01Who we are
OPT2IN LLC (“Opt2In,” “we,” “us”) is a Florida limited liability company that operates opt2in.com and is the controller of the personal information described here. This policy covers opt2in.com and the pages we operate, not third-party sites we link to.
- Mailing address: OPT2IN LLC, Miami, Florida, USA
- Privacy contact: privacy@opt2in.com
- Founder / operator: Robert Maatougui (robert@opt2in.com)
02What we collect
Data you intentionally give us
- Account details: only if you create an account: your email (required) and, optionally, your name. We no longer ask for or store your phone number or date of birth. From your parsed report we also store your gender, primary city, and Instagram handle if present. Sign in with Google instead and we receive your email, name, profile picture, and a Google account ID. In the iOS app you can also sign in from the opening screen, before any report exists: with Apple (we receive the name and email you approve — a real address or a Hide My Email relay — plus Apple’s identifier for you), with Google, or with a 6-digit code we email you. Accounts created before July 26, 2026 may still hold a phone number and date of birth collected under an earlier version of this policy. Nothing in the product reads them, and you can have them erased at privacy@opt2in.com.
- Your saved report: when a report is saved — automatically whenever you run one while signed in, or when you tap “Save” from a save prompt — we store the analyzed report your dashboard shows. That’s more than counts, so the honest list: value estimates; the advertisers and off-platform apps in your data; inferred topics and interests; follower and following counts, and the brand accounts among the ones you follow — not the individual people; engagement summaries (Threads viewed, comments, story interactions, hidden ads); the cities Instagram tied to you, city-level only; and profile identifiers: name, email, Instagram handle, device, and a persistent Meta ID (an FBID) that links your activity across Instagram, Facebook, Threads, and ad measurement. We don’t store your raw messages or photos. Two things in your report are never stored at all: the precise GPS coordinate your export may carry, and your synced-contacts list. In the iOS app both are removed before the report leaves your phone; on the website both travel inside the report and are deleted during processing, before anything is written. Of your contacts we keep only the counts (how many contacts, phones, emails). If you are signed out, nothing is uploaded unless you create an account from a save prompt.
- Cohort-share consent: optional. On the website you can share aggregated, non-identifying signals (category/app/advertiser totals, location buckets, never raw data, contacts, messages, or identifiers) by ticking the box when you save. Leaving it unticked still saves your report. The iOS app does not ask and never sends it. It’s recorded on your account; change or withdraw it anytime at privacy@opt2in.com.
- Payout details: if you cash out, you can set a payout email separate from your sign-in email. We store a record of each payout (section 5, Tremendous). We never see bank or card numbers.
- AI chat questions: sent to Anthropic to answer; see section 5. We don’t store them.
- Emails you send us: kept so we can reply.
Data collected automatically
- “A report was run” event: each time the report renders we log the platform, where you came from (referrer / UTM; we keep only the referring website’s name, never the specific page, post, or search you came from), aggregate counts (advertisers, topics, interests), which format your archive was in (JSON or HTML) and whether it contained the ads-and-topics folder, a random run ID, your IP address, rough location (city-level), browser and device type, a short non-reversible code derived from your IP and device so repeat runs from the same device can be counted, and your email only if signed in. Your report contents are not included.
- “An export was refused” event: if the file you pick can’t be turned into a report at all — it isn’t a ZIP, it’s larger than we can process (over 1 GB), it’s from another platform, it isn’t an Instagram export, the ZIP is damaged or password-protected, or your device runs out of memory reading it — we log that too, with a short fixed label for which of those it was, alongside the same context as the event above (platform, where you came from, your IP, rough location, browser and device type, and the short non-reversible code derived from your IP and device). It carries nothing from inside the file, and nothing about the file itself — no counts, no folder or file names, not your archive’s name, and not its size, not even in the case where the size is the reason it was refused — and not the on-screen error text either, since that can quote filenames from your archive. It exists so a rejected upload is distinguishable from nobody visiting; without it we could not tell that anyone had tried.
- QR scan on merch: our hoodies and stickers carry a QR code. Scanning one records which garment was scanned (a short code identifying the item, not you), and sends us an internal alert containing your IP address, rough location (city-level), browser and device type, and a short non-reversible code derived from your IP and device so a repeat scan can be told apart from a new person. We keep a running count per garment and a count for the current day; we do not keep a row per scan, a timestamp per scan, or any history tying scans together over time. If you then open your report from that page, the garment code travels with the link so we can tell whether the merch led to a report — it carries nothing about you.
