opencards
ENUK

Version 2026-10-04 · Effective 2026-10-04

OpenCards Privacy Policy

Version 2026-10-04. A Ukrainian version is published alongside this one. If the two differ, the Ukrainian version prevails.

This policy explains what personal data OpenCards collects when you use the service at opencards.dev, why, how long it is kept, who else receives it, and what rights you have. We collect as little as we can: OpenCards has no analytics, no advertising, no tracking scripts, no third-party fonts, and it does not store your IP address.

1. Who we are

OpenCards is operated by a sole proprietor registered in Ukraine:

  • Name: ФОП Войтович Ростислав Владиславович (Rostyslav Voitovych, sole proprietor)
  • Tax ID (РНОКПП): 3521612832
  • Address: вул. Розвадовського, буд. 10, кв. 77, м. Кам'янець-Подільський, Хмельницька обл., 32300, Україна
  • Email (including privacy requests): [email protected]

In this policy, "we" and "us" means the operator, and "you" means a person who signs in to OpenCards.

2. Two roles: your account and your workspace content

We handle personal data in two different roles:

  • Your account — your sign-in identity, sessions, memberships and similar data described in section 3. We decide why and how this data is processed, so we are its controller (in Ukrainian law, the володілець персональних даних).
  • Workspace content — test cases, requirements, specifications, test runs, CI reports and anything else your team puts into a workspace. Your organisation decides what goes in and why. For that content we act only as a processor (розпорядник) on behalf of the organisation that owns the workspace. If you have a question about personal data inside a workspace, ask that organisation first. A data processing agreement is available on request.

3. What we collect and where it comes from

DataSourceWhy
Your Google account identifier, email address, name, and whether Google has verified the emailGoogle, when you sign in with GoogleTo create your account and sign you in
Session records: when a session started and when it expiresCreated by OpenCardsTo keep you signed in
Workspace memberships and rolesCreated when you join or create a workspaceTo decide what you can see and do
Invitations: the invited email address and who invited themEntered by a workspace memberTo let the invited person join
Connected clients (AI assistants and other MCP clients, CI tokens you create): which client, when connected, when revokedCreated when you connect a client or create a tokenTo let the client act on your behalf, and to let you revoke it
Your email address in run history ("who recorded this result", including "via <client>")Created when you or your client record a test resultSo your team can see who did what
The time you last signed in, and the version of the Terms you accepted and whenCreated by OpenCardsSecurity, and a record of acceptance
Administrative actions taken by the operator (for example, suspending a workspace), with the operator's emailCreated by OpenCardsAccountability and security
Your IP addressYour browser or clientRate limiting against abuse: held in memory for at most 60 seconds, never written to disk. Cloudflare also sees it (section 6)

We do not ask for, and you should not put into OpenCards, special categories of personal data (health, religion, political opinions, biometric data and the like).

4. Why we process it, and on what legal basis

PurposeLegal basis
Providing the service: sign-in, workspaces, runs, connected clientsPerformance of our contract with you (the Terms); Law of Ukraine "On Personal Data Protection", Art. 11(1)(3); GDPR Art. 6(1)(b)
Security: rate limiting, abuse prevention, the admin audit log, keeping backupsOur legitimate interest in a secure, available service; Art. 11(1)(6); GDPR Art. 6(1)(f)
Complying with the law, and establishing or defending legal claimsLegal obligation; Art. 11(1)(5); GDPR Art. 6(1)(c)

We do not use your data for advertising, we do not sell it, and we do not make decisions about you by automated means that have legal or similarly significant effects.

