Privacy Policy
Last updated: 25 September 2026
This policy explains what personal information Opensrcs collects, why, who it's shared with, and the choices you have. Opensrcs is run by Design Ustaad, a sole proprietorship based in Pakistan ("we", "us"), which is responsible for your information. Questions: support@opensrcs.com.
The short version: we collect only what we need to run the site, we don't sell your information, we don't show ads, and we don't use tracking or analytics cookies.
1. What we collect
When you just browse. Nothing that identifies you. Like any website, our hosting provider receives technical information with each request (your IP address, browser type, the page asked for). It's used to deliver the page and keep the site secure. We don't use analytics or tracking tools.
When you create an account:
- your name, email address and password. We never see or store your password itself, only a secure scrambled version (a hash);
- a username we create from your name;
- anything you add to your profile: avatar image, bio, GitHub username, and whether your profile is public;
- the projects you save and your plan (Free or Pro);
- details that keep your account secure: your active sign-in sessions and when they expire, recent failed login attempts, and one-time links for confirming your email or resetting your password.
When you use the site while signed in:
- Comments you post, which anyone can read.
- Ideas you save: the title and description, and whether the project makes money, keeps its code private, and how it will be delivered. Ideas are private to you.
- Project submissions and change requests: the GitHub link, project name, your name, email address and notes. We also give each submission a simple automatic spam score, based on whether the GitHub link works and how many links the notes contain.
- Notifications we show you, such as replies and updates to your projects.
- The Opensrcs MCP (Pro): your personal MCP key, which AI tools you've connected, and when each one last used it. We don't store the questions your AI tool asks.
When you contact us through the Contact us form: your name (if you give it), your email address, your message and the page you sent it from, so we can reply. If you email us directly, we keep your email the same way.
When you join the newsletter: your email address, where on the site you signed up, and when you confirmed. We only add you after you click the confirmation link we email you.
2. Voice input stays on your device
On the Ideas page you can describe an idea by voice. Your speech is turned into text inside your browser; the audio is never sent to us or anyone else. The first time you use it, your browser downloads the speech model (about 75 MB) from Hugging Face through jsDelivr, which means those two services see your IP address, as with any download. Your browser keeps the model so it doesn't need downloading again.
3. Why we use it
- To provide the service you asked for (our contract with you): running your account, signing you in, saving your ideas and projects, showing your comments, handling submissions, and providing the MCP to Pro members.
- To keep Opensrcs safe (our legitimate interest): limiting how often forms can be sent, spotting spam and abuse, and moderating comments. For rate limits we briefly hold your IP address in the server's memory; it isn't saved.
- To answer you when you contact us (our legitimate interest in helping you).
- To send you email: account emails you need (confirming your address, resetting your password), and the newsletter only if you've subscribed (your consent).
- To meet legal obligations, when the law requires it.
We don't sell your information, use it for advertising, or make automated decisions about you that have legal or similar effects.
4. Cookies
We use only the cookies Opensrcs needs to work. Because they are strictly necessary, we don't need to ask for consent, and we don't use any analytics, advertising or third-party cookies.
member_tokenkeeps you signed in. It is secure and can't be read by scripts in the page. It lasts 30 days, or until you log out.member_signed_intells pages that someone may be signed in, so they can show your account menu. It contains no personal information and lasts as long as your sign-in.payload-tokensigns in Opensrcs staff to the admin area. Members and visitors never get it. It lasts 2 hours, or until the staff member logs out.
Your browser may also keep copies of pages, images and the voice model (see section 2) to load them faster. That's normal browser caching and doesn't identify you.
5. Who we share it with
We share information only with the services that run Opensrcs for us, and only as needed:
- Vercel: hosts the website and delivers pages.
- Supabase: stores the database and uploaded images such as avatars.
- Our email delivery provider: sends account emails and the newsletter.
These providers process your information on our behalf and aren't allowed to use it for anything else. We may also share information if the law requires it, to protect the rights and safety of our users or others, or with a buyer if Opensrcs is ever sold (in which case this policy would continue to apply).
Things you choose to share. If you send an idea or prompt to an AI tool (for example "Open in ChatGPT" or through the MCP), or follow a link to GitHub or another website, that service's own privacy policy applies to what you share with it.
6. Where your information is stored
Our database runs in Singapore, and our providers may process information in other countries, including the United States. Wherever it's processed, we rely on our providers' security and their standard contractual safeguards for international transfers.
7. How long we keep it
- Your account and saved ideas: until you delete your account. Deleting it removes your account, profile, saved ideas and notifications straight away.
- Comments: stay after you delete your account, shown as "Deleted member", so conversations still make sense. Ask us and we'll remove them too.
- Submissions and change requests: kept as a record of the directory's history. Ask us if you'd like your name and email removed.
- Messages you send us: as long as needed to answer and follow up, then up to 12 months, after which we delete them. Ask us and we'll delete yours sooner.
- Newsletter: until you unsubscribe.
- Sign-in sessions: expire after 30 days, or straight away when you log out or use Log out everywhere.
- Server logs at our hosting provider: kept only for a short time.
- Backups may hold copies for a limited period before they're overwritten.
8. Your choices and rights
You can:
- see and correct your details in Settings;
- make your profile private in Settings;
- log out of every device with Log out everywhere;
- delete your account in Settings;
- unsubscribe from the newsletter at any time. Once we start sending it, every issue will include an unsubscribe link; until then, email us.
You can also ask us for a copy of your information, to correct or delete it, to restrict or object to how we use it, or to move it to another service. Email support@opensrcs.com and we'll reply within 30 days. If you're in the European Union or the United Kingdom, you can also complain to your local data protection authority.
9. Security
We protect your information with encrypted connections (HTTPS), scrambled (hashed) passwords, sign-in cookies that scripts can't read, and sessions that can be ended from any device. No system is perfectly secure, so please use a strong password that you don't use elsewhere, and tell us straight away if you think your account has been misused.
10. Children
Accounts are for people aged 16 or over. If we learn that someone younger has created an account, we'll delete it. If you believe a child has given us information, please contact us.
11. Changes to this policy
We'll update this policy when Opensrcs changes. We'll change the date at the top, and for important changes we'll tell account holders by email or on the site before they take effect.
12. Contact
Questions about your privacy, or requests about your information: support@opensrcs.com.