Privacy & Data Policy
This notice covers the short-lived OpsChaos Scanner, client accounts, paid Watchdog monitoring, payments, support, and optional product analytics.
Two products, different data lifecycles
Scanner: the core diagnostic session expires after 72 hours; a separate aggregate report cache can remain for up to 30 days unless you use that report’s deletion control first.
Watchdog and the cabinet: an ongoing service with an account, payment, and connectors; this data does not expire after 72 hours.
Product events and contacts
After your optional-analytics choice, Scanner retains semantic product events for up to 180 days. It does not put raw chat text, form values, scan targets, secrets, URL queries, or fragments into analytics. Withdrawing the choice clears the undelivered browser queue.
When you submit an enquiry, register an account, or complete Watchdog intake, the contact is stored in an encrypted CRM profile for up to 24 months after the latest interaction unless an active service or law requires longer. Admin lists and the Telegram Mini App show masked values; full reveal is limited to the owner role, requires a reason, and is audit-logged.
🔒 Connector access and your choices
Scanner and Watchdog connections are designed for monitoring with the least access practical for each provider. You choose every system separately. OAuth screens or secure key forms show the requested access; some provider APIs may expose content fields within a read scope, so the exact connector notice matters. OpsLab does not use a monitoring connection to change data in your tool unless you separately request and authorize a service that requires it.
Google Workspace
- Calendar connections request calendar read access for meeting and schedule signals such as time, recurrence, title, description, and attendee information returned by Google.
- The current calendar flow does not request Gmail inbox access.
- The current calendar flow does not request Google Drive file access.
Slack
- Channel and user scopes identify the workspace structure and participants needed for operational metrics.
- History scopes can return message payloads to the service. The monitoring pipeline is intended to retain derived counts, timestamps, thread structure, and approved evidence rather than build a message archive.
- Private-channel access depends on the Slack installation and the channels to which the app is granted access.
ClickUp
- The ClickUp OAuth app reads the workspaces available to the approving user under ClickUp's app-level permission model.
- Task lifecycle, assignees, due dates, statuses, and time-tracking signals may be used to calculate operational metrics.
- Review the ClickUp authorization screen and connect only a workspace you are authorized to share.
Notion
- The integration can access only the pages and databases selected during Notion authorization.
- Page and database metadata, properties, relations, and selected evidence may be processed to assess documentation health.
- Remove pages from the integration or revoke the integration in Notion to stop future access.
⏱️ Scanner data: the 72-hour window
- ✓Scanner sessions, self-assessment answers, temporary metrics, and generated scan reports are configured to expire 72 hours after the session is created.
- ✓A separate deterministic cache can retain aggregate report output for up to 30 days so identical inputs return a consistent result. It is keyed by an input fingerprint and does not contain provider credentials.
- ✓Scanner OAuth tokens are cleared after analysis; Watchdog connector credentials follow the separate, longer-lived Watchdog lifecycle below.
- ✓The scanner aims to retain derived operational metrics rather than source-system exports. A connector may still process fields returned by its provider while calculating those metrics.
- ✓The "Delete My Data" control removes the Scanner session, its temporary connector rows, optional product events linked by that session ID, and the linked deterministic report-cache entry. Separate account, security-log, support, payment, and Watchdog records are outside this Scanner control.
- ✓Optional analytics, account security records, and contact requests have their own retention periods and are not part of the scanner's 72-hour session.
🚫 Our data-use boundaries
- ✗We do not sell personal or operational data.
- ✗We do not use connector content for advertising or cross-site behavioural targeting.
- ✗Optional product analytics is not required to use the essential site, scanner, account, or payment functions.
- ✗Monitoring connectors are not used to send messages or change source-system records without a separate, explicit instruction and authorization.
- ✗Passwords and connector secrets should be entered only in the designated secure sign-in, OAuth, or connector form — not in chat, email, or support notes.
