Privacy you can verify.

Your report runs in your browser. Your raw Instagram export is never uploaded. The only thing that reaches our servers on its own is a small counter that a report ran, with no export contents in it; it’s tied to your account only if you’re signed in. Nothing else reaches us unless you create an account, save, click an offer, or cash out. We don’t sell your data or run ad-tracking. Below: exactly what we collect, who we share it with, and how to remove it, written to match what the code does, not to sound good.

Last updated July 15, 2026 · Version 2.2

Your raw export never leaves your browser. When you upload your data export, it’s unzipped, parsed, and turned into your report entirely on your device. The raw file (your messages, photos, the whole ZIP) is never uploaded. Open your browser’s Network tab while the report builds and watch: you’ll see one small ping that a report ran (no export data in it, and it’s tied to your account only if you’re signed in) and nothing else until you use a feature that needs it.

The one honest caveat: if you choose to save a report to an account, the analyzed report (what your dashboard shows) is sent to us and stored. Section 2 spells out exactly what that includes.

01Who we are

OPT2IN LLC (“Opt2In,” “we,” “us”) is a Florida limited liability company that operates opt2in.com and is the controller of the personal information described here. This policy covers opt2in.com and the pages we operate, not third-party sites we link to.

02What we collect

Including what a saved report really contains: the full list, not a flattering subset.

Data you intentionally give us

  • Account details: only if you create an account when saving: your email (required), and optionally your name, phone, and date of birth. From your parsed report we also store your gender, primary city, and Instagram handle if present. Sign in with Google instead and we receive your email, name, profile picture, and a Google account ID. Phone and date of birth are stored but not currently used for anything. We don’t yet run age verification or age-based matching.
  • Your saved report: if you click “Save,” we store the analyzed report your dashboard shows. That’s more than counts, so the honest list: value estimates; the advertisers and off-platform apps in your data; inferred topics and interests; follower stats; who you follow and who follows you; engagement summaries (Threads viewed, comments, story interactions, hidden ads); the cities Instagram tied to you (city-level, though a precise GPS coordinate from your export may currently survive in your saved locations); and profile identifiers: name, email, Instagram handle, device, and a persistent Meta ID (an FBID) that links your activity across Instagram, Facebook, Threads, and ad measurement. We don’t store your raw messages or photos. Your synced-contacts list is sent on save but discarded during processing, not stored, and we keep only the counts (how many contacts, phones, emails).
  • Cohort-share consent: saving a report requires agreeing to share aggregated, non-identifying signals (category/app/advertiser totals, location buckets, never raw data, contacts, messages, or identifiers). It’s recorded on your account; withdraw it anytime at privacy@opt2in.com.
  • Payout details: if you cash out, you can set a payout email separate from your sign-in email. We store a record of each payout (section 5, Tremendous). We never see bank or card numbers.
  • AI chat questions: sent to Anthropic to answer; see section 5. We don’t store them.
  • Emails you send us: kept so we can reply.

Data collected automatically

  • “A report was run” event: each time the report renders we log the platform, where you came from (referrer / UTM), aggregate counts (advertisers, topics, interests), a random run ID, your IP address, rough location (city-level), browser and device type, a short non-reversible code derived from your IP and device so repeat runs from the same device can be counted, and your email only if signed in. Your report contents are not included.
  • Offer-click records: clicking an offer records the offer, a random click ID, and (if signed in) your account, so we can measure interest and (if we’re ever permitted to share a commission) attribute a future conversion to you. No current offer pays you a commission (section 6). Clicks are logged even with no account, under an anonymous key; for signed-in users we keep a click count and last-seen time.
  • Survey answers: if the short 3-question prompt appears before your offers, your answers (how accurate the report felt, what you’re currently looking to do, and which deal categories you want to see) are stored so we can gauge report quality and show you relevant deals. They’re linked to your account only if you’re signed in; otherwise they’re stored anonymously. You can Skip it, and it won’t ask again on that device.
  • Web logs & abuse limits: our host (Netlify) logs your IP, user-agent, and the page requested; we also use your IP to rate-limit sign-in, save, and click endpoints against abuse.
  • Aggregate traffic: visitor and page-view counts. No Google Analytics, Plausible, Segment, ad pixels, or cross-site tracking, and no tracking cookies.
  • localStorage summary: your browser (not our servers) stores a compact summary so the offers view can personalize: your name and username, top advertiser/app/topic names, the accounts you follow, the value estimate, and the export filename. If you never create an account, this stays on your device. Clear it via your browser’s site data, or “Switch account” in the nav.
Run the report and close the tab and your export and report contents never leave your browser. The one thing that reaches us is a “a report was run” event (counts, IP, rough location, device type; your email only if signed in).

