Privacy Policy
Scope
o.cafe is a free project maintained by an independent developer. This policy covers o.cafe, hub.o.cafe, creator profiles, posts, community pages, the Dashboard, and related features we provide.
We aim to handle only what is reasonably needed to provide the product, keep it secure, and resolve problems. We do not plan to build cross-site identities, device fingerprints, or long-term personal profiles.
Public visits and network data
When you visit, infrastructure providers such as Cloudflare may process basic request information to serve the page, block attacks, and diagnose failures. This can include an IP address, request time, path, basic browser information, and response status.
o.cafe does not intentionally put raw IP addresses, cookie contents, tokens, or complete requests into product analytics events.
Public GitHub and project data
To build the directory and creator pages, we may process information already public on GitHub or a project's website, including:
- GitHub usernames, avatars, and public bios;
- public repository names, descriptions, README files, licenses, languages, Star counts, and update times;
- project websites, documentation, and source links;
- contact details a maintainer has clearly made public in a profile, README, or contact page.
Public contact details are kept private within o.cafe and used only to verify attribution, resolve corrections, and maintain a private contact-fact ledger. They are not currently used for automated or manual outreach. They are not placed in the public directory, ordinary exports, or advertising lists, and they are not sold. Before starting any future project outreach, we will update the applicable rules and this policy and provide appropriate choice and opt-out mechanisms.
GitHub sign-in and accounts
If you choose to sign in when the feature is available, GitHub and our authentication provider may give us a stable GitHub identifier, public profile details, an authentication result needed to create a session, and any other information within the permissions you clearly approve.
We do not intentionally put GitHub access tokens, refresh tokens, OAuth codes, or other sensitive credentials into public pages, product analytics, or ordinary logs.
Information you submit
You may submit a handle, display name, avatar choice, bio, project presentation, ordering, links, posts, comments, project references, reports, appeals, support requests, and rights-related material.
Anything you publish can be seen by other visitors and may be indexed or archived by outside services. Do not place passwords, API keys, access tokens, a private address, financial details, or other unnecessary sensitive information in public content.
First-party product analytics
If analytics is enabled, we may record a limited set of first-party events, such as whether a page was viewed, a button was used, a search returned results, or a flow was completed.
Our analytics are designed so that comment text, private contact details, report evidence, and credentials are not written to analytics events; full external URLs and query strings are not stored; Canvas, font data, and similar techniques are not used to fingerprint devices; and raw analytics data is not sold to advertisers.
How we use information
We use information only where reasonably needed to:
- serve pages, search, and the project directory;
- manage sign-in, sessions, and accounts;
- create profiles, display projects, and publish posts;
- provide comments, reporting, appeals, and project corrections;
- prevent spam, manipulation, malware, phishing, impersonation, and account abuse;
- fix errors, understand basic usage, and improve the product;
- handle copyright, privacy, ownership, and security concerns;
- maintain backups, audit trails, and service continuity.
We do not sell personal information or give private contact details or raw behavior records to sponsors for targeted outreach.
What may be public
Public information may include profile details you choose to publish, projects you choose to display, your public posts and comments, directory facts and summaries that pass publication checks, and support relationships or other states you explicitly choose to make public.
Internal IDs, security decisions, report evidence, moderation reasoning, private contacts, and raw analytics events are not part of ordinary public pages.
Service providers
Our current or planned core providers are:
- Cloudflare for site delivery, CDN, attack protection, rate limiting, R2 object storage, and Email Routing;
- Supabase for authentication, databases, and backend services;
- GitHub for sign-in, public project data, and GitHub actions you start yourself.
They process the information needed to provide their part of the service under their own policies. We will update this policy before adding monitoring, AI, or another provider that changes how information is handled.
How long we keep information
We do not promise to keep every record forever. In general:
- temporary sign-in and handle-reservation data expires in minutes or hours;
- accounts and public content remain until deletion, account closure, or when they are no longer needed;
- security, report, appeal, and rights records may be kept for a reasonable period to resolve disputes and prevent repeated abuse;
- removal from backups and caches can take additional time;
- public GitHub facts are refreshed, and a deleted, private, or unavailable project may stop appearing;
- public contact details are reviewed and removed or marked “do not contact” when no longer needed.
Your choices
Depending on the features available, you may edit or delete content you submitted, sign out and revoke GitHub access, correct clear errors, ask us to close an account and remove related content, object to continued storage of a public contact address, or report material that violates privacy or another right.
Email hi@o.cafe with enough information to identify the account or content. We may ask for reasonable proof of identity or control so that someone else cannot make the request for you.
Some information may not disappear immediately because of security, an active dispute, backup rotation, or another person's rights. We will try to explain the main reason.
Security
We use safeguards appropriate to the size of the project, including server-side authorization, private databases, access restrictions, rate limits, credential separation, backups, and feature kill switches.
No internet service can promise perfect security. If you find a site vulnerability, account takeover, or exposed secret, email security@o.cafe privately. Do not post immediately exploitable details in a public comment or issue.
Children and younger users
o.cafe is not designed specifically for children. Anyone who is not old enough to use an online service independently where they live should use it with a parent or guardian and avoid publishing sensitive personal information.
Changes and contact
We may update this policy when features, providers, or security needs change. We will use a site notice, page notice, or another reasonable method for important changes.
- Privacy, account, deletion, and content questions: hi@o.cafe
- Site vulnerabilities and exposed secrets: security@o.cafe