What opti-pipe actually collects, why, and who it's shared with - written to match what the code really does, not boilerplate. If you find a mismatch, tell us at info@optipipe.dev.
Last updated: September 23, 2026
Account information. When you sign up: your email, a password (we store it hashed via PBKDF2, never in plain text), first and last name, company name, job title, and phone number. Date of birth is optional and only ever asked for, never required - there's no product reason we need it.
Your uploaded pipeline data. This is the important one: opti-pipe only ever reads numeric metrics out of a Spark event log, dbt run_results.json, or Flink metrics export - timings, row counts, memory figures, and similar. Your SQL, model names, DataFrame code, and file paths are never read, stored, or sent anywhere, including to the optional "Ask AI" feature, regardless of what's technically present in the file you upload.
Usage data. Page views via GoatCounter, a privacy-respecting analytics tool that doesn't use cookies and doesn't collect personal data. If you accept the Google Analytics cookie, it additionally sees aggregate traffic and engagement data - see section 6.
We don't use your data to train any model, ours or a third party's.
The optional "Ask AI" second opinion is powered by Anthropic's API. The same anonymization boundary from section 1 applies here too: only the numeric metrics already extracted from your file are ever sent, never your SQL, model names, DataFrame code, or file paths. You choose when to use this feature - it's never invoked automatically.
opti-pipe is currently free and collects no payment information at all. When paid plans launch, billing will run through Lemon Squeezy, our merchant of record - they collect and process your card details directly on their own hosted checkout page. opti-pipe itself never sees or stores your card number; we only receive an account-level status (trial, active, cancelled, etc.) via their webhooks.
We keep your account data for as long as your account is active. There's no self-service "delete my account" button yet - to request deletion of your account and associated data, email info@optipipe.dev and we'll action it directly. We'll only keep what we're legally required to (for example, records needed for tax/billing compliance once paid plans exist) beyond that.
Passwords are hashed with PBKDF2, never stored in plain text. Optional two-factor authentication (TOTP) is available on every account. Session cookies are HTTP-only, so they can't be read by page scripts even if a page had malicious code injected into it. No system is perfectly secure, but these are real, load-bearing protections, not just a line in this policy.
opti-pipe is operated from Israel; the service itself is hosted on AWS infrastructure in the United States (us-east-1). Using opti-pipe means your data is processed in the United States as a result. If you're in a region with specific transfer requirements (for example, the EU), by using the service you're consenting to this transfer as necessary to provide it.
opti-pipe isn't directed at, or intended for use by, anyone under 16. We don't knowingly collect data from children. If you believe a child has created an account, contact us and we'll remove it.
You can ask to access, correct, or delete the personal data we hold about you at any time by emailing info@optipipe.dev. Depending on where you live, you may have additional rights (for example, under GDPR or similar law) - we'll honor those requests too; just reach out and tell us what you need.
We'll update the "Last updated" date above whenever this changes - most likely as real billing gets turned on. A meaningful change (for example, a new sub-processor that touches personal data) will be communicated to existing users directly, not just posted silently here.
Questions about this policy, or a data request: info@optipipe.dev.