oportunities.

Legal

Privacy Policy

LAST UPDATED 22 AUG 2026 · EFFECTIVE ON FIRST USE

Oportunities is an AI agent that helps creators land brand deals. To do that, it reads your connected accounts to find signals, and — only after you approve each one — sends pitches from your own inbox. This policy explains exactly what we access, how we use it, who processes it, and the controls you have. In plain terms: we use your data only to run the features you signed up for. We never sell the contents of your mailbox, and we never use your data for ads. Your mail is read by software, not by people.

1. Who we are

Oportunities (“Oportunities,” “we,” “us”) is operated by Anycast Technology Private Limited, an Indian company (GSTIN 06AARCA1577E1ZL), registered at WeWork DLF Two Horizon Centre, 5th Floor, DLF Phase 5, Sector 43, Golf Course Road, Gurugram, Haryana 122002, India. We are the data controller for the personal data described in this policy.

2. What data we access

We access only what the agent needs to find opportunities and send the pitches you approve. You grant each connection explicitly, and you can disconnect any of them at any time.

Google — Gmail

When you connect your Gmail, we request exactly three permissions — and nothing broader:

ScopeWhat it lets the agent doWhy
openidConfirm which Google account you connected.So we can tell your connected mailboxes apart and avoid connecting the same one twice.
gmail.readonlyRead your messages. Read-only — it grants no ability to change anything in your mailbox.To detect signals (plans, habits, wishes, brand conversations) that a brand would want to sponsor.
gmail.sendSend the specific pitches and follow-ups you have approved, threaded into your conversations.So approved outreach goes out from your inbox, in your name — not a no-reply relay.

We do not request gmail.modify and we do not request the full-access https://mail.google.com/ scope. Because of this the agent technically cannot delete, archive, label, move or draft anything in your mailbox — that is a limit of what we asked for, not a promise about how we behave. It can only read, and send what you approve.

Signing in is a separate permission. Signing in with Google asks for your name and email address, so we can create your account. Signing in with Apple asks for the same two. Neither gives us any access to a mailbox — that is the Gmail connection above, and you grant it separately.

We do not connect to your Google Calendar, Drive or Contacts. We request no permission for any of them, and no part of the running product reads them.

How much we read. The permission we hold covers your whole mailbox, including the messages you have sent. Day to day the agent reads your inbox, going back 90 days from the day you connect, and new mail as it arrives; if you disconnect and connect again later, we look back over the time you were away, up to the same 90 days. Separately, a brand-collaboration search looks for past brand, sponsorship and collaboration conversations going back up to two years, and that search can read mail you sent — your own reply to a brand is often the only evidence the conversation happened at all. The agent also revisits a thread it has already sent an approved pitch into, to look for the brand’s reply.

Instagram (optional)

If you connect Instagram, we read one thing through the official Meta Graph API, with separate Meta consent: your own profile — your username, account type, follower count, post count and profile picture. We do not read your posts, your captions, your audience insights, your follower list, other people’s content or anyone’s private data, and we never scrape Instagram. We use the profile to understand your niche and audience size.

Account & usage data

Your name, email, profile details you enter, subscription status (via the app stores / RevenueCat), and behavioral product analytics (which screens you use, which pitches you approve). Analytics are behavioral only — they never contain the content of your emails.

The forms on this website

This website has two forms of its own — the brand waitlist and the creator application — and they are separate from the app. If you fill one in, we keep what you typed (your email address, plus a brand’s web address, or your social handle and the short description you write) together with your IP address, the identification string your browser sends (which names your browser and device) and, on the waitlist form, the page you arrived from. That record is held in a database run by Cloudflare, who also serve this site, and a copy of it is emailed to our own team through Resend. That record does not sit in the AWS region named in §7 — it sits on Cloudflare’s network, and we have not restricted that database to a single region. Filling in either form gives us no access to any mailbox and creates no account.

3. Google user data & Limited Use

Google API Services User Data Policy — Limited Use

Oportunities’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain language, that means:

4. How we use your data

We never use your data to train shared AI models, to build advertising profiles, or for any purpose unrelated to running Oportunities for you.

5. No human reads your mail

Your emails are read by software, not by people. We have no tool that shows a member of our staff your mailbox, and we do not review inboxes.

