← Back

Privacy Policy

Last updated: July 7, 2026

Note to owner: This is placeholder copy. Review with qualified legal counsel before publishing, particularly if you have EU users (GDPR) or California users (CCPA).

1. Who we are

Open Source Self (“we”, “us”, “our”) is a public profile platform that lets developers share their open-source work, objectives, and updates. This policy explains what personal data we collect, why, and your rights over it.

[PLACEHOLDER: Add legal entity name, registered address, and contact email.]

2. Data we collect

2.1 Account data

When you sign in with Google or a magic-link email, we receive your email address and, for Google sign-in, your Google account name and profile picture URL. Supabase Auth stores these to authenticate you.

2.2 Profile content

You choose to write and publish profile content including your handle, display name, bio, objectives, updates, projects, and stack. This content is publicly visible on your profile page.

2.3 Analytics events

With your consent, we use PostHog to collect product analytics events (page views, feature interactions). PostHog is configured with person_profiles: "identified_only", meaning anonymous visitors do not create person profiles. No analytics events are sent before you grant consent via the banner on your first visit.

2.4 Technical data

Vercel (our hosting provider) and Sentry (our error monitoring provider) may process IP addresses, User-Agent strings, and request metadata as part of normal infrastructure operation.

[PLACEHOLDER: Review whether Sentry telemetry requires separate disclosure or consent in your jurisdictions.]

3. How we use your data

  • To authenticate you and secure your account.
  • To display your public profile to visitors.
  • To send transactional emails (magic-link sign-in). We do not send marketing email.
  • To improve the product via aggregated analytics (only with consent).
  • To monitor and fix application errors.

4. Third-party services

We share data with these processors under appropriate data processing agreements:

  • Supabase — database and authentication. Data stored in their managed PostgreSQL service. Supabase Privacy Policy
  • PostHog — product analytics (consent-gated). PostHog Privacy Policy
  • Vercel — hosting and CDN. Vercel Privacy Policy
  • Sentry — error monitoring. Sentry Privacy Policy
  • Nango — OAuth integration gateway (used when you connect external services). Nango Privacy Policy

[PLACEHOLDER: Confirm DPAs are in place with each processor before EU launch.]

5. Data retention

Your account and profile data are retained for as long as your account is active. If you delete your account, your data is removed from our primary database within 30 days. Backups may retain data for up to 90 days.

[PLACEHOLDER: Confirm exact retention periods with your backup policy.]

6. Your rights

Depending on your location you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Export — download your profile data in machine-readable format via the Export option in your Settings page (backed by /api/export).
  • Correction — update inaccurate data via your profile settings.
  • Deletion — request deletion of your account and data by contacting us (see below). Account deletion is also available in Settings.
  • Objection / withdrawal of consent— you can withdraw analytics consent at any time by clicking “Decline” in the analytics banner or by clearing your browser's local storage.

[PLACEHOLDER: Add GDPR/CCPA-specific rights and response timeframes.]

7. Cookies and local storage

We use browser localStorage to remember your analytics consent choice (key: oss-analytics-consent). We do not set tracking cookies. Supabase Auth uses a session cookie to keep you signed in.

8. International transfers

[PLACEHOLDER: Describe where data is processed geographically, e.g. “Supabase stores data in [region]. PostHog is hosted in the US (...).” Add transfer mechanism for EU data (SCCs, adequacy decision, etc.) if applicable.]

9. Changes to this policy

We may update this policy. Material changes will be announced on the site or by email. The “Last updated” date at the top always reflects the current version.

10. Contact

[PLACEHOLDER: Add email address / postal address for privacy inquiries, and if EU-based, the Data Protection Officer contact if required.]