- Recap share counts: if you build or share the animated recap of your own report, we record that it happened — the event name alone (a card was built, a share completed, an image was saved). No identity, no account, and no numbers from your report. The recap image is drawn on your device and is never uploaded, and nothing is recorded when the recap is of the sample report.
- Offer-click records: clicking an offer records the offer, a random click ID, and (if signed in) your account, so we can measure interest and match a conversion the brand reports back to us. No offer pays you a commission; the commission, where one exists, is Opt2In’s revenue (section 6). Clicks are logged even with no account, under an anonymous key; for signed-in users we keep a click count and last-seen time.
- Deal views and saves: when a deal card is at least half on screen we record which cards were seen, and tapping Save records the card and whether you saved or unsaved it, so we can tell whether the feature is worth keeping. These records carry the card ids, a label for which part of the product they came from, and (for views) whether you were signed in. They never carry your email or your account, on the website or in the app.
- Survey answers: if the short 3-question prompt appears before your offers, your answers (how accurate the report felt, what you’re currently looking to do, and which deal categories you want to see) are stored so we can gauge report quality and show you relevant deals. They’re linked to your account only if you’re signed in; otherwise they’re stored anonymously. You can Skip it, and it won’t ask again on that device.
- Web logs & abuse limits: our host (Netlify) logs your IP, user-agent, and the page requested; we also use your IP to rate-limit sign-in, save, click, sample-report view, and short-link (/ig, /steps, /r, /h) endpoints against abuse. The limiter stores a hashed form of the IP with its recent request times, not the address itself.
- Aggregate traffic: visitor and page-view counts. No Google Analytics, Plausible, Segment, ad pixels, or cross-site tracking, and no tracking cookies.
- localStorage summary: your browser (not our servers) stores a compact summary so the offers view can personalize: your name and username, top advertiser/app/topic names, the accounts you follow, the value estimate, and the export filename. If you never create an account, this stays on your device. Clear it via your browser’s site data, or “Switch account” in the nav; in the iOS app, deleting the app removes it with the app.
- How you arrived: your browser also keeps one short-lived note of where you came from (for example “reddit” or “receipt”) so the “a report was run” event above can say which channel sent you. It is the referring website’s name only, never the page, link, or search, and it is cleared when you close the tab. It is not a cookie and not an ID that follows you between visits. When you open the sample report, that channel name is also added to an anonymous per-day tally of sample views by channel, with nothing else attached.
03What we don’t collect
- Your raw export. The ZIP stays on your device. We never receive it, store it, or have any way to retrieve it after your session ends.
- Your messages and photos. Read on your device to build the report, never uploaded or stored.
- Your synced-contacts list. Never stored. In the iOS app it is stripped out before a saved report leaves your phone; on the website it travels inside the report and is discarded during processing. We keep only the counts, never names or numbers.
- Your browsing history across other sites. No tracking cookies, no cross-site fingerprinting.
- Ad-tech tracker data. No third-party advertising analytics, social pixels, or remarketing tags.
- Your bank or card details. Opt2In is free; when money moves it moves to you, through Tremendous, which handles the financial instruments. We never see them.
- Your data, sold. We don’t sell personal information. This is not a data-broker business.
04How we use it
- Deliver the service: parse your export on your device, render the report, answer your AI-chat questions.
- Run your account: keep saved reports available across devices, sign you in, show your balance.
- Match offers & pay out a balance: use your report’s interests, topics, and apps to surface offers, and (if you ever have a balance) send the payout you request. (Today’s offers don’t fund a balance; see section 6.)
- Communicate: sign-in links and confirmations, a notice about a feature you asked to hear about, replies to your emails.
- Understand & protect: measure usage from aggregate counts; use logs and rate limits to fix bugs and catch abuse.
- Legal compliance: respond to lawful requests and comply with applicable US law.
Payouts and balances are features of the Opt2In website only; the iOS app never shows or moves money. Accounts exist in the app too: you can sign in there with Apple, Google, or an emailed code (an Apple “Hide My Email” relay address is its own separate account — we never merge accounts behind the scenes) and save your report. Reports you run in the app save to your account automatically while you are signed in, exactly as they do on the website. The current iOS app contains no offers, deals, or referral links of any kind, and records no offer clicks, saves, or impressions; matched offers are a website feature. Saving a report earns you nothing on either surface — Opt2In no longer pays a bonus for a save, and the app neither pays nor promises money at all.