The only narrow exceptions are: where you give us explicit permission for a specific item (for example, you send us a message while getting support); where it is strictly necessary to investigate abuse or a security incident, or to comply with applicable law; or where the data has been aggregated/anonymised so it is no longer about you. We never browse inboxes for any other reason.

Being precise about the edge, because a policy that claims perfection is not credible: our engineers can query the databases that hold the derived records described in §6 — under access controls, for debugging and support. A few of those records contain text taken from a message (a subject line, and an excerpt of a brand’s reply, which is held on both the reply record and the deal record — see §6). So the accurate statement is that nobody reads your mailbox, not that no employee could ever see any string that came from an email.

The same precision applies to outgoing mail, and it is the bigger of the two: as §4 says, every pitch you approve is blind-copied to our tracking mailbox, and that is a real mailbox our team can open. So a pitch you sent is a message an employee could read. That is a copy of your own outbound message, which you approved before it went — never anything a brand sent you, and never anything else in your inbox. We would rather you knew that than discover it from a mail header.

There is a second edge, and it is not about our staff at all: once we switch on the second AI provider named in §6, a person at that provider may be able to see text that came from your mail. Not by browsing your mailbox — nobody outside Oportunities can reach it — but because that provider keeps a copy of what we send it for a period, and may have a person look at it when their own systems flag something. §6 sets out exactly what is kept, for how long, and why. We are putting it here as well because the heading above this section is a promise, and a promise that quietly depends on which supplier we happen to be using is not one.

6. AI processing

Oportunities uses AI models to read signals, classify replies, and write pitches. The AI providers that handle this work are Anthropic and OpenAI. Either may handle any given piece of it. We may add other AI providers. Any provider we use is listed in §9 before it handles anything, with what it keeps and whether a person there may see it — and whichever provider handles your data, the bound below is the same and does not change. We do not list the individual models. Moving to a newer or faster model from a provider already listed changes nothing in this section and is not announced. Every one of them is called through its business API. What we send is bounded: a message’s sender, its subject, a short snippet, and a limited portion of its text — enough to judge whether it is a brand-worthy moment and to pull out the structured facts. Where a message carries a PDF that the text alone does not explain (a ticket or a booking confirmation, for example), that PDF may also be sent for the same purpose. We do not send your whole mailbox and we do not send your contacts.

Anthropic’s business API terms state that data submitted through it is not used to train their models. OpenAI’s API terms state the same: data submitted through their API is not used to train their models by default. We will not add an AI provider whose terms permit training on your data.

On OpenAI, stated plainly rather than buried. OpenAI receives the same bounded material described above and nothing more — never your whole mailbox, never your contacts. We name every provider here before it handles anything rather than after, because that is what this policy promises in §7, so a provider appearing in this policy does not by itself tell you it is carrying your data at this moment. If you want to know which provider handled your data at a given moment, ask us at support@oportunities.ai and we will tell you.

OpenAI keeps a copy of what we send them for up to 30 days. This is the part of the change we would least like to be true, so it is stated here rather than left for you to find. OpenAI’s published policy is that content sent to their API is written to abuse-monitoring logs and kept for up to 30 days — and for longer where the law requires it, or where OpenAI reasonably needs it to protect their service or someone else from harm. So “up to 30 days” is their normal case, not a hard ceiling, and we would rather quote it that way than round it into a promise they have not made. Those logs can contain the prompts we send and the answers that come back. What we send is drawn from your mailbox — a sender, a subject, a snippet, a limited portion of a message’s text, and sometimes an attached PDF. Where OpenAI handles it, that material sits on OpenAI’s systems for that period as well as passing through ours. It is used to detect misuse of their API, and OpenAI’s terms state it is not used to train their models.

And a person at OpenAI may read it. OpenAI states that content held in those logs can be reviewed by people — authorised OpenAI staff, and specialist contractors under confidentiality obligations — where their automated checks flag something as possibly breaking their usage rules, or where the law requires it. That is a much narrower thing than someone opening your mailbox, and it is nobody at Oportunities. But it is a human being able to see text that came from your mail, and §5 would not be honest without it.

There is a setting that switches this retention off, and we do not have it. OpenAI offers zero data retention, under which they keep nothing. It is not something a customer can simply turn on: OpenAI has to approve it, and they have not approved it for us. We are going ahead without it. We would rather tell you that plainly than describe a protection we do not hold. If we obtain it, this page will say so. Note also that §7 says no provider may use your data for their own purposes — this abuse monitoring is the one exception, it is OpenAI’s own safety obligation rather than anything we ask for or gain from, and none of it changes what we send: the bound described at the top of this section is the same for both providers.

