Privacy Policy
Last updated: June 29, 20261. Who We Are
OpenThorn is operated by Thomas Tschinkel, located in Rome, Italy (the "Data Controller"). For privacy-related enquiries, contact us at btalabs.contact@gmail.com.
2. What Data We Process
We process the data needed to provide, secure, and improve OpenThorn:
- Account and profile data - email address, display name, avatar URL, OAuth account metadata, authentication identifiers, and session data.
- Project and repository data - project names, prompts, chat history, generated code, uploaded or edited files, preview/deploy metadata, starred status, and repository names or owner names when you connect GitHub.
- API provider data - AI provider names, model settings, base URLs, enabled/disabled status, and API keys you save. API keys are encrypted before database storage and are decrypted only when needed to send your request to the AI provider you selected.
- AI request data - prompts, project context, generated files, runtime errors, and other technical context needed to produce or refine output. This data may be sent to the AI provider you choose.
- GitHub integration data - GitHub OAuth access tokens, GitHub username, repository owner/name, repository descriptions, auto-sync setting, and code pushed to GitHub when you enable repository sync.
- Deployment data - generated HTML, project identifiers, Cloudflare Pages project names, deploy IDs, deploy URLs, and related deployment status data when you use the deployment feature.
- Community and collaboration data - public shared projects, author/profile details displayed with community projects, likes, collaborator email addresses, collaborator permissions, invite status, and real-time presence or generation state used to support collaboration.
- Local user memory - optional browser-local preferences, fixes, and facts inferred from your prompts so OpenThorn can keep useful context across projects on the same browser.
- Technical data - IP address, browser/device data, request logs, error information, and security events processed by our hosting, authentication, database, font, CDN, and integration providers.
- Aggregated usage data - anonymous page views and visit statistics collected via Vercel Web Analytics, and anonymous performance metrics (such as page load and responsiveness timings, route, device type, and connection speed) collected via Vercel Speed Insights. Both services are cookieless: they store no cookies or identifiers in your browser and do not track you across sites or sessions. Visitors are counted using a temporary hash derived from the incoming request that is discarded and cannot be used to identify you across days or websites.
3. Why We Process Data and Legal Bases
- Providing the service - account access, project storage, AI generation, GitHub sync, Cloudflare Pages deploys, collaboration, and community features are processed under Art. 6(1)(b) GDPR (performance of a contract).
- Security, abuse prevention, reliability, and essential diagnostics - processed under Art. 6(1)(f) GDPR (legitimate interests).
- Anonymous usage and performance statistics - cookieless, aggregated page-view analytics and web performance metrics used to understand how the service is used and to keep it fast, processed under Art. 6(1)(f) GDPR (legitimate interests). No persistent identifiers are stored and no cross-site or cross-session tracking takes place.
- Legal compliance - records or disclosures required by law are processed under Art. 6(1)(c) GDPR.
- Optional connected services - when you choose OAuth login, GitHub sync, provider keys, public sharing, or deployment, we process the data needed for that feature under Art. 6(1)(b) GDPR and, where required, your consent under Art. 6(1)(a) GDPR.
4. Third-Party Services and Recipients
We use service providers and integrations that may process personal data:
- Vercel Inc. (hosting, infrastructure, web analytics, and performance monitoring) - request data, including IP addresses and technical logs, may be processed by Vercel. We also use Vercel Web Analytics and Vercel Speed Insights, cookieless services that record anonymous, aggregated page views and web performance metrics without storing cookies or persistent identifiers in your browser.
- Supabase, Inc. (authentication, database, realtime) - account, profile, session, project, collaboration, community, encrypted provider-key, and GitHub integration records are stored or processed on Supabase infrastructure.
- AI providers you select (for example OpenAI, Anthropic, Google, Mistral, Groq, OpenRouter, or custom providers) - prompts, project context, generated files or errors, and your API key or authorization credentials are transmitted as needed to fulfil your AI request.
- GitHub, Inc. - OAuth login data and, if you connect a repository, OAuth access tokens, repository metadata, and project code are processed by GitHub.
- Cloudflare, Inc. - when you deploy, generated HTML and deployment metadata are sent to Cloudflare Pages to create or update a site.
- CDN and package providers - generated previews may load runtime resources such as JavaScript packages, type definitions, or WebAssembly files from public CDNs when needed to build, preview, or typecheck generated code. OpenThorn's own fonts are self-hosted and do not involve requests to Google Fonts or other third-party font services.
- OAuth providers (Google and GitHub) - if you sign in with an OAuth provider, that provider processes authentication data according to its own terms and privacy policy.
OpenThorn does not sell your personal data. API keys are not used for OpenThorn billing and are not disclosed except where technically necessary to communicate with the provider you selected or where legally required.
Where a provider acts as our processor, we aim to use appropriate data processing terms, confidentiality obligations, and transfer safeguards. Where a third-party service is independently selected by you, such as your AI provider or GitHub account, that service may also act as an independent controller under its own terms.
5. Security Measures
We use technical and organisational measures intended to protect personal data, including Supabase row-level security, authenticated access controls, HTTPS, provider-side infrastructure security, and encryption of saved provider API keys before database storage.
Saved provider API keys are sensitive credentials. OpenThorn encrypts them before database storage and decrypts them only when needed to send your request to the provider you selected. This reduces exposure but does not make stored keys risk free. You remain responsible for managing provider-side permissions, spend limits, and key rotation, and you should revoke a key immediately if you suspect misuse.
6. Public Sharing
If you publish a project to the Community, its title, preview, generated content, author/profile information, likes count, and related metadata may be visible to other users or visitors. Do not publish secrets, credentials, private repository data, or personal information you do not want to make public.
7. Data Retention
- Account, profile, project, provider-key, integration, collaboration, and community data - retained while your account is active or until you delete it or request deletion, unless a longer retention period is required by law.
- GitHub tokens and repo settings - retained until you disconnect GitHub, delete the related data, or request deletion.
- Deployment metadata - retained while needed to show and update your deployment. Data hosted by Cloudflare may remain in your Cloudflare Pages-managed site according to Cloudflare's retention practices.
- Browser-local data - remains on your device until you clear it, sign out where applicable, or the app removes it.
- Server logs and security records - retained for a limited period needed for security, debugging, and legal compliance.
8. International Data Transfers
Some providers are based in or process data in the United States and other countries outside the EU/EEA. Where required, transfers are protected by adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, or other safeguards under Chapter V GDPR.
9. Your Rights
Under the GDPR you have the right to:
- Access - request a copy of your personal data.
- Rectification - ask us to correct inaccurate data.
- Erasure - ask us to delete your account and associated data.
- Restriction - ask us to pause processing in certain circumstances.
- Portability - receive your data in a structured, machine-readable format.
- Object - object to processing based on legitimate interests.
- Withdraw consent - withdraw consent where processing is based on consent, without affecting prior lawful processing.
To exercise any of these rights, email us at btalabs.contact@gmail.com. We will respond within 30 days.
10. Complaints
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Italian data protection authority: Garante per la protezione dei dati personali (garanteprivacy.it).
11. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes that affect your rights under the GDPR - such as new categories of data collected, new processors, or a new legal basis - we will notify you by email or a prominent notice in the service and, where required by law, seek your renewed consent.
12. Contact
For any questions about this privacy policy or your personal data, contact us at btalabs.contact@gmail.com.
