Legal
Privacy Policy
LAST UPDATED 22 AUG 2026 · EFFECTIVE ON FIRST USE
Oportunities is an AI agent that helps creators land brand deals. To do that, it reads your connected accounts to find signals, and — only after you approve each one — sends pitches from your own inbox. This policy explains exactly what we access, how we use it, who processes it, and the controls you have. In plain terms: we use your data only to run the features you signed up for. We never sell the contents of your mailbox, and we never use your data for ads. Your mail is read by software, not by people.
On this page
1. Who we are
Oportunities (“Oportunities,” “we,” “us”) is operated by Anycast Technology Private Limited, an Indian company (GSTIN 06AARCA1577E1ZL), registered at WeWork DLF Two Horizon Centre, 5th Floor, DLF Phase 5, Sector 43, Golf Course Road, Gurugram, Haryana 122002, India. We are the data controller for the personal data described in this policy.
2. What data we access
We access only what the agent needs to find opportunities and send the pitches you approve. You grant each connection explicitly, and you can disconnect any of them at any time.
Google — Gmail
When you connect your Gmail, we request exactly three permissions — and nothing broader:
| Scope | What it lets the agent do | Why |
|---|---|---|
openid | Confirm which Google account you connected. | So we can tell your connected mailboxes apart and avoid connecting the same one twice. |
gmail.readonly | Read your messages. Read-only — it grants no ability to change anything in your mailbox. | To detect signals (plans, habits, wishes, brand conversations) that a brand would want to sponsor. |
gmail.send | Send the specific pitches and follow-ups you have approved, threaded into your conversations. | So approved outreach goes out from your inbox, in your name — not a no-reply relay. |
We do not request gmail.modify and we do not request the full-access https://mail.google.com/ scope. Because of this the agent technically cannot delete, archive, label, move or draft anything in your mailbox — that is a limit of what we asked for, not a promise about how we behave. It can only read, and send what you approve.
Signing in is a separate permission. Signing in with Google asks for your name and email address, so we can create your account. Signing in with Apple asks for the same two. Neither gives us any access to a mailbox — that is the Gmail connection above, and you grant it separately.
We do not connect to your Google Calendar, Drive or Contacts. We request no permission for any of them, and no part of the running product reads them.
How much we read. The permission we hold covers your whole mailbox, including the messages you have sent. Day to day the agent reads your inbox, going back 90 days from the day you connect, and new mail as it arrives; if you disconnect and connect again later, we look back over the time you were away, up to the same 90 days. Separately, a brand-collaboration search looks for past brand, sponsorship and collaboration conversations going back up to two years, and that search can read mail you sent — your own reply to a brand is often the only evidence the conversation happened at all. The agent also revisits a thread it has already sent an approved pitch into, to look for the brand’s reply.
Instagram (optional)
If you connect Instagram, we read one thing through the official Meta Graph API, with separate Meta consent: your own profile — your username, account type, follower count, post count and profile picture. We do not read your posts, your captions, your audience insights, your follower list, other people’s content or anyone’s private data, and we never scrape Instagram. We use the profile to understand your niche and audience size.
Account & usage data
Your name, email, profile details you enter, subscription status (via the app stores / RevenueCat), and behavioral product analytics (which screens you use, which pitches you approve). Analytics are behavioral only — they never contain the content of your emails.
The forms on this website
This website has two forms of its own — the brand waitlist and the creator application — and they are separate from the app. If you fill one in, we keep what you typed (your email address, plus a brand’s web address, or your social handle and the short description you write) together with your IP address, the identification string your browser sends (which names your browser and device) and, on the waitlist form, the page you arrived from. That record is held in a database run by Cloudflare, who also serve this site, and a copy of it is emailed to our own team through Resend. That record does not sit in the AWS region named in §7 — it sits on Cloudflare’s network, and we have not restricted that database to a single region. Filling in either form gives us no access to any mailbox and creates no account.
3. Google user data & Limited Use
Oportunities’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain language, that means:
- We use Google user data only to provide and improve the user-facing features you signed up for (finding signals and sending the pitches you approve).
