Privacy policy

Your data should not become the price of participation.

This policy describes the information OpenSoil currently receives, why it is used, and the choices available to you.

Effective July 31, 2026 · Launch-stage policy

Plain-language summary

OpenSoil uses information to operate accounts, receive private messages, protect the service, and build future soil records you control.

OpenSoil does not currently sell personal information, run behavioral advertising, or store your Google password or Google access tokens. Current form submissions enter a private administrator inbox and are not automatically published.

Information collected

Google account identity

When you sign up or log in with Google, OpenSoil receives a stable Google account identifier, verified email address, display name, and profile image when available. Google handles your password.

Account and session information

OpenSoil stores account creation and update dates, account status, session creation and expiration, recent session activity, IP address, and browser user-agent information used for security and operation. The browser receives a random session cookie; the database stores only a cryptographic hash of that session token.

Messages and support requests

Soil questions, contributor interest, and support forms may include your name, email, subject, message, region, crop, soil context, desired outcome, privacy choice, and other details you submit.

Server and security logs

Hosting and web-server systems may record request time, requested page, response status, IP address, browser information, and errors. These records help operate, diagnose, and protect the service.

How information is used

  • • Create and authenticate your OpenSoil account.
  • • Maintain sessions and protect against misuse.
  • • Receive, review, and respond to private form messages.
  • • Diagnose failures, monitor availability, and improve accessibility.
  • • Enforce community, privacy, and security rules.
  • • Meet legal obligations and investigate credible threats.
  • • Build requested features without silently changing a private submission into a public record.

Cookies and Google authentication

OpenSoil currently uses strictly necessary cookies for Google login flow binding and the OpenSoil session. They are marked Secure and HttpOnly and use SameSite protections. OpenSoil does not use these cookies for advertising. Google’s own services are governed by Google’s policies when you choose to authenticate there.

When information may be shared

Authorized OpenSoil administrators can access account and message information needed to operate the service. Infrastructure providers may process limited information while providing hosting, database, DNS, certificate, or authentication services. Information may also be disclosed when reasonably necessary to comply with law, protect rights and safety, or investigate abuse.

OpenSoil does not currently publish private form submissions or sell personal information. Future public field records will require a deliberate visibility and licensing choice.

Your choices and requests

You may request access, correction, deletion, or clarification about your account or submitted messages through the support page. OpenSoil may ask you to verify control of the associated Google account or email. Some information may be retained when necessary for security, legal compliance, dispute resolution, or preserving the integrity of a record you chose to publish.

Submit a privacy or data request →

Retention and security

Active OpenSoil sessions are designed to expire after 30 days and can be revoked at logout. Other account, message, and operational records are retained while reasonably needed for the purposes described above and while retention procedures are being formalized. OpenSoil uses HTTPS, restricted server access, loopback-only application services, protected secret files, hashed session tokens, rate limits, and database access controls. No online service can promise absolute security.

Children and third-party information

OpenSoil is intended for adults and appropriately supervised educational use. Do not submit a child’s personal information. Do not submit another person’s private information, client records, exact location, or proprietary material unless you are authorized to do so.

Changes and contact

This policy will change as field records, uploads, research collaboration, and analysis features are introduced. Material changes should be dated and explained on this page. Questions and concerns can be submitted through the private support form.

Contact OpenSoil support →