Privacy Policy

Last updated: October 7, 2026

The small print on how we take care of your data.OperaX Local Browser ExtensionAutoBoost Chrome extension (version 2.5.0)

1. Introduction

This Privacy Policy describes how OperaX and its affiliates ("OperaX," "we," "us," or "our") collect, use, share, and protect personal information when you use our websites (operax.ai), applications (app.operax.ai), and related services (collectively, the "Services"). By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Services.

2. Information We Collect

Information You Provide

- Account information: Name, email address, company name, password when you create an account - Shop data: TikTok Shop credentials and OAuth tokens when you connect your store - Payment information: Billing address and payment method details (processed by our payment provider; we do not store full card numbers) - Communications: Messages you send us via contact forms, email, or support channels - User content: Any configurations, rules, or preferences you set within the platform (commission tiers, approval criteria, outreach templates)

Information Collected Automatically

- Usage data: Features used, actions taken, pages visited, time spent, and interaction patterns within the platform - Device information: Browser type, operating system, device identifiers, IP address - Log data: Server logs including access times, pages viewed, and referring URLs - Cookies and similar technologies: Session cookies for authentication, analytics cookies for understanding usage patterns (see Section 9)

Information from Third Parties

- TikTok Shop: Store performance data, creator information, order data, and campaign metrics accessed through authorized API connections - Messaging platforms: Message metadata from Slack, Lark, WhatsApp, and other connected channels (only when explicitly configured by you) - Analytics providers: Aggregated website analytics data

3. How We Use Your Information

We use the information we collect to: - Provide and operate the Services: Connect your shops, manage creator relationships, process sample reviews, optimize ad campaigns, generate reports - AI processing: Our AI agents process your shop data to execute operations (creator outreach, sample review, ad optimization, anomaly detection, morning reports). This processing is essential to delivering the core functionality of OperaX - Improve our Services: Analyze usage patterns, identify bugs, develop new features, and optimize performance - Communicate with you: Send service notifications, morning reports, anomaly alerts, and respond to your inquiries - Security and fraud prevention: Detect and prevent unauthorized access, abuse, or fraudulent activity - Legal compliance: Comply with applicable laws, regulations, and legal processes

4. AI and Machine Learning

OperaX uses AI agents to process your data and execute operations on your behalf. It is important to understand how this works: Your individual data: Your shop data, creator information, and operational history are used exclusively to serve your account. We do not share your individual data with other customers. Aggregated learning: We may use aggregated, anonymized data across the platform to improve our AI models, discover operational patterns, and enhance the quality of recommendations. This aggregated data cannot be traced back to any individual customer or store. This does not apply to data collected through OperaX Local Browser, which is governed by Section 16. Opt-out: You may opt out of cross-platform aggregated learning at any time by contacting us at alex.yang@boostengine.ai. Opting out will not affect your access to the Services but may limit certain recommendation features. Human oversight: You choose the tasks you ask OperaX to perform. Confirmation and manual-control options depend on the feature. For local-browser tasks, you can take over or disconnect as described in Section 16; the extension does not ask for separate confirmation of every browser action.

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances: - Service providers: With trusted third-party providers who help us operate the Services (hosting, payment processing, analytics). These providers are bound by contractual obligations to protect your data - Platform integrations: With TikTok Shop, Slack, Lark, WhatsApp, and other platforms you explicitly connect, only to the extent necessary to deliver the Services - Legal requirements: When required by law, regulation, legal process, or government request - Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to you - With your consent: When you explicitly authorize us to share information with a third party

6. Data Security

We implement industry-standard security measures to protect your information: - Encryption: All data is encrypted in transit (TLS 1.2+) and at rest - Access control: Strict role-based access controls and multi-tenant data isolation (x-shop-id isolation ensures your data is separated from other customers) - Authentication: JWT-based authentication with SSO support - Infrastructure: Hosted on enterprise-grade cloud infrastructure with regular security audits - Monitoring: Continuous security monitoring and incident response procedures No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Data Retention