03What we don’t collect

The things most data services exist to take.
  • Your raw export. The ZIP stays in your browser. We never receive it, store it, or have any way to retrieve it after your session ends.
  • Your messages and photos. Read on your device to build the report, never uploaded or stored.
  • Your synced-contacts list. Sent when you save, discarded during processing, and we keep only the counts, never names or numbers.
  • Your browsing history across other sites. No tracking cookies, no cross-site fingerprinting.
  • Ad-tech tracker data. No third-party advertising analytics, social pixels, or remarketing tags.
  • Your bank or card details. Opt2In is free; when money moves it moves to you, through Tremendous, which handles the financial instruments. We never see them.
  • Your data, sold. We don’t sell personal information. This is not a data-broker business.

04How we use it

  • Deliver the service: parse your export in your browser, render the report, answer your AI-chat questions.
  • Run your account: keep saved reports available across devices, sign you in, show your balance.
  • Match offers & pay out a balance: use your report’s interests, topics, and apps to surface offers, and (if you ever have a balance) send the payout you request. (Today’s offers don’t fund a balance; see section 6.)
  • Communicate: sign-in links and confirmations, a notice about a feature you asked to hear about, replies to your emails.
  • Understand & protect: measure usage from aggregate counts; use logs and rate limits to fix bugs and catch abuse.
  • Legal compliance: respond to lawful requests and comply with applicable US law.

05Third parties we use

Sub-processors, and exactly what each receives.

A small set of well-known providers, each handling one part of the service and receiving only the data it needs. Automated email comes from noreply@opt2in.com (not monitored for replies: use privacy@opt2in.com to reach a person).

Netlify
Hosting + data store

Hosts the site and runs our functions. Its storage (Netlify Blobs) holds your account, saved reports, payout records, and click/activity logs. Server logs include your IP and user-agent; traffic stats are aggregate and cookie-free.

netlify.com/privacy →
Anthropic
AI analyst chat

If you use the chat, your question goes to Anthropic’s Claude API with context from your report: your username, home city and the precise GPS coordinate from your export (if present), advertiser and creator names, and basics like age and gender. This is not anonymized. We don’t store these chats; Anthropic processes them under its terms. Don’t use the chat if you’d rather not share this.

anthropic.com/legal/privacy →
Twilio SendGrid
Account email

Delivers sign-in links, save confirmations, and deletion-confirmation links. Receives your email address and the message content.

twilio.com/legal/privacy →
Tremendous
Payouts

Fulfills cashouts. Receives your payout email, name, and the reward amount, then lets you pick how to receive it (gift card, PayPal, Venmo, bank transfer, and more). We never send it bank or card numbers.

tremendous.com/privacy →
Google
Sign-in · maps

Two optional uses, each reached only when you choose it: Sign in with Google (loads Google’s sign-in library and shares your email and name only when you click it); and the Locations map (loads Google Maps in your browser only when you open that tab, so Google then sees your IP and the area shown, and geocodes a city without GPS). Our fonts are self-hosted, so Google Fonts is not used. The city photo above the map is fetched through our own server.

policies.google.com/privacy →
Kit (ConvertKit)
Email list

If you submit your email to the capture form, Kit stores it and sends the launch email. A few report-derived tags go with it (platform, a value tier, your top category). Unsubscribe in one click.

kit.com/privacy →
DuckDuckGo
Brand logos (toggleable)

Brand logos load from DuckDuckGo’s favicon service, which receives the domain names requested (from your advertiser list). It’s off by default (letter tiles render, nothing is fetched); the “Brand logos” switch turns it on if you want the real logos.

duckduckgo.com/privacy →
Telegram
Operator alerts

Significant events (report run, signup, offer conversion, cashout, payout failure) send us a short alert via Telegram and/or email, which can include your email, the amount involved, and, for report runs, your IP, rough location, and device type. These are internal notifications, not data shared for the recipient’s own use; a copy is kept in our admin log.

telegram.org/privacy →

Every library and font is served from opt2in.com itself (React, JSZip, Leaflet, DOMPurify, and our webfonts). On a plain visit, and while your report renders, no third party is contacted at all. Google (sign-in, maps) and DuckDuckGo (brand logos) are reached only if you turn those features on.

By default, no report-derived data leaves your browser for any third party while the report renders. Turning on brand logos (DuckDuckGo) or opening the Locations map (Google) each sends some derived data to that provider, and both stay off until you choose them.

06Offers & affiliate links

How the free tool stays free, told straight.