05Third parties we use
A small set of well-known providers, each handling one part of the service and receiving only the data it needs. Automated email comes from noreply@opt2in.com (not monitored for replies: use privacy@opt2in.com to reach a person).
Hosts the site and runs our functions. Its storage (Netlify Blobs) holds your account, saved reports, payout records, and click/activity logs. Server logs include your IP and user-agent; traffic stats are aggregate and cookie-free.
netlify.com/privacy →If you use the chat, your question goes to Anthropic’s Claude API with context from your report: your username, home city and the precise GPS coordinate from your export (if present), advertiser and creator names, the topics and hashtags your recent activity clustered into, your device and OS as the export records them, and your gender and date of birth as they appear in your export. This is not anonymized. Nothing is sent until you explicitly allow it in the chat itself, and you can decline. We don’t store these chats; Anthropic processes them under its commercial API terms, which require it to protect this data and do not permit it to use your chats to train its models. Don’t use the chat if you’d rather not share this.
anthropic.com/legal/privacy →Delivers sign-in links, save confirmations, and deletion-confirmation links. Receives your email address and the message content.
twilio.com/legal/privacy →Fulfills cashouts. Receives your payout email, name, and the reward amount, then lets you pick how to receive it (gift card, PayPal, Venmo, bank transfer, and more). We never send it bank or card numbers.
tremendous.com/privacy →Two optional uses, each reached only when you choose it: Sign in with Google (loads Google’s sign-in library and shares your email and name only when you click it); and the city photo on the Locations tab, which our server looks up through Google Places so the key never reaches your browser, though your browser then loads the image from Google’s host, which sees your IP address. Our fonts are self-hosted, so Google Fonts is not used.
policies.google.com/privacy →The map on the Locations tab is Apple MapKit JS, loaded only when you open that tab. Apple sees your IP address and the area shown. Our server issues a short-lived token so no long-lived key is exposed, and no GPS or device location is used: the map is centred on the city Instagram guessed, from your export. In the iOS app you can also use Sign in with Apple: Apple gives us a signed token with your name and your chosen email (real or a Hide My Email relay), and we verify it against Apple’s public keys before creating your account.
apple.com/legal/privacy →If you submit your email to the capture form, Kit stores it and sends the launch email. A few report-derived tags go with it (platform, a value tier, your top category). Unsubscribe in one click.
kit.com/privacy →Brand logos load from DuckDuckGo’s favicon service, which receives the domain names requested (from your advertiser list) and your IP address. They are on by default, so this happens while your report renders. The “Brand logos” switch at the top of the report turns them off at any time: letter tiles render instead and nothing is fetched.
duckduckgo.com/privacy →Events on the site send us a short alert via Telegram and/or email as they happen: a report run, a refused save, a merch QR scan, a signup, a sign-in, a report saved again, a sample-report open, a click on one of our short links, an offer click or save, a survey answer, a request for a laptop link, an offer conversion, a cashout, and a payout failure. Which alerts include an email: signups, sign-ins, reports saved again, requests for a laptop link, conversions, cashouts and payout failures always; offer clicks and survey answers only if you were signed in at the time. Which carry nothing about you: sample-report opens and short-link clicks (a count and, where relevant, the campaign tag we put on our own link), offer saves (the offer’s name only), and refused saves (a reason and a status). Report runs carry your IP, rough location and device type; a merch QR scan carries those only on the first-ever scan of a given item, and after that only the item’s code and a count. Alerts never contain anything read out of your export beyond the aggregate counts already described above. These are internal notifications, not data shared for the recipient’s own use; a copy is kept in our admin log.
telegram.org/privacy →Every library and font is served from opt2in.com itself (React, JSZip, Leaflet, DOMPurify, and our webfonts). On a plain visit, no third party is contacted at all. While your report renders, DuckDuckGo is contacted for brand logos unless you switch them off. Google (sign-in, city photos) and Apple (the Locations map) are reached only if you use those features.
06Offers & affiliate links
Opt2In is free because brands pay referral fees. Each offer card shows its bonus or discount, what you must do to qualify, and a note on how the link is tracked.
- What today’s offers are. Every live offer is a brand’s own discount or a signup bonus paid directly by the brand into your account with them. We don’t credit any offer bonus to an Opt2In balance, and no offer pays you a commission; where a commission exists, it is Opt2In’s revenue and is what keeps the tool free.