What we keep, and what we do not

Message bodies and attachments are not saved. They are fetched from Gmail, held in memory while the software processes them, and discarded when processing finishes. They are not written to our database, not written to files, and not written to our logs. Where we cache something about a message so we do not pay to process it twice, the message is looked up by a one-way cryptographic fingerprint — we never store the message itself. What is stored against that fingerprint is the same short structured result described below (for example the product and brand the email was about). The cached result is keyed by the message, not by you, so two creators who receive the same email share one row. Alongside it we keep an index of which creators’ mail produced each row. That index holds a creator id and the message fingerprint — no name, no address, no message text. Deleting your account deletes that index and the cached results your mail produced. A cached result stops being used after 30 days. It is not deleted at that point: the job that removes expired rows is built and is not switched on.

What we do keep is the derived, structured intelligence the agent needs — for example “travels to Goa in July” or “works with skincare brands” — plus your confirmations, the matches and pitch drafts, a record of which brand contact was emailed and when, and a content-free thread index so we do not re-read the same mail.

One thing that comes out of this is common to everyone: the app offers you lists of habits, wishes and plan types to pick from, and when the agent meets a category those lists do not yet have, it adds an entry so the next creator can pick it too. Most are ordinary category words — “Coffee”, “Pizza”, “Groceries”. Some are more specific and can carry a place or a brand, because the entry is built from the label the agent worked out — “Mussoorie Getaway”, for example. They are never a sentence from your mail, and none of them is linked to you: a reader of that list cannot tell which creator it came from. Your own picks stay yours and are deleted with your account. The shared lists are not.

Four narrow exceptions:

The first two relate to mail that is already being shown to you, and both are removed when we action a deletion request (§8). Neither has a fixed expiry date of its own — we keep them for as long as we keep the card or the conversation they belong to. The brand addresses in the third and fourth are not deleted when you delete your account. The record of which creator’s inbox an address came from is deleted, with the rest of your data. §8 says what that leaves behind. Apart from these, we do not retain the text of your messages.

7. Subprocessors

We use the service providers below to run Oportunities. This list names every provider our software is built to reach — including ones we have set up but are not relying on yet, because we would rather name a provider before it handles anything than after. We do not sell data to any of them, and none of them may use your data for their own purposes.

Providers that handle your data

SubprocessorPurpose
Google (Gmail API)The mailbox you connect, and the route your approved pitches take out
Anthropic (Claude)AI — signal extraction, reply classification, pitch writing
OpenAIAI — the same work as the row above, It receives the same bounded material described in §6 and nothing more. It keeps a copy for up to 30 days for abuse monitoring, and a person there may read it — §6 explains exactly what that means.
Amazon Web Services (AWS)Cloud hosting, database and logging for the app. Your account data and the records derived from your inbox are stored in AWS’s Mumbai (ap-south-1) region — that does not cover the website forms described in §2
ExpoDelivers push notifications to your device, which Expo relays via Apple and Google push services. It receives your device push token and the notification text — which is templated, and can include a brand name and counts drawn from your inbox, never the text of a message
PostHogProduct analytics — which screens you use, and which pitches you approve. It receives the name of the action and an identifier for your account, so this is not anonymous counting: the actions are tied to you. It never receives the content of your emails
SlackWhere our own operational alerts go, so a person on our team sees a failure. An alert carries the name of what failed and a short set of technical fields, which can include the internal identifier for your account. It never carries the content of your emails
Meta / Instagram GraphYour own Instagram data (separate, optional consent)
RevenueCatSubscription status across the app stores
Apple App Store & Google PlayPayments / Merchant of Record for subscriptions. They hold your payment details — we never see your card. Apple and Google also handle signing in, where they pass us your name and email address
CloudflareServes this website, and holds what you submit through the two forms on it (§2) — including your IP address and your browser’s identification string. This store is not in the AWS region above, and we have not restricted it to a single region
ResendEmails our own team a copy of anything you submit through this website’s forms, so that a person actually sees it. That copy carries your email address, what you typed and your IP address. Resend is not used to send anything to you

Providers that handle brand data, not yours

These help us find and reach the right person at a brand. They never receive your identity, your address, or anything from a message — no sender, subject, snippet, body or attachment ever reaches them. What they do receive is a company name, a company’s web domain, or the name of a person who works there.

