Opura / Legal
Privacy Policy (DRAFT)
As of: 8 September 2026
1. Controller
YARX GmbH
Wolfgrubenstrasse 56, 5742 Kölliken
Switzerland
Email: [email protected]
2. Principle
Opura is built to use as little data as possible: the apps process photos and videos only locally on your Mac. Your media never leave your computer. There are no advertising trackers, no analytics cookies and no disclosure of data for advertising. Fonts are loaded from our own servers (no Google Fonts request).
3. Data we process
3.1 Opura account
- Email address, name, optional company name
- Purpose: account, licence management, downloads, update entitlement
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR)
3.2 Licences and device activation
To limit new trials to once per account and Mac per app, we also store a purpose-bound device-consumption record. It contains the product code, a further SHA-256 hash of the existing device fingerprint, hashed references of entitled trial licences, and the time of first use. This separate record contains no email address, account ID or raw hardware ID. It is pseudonymous and not a hardware attestation. It remains after account deletion for as long as the trial offer and protection against repeated trial use need this record; if that purpose ends, it is deleted. Trial licences already issued keep their expiry date.
- Licence key, licence status, update period
- Per activated device: a salted, one-way device fingerprint (hash), device name, model, macOS and app version, activation / last-seen time
- Purpose: enforcing the seat limit (3 devices), abuse prevention
- Legal basis: performance of a contract; legitimate interest
3.3 Purchase and payment
Purchases are handled entirely by our payment partner Polar Software Inc. as merchant of record. Polar is an independent controller for the transactions. Card data (card numbers and similar) never reach our application.
When a checkout starts we send Polar: account email, account ID, IP address, product identifier, the internal checkout reference and, for a renewal, the licence ID.
Polar webhooks may contain further fields, including a customer email. For licensing and accounting we retain from them order, checkout and Polar customer IDs, product identifier, amounts, currency, tax, invoice number and refund status, plus a hash used to recognise the message, not its full contents. A customer email that arrives in the webhook is not stored on this path. Polar's privacy policy: https://polar.sh/legal/privacy-policy
If you delete your Opura account, we instruct Polar to anonymise your customer record there: name, email address, billing address and the link to your Opura account are removed. Invoices issued by Polar remain unaffected.
Account deletion deletes the data linked to your account on our side and ends the related entitlements (licences and device seats). Invoice records we keep by law are detached from your account. Polar, as an independent controller, keeps its own transaction and invoice records.
3.4 Server logs
Visiting the website and using our interfaces produces technically necessary log data (IP address, time, requested resource, user agent). Purpose: operation, security, fault diagnosis. We normally keep server and CDN logs for 30 days; in a security incident we may keep them for up to 90 days.
3.5 In the apps
The apps send no telemetry. App network connections are limited to three purposes: signing in to your Opura account, licence activation/checks, and the authenticated update channel (checking and downloading new versions).
4. Recipients
| Service | Purpose | Location/region |
|---|---|---|
| Supabase (account/licence database, Auth, downloads) | Backend | Primary data storage Zurich, Switzerland (Supabase region eu-central-2). Not all processing is limited to Switzerland. |
| Cloudflare (website hosting, CDN, support emails) | Website delivery; processing of inbound support emails | global |
| Resend / Plus Five Five, Inc. | Delivery of account sign-in and management emails | USA |
| Polar Software Inc. (independent controller, merchant of record) | Checkout, tax, invoicing | USA |
Scroll horizontally for further columns.
5. Cookies and local storage
The website does not set tracking cookies. For the account area the session is stored locally in your browser (strictly necessary). A motion preference is stored locally (no personal reference).
6. Retention
- Server and CDN logs: normally 30 days, up to 90 days in a security incident.
- Account data: deleted after confirmed account deletion.
- Device and licence activation data: during the active licence and 90 days thereafter; deleted after confirmed account deletion. Excepted is the purpose-bound device-consumption record for trials under section 3.2.
- Residual copies in backups: deleted after 35 days.
- Purchase and invoice records are subject to the ten-year retention duty from the end of the financial year (CO Art. 958f(1) and (2)); account deletion does not shorten this, the account link is removed, the invoice itself still contains the details required for invoicing and bookkeeping (Art. 17(3)(b) in conjunction with Art. 6(1)(c) GDPR) and is not visible in the Opura account.
- Support emails: 2 years after the support case is closed.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Requests to: [email protected]. You may also lodge a complaint with a supervisory authority (CH: FDPIC; EU: your national data-protection authority).
8. Changes
We update this policy when services or the law change. The version published here applies.