- ✗We limit service-provider disclosures to what is needed to host, secure, communicate, analyze, support, and bill for the service.
Data Collection & Processing
What we process depends on how you use OpsLab. Essential service data can include request/security logs; language and consent preferences; scan answers and connector-derived metrics; account name, email, company, contact details, authentication sessions, consent records, and support messages. Watchdog can additionally store organization settings, monitoring targets, encrypted connector credentials, provider/workspace identifiers, sync records, derived metrics, selected evidence, alerts, recommendations, and briefs. Payment records can include plan, amount, currency, status, provider reference, payer contact, and timestamps; WayForPay handles the payment form and payment-instrument details. If you accept optional first-party analytics, we may also record page or funnel events, a safe entry path, sanitised campaign parameters (UTM), the external referrer host, an inferred advertising source when a click identifier is present (without retaining its raw value), an anonymous identifier, and an account or scan-session reference where available. Do not submit special-category or unrelated confidential data unless the agreed service scope requires it.
Data Retention
Core Scanner-session data follows the 72-hour lifecycle described above. A separate deterministic cache of aggregate Scanner report output can remain for up to 30 days so identical inputs produce consistent results; it is keyed by an input fingerprint and does not contain provider credentials. Using the deletion control on a Scanner report also removes the cache entry linked to that scan and optional product events linked by its session ID. Client login sessions currently expire after 30 days; security/authentication-attempt records are scheduled for deletion after 30 days. Optional first-party product events are scheduled to expire after 180 days. Account, contract, support, Watchdog, connector, consent, and payment records are longer-lived: they are kept while needed to provide and secure the service, document instructions and consent, handle billing or disputes, and meet applicable accounting or legal duties. A Watchdog connection is continuous until it is disconnected, the service ends, or deletion is completed; it is not covered by the Scanner lifecycle. We review a verified deletion request against contractual, security, backup, and legal-retention needs and remove or anonymize data that no longer has to be kept.
Service providers and connected platforms
We use service providers only where applicable to the feature: Hetzner hosts the production application and database in Germany; Railway hosts test infrastructure in an EU region; OpenAI API supports report generation, recommendations, chat, and embeddings and may receive the specific metrics or evidence needed for that task; WayForPay processes checkout and payment status; Resend delivers transactional or opted-in email; and Telegram supports Telegram login, bot connections, and operational notifications where enabled. A connector also exchanges data with the platform you choose, such as Google, Slack, Atlassian, GitHub, Notion, or ClickUp, under that platform's terms. Providers may process data in other countries. We do not describe these providers as receiving “no data”: each receives the limited fields needed for its role.
Your Rights
- •Subject to applicable law, you may ask for access, correction, deletion, restriction, objection, or a portable copy of relevant personal data.
- •You can withdraw optional analytics at any time through “Manage privacy choice” below. Withdrawal does not affect processing that occurred before the change.
- •From your verified cabinet, you can disconnect a Watchdog connector and choose either to keep its collected history under the retention policy or to delete that connector’s collected data plus tenant-wide derived Watchdog outputs. Local disconnection removes the stored credential and stops future syncs; revoking the OAuth grant or API key at the provider is a separate action.
- •You can delete a Scanner session from its report. Account-wide deletion, including requests involving account, payment, support, or records retained for legal, security, or accounting purposes, is a separate verified request and remains subject to applicable retention duties.
- •You may complain to the data-protection authority responsible for your location if you believe your request has not been handled lawfully.
Changes to This Policy
We will update this notice when products, providers, or data practices materially change and will request a fresh choice where consent is required. Version: privacy-v2. Last updated: 28 July 2026.
Privacy contact
The data controller is FOP Mykhailo Ivashchuk (trading as OpsLab; full registration details at /requisites). Email janedavydiuk@opslab.uk for privacy questions or a verified access, correction, export, objection, connector-disconnection, or deletion request. Please do not include passwords, payment credentials, API keys, or connector secrets in the message.