Privacy notice
What OpsOptic processes, for whom, for how long, and what this website collects (nothing beyond what its host reports in aggregate).
Who is who
OpsOptic is a monitoring service. Customers install the OpsOptic SDK in their own applications, and it sends operational telemetry so they can watch the health, errors and usage of their products. For that telemetry the customer is the controller and Mazacode LTDA is a processor acting on the customer's instructions. For people who hold an account and for visitors of this website, Mazacode LTDA is the controller.
Telemetry we process for customers
- HTTP request metadata: method, path, status code and latency.
- Error messages and stack traces.
- Custom events and the properties the customer chooses to send.
- Revenue events: an amount and a currency.
- User identifiers the customer assigns: an external ID and, optionally, an email address and a plan name.
- Application log lines sent through the SDK loggers or as OTLP/JSON, with their level, message and attributes. A log line can contain personal data if the application writes it, so customers should not log what they do not need.
Email addresses and payment card numbers found inside event properties are redacted before they reach the database. Only an email address supplied in the designated field of an identify event is kept. This masking is a safeguard and not a guarantee, so do not send secrets or personal data you do not need.
Account data
The app is closed to the public and accounts are created by hand during early access. For an account we store your name, email address, a password hash, optional two-factor authentication secrets, your workspace membership and role, and an audit log of security-relevant actions such as changes to alert rules, API keys and billing.
This website
This website sets no cookies, runs no analytics or advertising scripts and makes no requests to third parties. Fonts and images are served from the same host. The site is hosted on Cloudflare, whose Web Analytics feature can add a small script that reports aggregate traffic without cookies. We do not control or read that beacon and it is not part of the page code.
The contact button opens a WhatsApp conversation with the founder. From that point the conversation is also governed by WhatsApp's own terms and privacy policy, and Mazacode LTDA receives the phone number and the messages you choose to send.
Retention
| Data | Free | Pro | Enterprise |
|---|---|---|---|
| Events and logs | 7 days | 90 days | 365 days |
| Uptime check history | 2 days | 30 days | 90 days |
| Aggregated metrics | 90 days | 365 days | 730 days |
Data older than the window is deleted automatically. Scheduling the deletion of a workspace removes its events, logs, user profiles, API keys and derived aggregates within 30 days.
Subprocessors and destinations
We use a cloud hosting provider for compute and database, a transactional email provider for account and alert emails, Stripe for payments once paid plans open. Each processes only what its function needs. When a customer configures an alert channel (Slack, a webhook, Zapier, PagerDuty, SMS or push), alert content is sent to that destination on the customer's instruction.
Your rights
Workspace admins can export all workspace data as NDJSON and can export or erase individual tracked users from the project Users page. If you hold an account, you can ask for access, correction or deletion of your account data by messaging the founder on WhatsApp through the button on this site. If you are an end user of a product that uses OpsOptic, contact that product's operator, who controls your data.
Transfers and changes
Data is processed in the region of the hosting provider. Where it crosses borders, we rely on appropriate contractual safeguards with our subprocessors. We will update this notice, and its date, when the product's data handling changes.
Questions about this notice can go to the founder on WhatsApp.
Talk to the founder on WhatsApp