Privacy policy
Your data should not become the price of participation.
This policy describes the information OpenSoil currently receives, why it is used, and the choices available to you.
Effective August 5, 2026 · Launch-stage policy
Plain-language summary
OpenSoil uses information to operate accounts, host discussions, receive private messages, protect the service, and maintain soil-test, field, trial, timeline, method, and tool records you control.
OpenSoil does not currently sell personal information, run behavioral advertising, or store your Google password or Google access tokens. Form messages, question drafts, and field workspace records default to private. Published questions, answers, soil tests, methods, and tool descriptions are shared according to the choices described below.
Information collected
Google account identity
When you sign up or log in with Google, OpenSoil receives a stable Google account identifier, verified email address, display name, and profile image when available. Google handles your password.
Account and session information
OpenSoil stores account creation and update dates, account status, session creation and expiration, recent session activity, IP address, and browser user-agent information used for security and operation. The browser receives a random session cookie; the database stores only a cryptographic hash of that session token.
Community questions and answers
Community records may include question drafts, published questions, answers, replies, field context, evidence labels, citations, confidence statements, conflict disclosures, AI-assistance disclosures, votes, saved questions, reports, moderation actions, and in-service notifications. Votes and saves are associated with your account but are not displayed as a public list of your activity.
Soil-test records and location
A soil-test record may contain its sample name and date, laboratory, method, depth, NPK and micronutrient values and units, region, notes, latitude, longitude, GPS accuracy, optional field link, and your sharing choices. Exact coordinates and private notes are stored separately from public location data. Browser location is requested only after you press the location button and grant permission.
Field workspace records
Private field records may include farm and field names, general region, management system, area, soil series, texture, irrigation, drainage, slope, trial questions and hypotheses, baseline, control, treatments, replication, plot plan, measurements, dates, costs, risks, limitations, observations, measured values, units, methods, sources, and uncertainty notes. Exact field boundaries and uploaded files are not accepted by the current workspace.
Methods and tool registrations
A registration may include name, type, version, instructions, documentation, schemas, runtime, entrypoint, limitations, release notes, source links, visibility, and publication state. Private registrations remain account-scoped. Public registrations are labeled as unreviewed community contributions.
Messages and support requests
Contributor interest, support, and privacy forms may include your name, email, subject, message, region, crop, soil context, desired outcome, privacy choice, and other details you submit.
Server and security logs
Hosting and web-server systems may record request time, requested page, response status, IP address, browser information, and errors. These records help operate, diagnose, and protect the service.
How information is used
- • Create and authenticate your OpenSoil account.
- • Save drafts and operate questions, answers, citations, votes, saved discussions, reports, and notifications.
- • Save, edit, import, export, normalize, and compare your soil-test records.
- • Save and organize private farms, fields, trial plans, generated plots, linked tests, and timeline evidence.
- • Store and display versioned method and tool documentation according to your visibility choice.
- • Share community contributions, soil measurements, identity, and location only at the level you choose.
- • Maintain sessions and protect against misuse.
- • Receive, review, and respond to private form messages.
- • Diagnose failures, monitor availability, and improve accessibility.
- • Enforce community, privacy, and security rules.
- • Meet legal obligations and investigate credible threats.
Product workflow measurement
OpenSoil records a small allowlist of workflow events, such as viewing the importer or public-data hub, completing an upload or public location report, confirming a report, linking a test to a field, adding a timeline event, or completing a comparison. Events contain an event name and time only. For signed-in members, OpenSoil derives a one-way pseudonymous identifier from the internal account identifier so administrators can measure activation and return use without placing names or email addresses in the product-events table. Anonymous events have no actor identifier.
Product events do not accept report contents, filenames, locations, measurements, analytes, notes, IP addresses, or browser fingerprints. A completed public location report records only the event name—not the queried coordinate or returned values. The browser does not send these events when Global Privacy Control or Do Not Track is enabled. OpenSoil uses aggregate event counts to find where workflows fail; it does not use them for advertising.
Your choices and requests
You can edit or close your community questions, keep a draft private, choose anonymous publication, remove a saved question, edit or delete a soil test, and export soil tests from your dashboard. Field workspace and method/tool editing or self-deletion are not yet available; request correction or deletion through support. You may also request access, correction, or deletion of your account, community contribution, or submitted message. OpenSoil may ask you to verify control of the associated Google account or email. Limited moderation, audit, or security information may be retained when necessary for legal compliance, dispute resolution, or abuse prevention.
Submit a privacy or data request →Retention and security
Active OpenSoil sessions are designed to expire after 30 days and can be revoked at logout. Property-free product workflow events are deleted after 13 months. Other account, community, moderation, message, and operational records are retained while reasonably needed for the purposes described above and while retention procedures are being formalized.
When the documented encrypted backup system is enabled, deleted account or report data may remain inside access-restricted disaster-recovery archives for up to 35 days before lifecycle expiration. Backups are not used as a product history or restored to recover one deleted member record; they are accessed only for controlled restoration or disaster recovery, and a recovery must reapply deletions that occurred after the restored recovery point before normal service resumes.
OpenSoil uses HTTPS, restricted server access, loopback-only application services, protected secret files, hashed session tokens, rate limits, database access controls, and tested backup tooling that still requires production configuration. No online service can promise absolute security.
Children and third-party information
OpenSoil is intended for adults and appropriately supervised educational use. Do not submit a child’s personal information. Do not submit another person’s private information, client records, exact location, or proprietary material unless you are authorized to do so.
Laboratory report imports
When you use the laboratory report importer, OpenSoil stores the original PDF or CSV bytes, original filename, media type, file size, SHA-256 integrity hash, validation metadata, extracted draft fields, review warnings, and the account and soil test linked to the report. Source reports and extracted drafts remain private to your authenticated account and are not included in the public soil-test feed.
PDFs and CSVs are limited to 5 MB. OpenSoil performs bounded format checks and screens PDFs for known active-content markers, but this is not a full antivirus scan. CSV extraction is only a draft; you must compare it with the original before confirmation. You can download or delete a report. Deleting it removes the source file and import record but retains any soil test you already confirmed; that soil test can be edited or deleted separately.
Changes and contact
This policy will change as uploads, richer field records, research collaboration, and advanced analysis features are introduced. Material changes should be dated and explained on this page. Questions and concerns can be submitted through the private support form.
Contact OpenSoil support →