- Active accounts: We retain your data for as long as your account is active and as needed to provide the Services - Account deletion: Upon account deletion request, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing agreements) - Aggregated data: Anonymized, aggregated data may be retained indefinitely for analytics and service improvement purposes - Backups: Backup copies may be retained for up to 90 days after deletion for disaster recovery purposes

8. Your Privacy Rights

Depending on your location, you may have the following rights: - Access: Request a copy of the personal data we hold about you - Correction: Request correction of inaccurate or incomplete data - Deletion: Request deletion of your personal data (subject to legal retention requirements) - Portability: Request your data in a structured, commonly used, machine-readable format - Restriction: Request restriction of processing in certain circumstances - Objection: Object to processing based on legitimate interests - Opt-out of AI learning: Request that your data not be included in aggregated AI model training - Withdraw consent: Where processing is based on consent, withdraw that consent at any time To exercise any of these rights, contact us at alex.yang@boostengine.ai. We will respond within 30 days.

9. Cookies

We use the following types of cookies: - Essential cookies: Required for authentication, session management, and security. These cannot be disabled - Analytics cookies: Help us understand how visitors interact with our website. You can opt out through your browser settings - Preference cookies: Remember your language and display preferences We do not use advertising or tracking cookies. You can control cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Services.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers, including: - Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA - Compliance with applicable data transfer frameworks - Contractual protections with all service providers

11. GDPR Compliance (European Economic Area)

If you are located in the European Economic Area (EEA), the following applies: Legal basis for processing: We process your data based on: (a) your consent, (b) performance of a contract, (c) compliance with legal obligations, or (d) legitimate interests (such as improving our Services). Data Protection Officer: For GDPR-related inquiries, contact alex.yang@boostengine.ai. Supervisory authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

12. CCPA Compliance (California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA): - Right to know: What personal information we collect, use, and share - Right to delete: Request deletion of your personal information - Right to opt-out: Opt out of the "sale" of personal information (note: we do not sell personal information) - Non-discrimination: We will not discriminate against you for exercising your CCPA rights To exercise these rights, contact alex.yang@boostengine.ai or submit a request through our Contact page.

13. Children's Privacy

Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at alex.yang@boostengine.ai.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by: - Posting the updated policy on this page with a revised "Last updated" date - Sending you an email notification for significant changes - Displaying a notice within the platform Your continued use of the Services after changes become effective constitutes acceptance of the updated policy.

15. Contact Us

If you have questions about this Privacy Policy, your data, or your privacy rights, contact us at: OperaX Email: alex.yang@boostengine.ai Website: https://www.operax.ai/contact

16. OperaX Local Browser Extension

OperaX Local Browser connects a browser profile to your OperaX workspace so you and your AI assistant can work with its existing signed-in pages. This section applies to the extension in Chrome and compatible browsers. For extension data, it takes precedence over any conflicting general provisions above, including those about AI learning and business transfers.

Information accessed and collected

- Open tabs: After you connect, eligible open-tab titles, addresses and tab identifiers are shared with OperaX so you or your assistant can select a page. This can reveal browsing activity. - Selected pages: Page text and structure, form values, screenshots and, when enabled, video previews are processed to display and operate the selected page. Depending on the website, this may include names, contact details, order or financial information, personal communications and other sensitive content visible on the page. Sensitive content is not automatically removed from every page or image. - Browser actions: Clicks, scrolling, navigation and text you or the assistant enter through OperaX are relayed to the selected browser to carry out your task. - Connection information: We process the browser name you provide, connection and session identifiers, pairing credentials, extension version, supported features and connection diagnostics. Our servers also receive network information such as IP addresses, which may indicate approximate location; the extension does not request precise device location. The extension does not read or export the browser's cookie store, saved-password database or full browsing-history database. Website login sessions remain in the local profile. Incognito tabs and browser-internal pages are excluded. Video capture is limited to the selected tab, without microphone or camera access.