- Click attribution. For partners that support it (currently AdGuard, NordVPN, NordPass, NordLocker, Coveron, and Ledger), a random click ID is attached to the outbound link so they can report a signup back to us. Other links carry no Opt2In identifier. We never send the brand your name or email.
- Conversions. When a partner reports a conversion we store a record (amount and attribution), linked to your account only if the click was signed in.
- Not ranked by what pays us. Offers are matched to your interests, topics, advertisers, and apps. Payout never changes which surfaces first.
Per the FTC’s endorsement guidelines: Opt2In may earn a referral fee on some links (currently AdGuard, NordVPN, NordPass, NordLocker, Coveron, Optery, and Ledger), disclosed here and in the offers view.
07Your rights
You have the rights below over the limited personal information we hold, under the CCPA/CPRA and equivalent laws in Colorado, Connecticut, Virginia, Utah, Texas, and other states with active privacy laws as of 2026. To exercise any of them, email privacy@opt2in.com.
- Know what we hold about you. With an account: your account details (section 2), saved reports, payout records, and consent choices. Without one: usually nothing.
- Delete: from your account page (see section 9) or by email. Payout records stay as business records (section 8).
- Correct inaccurate personal information.
- Opt out of sale or sharing: we don’t sell or share personal information as CCPA defines it, so there’s nothing to opt out of. If that changes, we’ll update this policy and add a mechanism first.
- Non-discrimination: we won’t deny service, change pricing, or degrade your experience for exercising a right.
We respond to verified requests within 45 days and may ask you to confirm access to the email a request concerns; you may use an authorized agent with proof. EEA / UK: Opt2In is operated from the US and isn’t directed at the EEA/UK, but if you believe GDPR applies to you, email us and we’ll honor equivalent access, deletion, and portability rights on a best-efforts basis.
08How long we keep data
- Export & the report you view: the export is never uploaded and never stored. The report you view stays on your device for the session, unless it is saved to your account — see saved reports below.
- localStorage summary: on your device until you clear it. We can’t see or delete it remotely.
- Account details & saved reports: until you delete them (per report, or all at once, section 9).
- Offer-click & activity records: targeted for deletion after ~180 days (best-effort, so an entry can linger until the next pass); account deletion scrubs them.
- Payout records: kept after deletion as business records (amount, date, delivery status, the payout email and name used, and provider order/reward IDs) for accounting, tax, and fraud. No longer linked to a live account, though the email and name used remain in the record.
- Anti-fraud bounty ledger: hashed, non-reversible records tied to your email (and to the network address a bonus was claimed from) are kept after deletion so the same person can’t re-claim a one-time bonus. No readable personal data.
- AI chat questions: not stored by us; retained by Anthropic under its terms.
- Operator alert log: internal alerts (which can include your email, a payout amount, and for report runs and refused exports your IP, rough location, and device type) are kept in our admin log.
- Server access logs: ~30 days (Netlify). Emails you send us: while relevant, typically under 2 years.
09How deletion works
You can delete a single saved report (immediate) or your whole account. On the website, account deletion is deliberately careful and reversible:
- 1. Request. Click “Delete my data.” Nothing is deleted yet. We email a one-time confirmation link (valid 30 minutes), so no one but you can trigger it.
- 2. Confirm. Clicking the link schedules deletion and starts a 30-day window to change your mind.
- 3. Restore (optional). Sign back in within 30 days to cancel; your data still exists during this window.
- 4. Purge. After 30 days, a daily job permanently removes your profile, saved reports, click records, and activity. Payout records and the hashed bounty ledger stay as business records (section 8).
In the iOS app it is faster, on purpose. “Delete my account” on the Account screen removes your saved reports and your details immediately and permanently, with no email step and no grace period; a link under it starts the emailed 30-day flow above instead, if you would rather have the safety net. We default to the immediate path because an Apple “Hide My Email” relay can silently drop our mail, and deleting your account must never depend on an email arriving. Payout records and the hashed bounty ledger stay either way (section 8).
Cash out first. Deleting with a balance forfeits it, and the flow warns you before you confirm. Balances exist on the website only — the iOS app never shows or moves money.
Prefer email? Write privacy@opt2in.com and we’ll process it.
10How we protect your data
The strongest protection in this product is the one built into its shape: most of your data never reaches us at all. Your export is unzipped, parsed, and turned into a report on your own device, and the file itself is never transmitted. What we do receive and hold — your account details, your saved reports, payout records, and the events named in section 2 — is protected as follows.