Opt2In is free because brands pay referral fees. Each offer card shows its payout or discount, what you must do to qualify, and a note on how the link is tracked.

  • What today’s offers are. Every live offer is a brand’s own discount or a signup bonus paid directly by the brand into your account with them. We don’t currently credit any offer bonus to an Opt2In balance. Where we’re ever permitted to share a commission, we’ll split it, but no current offer does.
  • Click attribution. For partners that support it (currently AdGuard and NordVPN), a random click ID is attached to the outbound link so they can report a signup back to us. Other links carry no Opt2In identifier. We never send the brand your name or email.
  • Conversions. When a partner reports a conversion we store a record (amount and attribution), linked to your account only if the click was signed in.
  • Not ranked by what pays us. Offers are matched to your interests, topics, advertisers, and apps. Payout never changes which surfaces first.

Per the FTC’s endorsement guidelines: Opt2In may earn a referral fee on some links (currently AdGuard and NordVPN), disclosed here and in the offers view.

07Your rights

Under CCPA and other US state privacy laws.

You have the rights below over the limited personal information we hold, under the CCPA/CPRA and equivalent laws in Colorado, Connecticut, Virginia, Utah, Texas, and other states with active privacy laws as of 2026. To exercise any of them, email privacy@opt2in.com.

  • Know what we hold about you. With an account: your account details (section 2), saved reports, payout records, and consent choices. Without one: usually nothing.
  • Delete: from your account page (see section 9) or by email. Payout records stay as business records (section 8).
  • Correct inaccurate personal information.
  • Opt out of sale or sharing: we don’t sell or share personal information as CCPA defines it, so there’s nothing to opt out of. If that changes, we’ll update this policy and add a mechanism first.
  • Non-discrimination: we won’t deny service, change pricing, or degrade your experience for exercising a right.

We respond to verified requests within 45 days and may ask you to confirm access to the email a request concerns; you may use an authorized agent with proof. EEA / UK: Opt2In is operated from the US and isn’t directed at the EEA/UK, but if you believe GDPR applies to you, email us and we’ll honor equivalent access, deletion, and portability rights on a best-efforts basis.

08How long we keep data

  • Export & the report you view: never stored, in your browser only, for the session.
  • localStorage summary: on your device until you clear it. We can’t see or delete it remotely.
  • Account details & saved reports: until you delete them (per report, or all at once, section 9).
  • Offer-click & activity records: targeted for deletion after ~180 days (best-effort, so an entry can linger until the next pass); account deletion scrubs them.
  • Payout records: kept after deletion as business records (amount, date, delivery status, the payout email and name used, and provider order/reward IDs) for accounting, tax, and fraud. No longer linked to a live account, though the email and name used remain in the record.
  • Anti-fraud bounty ledger: hashed, non-reversible records tied to your email (and to the network address a bonus was claimed from) are kept after deletion so the same person can’t re-claim a one-time bonus. No readable personal data.
  • AI chat questions: not stored by us; retained by Anthropic under its terms.
  • Operator alert log: internal alerts (which can include your email, a payout amount, and for report runs your IP, rough location, and device type) are kept in our admin log.
  • Server access logs: ~30 days (Netlify). Emails you send us: while relevant, typically under 2 years.

09How deletion works

A confirmed, reversible flow: not an instant wipe.

You can delete a single saved report (immediate) or your whole account. Account deletion is deliberately careful and reversible:

  • 1. Request. Click “Delete my data.” Nothing is deleted yet. We email a one-time confirmation link (valid 30 minutes), so no one but you can trigger it.
  • 2. Confirm. Clicking the link schedules deletion and starts a 30-day window to change your mind.
  • 3. Restore (optional). Sign back in within 30 days to cancel; your data still exists during this window.
  • 4. Purge. After 30 days, a daily job permanently removes your profile, saved reports, click records, and activity. Payout records and the hashed bounty ledger stay as business records (section 8).

Cash out first. Deleting with a balance forfeits it. The flow warns you before you confirm.

Prefer email? Write privacy@opt2in.com and we’ll process it.

10Children

Opt2In is for adults 18 and older. We don’t knowingly collect personal information from anyone under 18. If you believe a minor has submitted information, email privacy@opt2in.com and we’ll delete it promptly.

11Changes to this policy

We update this policy when our practices change. For a material change we update the “Last updated” date above and, where appropriate, notify current email subscribers. If you strongly disagree with a change, you can delete your data.

12Contact

California residents: if we haven’t responded to a rights request in a reasonable time, you may contact the California Attorney General at oag.ca.gov/privacy.