OpenCards Privacy Policy
Version 2026-10-04. A Ukrainian version is published alongside this one. If the two differ, the Ukrainian version prevails.
This policy explains what personal data OpenCards collects when you use the service at opencards.dev, why, how long it is kept, who else receives it, and what rights you have. We collect as little as we can: OpenCards has no analytics, no advertising, no tracking scripts, no third-party fonts, and it does not store your IP address.
1. Who we are
OpenCards is operated by a sole proprietor registered in Ukraine:
- Name: ФОП Войтович Ростислав Владиславович (Rostyslav Voitovych, sole proprietor)
- Tax ID (РНОКПП): 3521612832
- Address: вул. Розвадовського, буд. 10, кв. 77, м. Кам'янець-Подільський, Хмельницька обл., 32300, Україна
- Email (including privacy requests): [email protected]
In this policy, "we" and "us" means the operator, and "you" means a person who signs in to OpenCards.
2. Two roles: your account and your workspace content
We handle personal data in two different roles:
- Your account — your sign-in identity, sessions, memberships and similar data described in section 3. We decide why and how this data is processed, so we are its controller (in Ukrainian law, the володілець персональних даних).
- Workspace content — test cases, requirements, specifications, test runs, CI reports and anything else your team puts into a workspace. Your organisation decides what goes in and why. For that content we act only as a processor (розпорядник) on behalf of the organisation that owns the workspace. If you have a question about personal data inside a workspace, ask that organisation first. A data processing agreement is available on request.
3. What we collect and where it comes from
| Data | Source | Why |
|---|---|---|
| Your Google account identifier, email address, name, and whether Google has verified the email | Google, when you sign in with Google | To create your account and sign you in |
| Session records: when a session started and when it expires | Created by OpenCards | To keep you signed in |
| Workspace memberships and roles | Created when you join or create a workspace | To decide what you can see and do |
| Invitations: the invited email address and who invited them | Entered by a workspace member | To let the invited person join |
| Connected clients (AI assistants and other MCP clients, CI tokens you create): which client, when connected, when revoked | Created when you connect a client or create a token | To let the client act on your behalf, and to let you revoke it |
| Your email address in run history ("who recorded this result", including "via <client>") | Created when you or your client record a test result | So your team can see who did what |
| The time you last signed in, and the version of the Terms you accepted and when | Created by OpenCards | Security, and a record of acceptance |
| Administrative actions taken by the operator (for example, suspending a workspace), with the operator's email | Created by OpenCards | Accountability and security |
| Your IP address | Your browser or client | Rate limiting against abuse: held in memory for at most 60 seconds, never written to disk. Cloudflare also sees it (section 6) |
We do not ask for, and you should not put into OpenCards, special categories of personal data (health, religion, political opinions, biometric data and the like).
4. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service: sign-in, workspaces, runs, connected clients | Performance of our contract with you (the Terms); Law of Ukraine "On Personal Data Protection", Art. 11(1)(3); GDPR Art. 6(1)(b) |
| Security: rate limiting, abuse prevention, the admin audit log, keeping backups | Our legitimate interest in a secure, available service; Art. 11(1)(6); GDPR Art. 6(1)(f) |
| Complying with the law, and establishing or defending legal claims | Legal obligation; Art. 11(1)(5); GDPR Art. 6(1)(c) |
We do not use your data for advertising, we do not sell it, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. How long we keep it
| Data | Kept for |
|---|---|
| Your account | Until you or a workspace administrator asks us to delete it. Inactive accounts are kept. |
| Sessions | 30 days from last use, then deleted |
| Connected-client authorisation codes | Until used, or 60 seconds |
| Connected-client access tokens | 1 hour; refresh tokens 30 days. Tokens of a revoked connection are deleted after 30 days |
| Revoked client connections | 90 days after revocation |
| Invitations | Until accepted, or 7 days |
| Record of your Terms acceptance | As long as your account exists |
| Workspace content | As long as the workspace exists. A deleted organisation is hidden from everyone at once and kept for up to 30 days, during which we can restore it at an owner's request; a personal workspace is deleted at once, with its account |
| Server logs | Rotated: at most about 50 MB per service, typically a few days to weeks |
| Database backups | 14 days. Our hosting provider additionally keeps whole-server snapshots for up to 4 weeks |
| IP addresses for rate limiting | At most 60 seconds, in memory only |
When we delete your account, your email address in run history is replaced with a pseudonym so that your team's test history stays intact without identifying you. Deleted data disappears from backups when those backups expire.
