Opalapp
opalapp.comOpal is a consumer screen-time and digital-wellbeing app. Its published terms combine an Apple Standard EULA, a marketing-style introduction, and a lengthy privacy policy. The privacy-forward introduction and Social Features section promise on-device processing, opt-in data collection, hashing, and strong non-sale commitments; however, the underlying legacy privacy policy (effective July 16, 2020) is broad, boilerplate, and in several places contradicts those promises — it permits advertising-tailored data use, curated partner offers, and refuses to honor 'do-not-track' signals. The policy is stale relative to the 2026 product surface, mentions no security certifications, and internally conflicts on data-sharing and marketing. It is reasonable for consumer use but should be treated with caution before submitting sensitive data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The documents describe what data is collected but never make an explicit statement that the user retains ownership of the data, prompts, or content they submit. The EULA reserves all rights not expressly granted to the Licensor, and the app's core function keeps detailed app-usage data on the device, but ownership of submitted content is not clearly addressed.
Output Data Ownership
The policy is silent on ownership of any content the product generates (e.g., Opal Scores, gems, screen-time summaries). No explicit grant or reservation of output ownership appears, so the position is undefined. Silence here is itself a finding.
Training Data Usage
There is no AI/ML model in evidence, but the policy broadly permits using collected information to 'improve products,' conduct research on user demographics and behavior, and develop new tools. The EULA also permits use of de-identified technical data to improve products. There is no explicit training carve-out, and the improvement language is expansive rather than limited.
Data Retention & Deletion
The policy offers deletion on request using 'commercially reasonable efforts' but reserves broad rights to retain data in archives, backups, and for fraud or legal purposes with no general deletion SLA. The Social Features section is more specific — friend removal server records deleted within 48 hours and all social data within 30 days — but these apply only to the opt-in social feature, not to core account data.
Third-Party Data Sharing
The policy contains a strong non-sale commitment and states data is not made available to third parties for their marketing without consent. However, it simultaneously permits sharing with service providers, corporate-restructuring transferees, 'curated offers from selected partners,' and use of data to serve advertisements, which is broader and partly contradicts the strong promises. This tension warrants caution.
Opt-Out Rights
The policy provides multiple concrete opt-out mechanisms: email unsubscribe, cookie controls, SNS de-linking, CCPA opt-out of sale, EU objection/restriction rights, consent withdrawal, and fully opt-in social features. These are real, stated mechanisms even if some are exercised only by contacting the vendor.
Compliance & Certifications
As a consumer-general app, the relevant baseline includes GDPR, CCPA/CPRA, and COPPA (minors). The policy addresses COPPA, CCPA, and GDPR lawful bases/SCCs at a compliance-claim level, but names no third-party audits or security certifications (no SOC 2, ISO 27001, etc.). No framework is certified with evidence, and the policy's refusal to honor do-not-track sits in tension with modern privacy expectations.
Model Explainability & Auditability
The documents contain no discussion of model behavior, transparency, algorithmic explainability, or enterprise auditing capabilities. This topic is entirely absent, which for a wellbeing-scoring product is a gap.
Security Practices & Breach History
The policy makes general claims of 'state of the art encryption technologies' and password protection, and the Social Features section states data is transmitted encrypted. However, there is no detail on encryption at rest, access controls, penetration testing, bug bounty, incident response, no trust center or security page reference, and no breach history disclosure. Claims are unsubstantiated.
Enterprise vs. Consumer Risk Delta
There are free and premium (Opal Pro) tiers plus an Android free ad-supported tier, and the introduction notes Pro removes advertising. This implies the free ad-supported tier involves advertising-related data handling that the paid tier avoids, but the privacy policy treats free and premium collectively and does not detail data-handling differences between them.
Human Review of User Inputs
The policy states workforce members with access to Personal Data must follow the policy, and staff may access data to respond to bug reports and customer service. It does not describe systematic human review of user content, but access by staff for support and correspondence is acknowledged. Public forum content is expressly non-private.
Regulatory & Litigation Exposure
The policy discloses that it will respond to lawful government and law enforcement requests and may disclose data for legal compliance, safety, and fraud. It also acknowledges US-based data may be subject to lawful government access requests. No specific litigation or past disputes are disclosed.
PII & SPI Data Inventory
Opal collects significant PII (name, email, phone number, IP address, location, device data, usage) and some SPI-adjacent categories (financial/credit card details, precise location, audio/visual uploads, hashed contact lists). The introduction claims minimization and on-device processing, but the legacy CCPA notice and collection sections enumerate a broad set of categories with adequate disclosure but expansive scope.
Policy–Product Currency
The privacy policy is effective July 16, 2020 — over six years before the 2026 analysis date and materially stale. While the introduction and Social Features sections appear more recently added, the core policy predates and does not reflect current product capabilities such as Opal Score, cross-platform desktop/Mac support, and the Android ad-supported tier. The staleness of the governing dated section independently justifies a RED rating.
Cross-Document Consistency
Two overlapping documents were supplied (English and French terms, both containing the same combined EULA + privacy policy). Within these documents there are material tensions between the privacy-forward introduction/Social Features language and the legacy privacy policy — notably strong non-sale and no-third-party-marketing promises alongside language permitting advertising-tailored data use and curated partner offers. Because the supplied docs are essentially the same text in two languages rather than distinct instruments (Terms vs Privacy vs DPA), and the conflicts appear within a single combined document, the strongest cross-document evidence is the marketing-vs-legacy conflict noted below.
You've read all 15 risk ratings for Opalapp. Create a free account to see the exact policy wording behind each rating.