Privacy
Privacy notice
OPAP is a browser-based demonstrator. It has no account system, application backend, advertising, analytics or tracking cookies. It does make the network requests and use the local device storage described below.
Last updated: 21 July 2026
Who operates this site
The public demonstrator is operated by Patrick Savalle, the maintainer of the open-source Browser Payer. Privacy enquiries can be directed through the contact options on the operator’s GitHub profile. Do not include personal or payment data in a public GitHub issue.
Network requests
Site delivery and security
Cloudflare Pages delivers the site. Cloudflare may process IP addresses, request metadata and security logs to deliver and protect the service. The application does not enable analytics or set tracking cookies.
OPID resolution
When you resolve an OPID, the browser requests its derived public OPAP record directly from the publisher’s domain and sends DNS TXT lookups to Google Public DNS. Those services receive normal connection metadata, including your IP address. Requests omit credentials and this site sends no referrer.
Wallets and public test networks
A wallet is contacted only when you choose to connect it. Wallet addresses and submitted transactions can be visible to the wallet provider, RPC provider and public blockchain. Blockchain records are public and may be permanent. This release blocks production Monerium payments.
Storage on your device
- Verification history stores an OPID, its strongest previous verification level and a record fingerprint. This security memory prevents silent verification downgrades.
- Payment history is optional. If enabled, it stores at most 20 entries containing the OPID, chain, transaction hash, timestamp and outcome.
- The service worker caches only the application shell for reliable and offline loading. It does not cache OPAP records.
This information remains in your browser until you use the Clear payment and verification history control or clear this site’s browser data. It is not uploaded to the site operator.
Purposes and legal bases
Site delivery, security and abuse prevention are based on the operator’s legitimate interests in providing a safe public demonstrator. OPID, DNS, wallet and test-network requests are made to provide the function you request. Optional payment history is stored only after you opt in. The operator does not sell personal data or use it for advertising or profiling.
Providers, retention and international processing
- Cloudflare processes limited visitor metadata for hosting and security under its data-processing terms. Its network operates globally.
- Google Public DNS states that temporary logs containing an IP address and DNS query are normally deleted within 24–48 hours. Aggregated records without the full IP address may be retained longer.
- OPID publishers, wallet providers, RPC providers and blockchains are independent recipients selected by the address or by you. Their own privacy terms and retention periods apply.
Your choices and rights
You can decline optional payment history, clear all local history, avoid connecting a wallet and stop before submitting any payment. Depending on the circumstances, GDPR rights can include access, correction, deletion, restriction and objection. Contact the operator for requests concerning operator-controlled data. You may also complain to the Dutch Data Protection Authority.
Published payment records
OPAP records are intentionally public. The records on this demonstrator contain demonstration payment identifiers. Do not publish a real name, personal bank account or wallet address in an OPAP record unless you understand and accept that it can be copied, indexed and retained by others.