Scope and data controller
Opera’s published Privacy Statement applies to its browsers, websites and related services. The categories of data processed vary by product, purpose and, in some cases, user location.
Opera Norway AS is identified as the primary data controller for Opera browsers and services. Opera uses the GDPR as a guidepost because it applies directly to the company as a European business, and other Opera Group companies generally act as processors when handling data on its behalf.
Opera states that it does not sell users’ personal data, whether for monetization or advertising.
What types of data Opera may process
Depending on the service, Opera may process account information, random browser or installation identifiers, device and operating-system information, feature usage, general location, crash and diagnostic data, content interactions, advertising preferences and data supplied directly by the user.
The data involved is feature-specific. Regular browsing, Opera Account, Sync, Opera AI, VPN, My Flow, personalized content and advertising do not rely on the same categories of information.
Opera Account and Sync
Regular browsing does not require an Opera Account. If a user creates one, Opera may process a chosen username and email address; social sign-in can also provide a name, profile picture and email address from the selected provider.
Opera Account data is not associated with the random ID of the browser installation. Account-linked services such as VPN Pro or Cashback may associate their service data with the Opera Account.
After a user chooses to delete an Opera Account, Opera retains the account data for seven days before permanent deletion. A verified account is automatically deleted after two years without sign-in, while an account with an unverified email address is deleted after six months of inactivity.
Synced browser data is retained until the Opera Account is deleted and is not associated with the browser installation’s random ID.
Opera AI and AI Chat
Opera’s current Privacy Statement describes AI Chat as powered by OpenAI and Google. Core access does not require signing in to an Opera Account, although signing in can provide additional or extended features. Opera states that Opera Account data is not shared with OpenAI or Google for this service.
AI Chat can process information the user types or attaches, together with content from opened websites, tabs or groups of tabs when that context is made available to the service. Requests may be routed to OpenAI or Google depending on which model Opera selects for the task.
Google Search Suggestions can be generated from user input and can be disabled. When shopping suggestions are relevant and consent has been given, Opera may share relevant keywords, country, language and a partial IP address with shopping partners. Opera states that prompts are not shared with advertising partners for this purpose and are not used to build an advertising-interest profile from AI prompts.
Opera stores chats, visited-site URLs and tab names on its servers so conversations can continue. The Privacy Statement specifies automatic deletion after 365 days for logged-in AI Chat use and after 30 days when the user is not logged in; chats can also be deleted manually.
If a user connects a separate third-party AI tool, browser data such as tabs or page content may be shared according to the user’s settings, and the third party’s own privacy policy then applies.
Free VPN and VPN Pro
Opera Free VPN is described as a no-log browser VPN. Opera states that it does not log personal data or other data related to browsing activity and the originating network address on its VPN servers while the service is in use. Browser traffic is encrypted with AES-256.
VPN Pro uses third-party infrastructure and is also described as a no-log service for pages visited and links clicked. When an Opera Account is used to verify a VPN Pro subscription, Opera states that only a random subscriber identifier is shared with the infrastructure provider, not the user’s email address or name.
My Flow and cross-device transfer
My Flow assigns a random ID to each connected client device for pairing. These IDs remain only while the devices stay connected to My Flow.
Opera states that My Flow data is protected with end-to-end encryption and retained only while the feature continues to be used. Users can disconnect devices and delete Flow data from Opera settings.
Sidebar messaging and third-party services
Sidebar messengers and many browser extensions are provided by third parties and are subject to those providers’ own privacy terms.
Opera states that sidebar messaging services do not collect data through Opera unless the user signs in to and uses the third-party service, and that Opera itself does not collect data when users use those messaging services.
Usage statistics, diagnostics and crash reports
Opera applications can generate a random installation ID and collect Machine ID, hardware specifications, operating-system information, environment configuration and feature-usage data for product analysis, promotion measurement, debugging and improvement.
Desktop usage statistics may be retained for up to three years. Extended usage reporting can be disabled in Privacy & security settings.
Crash reports may contain browser version, operating system, platform and crash-related memory data. Opera states that crash logs are retained for up to five months and that automatic crash reporting can be disabled.
Website IP access logs used to diagnose server problems and administer Opera websites may be retained for up to six months.