- Some things derived from Gmail are shared between creators. The addresses brands email from — a department mailbox like
partnerships@thebrand.com, or a named person at the brand — go into a contact book creators draw on, so the pitch you approve reaches someone (§4, §6, §7). What is kept is the address, the brand, a person’s first name where the sender is a person, and which creator’s inbox it came from. No message, subject, snippet or attachment is kept for this, and nothing else about you is shared with another creator. Two smaller things are also common to everyone rather than yours alone, and §6 names both: the shared lists of habits, wishes and plan types the app offers you to pick from, which grow a new entry when the agent meets a category they did not have — usually a category word, sometimes one carrying a place or a brand, never linked to you; and a processing cache that stops us paying to read the same email twice. Everything else derived from your Gmail belongs to your account alone — your signals, your matches, your pitches and your replies are never visible to, or used for, another creator. Brands can see the signals you confirm. They cannot see unconfirmed or dismissed signals, and never the emails behind them. Brands use these signals to find creators and reach out with deals. You can remove a confirmed signal at any time. - We do not use Gmail data for advertising of any kind.
- We do not sell or transfer Google user data to third parties, except as needed to provide the service (the subprocessors in §7), to comply with law, or as part of a merger you are notified of.
- We do not use your Google data to train generalised AI models. Our AI provider’s business terms state that data submitted through their business API is not used to train their models.
- Your mail is read by software, not by people — see §5. We do not allow humans to read Google user data unless we have your affirmative consent for a specific message, it is necessary for security/abuse investigation or to comply with law, or the data has been aggregated and anonymised.
4. How we use your data
- Find signals — the agent reads your inbox to detect upcoming plans, recurring habits, and wishes that brands would want to sponsor.
- Match brands — it matches those signals to brands with the budget and the right contact, and scores the fit.
- Learn how to reach a brand — when a brand’s email arrives in your inbox, the agent keeps the address it was sent from and adds it to our brand contact book. That is either a department mailbox (
partnerships@thebrand.com) or a named person at the brand, kept with their first name. The contact book is shared across creators on Oportunities, and we record which creator’s inbox each address came from. See §6 for what is taken and what is refused. - Write pitches in your voice — it drafts outreach informed by the signals you confirmed, your profile and your niche.
- Send what you approve — nothing is ever sent until you approve it. The agent then sends from your Gmail and follows up at most once. We keep a copy of every pitch we send on your behalf. Each one is blind-copied to our own mailbox (
tracking@oportunities.ai). Why: the agent is writing to real companies in your name, and this is how we can see a badly-written pitch and fix it before a brand complains — which matters most now, while the product is new and few pitches have ever gone out. It also lets us confirm a pitch actually left and match a brand’s reply back to it. The copy contains the pitch exactly as sent: your name and sending address, the brand contact’s address, the subject and the body. The brand cannot see it — a blind copy is invisible to them. It is not a copy of your mailbox; only of the outreach you personally approved. Being straight about the limits of it: that mailbox is read by our team, we have not set it to delete copies after any period, and we have not restricted it to particular people. If we change either, we will say so here. - Track results — it classifies brand replies so you can see when an opportunity is created.
- Run your account — authentication, subscriptions, support, and security.
We never use your data to train shared AI models, to build advertising profiles, or for any purpose unrelated to running Oportunities for you.
5. No human reads your mail
Your emails are read by software, not by people. We have no tool that shows a member of our staff your mailbox, and we do not review inboxes.
The only narrow exceptions are: where you give us explicit permission for a specific item (for example, you send us a message while getting support); where it is strictly necessary to investigate abuse or a security incident, or to comply with applicable law; or where the data has been aggregated/anonymised so it is no longer about you. We never browse inboxes for any other reason.
Being precise about the edge, because a policy that claims perfection is not credible: our engineers can query the databases that hold the derived records described in §6 — under access controls, for debugging and support. A few of those records contain text taken from a message (a subject line, and an excerpt of a brand’s reply, which is held on both the reply record and the deal record — see §6). So the accurate statement is that nobody reads your mailbox, not that no employee could ever see any string that came from an email.
