跳到正文 / Skip to content
O.CAFE / POLICIESBack to o.cafe

Privacy Policy

This policy explains what o.cafe handles, why we need it, what may be public, and the choices available to you.

Privacy Policy

Scope

o.cafe is a free project maintained by an independent developer. This policy covers o.cafe, hub.o.cafe, creator profiles, posts, community pages, the Dashboard, and related features we provide.

We aim to handle only what is reasonably needed to provide the product, keep it secure, and resolve problems. We do not plan to build cross-site identities, device fingerprints, or long-term personal profiles.

Public visits and network data

When you visit, infrastructure providers such as Cloudflare may process basic request information to serve the page, block attacks, and diagnose failures. This can include an IP address, request time, path, basic browser information, and response status.

o.cafe does not intentionally put raw IP addresses, cookie contents, tokens, or complete requests into product analytics events.

Public GitHub and project data

To build the directory and creator pages, we may process information already public on GitHub or a project's website, including:

  • GitHub usernames, avatars, and public bios;
  • public repository names, descriptions, README files, licenses, languages, Star counts, and update times;
  • project websites, documentation, and source links;
  • contact details a maintainer has clearly made public in a profile, README, or contact page.

Public contact details are kept private within o.cafe and used only to verify attribution, resolve corrections, and maintain a private contact-fact ledger. They are not currently used for automated or manual outreach. They are not placed in the public directory, ordinary exports, or advertising lists, and they are not sold. Before starting any future project outreach, we will update the applicable rules and this policy and provide appropriate choice and opt-out mechanisms.

GitHub sign-in and accounts

If you choose to sign in when the feature is available, GitHub and our authentication provider may give us a stable GitHub identifier, public profile details, an authentication result needed to create a session, and any other information within the permissions you clearly approve.

We do not intentionally put GitHub access tokens, refresh tokens, OAuth codes, or other sensitive credentials into public pages, product analytics, or ordinary logs.

Information you submit

You may submit a handle, display name, avatar choice, bio, project presentation, ordering, links, posts, comments, project references, reports, appeals, support requests, and rights-related material.

Anything you publish can be seen by other visitors and may be indexed or archived by outside services. Do not place passwords, API keys, access tokens, a private address, financial details, or other unnecessary sensitive information in public content.

First-party product analytics

If analytics is enabled, we may record a limited set of first-party events, such as whether a page was viewed, a button was used, a search returned results, or a flow was completed.

Our analytics are designed so that comment text, private contact details, report evidence, and credentials are not written to analytics events; full external URLs and query strings are not stored; Canvas, font data, and similar techniques are not used to fingerprint devices; and raw analytics data is not sold to advertisers.

How we use information

We use information only where reasonably needed to:

  1. serve pages, search, and the project directory;
  2. manage sign-in, sessions, and accounts;
  3. create profiles, display projects, and publish posts;
  4. provide comments, reporting, appeals, and project corrections;
  5. prevent spam, manipulation, malware, phishing, impersonation, and account abuse;
  6. fix errors, understand basic usage, and improve the product;
  7. handle copyright, privacy, ownership, and security concerns;
  8. maintain backups, audit trails, and service continuity.

We do not sell personal information or give private contact details or raw behavior records to sponsors for targeted outreach.

What may be public

Public information may include profile details you choose to publish, projects you choose to display, your public posts and comments, directory facts and summaries that pass publication checks, and support relationships or other states you explicitly choose to make public.

Internal IDs, security decisions, report evidence, moderation reasoning, private contacts, and raw analytics events are not part of ordinary public pages.

Service providers

Our current or planned core providers are:

  • Cloudflare for site delivery, CDN, attack protection, rate limiting, R2 object storage, and Email Routing;
  • Supabase for authentication, databases, and backend services;
  • GitHub for sign-in, public project data, and GitHub actions you start yourself.

They process the information needed to provide their part of the service under their own policies. We will update this policy before adding monitoring, AI, or another provider that changes how information is handled.

Cookies and local storage

We use a small set of first-party cookies and browser storage for current features. We do not use cross-site advertising cookies or use cookies to build a profile of you across other websites.

Cookies may include:

  • ocafe_locale for your language preference, usually for about one year;
  • __Host-ocafe-auth for a signed-in session, until it expires, you sign out, or it is revoked;
  • __Host-ocafe-oauth-flow for the temporary GitHub OAuth flow and replay protection, usually about ten minutes;
  • __Host-ocafe-auth-bucket for short-term login and write-abuse protection, usually about 24 hours;
  • __Host-ocafe-handle-hold for a temporary handle reservation, usually about ten minutes;
  • __Host-ocafe-handle-holder to recognize the same browser during that reservation, usually about 24 hours.

Local or session storage may hold interface preferences, an unfinished local draft, a random first-party analytics session ID, or other non-sensitive interaction state. Trusted identity and account permissions are not decided from browser storage alone.

You can inspect, delete, or block cookies and clear local storage in your browser. Blocking a necessary cookie may stop sign-in, handle reservation, or a security check from working. Public browsing generally does not require an authentication cookie.

How long we keep information

We do not promise to keep every record forever. In general:

  • temporary sign-in and handle-reservation data expires in minutes or hours;
  • accounts and public content remain until deletion, account closure, or when they are no longer needed;
  • security, report, appeal, and rights records may be kept for a reasonable period to resolve disputes and prevent repeated abuse;
  • removal from backups and caches can take additional time;
  • public GitHub facts are refreshed, and a deleted, private, or unavailable project may stop appearing;
  • public contact details are reviewed and removed or marked “do not contact” when no longer needed.

Your choices

Depending on the features available, you may edit or delete content you submitted, sign out and revoke GitHub access, correct clear errors, ask us to close an account and remove related content, object to continued storage of a public contact address, or report material that violates privacy or another right.

Email hi@o.cafe with enough information to identify the account or content. We may ask for reasonable proof of identity or control so that someone else cannot make the request for you.

Some information may not disappear immediately because of security, an active dispute, backup rotation, or another person's rights. We will try to explain the main reason.

Security

We use safeguards appropriate to the size of the project, including server-side authorization, private databases, access restrictions, rate limits, credential separation, backups, and feature kill switches.

No internet service can promise perfect security. If you find a site vulnerability, account takeover, or exposed secret, email security@o.cafe privately. Do not post immediately exploitable details in a public comment or issue.

Children and younger users

o.cafe is not designed specifically for children. Anyone who is not old enough to use an online service independently where they live should use it with a parent or guardian and avoid publishing sensitive personal information.

Changes and contact

We may update this policy when features, providers, or security needs change. We will use a site notice, page notice, or another reasonable method for important changes.

  • Privacy, account, deletion, and content questions: hi@o.cafe
  • Site vulnerabilities and exposed secrets: security@o.cafe

Need to reach us?

General questions and security reports use separate inboxes so sensitive vulnerability details do not enter an ordinary feedback flow.