Why browser permissions are needed

The debugger permission supports page reading, screenshots and browser actions. The tabs permission identifies and manages open tabs. The activeTab, tabCapture and offscreen permissions support selected-tab previews. Storage remembers connection settings and session state, and alarms help maintain the connection. Host permissions allow communication with OperaX environments and local development endpoints. These permissions support the browser connection feature; they are not used to collect unrelated browsing activity.

Transmission, AI processing and sharing

Page previews and browser commands pass through OperaX infrastructure to connect the extension and your workspace. When an AI assistant requests page information, relevant text or screenshots are sent to the AI service used by your workspace. Data is therefore not processed exclusively on your device. Opening a preview does not itself send a continuous video feed to an AI model. Hosting, connection-relay and AI service providers process the information needed to deliver this feature under our service arrangements. Browser actions also submit information to the websites you choose to use, whose own privacy policies apply. Connections to hosted OperaX services use encrypted transport.

Storage and retention

The preview relay uses temporary memory buffers and does not save a continuous screenshot history or video recording. Page text, screenshots and action results returned to an AI task may be retained in that task's conversation or tool history under Section 7. Disconnecting does not erase records already created. Connection settings such as the browser name and OperaX address are stored locally. Pairing credentials are kept in browser-session storage, rather than synchronized profile storage. OperaX retains connection metadata and credential hashes to authenticate and recover connections, plus operational logs for reliability and security. These retained records follow Section 7; preview buffers are transient.

Your controls and deletion requests

You choose which browser to connect and can select a tab in OperaX. Taking manual control stops assistant actions but can leave the preview active. To stop the browser connection, use Disconnect in OperaX or the extension, or disable or remove the extension. Cancelling Chrome's debugging session stops control of that tab. To request access to or deletion of retained extension-related data, contact alex.yang@boostengine.ai with your OperaX account and the relevant connection or task. Do not send passwords or pairing credentials. The response and deletion periods in Sections 7 and 8 apply, including the stated legal-retention and backup exceptions.

Limited Use commitment

OperaX Local Browser complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data, including derived or anonymized data, is used only for this browser feature and its operation, security and reliability. We do not sell it, use it for advertising or credit decisions, or use it to train general-purpose AI models. The aggregated-learning provision in Section 4 does not apply. Third-party transfers are limited to this purpose, legal obligations or abuse prevention; business transfers require prior explicit consent. Staff access requires your specific consent, a security or legal need, or anonymized internal operations permitted by Limited Use.

17. AutoBoost Chrome extension (version 2.5.0)

This section applies specifically to AutoBoost version 2.5.0, published by Boostengines in the Chrome Web Store (extension ID: geifgcelnbooakeglcoecndmcejehfkh). It is separate from OperaX Local Browser in Section 16 and from older AutoBoost extension versions. Purpose and behavior: The extension opens https://autoboost.operax.ai/ in a new tab when installed or updated and when you click its toolbar icon. Creator management and other business features run on that website, not in the extension. Data collection and permissions: The extension does not read, collect, store, or transmit personal information, authentication information, cookies, browsing history, page content, or user activity. It has no content scripts, analytics, advertising trackers, or remote code. It requests no host permissions or permissions to read tabs, cookies, identity, downloads, or browser storage. Opening the fixed website address does not give the extension access to that page or other tabs. Website use: Opening the website causes an ordinary browser request to the website and its hosting infrastructure, which can process request information such as an IP address and browser details. Information provided when signing in or using AutoBoost on the website is governed by the applicable website and service provisions above. The extension does not add user identifiers or tracking parameters to the URL and does not read or forward your website account or shop data. Sharing and retention: The extension has no collected user data to sell, share, retain, or use for advertising or AI model training. These statements concern the extension itself; they do not mean that the AutoBoost website processes no data. Your control and contact: You can close the opened tab and disable or uninstall the extension at any time. Uninstalling it does not delete a website account or website records. For questions about this extension or requests concerning website data, contact alex.yang@boostengine.ai. Do not send passwords or authentication credentials.