5. How long we keep it

DataKept for
Your accountUntil you or a workspace administrator asks us to delete it. Inactive accounts are kept.
Sessions30 days from last use, then deleted
Connected-client authorisation codesUntil used, or 60 seconds
Connected-client access tokens1 hour; refresh tokens 30 days. Tokens of a revoked connection are deleted after 30 days
Revoked client connections90 days after revocation
InvitationsUntil accepted, or 7 days
Record of your Terms acceptanceAs long as your account exists
Workspace contentAs long as the workspace exists. A deleted organisation is hidden from everyone at once and kept for up to 30 days, during which we can restore it at an owner's request; a personal workspace is deleted at once, with its account
Server logsRotated: at most about 50 MB per service, typically a few days to weeks
Database backups14 days. Our hosting provider additionally keeps whole-server snapshots for up to 4 weeks
IP addresses for rate limitingAt most 60 seconds, in memory only

When we delete your account, your email address in run history is replaced with a pseudonym so that your team's test history stays intact without identifying you. Deleted data disappears from backups when those backups expire.

6. Who receives your data

We use the following service providers (sub-processors). Each processes data only to provide its service to us.

ProviderWhat it doesDataLocationTransfer safeguard
DigitalOcean, LLCHosts the server and databaseEverything in section 3Frankfurt, Germany (EU)EU data centre; DigitalOcean DPA
Cloudflare, Inc.DNS, encrypted network tunnel to our server, protection against attacksIP address, request metadata, and the traffic passing through (encrypted in transit)Global network; US companyEU–US Data Privacy Framework; Standard Contractual Clauses
Google LLC"Sign in with Google"Your Google identity during sign-inUnited StatesEU–US Data Privacy Framework

The list is also published at /subprocessors. We add a provider to the list before it receives any personal data.

Your data is transferred from Ukraine to these providers because it is necessary to perform our contract with you (Law of Ukraine "On Personal Data Protection", Art. 29). We may also disclose data when the law requires it, for example on a binding request from a Ukrainian court or authority.

AI assistants and other clients you connect. OpenCards can be used through AI assistants such as Claude Code, Claude Desktop or other MCP clients, and through CI tools, that you choose to connect. When you connect a client, it receives the workspace data its requests return. What that client and its provider do with the data is governed by their own terms and privacy policy, not by ours: they act as a separate controller, and we are not responsible for them. Connect only clients you trust, and revoke access in OpenCards when you no longer need it.

7. Cookies

OpenCards sets only cookies that are strictly necessary for the service, or that remember a choice you made. There are no analytics, advertising or tracking cookies, so we do not show a cookie banner.

CookiePurposeLifetime
opencards_sidKeeps you signed inThe cookie lasts up to 400 days, but the session behind it expires after 30 days without use
opencards_oauthProtects the "Sign in with Google" step against forgery10 minutes, sent only to sign-in addresses
opencards_admin_sessionKeeps the operator's administrators signed in to the admin console (not set for other users)As opencards_sid
opencards_themeRemembers your light or dark theme, if you choose one1 year

Older cookie names starting with proba_ may be removed from your browser; OpenCards no longer sets them.

8. Your rights

Under the Law of Ukraine "On Personal Data Protection" (Art. 8) and, where it applies to you, the GDPR, you have the right to:

  • know what data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • object to or restrict processing based on our legitimate interest;
  • receive your data in a machine-readable format (portability);
  • withdraw any consent you gave (we do not currently rely on consent);
  • complain to a supervisory authority.

To use these rights, email [email protected] from the address on your account. We answer within 30 days. We may ask you to confirm your identity. For data inside a workspace, we will pass your request to the organisation that owns the workspace and help it respond.

You can complain to the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини, ombudsman.gov.ua). If you live in the EU or EEA, you can also complain to the data protection authority in your country.

9. Security

Traffic is encrypted (HTTPS). The application is not directly reachable from the internet: it is reached only through an encrypted tunnel. Session and access tokens are random and stored only as hashes. Access to production systems is limited to the operator.

If a personal data breach affects you and is likely to put your rights at high risk, we will tell you without undue delay.

10. Age

OpenCards is a tool for professional use and is not intended for people under 16.

11. Changes to this policy

Each version is published with its date, and previous versions remain available at /privacy/<date>. If we make a material change, we will show it to you the next time you sign in.

12. Contact

ФОП Войтович Ростислав Владиславович — [email protected]

Terms of ServicePrivacy PolicySub-processorsContact