Open Source Self (“we”, “us”, “our”) is a public profile platform that lets developers share their open-source work, objectives, and updates. This policy explains what personal data we collect, why, and your rights over it.
[PLACEHOLDER: Add legal entity name, registered address, and contact email.]
When you sign in with Google or a magic-link email, we receive your email address and, for Google sign-in, your Google account name and profile picture URL. Supabase Auth stores these to authenticate you.
You choose to write and publish profile content including your handle, display name, bio, objectives, updates, projects, and stack. This content is publicly visible on your profile page.
With your consent, we use PostHog to collect product analytics events (page views, feature interactions). PostHog is configured with person_profiles: "identified_only", meaning anonymous visitors do not create person profiles. No analytics events are sent before you grant consent via the banner on your first visit.
Vercel (our hosting provider) and Sentry (our error monitoring provider) may process IP addresses, User-Agent strings, and request metadata as part of normal infrastructure operation.
[PLACEHOLDER: Review whether Sentry telemetry requires separate disclosure or consent in your jurisdictions.]
We share data with these processors under appropriate data processing agreements:
[PLACEHOLDER: Confirm DPAs are in place with each processor before EU launch.]
Your account and profile data are retained for as long as your account is active. If you delete your account, your data is removed from our primary database within 30 days. Backups may retain data for up to 90 days.
[PLACEHOLDER: Confirm exact retention periods with your backup policy.]
Depending on your location you may have the right to:
/api/export).[PLACEHOLDER: Add GDPR/CCPA-specific rights and response timeframes.]
We use browser localStorage to remember your analytics consent choice (key: oss-analytics-consent). We do not set tracking cookies. Supabase Auth uses a session cookie to keep you signed in.
[PLACEHOLDER: Describe where data is processed geographically, e.g. “Supabase stores data in [region]. PostHog is hosted in the US (...).” Add transfer mechanism for EU data (SCCs, adequacy decision, etc.) if applicable.]
We may update this policy. Material changes will be announced on the site or by email. The “Last updated” date at the top always reflects the current version.
[PLACEHOLDER: Add email address / postal address for privacy inquiries, and if EU-based, the Data Protection Officer contact if required.]