The same precision applies to outgoing mail, and it is the bigger of the two: as §4 says, every pitch you approve is blind-copied to our tracking mailbox, and that is a real mailbox our team can open. So a pitch you sent is a message an employee could read. That is a copy of your own outbound message, which you approved before it went — never anything a brand sent you, and never anything else in your inbox. We would rather you knew that than discover it from a mail header.
There is a second edge, and it is not about our staff at all: once we switch on the second AI provider named in §6, a person at that provider may be able to see text that came from your mail. Not by browsing your mailbox — nobody outside Oportunities can reach it — but because that provider keeps a copy of what we send it for a period, and may have a person look at it when their own systems flag something. §6 sets out exactly what is kept, for how long, and why. We are putting it here as well because the heading above this section is a promise, and a promise that quietly depends on which supplier we happen to be using is not one.
6. AI processing
Oportunities uses AI models to read signals, classify replies, and write pitches. The AI providers that handle this work are Anthropic and OpenAI. Either may handle any given piece of it. We may add other AI providers. Any provider we use is listed in §9 before it handles anything, with what it keeps and whether a person there may see it — and whichever provider handles your data, the bound below is the same and does not change. We do not list the individual models. Moving to a newer or faster model from a provider already listed changes nothing in this section and is not announced. Every one of them is called through its business API. What we send is bounded: a message’s sender, its subject, a short snippet, and a limited portion of its text — enough to judge whether it is a brand-worthy moment and to pull out the structured facts. Where a message carries a PDF that the text alone does not explain (a ticket or a booking confirmation, for example), that PDF may also be sent for the same purpose. We do not send your whole mailbox and we do not send your contacts.
Anthropic’s business API terms state that data submitted through it is not used to train their models. OpenAI’s API terms state the same: data submitted through their API is not used to train their models by default. We will not add an AI provider whose terms permit training on your data.
On OpenAI, stated plainly rather than buried. OpenAI receives the same bounded material described above and nothing more — never your whole mailbox, never your contacts. We name every provider here before it handles anything rather than after, because that is what this policy promises in §7, so a provider appearing in this policy does not by itself tell you it is carrying your data at this moment. If you want to know which provider handled your data at a given moment, ask us at support@oportunities.ai and we will tell you.
OpenAI keeps a copy of what we send them for up to 30 days. This is the part of the change we would least like to be true, so it is stated here rather than left for you to find. OpenAI’s published policy is that content sent to their API is written to abuse-monitoring logs and kept for up to 30 days — and for longer where the law requires it, or where OpenAI reasonably needs it to protect their service or someone else from harm. So “up to 30 days” is their normal case, not a hard ceiling, and we would rather quote it that way than round it into a promise they have not made. Those logs can contain the prompts we send and the answers that come back. What we send is drawn from your mailbox — a sender, a subject, a snippet, a limited portion of a message’s text, and sometimes an attached PDF. Where OpenAI handles it, that material sits on OpenAI’s systems for that period as well as passing through ours. It is used to detect misuse of their API, and OpenAI’s terms state it is not used to train their models.
And a person at OpenAI may read it. OpenAI states that content held in those logs can be reviewed by people — authorised OpenAI staff, and specialist contractors under confidentiality obligations — where their automated checks flag something as possibly breaking their usage rules, or where the law requires it. That is a much narrower thing than someone opening your mailbox, and it is nobody at Oportunities. But it is a human being able to see text that came from your mail, and §5 would not be honest without it.
There is a setting that switches this retention off, and we do not have it. OpenAI offers zero data retention, under which they keep nothing. It is not something a customer can simply turn on: OpenAI has to approve it, and they have not approved it for us. We are going ahead without it. We would rather tell you that plainly than describe a protection we do not hold. If we obtain it, this page will say so. Note also that §7 says no provider may use your data for their own purposes — this abuse monitoring is the one exception, it is OpenAI’s own safety obligation rather than anything we ask for or gain from, and none of it changes what we send: the bound described at the top of this section is the same for both providers.
