OSS Discovery

LEGAL DOCUMENT

Privacy Policy

Last updated May 02, 2026
contact@ossdiscovery.site

This Privacy Notice for OSS Discovery ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our website at http://www.ossdiscovery.site
  • Use OSS Discovery — an open-source tool discovery platform that helps developers find, explore, and compare open-source software. Users can browse a curated collection of open-source tools across multiple categories, filtered by programming language, license type, platform, and country of origin.
  • Engage with us in other related ways

Summary of Key Points

What personal information do we process?

When you visit or use our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use.

Do we process sensitive personal information?

No. We do not process sensitive personal information.

Do we collect information from third parties?

We may collect limited information from GitHub when you authenticate using GitHub OAuth.

How do we process your information?

We process your information to provide and improve our Services, communicate with you, for security and fraud prevention, and to comply with law.

How do we keep your information safe?

We have technical and organizational processes in place to protect your personal information. However, no electronic transmission over the internet can be guaranteed 100% secure.

What are your rights?

Depending on your location, you may have rights regarding your personal information. Contact us at contact@ossdiscovery.site to exercise them.

01

WHAT INFORMATION DO WE COLLECT?

In Short: We collect personal information that you provide to us directly, and some information automatically.

Personal Information You Provide:

  • Email addresses
  • Usernames
  • Passwords (for Magic Link auth)
  • Contact or authentication data
  • GitHub account data (username, avatar URL, public profile)
  • User preferences and settings (avatar selection, display preferences)
  • Tool submission data (GitHub repository URLs, tool descriptions, contact email for verification, self-described maintainer role)

We do not process sensitive information.

Social Login Data:

If you register using GitHub or Google OAuth, we receive certain profile information from those providers. See Section 7 for details.

Information Automatically Collected:

We automatically collect certain information when you visit our Services, including:

Log and Usage Data: IP address, browser type, device information, pages viewed, searches performed, date/time stamps, and other usage information.

Device Data: Information about your computer, phone, tablet, or other device used to access our Services, including IP address, browser type, operating system, and system configuration.

We also store your search history locally in your browser using localStorage.

For more information about our use of cookies, see our Cookie Notice at: http://www.ossdiscovery.site/cookies

02

HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and secure our Services.

We process your personal information for the following purposes:

  • To facilitate account creation and authentication
  • To deliver and facilitate delivery of our Services
  • To respond to user inquiries and offer support
  • To send administrative information (account updates, policy changes)
  • To request feedback about our Services
  • To protect our Services from fraud and abuse
  • To identify usage trends and improve our Services
  • To save or protect an individual's vital interest when necessary
04

WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?

In Short: We share information only with service providers necessary to operate our platform.

We share data with the following third-party providers:

AI Service Providers:

Groq
Cerebras
Fireworks
Together.ai
DeepInfra
SambaNova

Authentication:

GitHub OAuth
Google OAuth
Supabase Auth

Cloud & Infrastructure:

Vercel (hosting)
Supabase (database & backend)

All third-party providers are bound by contracts that prohibit them from using your data for any purpose other than providing services to us.

Business Transfers:

We may share your information in connection with any merger, sale, or acquisition of all or part of our business.

05

DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We use strictly necessary cookies for authentication only.

We use cookies to maintain your authentication session when you are logged in. We do not use advertising cookies, tracking pixels, or marketing cookies.

We also use localStorage to store your search history locally in your browser. This data never leaves your device.

For full details, see our Cookie Notice: http://www.ossdiscovery.site/cookies

06

DO WE OFFER AI-POWERED FEATURES?

In Short: Yes — we use AI to generate search summaries and tool descriptions.

We provide AI-powered features through the following third-party providers:

  • Groq (primary search summaries)
  • Cerebras (fallback search summaries)
  • Fireworks AI, Together.ai, DeepInfra, SambaNova (tool Q&A generation)

Your search queries may be processed by these providers to generate relevant summaries. We do not use your personal information to train AI models.

07

HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: When you log in with GitHub or Google, we receive limited profile information.

When you choose to register or log in using GitHub or Google OAuth, we receive the following profile information:

From GitHub: Username, email address, avatar URL, public profile information

From Google: Email address, name, profile picture

We use this information only to create and manage your account. We do not control how GitHub or Google use your information — please review their respective privacy policies for details.

