1. Introduction
This Privacy Policy explains what information Opal x Terminus collects through the website at https://opal.wtf, the Opal client and launcher, and the account, licensing, cloud, chat, and support systems behind them, and how that information is used and shared. We collect as little as the services need to work, and this policy describes what the services actually do rather than everything a policy could permit.
2. Information you provide
- Account details: a username, an email address, and a password. Passwords are stored only as salted hashes; we cannot read them. If you enable two-factor authentication we store the secrets needed to verify your codes.
- Connected accounts: if you link a Discord, GitHub, or Spotify account, we store the identifier of the linked account and the tokens needed to operate the connection. You can unlink these from your dashboard.
- Support messages: what you write to us through the support system or by email, kept so we can resolve your issue and see past context.
3. Purchase information
- Payments are handled by third-party payment processors for card payments and cryptocurrency. Your full card number never reaches our servers; the processors share with us only what we need, such as a payment reference and the billing email.
- We keep order records with the product, amount, any creator or coupon code, and the payment reference, because we need them for delivery, accounting, and fraud prevention.
- If you arrive through a campaign link, the referring site and campaign tags are kept in your browser's session storage and attached to your order so we know which campaigns work. This attribution is not stored in cookies and disappears when your browser session ends.
4. Device and client data
- License enforcement: the client and launcher read a device identifier when you sign in, and your license is bound to it to prevent sharing. You can reset the binding from your dashboard.
- Sign-in sessions: we keep a record of devices signed in to your account so you and we can spot unauthorized access.
- Diagnostics: the client reports technical events such as launch errors, using opaque error codes, and feature usage signals, so we can find and fix problems. These reports describe the software, not your gameplay identity on any server.
5. Chat and shared content
- The services include a cross-client chat. Messages you send are relayed to other users and retained for a limited time for moderation and abuse handling.
- Chat messages and shared scripts pass through automated moderation that screens for abuse. If moderation restricts you and you believe it was wrong, contact support and a person will review the decision.
- Configurations, profiles, and scripts you save to your account are stored on our servers. Scripts you mark as public are visible to other users along with the publishing account.
6. Website analytics
The website uses a first-party, anonymous analytics system. It sets no cookies, honors the Do Not Track signal, and filters out bots. Your IP address is hashed at the edge into a visitor identifier that rotates weekly and cannot be reversed to your IP, and the raw IP is discarded immediately. Only coarse, aggregate information such as country, page, and device type reaches our dashboards; nothing in the analytics pipeline identifies you personally.
7. Error monitoring
The website uses an error monitoring service to capture crashes and errors, including a small sample of session replays with text input masked. These reports exist so we can reproduce and fix bugs, and they are kept only as long as they are useful for that.
8. Cookies
- opal_session: keeps you signed in. HttpOnly, so scripts on the page cannot read it.
- opal_jwt: a short-lived token that authenticates your dashboard requests. Also HttpOnly.
- NEXT_LOCALE: remembers your language choice.
- That is the whole list. We set no advertising or tracking cookies, and our analytics work without cookies entirely.
9. How we use information
- To provide the services: signing you in, delivering purchases, syncing your cloud content, and relaying chat.
- To enforce licensing and prevent abuse, including device binding, anti-sharing checks, and fraud prevention.
- To moderate chat and shared content.
- To improve the software using diagnostics and anonymous analytics.
- To send transactional email such as verification messages, receipts, and security notices. We do not send marketing email.
- To comply with legal obligations.
10. Sharing
We share information only with the service providers needed to operate Opal, such as payment processors, the email delivery provider, the error monitoring service, and our hosting infrastructure, and with the developers who operate the services. We may disclose information if required by law, or to investigate fraud or protect the rights, property, or safety of Opal, our developers, or others. We do not sell, rent, or trade your personal information, and we do not share it with third parties for their own marketing.
11. Data retention
Account data is kept while your account exists. Order records are kept as long as accounting and legal obligations require. Chat and moderation logs are kept for limited periods appropriate to abuse handling. Analytics data is anonymous from the moment it is collected and is kept only in aggregate. If you want your account deleted, contact us at the support email below and we will remove what we are not legally required to keep.
12. Security
We protect your information with measures including salted password hashing, HttpOnly authentication cookies, transport encryption, and access controls, and we continuously test these protections. No method of transmission or storage is completely secure. We believe in transparency about failures as well: our security disclosures page at https://opal.wtf/disclosures documents past incidents, what was affected, and what we changed.
13. Your rights
You can access, correct, export, or delete your personal information by contacting us at the support email below. If you are in the European Economic Area or the United Kingdom, our GDPR page at https://opal.wtf/gdpr describes your rights and the legal bases we rely on. If you are a California resident, our California privacy page at https://opal.wtf/ccpa describes your rights under the CCPA.
14. Children
We do not knowingly collect or solicit personal information from anyone under the age of 13. If you are under 13, do not use Opal or send us any personal information. If we learn we have collected personal information from a child under 13, we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. Changes are effective when posted on this page, and the effective date above always reflects the current version. For significant changes we will make reasonable efforts to provide notice, for example through the dashboard or by email.
16. Contact
If you have questions about this Privacy Policy, or want to exercise any of your rights, contact us at support@mail.opal.wtf. We will do our best to respond quickly, and within any deadline the law sets.