Skip to content

Privacy policy

Last updated: 31 August 2026.
This English text is provided for convenience. Open Projects Lab is published from France and governed by French law: in the event of any discrepancy, the French version prevails.

Open Projects Lab respects your privacy. This page describes what is actually done today — not what is planned — in accordance with the GDPR (Regulation (EU) 2016/679).

Data controller

Open Projects Lab (non-professional publisher — see the legal notice) — contact: contact@openprojectslab.com.

Principle: as little data as possible

Open Projects Lab is built on a conviction: your data stays with you. The software runs 100% locally and sends no telemetry. The site follows the same line: no third-party analytics tool is installed — the only audience measurement is computed from the server logs, see point 1, no tracker, no advertising cookie, no third-party service loaded into your pages.

Data processed

1. Web server logs

Like any web server, the Open Projects Lab server technically records every request: IP address, date and time, page requested, response code, declared browser. Since an IP address is personal data, this processing is declared here.

These logs are used for security (detecting an attack or abuse), technical diagnostics, and a frugal audience measurement: a daily script derives totals from them — page views, estimated number of visitors, most-read pages, referring sites — with no cookie, no script in your pages, no third-party service. The report contains no IP address, no identifier, no fingerprint: the address is used only during the computation, in memory, and is never written. They are not cross-referenced with any account, not used for profiling, and not passed on to anyone.

Legal basis: legitimate interest (security and proper operation of the service), and the legal obligation on hosting providers to retain identification data (LCEN, article 6).

2. Member area

The member area is open, at app.openprojectslab.com. Creating an account is optional: the software can be downloaded and used without one.

If you create an account, the following are processed:

  • your email address — identification, address verification, password reset;
  • your username — displayed publicly next to your messages;
  • your password — never stored in plain text, only hashed with argon2id, an algorithm designed to stay expensive to crack; recovering it is technically impossible, including for the publisher;
  • your avatar, if you upload one — re-encoded to WebP; the original image’s metadata (including any geolocation) is not kept;
  • your short biography, if you write one;
  • your messages posted in the community chat, with their date;
  • the creation date of your account.

None of this data is sold, rented, or used for advertising purposes. No profiling, no automated decision-making.

Legal basis: performance of the service you request by creating an account.

3. Sending emails

Service emails (address confirmation, password reset) are sent through Brevo, a French company. Your email address is therefore passed to them for that single purpose. Brevo acts as a processor within the meaning of the GDPR and applies its own privacy policy.

Legal basis: performance of the service (without sending email, neither registration nor account recovery is possible).

4. Donations

Any donations go through Ko-fi, a third-party service, via an outbound link. No banking data passes through or is stored on Open Projects Lab servers; payment is handled entirely by Ko-fi, under its own privacy policy.

Hosting and location

The site and the member area are hosted in France, on an OVH server. Brevo, the email delivery provider, is a French company processing data within the European Union. No transfer outside the European Union is carried out by Open Projects Lab.

Retention periods

  • Server logs: automatic rotation, with retention capped at 12 months.
  • Member account: kept as long as the account exists. Deleting it erases the email address, username, avatar and biography.
  • Forum topics and messages: kept as long as the account exists; deleted along with it. A message removed by moderation is not erased: it is hidden, and appears in your export with its status — moderation can be contested, and erased text cannot be recovered.
  • Lab card customisation (banner, frame, ring, showcased tokens): kept as long as the account exists; deleted along with it. These are appearance choices, never identification data: no legal retention applies to them, and nothing remains after deletion. They appear in your data export.
  • Chat messages: kept as long as the account exists; deleted along with the account.
  • Contribution identification data (message identifier, member identifier, IP address, protocol, date and time): 12 months. It is stored separately from the content, in a table that holds none: no message text, no excerpt, no hash. This retention is required of every host by article 6-II of the LCEN and decree no. 2021-1362 — it rests on a legal obligation (GDPR, art. 6(1)(c)) and therefore survives account deletion: the username and email address are copied into it at the moment of deletion, then erased twelve months later. It is the sole exception to the previous point, and the GDPR provides for it expressly (art. 17(3)(b)).
  • Manifestly unlawful content: the text is destroyed in the database, not merely hidden. No copy is kept, not even as evidence — for the gravest offences, possession is itself punishable. One limit, stated plainly: encrypted backups already made before the erasure still contain it and cannot be rewritten; they will disappear on their own rotation. Only the identification data above remains, disclosable upon judicial request.
  • Verification and reset tokens: 24 hours, then unusable.
  • Display preferences cookie (opl_aspect): 400 days, or until you clear it from your browser. It holds no personal data.

Security

  • The whole site is served over HTTPS; session cookies are marked Secure and HttpOnly.
  • Passwords are hashed with argon2id (never encrypted, never reversible).
  • The member area is isolated from the rest of the server, in containers without administrator privileges.

Cookies

  • Public site: a single cookie, opl_aspect, which stores nothing but your display preferences — light or dark theme, accent colour, text size, density, language. It contains no identifier, is used for no tracking, is read by no third party, and is only written if you change one of those settings. It falls under cookies for user-requested interface personalisation, exempt from consent under article 82 of the French Data Protection Act. No banner is therefore necessary.
  • Member area: the same preferences cookie, plus a session cookie, strictly necessary to keep you signed in. It is used for no tracking whatsoever and falls under the same exemption.

No advertising cookie, no analytics cookie, no third-party cookie.

Minimum age

Creating an account is reserved for people aged 15 or over. Below that age, the consent of a holder of parental authority is required.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection regarding your data.

Some of these can be exercised directly from your account: changing your email, username, avatar or biography, downloading a copy of all your data as JSON (your rights of access and portability), and permanently deleting your account — all from the Settings page.

For any other request — rectifying data you cannot change yourself, restriction, objection — write to contact@openprojectslab.com: the request is handled manually, and answered within a maximum of one month.

You may also lodge a complaint with the CNIL, the French data protection authority (cnil.fr), if you believe your rights are not being respected.

Changes

This policy may evolve alongside the service. The date of the last update appears at the top of the page. In the event of a substantial change affecting your rights, registered members are informed by email.