← Operava
Privacy Policy
Operava · Last updated 8 October 2026
Operava (“the service”) is an operating view for people who run software products: what each product runs on, what it costs, when it bills, and whether it is up. This policy explains what the service collects, what it is used for, how it is protected, and how to have it deleted.
The service is operated by Infraxeon LLC (“we”, “us”), a New York limited liability company. Questions about this policy or your data: hello@operava.com.
What we collect
Your account
- Your email address, used to sign you in (by emailed link) and to send the emails described below.
- If you sign in with Google: the email address and name Google provides. We do not receive your Google password and we ask Google for nothing beyond identity.
- A session on your browser, kept by our authentication provider, so you stay signed in.
What you enter
Everything in your workspace is there because you typed it or ticked it: product names and descriptions, the vendors you use, what they cost and when they bill, links to dashboards and repositories, notes, to-dos, and the URLs of endpoints you ask us to check. Prices suggested at setup are our generic guesses for a vendor's entry plan, not information about your account with that vendor. The service refuses dashboard links that carry a credential and is not designed to store passwords or keys; please do not enter them.
What your own systems send
Only if you set it up, and only to a web address unique to your workspace that you can rotate at any time:
- Crash reports from your Sentry account: the issue title, where it happened, how often, and a link back to Sentry. We keep one row per issue.
- Sign-up and purchase events from your products, via RevenueCat, Stripe, Supabase, or a plain post from your backend: the kind of event, when it happened, an amount if there is one, and an identifier for the person it concerns. We store that identifier only as a one-way hash, so the service can count distinct people without holding who they are. We do not receive or store your customers' names, emails, or card details.
Endpoint checks
If you ask us to watch a URL, our servers request it every five minutes and keep the time, status code, and response time of each check. We fetch only the address you gave and keep nothing from the response body.
Technical and diagnostic data
- Our hosting providers keep standard server logs (IP address, request path, time) for a short period for security and reliability.
- If the service itself crashes in your browser, an error report may go to our own Sentry account. It carries the error and the page it happened on, not what you typed into forms.
We do not use advertising trackers, analytics cookies, or any third-party scripts that profile you.
What it is used for
- To show you your workspace: products, stack, costs, renewals, uptime, crashes, and people.
- To email you: a sign-in link when you ask for one, a digest before a vendor bills (you set the lead time, or turn it off per service), and a note when an endpoint fails two checks in a row and again when it recovers.
- To keep the service working and secure.
We do not sell your information. We do not share it with advertisers, data brokers, or marketers, and we do not use it to profile you or to train anything.
How it is protected
- All traffic between your browser and the service is encrypted in transit (TLS).
- Your workspace is stored in a managed PostgreSQL database, encrypted at rest with encrypted backups.
- Every request is checked against your sign-in, and every row is scoped to your workspace; one workspace cannot read another.
- Webhook addresses are long random tokens unique to your workspace and can be rotated from the service; a wrong token is simply refused.
Service providers
We rely on a small number of processors, each acting on our behalf:
- Supabase (on Amazon Web Services) – sign-in and the database.
- Render – runs the service's API.
- Cloudflare – serves the web app and this site.
- SendGrid (Twilio) – sends the emails described above.
- Sentry – receives error reports from the service itself.
- Google – only if you choose to sign in with Google.
Retention and deletion
- Your workspace is kept while you use it.
- Archiving a product keeps its history; deleting a service removes it and its checks.
- You may ask for your workspace and account to be deleted at any time by emailing hello@operava.com from the address you sign in with. We delete everything in the workspace within 30 days, and backups age out within a further 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information. To exercise any of these, contact us at the address above. Everything you entered is visible in the service and can be exported on request.
Children
The service is not directed to children under 13, and we do not knowingly collect information from them.
Changes to this policy
If this policy changes materially, we will update the date at the top of this page and, where appropriate, notify you in the service or by email.