Draft pending counsel review · Last updated 3 September 2026
Privacy notice
This Privacy notice explains how Openfork (“we”, “us”) collects, uses, shares, and retains information when you use openfork.co and related services (the “Service”). It should be read with our Terms of use.
1. Who is responsible
Openfork operates the Service. For privacy questions contact privacy@openfork.co. If we appoint a formal data controller entity or DPO, this page will be updated.
2. Information we collect
2.1 Account and identity
We sign you in with GitHub, X, Instagram, or TikTok OAuth. Depending on the provider,
we may store provider id, handle/username, display name, avatar URL, and follower
count at connect time. GitHub may also provide account creation date, public repo
count, and (with your consent via the user:email scope) a primary email
address for account notices. X may provide a confirmed email (with your consent via
the users.email scope). You can also add or change a contact email in Settings.
Email is not shown on public profiles. We do not keep OAuth access tokens after the
handshake completes.
2.2 Profile and preferences
Self-declared niches, open-to-intros status, intro role tags, and optional contact email you choose in settings.
2.3 Idea and activity data
Idea drafts and published fields, versions, comments, suggested edits, builds, forks, invites/collaborators, Amplify pledges, claimed follow-through URLs, non-financial interest signals, notices, blocks, reports, and Concierge requests/replies.
2.4 Technical and payment data
Session cookies, security logs, approximate request metadata (such as IP and user agent) needed to run and protect the Service, and Matching payment references processed by Paystack (we do not store full card numbers).
3. How we use information
- to provide, secure, and improve the Service;
- to show public profiles, public ideas, search, sitemaps, and exports;
- to send activity notices to the contact email on your account, unless you turn that off;
- to enforce guidelines, investigate abuse, and keep an admin audit log;
- to operate Matching and Concierge as described in-product;
- to comply with law and respond to lawful requests.
Follower counts and related identity facts are shown raw. They are not combined into a composite “credibility” score and do not boost Matching rank by follower count.
4. Public vs private content
Public ideas, comments, suggested edits, builds, forks, Amplify pledges, claimed follow-through URLs, and interest signals are visible to anyone and may be indexed or exported. Openfork stores follow-through URLs; it does not fetch them.
Private ideas are stored on our servers and shown only to you and people you invite. That is an access-control list, not cryptography. A compromised host, insider misuse, or a lawful request can still expose private text.
Concierge notes are visible to you and House, not the public decision log. The public Concierge log shows topic and outcome only.
5. Sharing
We share information with:
- the public, when you publish or post to public surfaces;
- people you invite to private ideas;
- service providers that host, process payments, or deliver mail and infrastructure under contract;
- authorities when required by law or to protect rights, safety, or the Service.
Matching ranks people who opted into intros; we do not sell that list as a marketing database. We do not sell personal information.
6. Cookies and similar technologies
We use essential session cookies to keep you signed in and to protect forms (CSRF). These are required for the Service to function. We do not use third-party advertising cookies on the core board experience described here.
7. Retention
We keep account, idea, and moderation records for as long as needed to operate the
Service and meet legal obligations. Public provenance records may be retained so the
board remains citable. If you delete an account, we aim to stop active use of your
profile and may pseudonymize display names on historical events (for example
deleted-user) without rewriting public diffs. Illegal or abusive content
may be hidden with a tombstone.
8. Security
We use administrative and technical measures appropriate to a hosted web application (access controls, session protections, transport encryption where configured). No method of transmission or storage is perfectly secure.
9. International transfers
The Service may be hosted or administered in countries other than your own. Where we transfer personal data internationally, we take steps designed to provide appropriate safeguards consistent with applicable law and our hosting arrangements.
10. Your choices and rights
Depending on where you live, you may have rights to:
- access, correct, or delete certain personal data;
- object to or restrict certain processing;
- withdraw consent where processing is consent-based;
- lodge a complaint with a supervisory authority.
You can update niches, intro preferences, contact email, and email notices in Settings, unlink extra social identities when another sign-in remains, and use in-product controls for many posts. Contact privacy@openfork.co for other requests. We may need to verify the request and may retain information as required by law or for legitimate security and provenance needs.
11. Children
The Service is not directed to children under 16 (or the higher age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
12. Changes
We may update this notice. The “Last updated” date will change when we do. Material changes will be reflected on this page.
13. Contact
Privacy requests: privacy@openfork.co. Legal terms: legal@openfork.co.
This page is a dated Draft until counsel revises it for your entity, hosting region, and regulatory obligations (including GDPR/NDPR where applicable).