaflet) load from Google Fonts and cdnjs. These are content-delivery services. They receive the fact that your browser requested a font or script file.
Our business model is referral commissions. When you click a brand’s affiliate link in the monetize section and sign up for their service, the brand may pay Opt2In a referral fee. We plan to share a portion of that fee with users once our affiliate-network partnerships are approved and fully operational.
We comply with the FTC’s endorsement guidelines: Opt2In earns commissions from some links; we disclose this on the monetize page and in our offer library.
You have the following rights regarding the limited personal information we do hold about you. These rights apply under the California Consumer Privacy Act (CCPA/CPRA) and equivalent laws in Colorado, Connecticut, Virginia, Utah, Texas, and other states with active privacy laws as of 2026.
You can ask what personal information we have about you. Email privacy@opt2in.com. For most users, the answer is simply “your email address, if you submitted it,” because we don’t collect much else.
You can ask us to delete your personal information. Email the same address. We’ll delete your email from our newsletter list within 10 business days and confirm when it’s done.
You can ask us to correct inaccurate personal information about you. Same email.
We do not sell or share personal information as those terms are defined under CCPA. If this ever changes, we will update this policy and provide an opt-out mechanism. Until then, there is nothing to opt out of.
We will not deny service, charge different prices, or provide a different level of service because you exercise any of the rights above.
We respond to verified consumer rights requests within 45 days. To verify your request, we may ask you to confirm you have access to the email address the request mentions.
You may designate an authorized agent to make a request on your behalf. We will require proof of authorization (such as a signed permission letter) before processing the request.
Opt2In is intended for adults age 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, email privacy@opt2in.com and we will delete it promptly.
We will update this policy when our practices change. When we make a material change, we will update the “Last updated” date at the top and, where appropriate, notify current email subscribers. If you strongly disagree with a change, you can request deletion of your data.
Questions, requests, complaints, or anything else privacy-related:
If you are a California resident and believe we have not responded to a rights request in a reasonable time, you may also contact the California Attorney General’s office at oag.ca.gov/privacy.