Two things to be exact about. To find brands worth pitching you, we send Apollo a short category phrase the agent has worked out from the signals you confirmed — something like “travel-size skincare brands” or “filter coffee subscriptions”. It describes a kind of company, it is inferred rather than quoted, and it carries no name, address, account or message text. It is still derived from your inbox, so “nothing from your inbox reaches them” would not be true. We also send Apollo a brand’s own web domain when we are looking for who to contact there. That is company data and carries nothing about you.

Our brand contact book is built from four sources: these paid providers, brands’ own published contact pages, and — as §4 and §6 describe — the addresses brands email from, noticed in connected creators’ inboxes, and people a brand names in a reply. Why the last two exist: bought contact data is frequently wrong, and an address that has delivered a real email is the one most likely to work.

SubprocessorPurpose
Apollo.ioCompany and business-contact data
Greenhouse · Lever · AshbyWe read brands’ public job boards as a signal that a brand is investing in marketing
Common CrawlA public index of the web. We read it to find which brands have a job board at all. We send it nothing about you
Brand websitesWe read publicly published company contact pages
Prospeo · AnyMailFinder · Hunter.ioFinding the work email address of the right person at a brand. They receive the brand’s web domain, and two of them also receive the name of the person we are looking for. We have built these in but have not switched them on
Rakuten AdvertisingChecking whether a brand runs a public affiliate programme. Receives a brand’s name or web domain only. We have built this in but have not switched it on

We will update this list before introducing any new subprocessor that processes personal data.

8. Retention & deletion

One request deletes your data: an explicit deletion request that you send us. Nothing else does — not cancelling, not going quiet, not uninstalling the app. We would rather say that plainly here than let you assume something is being deleted that is not.

Some records outlive a deletion, and we would rather name them than imply otherwise. Where the law requires us to keep something we keep it — for example tax and payment records of your subscription, and our own record that your deletion request was made and honoured, which cannot itself be deleted by the deletion. A small number of records are kept with the link to you removed instead of being deleted, because deleting them would harm someone else: a brand contact’s request never to be emailed again, and an unsubscribe link already sent to them, both have to keep working after your account is gone.

The shared brand contact book. An address first noticed in your inbox (§6) is not deleted when you delete your account, and by then it may be in use for other creators. What is deleted is the record that it came from your inbox. Deleting your account removes your data; the address stays in the contact book. Disconnecting Gmail stops any new address being taken from your inbox. You can also write to support@oportunities.ai.

If you are the brand. If your company mailbox is in our contact book and you want it removed or never emailed, write to support@oportunities.ai or use our email preferences page. You do not need an Oportunities account, and you do not need to have received anything from us yet.

9. Your rights & controls

Subject to applicable law (including India’s DPDP Act and the GDPR where it applies), you can access, correct, export, or delete your personal data, and withdraw consent at any time.

To exercise any right, contact us at support@oportunities.ai. Our Grievance Officer (for India DPDP requests) is reachable at grievance@oportunities.ai.

10. Security

Connections use OAuth — we never see or store your Google password. Your Google access tokens are encrypted at rest with AES-256-GCM. The main service refuses to start in production without that encryption key configured. One background worker does not. Data is encrypted in transit, hosting-level encryption at rest is applied by AWS, and access to production systems is restricted and logged.

Raw message content is kept out of our logs by automated redaction plus an automated check that runs against our own source code on every change.

Our use of Google user data will be assessed under Google’s independent security review (CASA) for restricted scopes before we open the product beyond its current limited group. We have not completed that review yet, and we would rather say so here than imply otherwise.

11. Age requirement

Oportunities is for creators 18 and older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor we close it and delete the data we hold, through the same team-actioned process described in §8.

12. Changes

If we make a material change to this policy, we will update the date above and notify you in the app or by email before it takes effect.

13. Contact

Questions or requests: support@oportunities.ai.
Grievance Officer (India DPDP): grievance@oportunities.ai.
Anycast Technology Private Limited, WeWork DLF Two Horizon Centre, 5th Floor, DLF Phase 5, Sector 43, Golf Course Road, Gurugram, Haryana 122002, India.