What we keep, and what we do not
Message bodies and attachments are not saved. They are fetched from Gmail, held in memory while the software processes them, and discarded when processing finishes. They are not written to our database, not written to files, and not written to our logs. Where we cache something about a message so we do not pay to process it twice, the message is looked up by a one-way cryptographic fingerprint — we never store the message itself. What is stored against that fingerprint is the same short structured result described below (for example the product and brand the email was about). The cached result is keyed by the message, not by you, so two creators who receive the same email share one row. Alongside it we keep an index of which creators’ mail produced each row. That index holds a creator id and the message fingerprint — no name, no address, no message text. Deleting your account deletes that index and the cached results your mail produced. A cached result stops being used after 30 days. It is not deleted at that point: the job that removes expired rows is built and is not switched on.
What we do keep is the derived, structured intelligence the agent needs — for example “travels to Goa in July” or “works with skincare brands” — plus your confirmations, the matches and pitch drafts, a record of which brand contact was emailed and when, and a content-free thread index so we do not re-read the same mail.
One thing that comes out of this is common to everyone: the app offers you lists of habits, wishes and plan types to pick from, and when the agent meets a category those lists do not yet have, it adds an entry so the next creator can pick it too. Most are ordinary category words — “Coffee”, “Pizza”, “Groceries”. Some are more specific and can carry a place or a brand, because the entry is built from the label the agent worked out — “Mussoorie Getaway”, for example. They are never a sentence from your mail, and none of them is linked to you: a reader of that list cannot tell which creator it came from. Your own picks stay yours and are deleted with your account. The shared lists are not.
Four narrow exceptions:
- Subject lines. Where a message reaches us through Gmail’s live notification rather than a scan, we keep the first 60 characters of its subject as the label you see on that card. On the scan path we do not keep the subject: that label is a sentence written from the signal itself.
- Brand replies. When a brand replies to a pitch you sent, we keep that reply’s subject line and a short excerpt of its body (up to 500 characters) so you can read it in the app, and so the software can tell an interested reply from a bounce or an out-of-office. When a reply turns into a live conversation, that same excerpt is also copied onto the deal record for that conversation, so it exists in two places rather than one. We also keep the address the reply came from, so we can tell which conversation is which. In the app you only ever see it masked (
•••@thebrand.com). The address itself is stored encrypted, only its domain is held in plain text, and the masked form is what the app displays. - The address a brand emails from. When an email in your inbox comes from a brand we already track, we keep the address it was sent from and add it to a brand contact book that creators share. We do not keep that message, its subject or its contents. A department mailbox —
partnerships@,collabs@,influencers@,press@and similar — is kept as an address. A named person at the brand is kept as an address and a first name, taken from theFrom:line. What is refused: any personal mail provider (Gmail, Yahoo, Outlook and the like), your own address, automated senders (no-reply@), transactional mailboxes (orders@,billing@), and any address we cannot tie to exactly one brand we already track. We store the address encrypted and show it to you masked. We record which creator’s inbox each address came from. That record is the address, the brand, the creator and the date; it holds no message, subject, snippet or attachment. It is deleted when you delete your account. The address itself is not — see §8. - A person a brand names in a reply. When a brand replies to a pitch you sent and names someone else to contact — “talk to Priya instead” — we keep that person’s first name and work address and add them to the brand contact book. The address has to be on the brand’s own domain. That contact is shared with every creator. We do not keep the sentence it came from.
The first two relate to mail that is already being shown to you, and both are removed when we action a deletion request (§8). Neither has a fixed expiry date of its own — we keep them for as long as we keep the card or the conversation they belong to. The brand addresses in the third and fourth are not deleted when you delete your account. The record of which creator’s inbox an address came from is deleted, with the rest of your data. §8 says what that leaves behind. Apart from these, we do not retain the text of your messages.
7. Subprocessors
We use the service providers below to run Oportunities. This list names every provider our software is built to reach — including ones we have set up but are not relying on yet, because we would rather name a provider before it handles anything than after. We do not sell data to any of them, and none of them may use your data for their own purposes.