08

IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: Yes — our servers and service providers are located in the US and Singapore.

Our infrastructure is hosted in the United States (Vercel) and Singapore (Supabase). If you are located in the EEA, UK, or Switzerland, your data may be transferred to these countries.

We protect international transfers using the European Commission's Standard Contractual Clauses (SCCs). Our service providers Supabase and Vercel both maintain SCCs as part of their GDPR compliance programs.

Standard Contractual Clauses can be provided upon request by contacting contact@ossdiscovery.site.

09

HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as your account is active.

We retain your personal information only for as long as necessary to provide our Services. When you delete your account, we will delete or anonymize your personal information within 30 days, unless retention is required by law.

10

HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We use technical and organizational measures to protect your data.

Our security measures include:

  • Row Level Security (RLS) on all database tables
  • Encrypted connections (SSL/TLS) for all data in transit
  • Secure OAuth authentication via GitHub and Google
  • API key hashing — raw keys are never stored
  • Supabase database encryption at rest
  • HTTPS enforced across all pages via Vercel

No electronic transmission over the internet can be guaranteed 100% secure. You should only access our Services within a secure environment.

11

DO WE COLLECT INFORMATION FROM MINORS?

In Short: No. Our Services are not directed at users under 18.

We do not knowingly collect data from or market to users under 18 years of age. If you believe we have collected data from a minor, please contact us immediately at contact@ossdiscovery.site and we will delete it promptly.

12

WHAT ARE YOUR PRIVACY RIGHTS?

In Short: You have rights to access, correct, and delete your personal information.

Depending on your location, your rights may include:

  • Right to access your personal information
  • Right to correct inaccurate information
  • Right to request deletion of your data
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent at any time

To exercise any of these rights, contact us at: contact@ossdiscovery.site

We will respond within 30 days in accordance with applicable law.

Account Management:

You can review and update your account information at any time by logging into your dashboard settings. To delete your account entirely, contact us at contact@ossdiscovery.site.

13

CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers include a Do-Not-Track ("DNT") setting. We do not currently respond to DNT signals as no uniform standard has been finalized. If a standard is adopted in the future, we will update this notice accordingly.

14

DO UNITED STATES RESIDENTS HAVE SPECIFIC RIGHTS?

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have additional rights under your state's privacy laws.

Categories of Personal Information We Collect:

CategoryCollected
A — Identifiers (email, username, IP address)YES
B — California Customer RecordsNO
C — Protected classificationsNO
D — Commercial informationNO
E — Biometric informationNO
F — Internet activityNO
G — Geolocation dataNO
H — Audio/visual recordingsNO
I — Professional informationNO
J — Education informationNO
K — Inferences/profilingNO
L — Sensitive personal informationNO

Your Rights Include:

  • Right to know what personal data we process
  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to request deletion
  • Right to obtain a copy of your data
  • Right to non-discrimination for exercising rights
  • Right to opt out of sale of personal data (we do not sell personal data)

To exercise these rights, contact us at: contact@ossdiscovery.site

We have not sold any personal information to third parties in the preceding 12 months.

Appeals:

If we decline your request, you may appeal by emailing contact@ossdiscovery.site. If your appeal is denied, you may contact your state attorney general.

15

DO OTHER REGIONS HAVE SPECIFIC RIGHTS?

Australia:

We process your personal information in accordance with Australia's Privacy Act 1988. You have the right to request access to or correction of your personal information at any time by contacting contact@ossdiscovery.site.

If you believe we are unlawfully processing your information, you may lodge a complaint with the Office of the Australian Information Commissioner.

16

DO WE MAKE UPDATES TO THIS NOTICE?

Yes. We may update this Privacy Notice from time to time to reflect changes in our practices or applicable law. The updated version will be indicated by an updated date at the top of this page.

For material changes, we will notify you by email or by prominently posting a notice on our Services.

17

HOW CAN YOU CONTACT US?

For questions or concerns about this Privacy Notice:

Email: contact@ossdiscovery.site

Postal address:

OSS Discovery
Noida, Uttar Pradesh
India
18

HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

To request access to, correction of, or deletion of your personal information, contact us at:

contact@ossdiscovery.site

We will respond within 30 days in accordance with applicable data protection laws.

Questions about this policy?

Contact us at contact@ossdiscovery.site

Send us an email