Information processed
Oploofy stores one encrypted recipient email for each active access code, keyed hashes used for lookup and abuse prevention, and minimal operational event data.
01 Legal and policy
How Oploofy limits and protects personal information.
Oploofy stores one encrypted recipient email for each active access code, keyed hashes used for lookup and abuse prevention, and minimal operational event data.
Information is processed solely to validate codes, request protected handoffs, prevent abuse, revoke access, and maintain service reliability.
Oploofy does not store documents, downstream destination URLs, generated one-time links, raw encrypted UIDs, or public contact submissions.
Code and audit records remain until the operator removes them under the issuing organization’s retention instructions. Revocation disables access immediately.
Recipient data is encrypted at rest. Access codes, API secrets, network signals, and lookup values are stored as hashes where recovery is unnecessary.