Skip to main content
OpenSourceAlternatives

Governance

Privacy notice

What OpenAlternative stores, why, and how long it is kept.

Review notice. Project policy copy for transparency; it requires qualified legal review and is not legal advice. Version 2026-09-02.

Browsing and third parties

Ordinary catalogue browsing does not require an account. We do not use advertising trackers or cross-site profiling. Product icons are requested from Google's favicon service, so Google can receive the requesting network address and viewed product domain.

Cloudflare Turnstile is loaded only on protected contribution and newsletter forms when configured. Its processing is governed by Cloudflare's terms.

Accounts and contributions

Supabase Auth provides account identity. The API stores the immutable Auth subject, private saves/lists/preferences, Project-change notifications, contributions, moderation history, and scoped memberships. It does not copy account email into the profile table. An opted-in report contact is encrypted, copied to a bounded delivery queue only when the report is resolved or dismissed, and destroyed after delivery, terminal failure, account deletion, or expiry. Submitted public-interest history is retained with actor references anonymized after account deletion; private drafts and inbox rows are deleted.

Newsletter, analytics, and commercial events

Newsletter addresses are encrypted and separately HMAC-indexed. The consent record includes its first-party subscription surface and only the five named, bounded UTM values. Suppression records are retained to honor opt-out, complaint, and bounce choices. First-party decision and commercial events use keyed session pseudonyms, strict property allowlists, and expiry dates; raw IP addresses, device fingerprints, bearer tokens, and email addresses are not analytics fields.

Optional AI assistance

When you explicitly ask the decision assistant to interpret a request or generate a comparison summary, the API may send the bounded request plus reviewed catalogue facts to the configured OpenAI project. It also sends a keyed pseudonymous safety identifier. OpenAI receives no account email, API bearer token, database credential, source URL fetch permission, or model tool access. Requests set provider storage off; our database stores structured intent, bounded results, model/run metadata, and keyed hashes—not the raw natural-language request, prompt, or provider response envelope.

Recommendation/model metadata, drafts, and feedback carry configured expiry dates and are removed by the retention process. Account-linked recommendation sessions are included in export/deletion. Editors may request source-grounded drafts, but a human must decide each field and complete the ordinary publication review. The operator must execute an appropriate data-processing agreement and retention setting with the provider before enabling production use.

Your choices

Account settings provide granular Project alert choices plus export and deletion workflows. Newsletter links provide permanent one-click unsubscribe for the single newsletter stream. For access, correction, deletion, or legal-hold questions, contact legal@opensourcealternatives.fyi.