Skip to main content
OP Open Payment Address Protocol
Local-first with no tracking

Privacy

Privacy notice

OPAP is a local-first browser reference app. It has no account system, application database, advertising, analytics or tracking cookies. A stateless Cloudflare transport relay retrieves external public OPAP records; verification, payment planning and security history remain in your browser.

Last updated: 4 August 2026

Who operates this site

The public reference app is operated by Patrick Savalle, the maintainer of the open-source Browser Payer. Privacy enquiries can be directed through the contact options on the operator’s GitHub profile. Do not include personal or payment data in a public GitHub issue.

Network requests

Site delivery and security

Cloudflare Pages delivers the site. Cloudflare may process IP addresses, request metadata and security logs to deliver and protect the service. The application does not enable analytics or set tracking cookies.

OPID resolution

For this site’s own OPIDs, the browser requests the public record directly. For an external OPID, the browser sends only its derived public record URL to a same-origin Cloudflare relay. Cloudflare retrieves that record from the publisher, so Cloudflare receives your connection metadata and the record URL while the publisher normally sees Cloudflare’s connection. The browser separately sends DNS TXT lookups to Google Public DNS. Requests omit credentials and this site sends no referrer.

Payment URLs and QR codes

The Browser Payer generates payment URLs and QR codes locally. It does not connect to wallets or banking networks, submit transactions, or observe settlement. If you open or scan a payment URL, the external app you choose applies its own privacy terms.

Storage on your device

  • Security history stores exact-host key pins and, per OPID, the highest revision, exact-byte fingerprint, strongest binding and accepted payment-target projection. This memory blocks silent key substitution, signed-record rollback and unconfirmed destination changes.
  • The service worker caches only the application shell for reliable and offline loading. It does not cache OPAP records.

This information remains in your browser until you use the Clear security history control or clear this site’s browser data. It is not uploaded to the site operator.

Purposes and legal bases

Site delivery, relay operation, security and abuse prevention are based on the operator’s legitimate interests in providing a safe public reference app. OPID and DNS requests are made to provide the function you request. Payment URLs and QR codes are generated locally. The operator does not sell personal data or use it for advertising or profiling.

Providers, retention and international processing

  • Cloudflare processes limited visitor metadata for hosting, relay operation and security under its data-processing terms. Its network operates globally.
  • Google Public DNS states that temporary logs containing an IP address and DNS query are normally deleted within 24–48 hours. Aggregated records without the full IP address may be retained longer.
  • External OPID publishers receive the derived public record request from Cloudflare. An external payment app receives data only after you open or scan the generated URL or QR code; its own privacy terms and retention periods apply.

Your choices and rights

You can clear local security history and stop before opening or scanning a payment request. Depending on the circumstances, GDPR rights can include access, correction, deletion, restriction and objection. Contact the operator for requests concerning operator-controlled data. You may also complain to the Dutch Data Protection Authority.

Published payment records

OPAP records are intentionally public. The records on this reference app contain example payment identifiers. Do not publish a real name, personal bank account or wallet address in an OPAP record unless you understand and accept that it can be copied, indexed and retained by others.