Providers that handle your data
| Subprocessor | Purpose |
|---|---|
| Google (Gmail API) | The mailbox you connect, and the route your approved pitches take out |
| Anthropic (Claude) | AI — signal extraction, reply classification, pitch writing |
| OpenAI | AI — the same work as the row above, It receives the same bounded material described in §6 and nothing more. It keeps a copy for up to 30 days for abuse monitoring, and a person there may read it — §6 explains exactly what that means. |
| Amazon Web Services (AWS) | Cloud hosting, database and logging for the app. Your account data and the records derived from your inbox are stored in AWS’s Mumbai (ap-south-1) region — that does not cover the website forms described in §2 |
| Expo | Delivers push notifications to your device, which Expo relays via Apple and Google push services. It receives your device push token and the notification text — which is templated, and can include a brand name and counts drawn from your inbox, never the text of a message |
| PostHog | Product analytics — which screens you use, and which pitches you approve. It receives the name of the action and an identifier for your account, so this is not anonymous counting: the actions are tied to you. It never receives the content of your emails |
| Slack | Where our own operational alerts go, so a person on our team sees a failure. An alert carries the name of what failed and a short set of technical fields, which can include the internal identifier for your account. It never carries the content of your emails |
| Meta / Instagram Graph | Your own Instagram data (separate, optional consent) |
| RevenueCat | Subscription status across the app stores |
| Apple App Store & Google Play | Payments / Merchant of Record for subscriptions. They hold your payment details — we never see your card. Apple and Google also handle signing in, where they pass us your name and email address |
| Cloudflare | Serves this website, and holds what you submit through the two forms on it (§2) — including your IP address and your browser’s identification string. This store is not in the AWS region above, and we have not restricted it to a single region |
| Resend | Emails our own team a copy of anything you submit through this website’s forms, so that a person actually sees it. That copy carries your email address, what you typed and your IP address. Resend is not used to send anything to you |
Providers that handle brand data, not yours
These help us find and reach the right person at a brand. They never receive your identity, your address, or anything from a message — no sender, subject, snippet, body or attachment ever reaches them. What they do receive is a company name, a company’s web domain, or the name of a person who works there.
Two things to be exact about. To find brands worth pitching you, we send Apollo a short category phrase the agent has worked out from the signals you confirmed — something like “travel-size skincare brands” or “filter coffee subscriptions”. It describes a kind of company, it is inferred rather than quoted, and it carries no name, address, account or message text. It is still derived from your inbox, so “nothing from your inbox reaches them” would not be true. We also send Apollo a brand’s own web domain when we are looking for who to contact there. That is company data and carries nothing about you.
Our brand contact book is built from four sources: these paid providers, brands’ own published contact pages, and — as §4 and §6 describe — the addresses brands email from, noticed in connected creators’ inboxes, and people a brand names in a reply. Why the last two exist: bought contact data is frequently wrong, and an address that has delivered a real email is the one most likely to work.
| Subprocessor | Purpose |
|---|---|
| Apollo.io | Company and business-contact data |
| Greenhouse · Lever · Ashby | We read brands’ public job boards as a signal that a brand is investing in marketing |
| Common Crawl | A public index of the web. We read it to find which brands have a job board at all. We send it nothing about you |
| Brand websites | We read publicly published company contact pages |
| Prospeo · AnyMailFinder · Hunter.io | Finding the work email address of the right person at a brand. They receive the brand’s web domain, and two of them also receive the name of the person we are looking for. We have built these in but have not switched them on |
| Rakuten Advertising | Checking whether a brand runs a public affiliate programme. Receives a brand’s name or web domain only. We have built this in but have not switched it on |
We will update this list before introducing any new subprocessor that processes personal data.
8. Retention & deletion
One request deletes your data: an explicit deletion request that you send us. Nothing else does — not cancelling, not going quiet, not uninstalling the app. We would rather say that plainly here than let you assume something is being deleted that is not.
