Privacy policy
Last updated: 27 September 2026
This is a translation. Only the German version is binding: German version
This privacy policy explains which personal data we process when you use the opia app or our website opia.app, why we do so and what rights you have. We comply with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
In short: opia is meant to connect you with people, not with ads. We don’t sell data, show ads or build advertising profiles.
1. Who is responsible?
The controller responsible for processing your personal data is:
opia appsimple partnership of Nico Stillhart and Julius Berger
Solarstrasse 25
8404 Winterthur
Switzerland
For any privacy questions, reach us at privacy@opia.app.
2. What data we process
Account. When you create an account, we process your email address, username, display name, date of birth (to check the minimum age) and, if you upload one, your profile picture. We only store your password in protected form. If you use “Sign in with Apple”, Apple gives us an identifier and the email address you choose to share, which may be an anonymous Apple relay address.
Content and activity. We store what you publish and do on opia: photos and videos (including sound for videos), descriptions, comments and likes, events you create, the events you attend, who you follow and who follows you.
Messages. We store chat messages and content shared in them on our servers in order to deliver them to their recipients.
Location. Only if you allow it, opia uses your device’s location: while you use the app, to show you events near you and on the map and to display the name of your city; and, if you choose “Always”, in the background, to show an event you’re attending live on your Lock Screen when you’re nearby. When you create an event, we store its location. You can change access at any time in your device settings.
Contacts. Only if you allow it, opia matches your address book to find friends who are already on opia. Email addresses and phone numbers are turned into irreversible checksums (hashes) on your device; only these checksums are sent to us for matching, never the addresses or numbers themselves.
Camera, microphone and photos. opia only accesses them when you take or pick a photo or video yourself. Only what you publish or send is transmitted. If you wish, opia saves your recordings to your photo library.
Motion sensors. They are only used for a 3D effect in the app; this data stays on your device.
Notifications. If you allow push notifications, we store a device token that lets us send you notifications via Apple, for example when someone follows you or messages you.
Reports and blocks. When you report content or block accounts, we store this to review misuse and adjust your feed accordingly.
Interests. The interests you choose for the “For you” sorting are stored on your device, and the sorting happens there.
Technical data. Running our servers produces technical data such as IP address, device type, operating system, app version and time of requests. We use it to operate opia securely and reliably.
3. Our website
Our website sets no cookies and uses no analytics or tracking services. Fonts and images are loaded from our own server. When you visit, technical data such as IP address, browser and time are briefly logged by our server to operate the website securely.
On our website we feature local artists. Their music plays through SoundCloud’s player (SoundCloud Global Limited & Co. KG, Berlin). The player only loads when you click “Listen to the mix”; SoundCloud then receives your IP address and technical information about your browser and may set cookies. SoundCloud’s privacy policy applies.
For some artists we show a video through YouTube’s player (Google Ireland Limited, Dublin) in privacy-enhanced mode. The player only loads when you click “Play the song”; Google then receives your IP address and technical details about your browser, may set cookies and may also process data in the USA. Google’s privacy policy applies.
If you send us a request through the support form, we process your name, your email address and your message in order to reply. The request is delivered to our support inbox through our own mail server. We keep it only as long as needed to handle it and use it for nothing else.
4. Why we use your data
We process your data to:
- run your account and provide opia’s features, such as discovering and attending events, posting, following and chatting;
- suggest events near you and friends;
- notify you about activity that concerns you;
- operate opia securely, detect and prevent misuse and handle reports;
- answer your requests;
- comply with legal obligations and enforce our rights.
We don’t use your data for advertising and don’t build advertising profiles.
5. Legal bases
Where the GDPR applies, we rely on the following legal bases: performance of our contract with you, i.e. the terms of use (Art. 6(1)(b) GDPR); your consent, for example for location, contacts and notifications (Art. 6(1)(a)), which you can withdraw at any time; our legitimate interest in a secure, working service (Art. 6(1)(f)); and legal obligations (Art. 6(1)(c)).
6. What others see
opia is a social network. Your profile (username, display name, profile picture), your posts, your comments and the events you attend are visible to all opia users. People who follow you see in their Circle which events you attend. Messages are only visible to the people in the chat. We don’t show others your date of birth, email address or location.
8. Processing abroad
Our servers are located in the European Union, whose member states provide an adequate level of data protection according to the Swiss Federal Council.
Apple may also process data in the USA. When we transfer data to a country without an adequate level of data protection, we rely on recognised safeguards such as the European Commission’s standard contractual clauses, or on the recipient’s certification, for example under the Swiss-U.S. or EU-U.S. Data Privacy Framework.
9. How long we keep data
We keep your data for as long as you have an account. You can delete your account at any time in the app’s settings. Your profile then disappears immediately, and we permanently delete your data within 30 days, including from our backups. Exceptions are data we must keep longer for legal reasons, and messages you sent to others, which remain in their chats.
We keep technical logs only as long as needed for operation and security, usually no more than 30 days.
10. Security
We protect your data with technical and organisational measures: the connection between app and server is encrypted, data on your device is stored encrypted, and only a few people have access to our systems. No one can guarantee absolute security, however.
11. Your rights
You have the right to access your data, have incorrect data corrected and data deleted, object to processing, receive your data in a common format and withdraw consent at any time. You can change or delete much of your information directly in the app. For everything else, write to privacy@opia.app. We may ask you to prove your identity.
You can also lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the authority of your country of residence.
12. Minimum age
opia is for people aged 16 and over. We don’t knowingly process data of younger people. If we learn of it, we delete the account.
13. No automated individual decisions
We don’t make decisions based solely on automated processing that have legal or similarly significant effects on you.
14. Changes
We update this privacy policy when opia or the law changes. The version published on this page applies. We’ll inform you about material changes in the app.