Personalized content, ads and interest profiles
On desktop, personalized content features may process interactions with content and a general location such as city or country. That information is linked to a random installation ID, may be stored for up to three months and is processed on the basis of consent.
For personalized advertising, Opera may use data such as IP address, hashed user ID, general location, device information, broad categories of websites visited and categories of ads clicked. Opera states that it does not log or store the user’s entire browsing history for this purpose.
Opera describes the resulting profile as broad interest categories rather than a full browsing record, and states that personal interests or browsing history are not shared with advertising partners. This advertising-profile data may be retained for up to one year and is processed on the basis of consent.
Search providers, Speed Dial and malicious-site checks
Opera lets users choose the search engine used from the address bar. Opera states that it does not share personal data with search providers merely to enable search, although the selected provider’s own terms and privacy policy apply when a search is performed.
Some default Speed Dial entries are advertisements. Clicking them may route through partners or third parties that can independently collect data such as third-party cookies, device IDs or session statistics.
Opera also uses a malicious-site checking framework that includes Google Safe Browsing. For this check, Opera states that the primary domain is compared with known malicious-site lists, full URLs are not collected for the purpose and no personal data is processed in that context.
Website cookies and marketing communications
Opera websites use cookies for session management and to retain settings or preferences. Third-party cookies may also be used for visitor statistics and marketing measurement.
Marketing, surveys, feedback forms, contests or download-link requests can involve information supplied directly by the user, such as name, age, phone number, email address or postal address. Users can opt out of marketing communications through account settings or the communication itself.
Third-party technologies
Opera applications and websites can include third-party technology for geolocation, Safe Browsing, analytics, advertising, payments, AI, support and other functions. Depending on how a provider handles the data, it may act as Opera’s processor or as an independent controller.
Opera’s published list currently includes providers and technologies from companies such as Google, OpenAI, payment processors, Zendesk, Mixpanel and others. The applicable list depends on the currently supported product and version.
Legal bases for processing
Opera identifies consent, contractual necessity, legitimate interests and legal compliance as the legal bases most relevant to its applications and services.
The applicable basis depends on the feature and purpose. For example, personalized advertising is described as consent-based, Opera Account access relies on contractual grounds, and certain diagnostics or product-improvement activities may rely on legitimate interests.
Data retention
Opera states that it does not keep personal data longer than necessary and publishes feature-specific retention periods for many types of information.
Examples in the current statement include seven days after an Opera Account deletion request, up to three months for desktop personalized-content data, 30 or 365 days for AI Chat depending on login state, up to three years for desktop usage statistics, five months for crash logs, six months for website access logs and up to one year for personalized-ad profiling data.
Other services, including payments, Cashback, GX services and marketing activities, can follow different retention periods because of contractual, operational or legal requirements.
Information security
Opera describes technical and organizational safeguards across its products and services, while also noting that no online service can promise absolute security.
Examples of privacy and security controls in the current statement include encrypted VPN traffic, end-to-end encryption for My Flow, encrypted AI Chat storage, malicious-site checks and account-related security measures.
International data transfers
Opera Group companies and selected third parties can process or receive data across countries. Where a transfer of personal data outside the European Economic Area requires a legal transfer mechanism, Opera states that it uses mechanisms such as the European Union’s Standard Contractual Clauses.
Children’s privacy
Opera states that children should involve their parents in the browser download process and encourages parents to review the Privacy Statement before allowing children to use Opera applications and services.
Access, deletion and other privacy rights
Users can request access to or deletion of personal data that Opera may possess. Opera may require additional information to authenticate a request.
Requests can be submitted through Opera’s privacy request process or to the Data Protection Officer. Users also have the right to lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority, where applicable.
Contact and statement updates
Opera states that significant changes to its Privacy Statement may be communicated through its website or in-app notifications, and the document shows the date of its latest update.
Opera’s published Data Protection Officer contact address is: Opera Norway AS, P.O. Box 4214, Nydalen 0401, Oslo, Norway.
This page is an informational summary for app-opera.com and does not replace Opera’s official Privacy Statement, Cookie Policy, product terms or privacy request process. Privacy practices for app-opera.com itself, including any site analytics, server logs, cookies or forms operated by this website, are separate responsibilities of this site’s operator.