- While you’re active — we keep your derived signal data and account data to run the service.
- If you cancel — we stop sending outreach, and we keep your derived data so you can resume where you left off if you come back. Cancelling is not a deletion request and does not start a deletion clock. That is deliberate: we will not destroy the inbox history of someone who cancels for a month and returns. If you want your data gone, ask us — see the next line.
- If you delete your account — use Delete account in the app, under Profile → Danger Zone. That button is the request: it records it, closes your account and starts a 30-day clock. Signing back in inside those 30 days cancels the request. After that the erasure is carried out by an automatic job, and we do not send you an email when it finishes. The erasure job is built and is not switched on yet, so a request made today is recorded and queued and the data has not been erased. Going quiet or cancelling your subscription does not delete anything — only the request does. If you can no longer get into the app, write to us instead and we will do it by hand.
- Disconnecting Google revokes our access immediately — the app calls Google’s revoke endpoint and deletes the stored token. If that call to Google fails, the token is kept, encrypted, so the revoke can be retried, and it stays until it is. You can also remove our access yourself at any time at myaccount.google.com/permissions.
- Pitches the agent has already sent live in your own Gmail Sent folder and are unaffected by deletion on our side.
Some records outlive a deletion, and we would rather name them than imply otherwise. Where the law requires us to keep something we keep it — for example tax and payment records of your subscription, and our own record that your deletion request was made and honoured, which cannot itself be deleted by the deletion. A small number of records are kept with the link to you removed instead of being deleted, because deleting them would harm someone else: a brand contact’s request never to be emailed again, and an unsubscribe link already sent to them, both have to keep working after your account is gone.
The shared brand contact book. An address first noticed in your inbox (§6) is not deleted when you delete your account, and by then it may be in use for other creators. What is deleted is the record that it came from your inbox. Deleting your account removes your data; the address stays in the contact book. Disconnecting Gmail stops any new address being taken from your inbox. You can also write to support@oportunities.ai.
If you are the brand. If your company mailbox is in our contact book and you want it removed or never emailed, write to support@oportunities.ai or use our email preferences page. You do not need an Oportunities account, and you do not need to have received anything from us yet.
9. Your rights & controls
Subject to applicable law (including India’s DPDP Act and the GDPR where it applies), you can access, correct, export, or delete your personal data, and withdraw consent at any time.
- Disconnect Gmail / Instagram — anytime from the app.
- Delete your account & data — use Delete account in the app, under Profile → Danger Zone. That button is the request, and it reaches us. It records the request, starts the 30-day clock and closes your account. You do not need to email as well — though you can write to support@oportunities.ai if you would rather ask us directly, or follow the steps on our support page.
- Export your data — email grievance@oportunities.ai; we respond within 30 days. Exports are prepared by hand today, not generated on demand.
To exercise any right, contact us at support@oportunities.ai. Our Grievance Officer (for India DPDP requests) is reachable at grievance@oportunities.ai.
10. Security
Connections use OAuth — we never see or store your Google password. Your Google access tokens are encrypted at rest with AES-256-GCM. The main service refuses to start in production without that encryption key configured. One background worker does not. Data is encrypted in transit, hosting-level encryption at rest is applied by AWS, and access to production systems is restricted and logged.
Raw message content is kept out of our logs by automated redaction plus an automated check that runs against our own source code on every change.
Our use of Google user data will be assessed under Google’s independent security review (CASA) for restricted scopes before we open the product beyond its current limited group. We have not completed that review yet, and we would rather say so here than imply otherwise.
11. Age requirement
Oportunities is for creators 18 and older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor we close it and delete the data we hold, through the same team-actioned process described in §8.
12. Changes
If we make a material change to this policy, we will update the date above and notify you in the app or by email before it takes effect.
13. Contact
Questions or requests: support@oportunities.ai.
Grievance Officer (India DPDP): grievance@oportunities.ai.
Anycast Technology Private Limited, WeWork DLF Two Horizon Centre, 5th Floor, DLF Phase 5, Sector 43, Golf Course Road, Gurugram, Haryana 122002, India.