6. Who receives your data
We use the following service providers (sub-processors). Each processes data only to provide its service to us.
| Provider | What it does | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| DigitalOcean, LLC | Hosts the server and database | Everything in section 3 | Frankfurt, Germany (EU) | EU data centre; DigitalOcean DPA |
| Cloudflare, Inc. | DNS, encrypted network tunnel to our server, protection against attacks | IP address, request metadata, and the traffic passing through (encrypted in transit) | Global network; US company | EU–US Data Privacy Framework; Standard Contractual Clauses |
| Google LLC | "Sign in with Google" | Your Google identity during sign-in | United States | EU–US Data Privacy Framework |
The list is also published at /subprocessors. We add a provider to the list before it receives any personal data.
Your data is transferred from Ukraine to these providers because it is necessary to perform our contract with you (Law of Ukraine "On Personal Data Protection", Art. 29). We may also disclose data when the law requires it, for example on a binding request from a Ukrainian court or authority.
AI assistants and other clients you connect. OpenCards can be used through AI assistants such as Claude Code, Claude Desktop or other MCP clients, and through CI tools, that you choose to connect. When you connect a client, it receives the workspace data its requests return. What that client and its provider do with the data is governed by their own terms and privacy policy, not by ours: they act as a separate controller, and we are not responsible for them. Connect only clients you trust, and revoke access in OpenCards when you no longer need it.
7. Cookies
OpenCards sets only cookies that are strictly necessary for the service, or that remember a choice you made. There are no analytics, advertising or tracking cookies, so we do not show a cookie banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
opencards_sid | Keeps you signed in | The cookie lasts up to 400 days, but the session behind it expires after 30 days without use |
opencards_oauth | Protects the "Sign in with Google" step against forgery | 10 minutes, sent only to sign-in addresses |
opencards_admin_session | Keeps the operator's administrators signed in to the admin console (not set for other users) | As opencards_sid |
opencards_theme | Remembers your light or dark theme, if you choose one | 1 year |
Older cookie names starting with proba_ may be removed from your browser; OpenCards no longer sets them.
8. Your rights
Under the Law of Ukraine "On Personal Data Protection" (Art. 8) and, where it applies to you, the GDPR, you have the right to:
- know what data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- object to or restrict processing based on our legitimate interest;
- receive your data in a machine-readable format (portability);
- withdraw any consent you gave (we do not currently rely on consent);
- complain to a supervisory authority.
To use these rights, email [email protected] from the address on your account. We answer within 30 days. We may ask you to confirm your identity. For data inside a workspace, we will pass your request to the organisation that owns the workspace and help it respond.
You can complain to the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини, ombudsman.gov.ua). If you live in the EU or EEA, you can also complain to the data protection authority in your country.
9. Security
Traffic is encrypted (HTTPS). The application is not directly reachable from the internet: it is reached only through an encrypted tunnel. Session and access tokens are random and stored only as hashes. Access to production systems is limited to the operator.
If a personal data breach affects you and is likely to put your rights at high risk, we will tell you without undue delay.
10. Age
OpenCards is a tool for professional use and is not intended for people under 16.
11. Changes to this policy
Each version is published with its date, and previous versions remain available at /privacy/<date>. If we make a material change, we will show it to you the next time you sign in.
12. Contact
ФОП Войтович Ростислав Владиславович — [email protected]