- Encrypted in transit. Every connection to opt2in.com, to the iOS app’s backend, and between us and the processors in section 5 runs over HTTPS with TLS 1.2 or greater. We send a
Strict-Transport-Securityheader, so a browser that has seen our site once will refuse to reach us any other way. - Encrypted at rest. Account records and saved reports are stored in Netlify Blobs, which encrypts stored data at rest with AES-256 or stronger. The infrastructure it runs on is covered by Netlify’s SOC 2 Type 2 and ISO 27001 reports.
- No passwords, anywhere. Opt2In has no password field and stores no password hashes, so there is no password database to steal. You sign in with Google, with Apple, with a one-time emailed link, or with a 6-digit emailed code. That code is written to storage only as a SHA-256 hash, expires in 10 minutes, is destroyed after 5 wrong attempts, and works once. Sign-in links carry 256 bits of cryptographic randomness, expire, and also work once. Sessions expire after 30 days.
- Every account endpoint is authenticated. Nothing about an account is returned without that account’s email and an unexpired session token, re-checked against the stored record on every single request. Opening a saved report additionally requires the report’s storage key to belong to the account asking for it, so a hand-edited request cannot reach anyone else’s report.
- Least exposure by default. What our servers may send back to a browser is an explicit list of permitted fields, not a list of forbidden ones. Session tokens and sign-in codes sit structurally outside it, and any field a future feature adds stays private until someone deliberately publishes it. That is a deliberate design choice: the failure mode of the opposite approach is a new field leaking because somebody forgot.
- Abuse limits. Sign-in, save, offer-click, survey, and AI-chat endpoints each carry per-network-address rate limits and request-size caps, and a tripped limit raises an internal alert. Our host adds automatic DDoS detection and blocking in front of all of it.
- Administrative access is single-person, time-boxed, and separately gated. Opt2In is operated by one person (section 1), and only that operator holds administrative access. The admin console requires a passcode that is never kept in the browser — the browser holds only a signed token that expires after 12 hours — and five failed attempts lock the originating network address out for 15 minutes, before any comparison is made. Anything irreversible or money-moving requires a second, separate passcode entered per action and never cached, so a stolen session cannot move money. Production credentials live only in our host’s encrypted environment settings: never in our code, never in our repository, never sent to your browser. Provider accounts that can reach production are protected with two-factor authentication.
- Private by default in what we publish. The public website is assembled at build time from an explicit list of files. Backend source code, internal notes, and operational tooling are not on that list and are not served on the web. A separate automated scan reads every file that is published, on every release, and stops the release if it finds a personal name, handle, local file path, or credential that should not be public.
- Hardened in your browser. A Content Security Policy limits what may execute on our pages to our own code and a short, named list of dependencies; we forbid framing of our pages (anti-clickjacking), forbid content-type guessing, and limit what is disclosed to other sites when you follow a link. No third-party analytics, ad pixels, or tracking cookies exist to be compromised (section 2).
- Checked before every release. An automated suite covering sign-in, payouts, offer handling, and data retention runs as a gate on every deploy. If it fails, the release stops.
- Reporting a problem. Security researchers can reach us at security@opt2in.com. Our disclosure policy, response times, and safe-harbor commitment are published at
opt2in.com/security.html, linked from the footer of every page.
What we don’t claim. Opt2In is a small company and has not completed a SOC 2 or ISO 27001 audit of its own; those certifications belong to the infrastructure we build on, not to us. Your saved report is encrypted in storage but not end-to-end — we can read it, because serving it back to you across devices and matching offers to it requires that we can. We never hold bank or card numbers (section 3). And if we ever discover a breach affecting your personal information, we will notify the users affected and any regulator the law requires, without undue delay.
11Children
Opt2In is for adults 18 and older. We don’t knowingly collect personal information from anyone under 18. If you believe a minor has submitted information, email privacy@opt2in.com and we’ll delete it promptly.
12Changes to this policy
We update this policy when our practices change. For a material change we update the “Last updated” date above and, where appropriate, notify current email subscribers. If you strongly disagree with a change, you can delete your data.
13Contact
- Privacy & data requests: privacy@opt2in.com
- Account & payout support: support@opt2in.com
- General: robert@opt2in.com
- Postal: OPT2IN LLC, Miami, Florida, USA (email first for a faster response)
California residents: if we haven’t responded to a rights request in a reasonable time, you may contact the California Attorney General at oag.ca.gov/privacy.