myopx — Privacy Policy

Last updated: 20 September 2026

Who we are

OpX Software Limited is the data controller for myopx. We are a company registered in England and Wales (company number 15201870), registered office Sbarc/Spark, Maindy Road, Cardiff, Wales, CF24 4HQ.

This notice covers myopx, the free single-person edition of OpXOS. If your organisation gave you an OpXOS account, a different arrangement applies: there we act as processor for your employer, and their privacy notice governs. On myopx you signed up yourself, so we are the controller and this notice is the one that applies to you.

Who can use myopx

myopx is for people aged 18 or over. We don't knowingly collect personal data from anyone under 18, and we will delete any account we find belongs to someone under 18.

What we collect

Things you give us. Your email address and password, your first name if you choose to give one, your profile picture if you add one, and your sector.

Things you create. Tasks, ideas, canvases, projects, comments, community posts, learning progress, badges and streaks.

Things that happen automatically. Sign-in events, technical logs, error reports, and basic information about the device and browser you use so that the app works and we can investigate faults.

Things you send us. Emails and support messages.

We do not buy personal data, scrape it, or use it for advertising. myopx shows no adverts.

What other people can see

This matters more than most of this notice, so it's worth reading.

The community is a single open pool shared by everyone using myopx. Anything you post there is visible to every other myopx user, alongside your name and your sector. Your organisation is not shown on public posts.

Profile pictures are publicly accessible. Avatar images are served from a public location, which means anyone holding the image's address can open it without signing in. Don't use a picture you would not want seen outside myopx.

Your profile is private until you choose to share it. If you turn sharing on, other myopx users can open your profile and see your name, photo, sector, headline, bio, company and any links you have added. You can turn it off again at any time. Your posts continue to show only your name and your sector.

Colleagues you invite can see the boards, canvases and ideas you share with them.

Everything else is private to you — your own tasks, your private canvases, your projects and the advisory readings on them.

How we use your data, and why we're allowed to

What forLawful basis
Running your account and providing myopxPerformance of a contract with you
Service emails — confirming your address, resetting a password, invitations you send, badges you earn, a project readingPerformance of a contract with you
Keeping the service secure, investigating faults and abuse, moderating the communityOur legitimate interests in operating a safe, working service
Following up when you tell us you're interested in a paid planOur legitimate interests in responding to you, and taking steps at your request
Meeting our legal obligationsLegal obligation
Anything else we ask you aboutYour consent, which you can withdraw

We don't send marketing email from myopx.

AI-assisted features

Some features generate a written reading of a project update automatically. When you ask for one, the text of that update, the last few updates on the same project and its basic details are sent to OpenAI, which produces the reading and returns it. OpenAI does not use data submitted through its API to train its models. The reading is private to you, it is advisory, and nothing is written to your project unless you choose it.

This is the only feature that sends your content to an AI provider, and OpenAI is the only AI provider we use.

Who else handles your data

We use a small number of service providers, who process data on our instructions and nothing else:

  • Supabase — the database, authentication and file storage behind myopx, hosted on AWS in London (eu-west-2).
  • Resend — delivering the emails described above.
  • Lovable — hosting the application, collecting error reports, and operating the gateway our outgoing email passes through on its way to Resend.
  • OpenAI — producing the project readings described above.
  • HubSpot — the customer record system used by OpX Software Limited and its parent company, Reinvigoration Group. Your details are recorded there only if you tell us you are interested in a paid plan, so that someone can follow it up.
  • Microlink — building the preview card when you post a web link. We send them the address and nothing else: not your name, not the rest of your post, not anything identifying you. Our server makes that request, so your device never contacts them, and the picture on the card is copied to our own storage rather than loaded from elsewhere. They keep a log of the addresses we send, and their logging providers operate in the United States.

That is the complete list. myopx uses no analytics, advertising or tracking services.

We do not sell personal data, and we do not share it with anyone else except where the law requires it.

Where your data is held

Your account and content are stored in the United Kingdom, in AWS's London region. Where a provider processes data outside the UK, that transfer is covered by UK International Data Transfer Agreements, Standard Contractual Clauses, or an adequacy decision.

Two things you do can send content outside the UK, both described above. When you ask for a project reading, the text of that update goes to OpenAI and may be processed in the United States or elsewhere. When you post a web link, that address goes to Microlink, whose logging providers are in the United States. Both transfers are covered by Standard Contractual Clauses with the UK Addendum. Nothing else you put into myopx leaves the UK in the ordinary course of using it.

How long we keep it

We keep your account and content for as long as your account exists. If you delete your account, see below. Technical logs are kept for a short operational period and then discarded. We may keep a minimal record of a deletion, and anything we are legally required to retain.

Deleting your account

You can delete your myopx account yourself, from inside the app — you don't have to ask us.

When you do: your account and sign-in details are removed, your private content is deleted, and your community posts and comments are anonymised or removed so they can no longer be traced to you. Content you shared into a colleague's work may remain with them. Deletion is permanent and cannot be undone.

Your rights

You have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time.

Email support@opx.io and we'll respond within one month.

If you think we've handled your data badly, please tell us first so we can put it right — but you also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Cookies and local storage

myopx does not use advertising or tracking cookies. It stores a small amount of information in your browser so the app works: your sign-in session, your light or dark theme choice, and an invitation you opened before signing up. Clearing your browser data removes these and signs you out.

Changes to this notice

If we change how we use your data in a way that affects you, we'll tell you and, where it matters, ask you to accept the change the next time you sign in.

Contact

support@opx.io
OpX Software Limited (company number 15201870), Sbarc/Spark, Maindy Road, Cardiff, Wales, CF24 4HQ