# Privacy Policy

How Openhandle processes personal data, for customers, and for the public social media data the service provides.

Effective date: September 3, 2026

Openhandle ("we", "us") is a sole proprietorship registered in the Netherlands with the Chamber of Commerce (KvK) under number 89247647, located at Oesterstraat 12, 4691 KT Tholen, the Netherlands, VAT ID NL004708770B55. We are the controller for the personal data described in this policy. Contact: hello@openhandle.dev.

This policy covers two kinds of personal data. Sections 1 to 6 are about data of **our customers**. Section 7 is about **public social media data** that the service reads on behalf of customers.

## 1. Data we process about customers

- **Account data.** Name, email address, and a hashed password. If you sign in with Google, we store your Google account identifier instead of a password. Workspace names and team membership.
- **Billing data.** Our payment processor, Stripe, collects and stores your card details. We store billing status, invoices, spend settings, and usage-based charges. We never store card numbers.
- **API usage data.** For each API request we store operational metadata: the endpoint, timing, result status, the source (live or cache), the request ID, and the charge. We never store the response content in logs or analytics.
- **Connected agents.** If you connect an MCP client such as Claude, ChatGPT, or Cursor, we store the client name, the API key created for it, and the tokens issued to it.
- **Support communication.** Emails you send us.
- **Platform requests.** If you ask us for a new platform or endpoint through the form on the site, we store your email address, what you asked for, the volume you expect, and the use case you describe.
- **Cookies.** A session cookie for dashboard sign-in. We use no advertising or cross-site tracking cookies.

## 2. Purposes and legal bases

| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the API, the MCP server, and the dashboard | Contract (art. 6(1)(b)) |
| Billing and invoicing | Contract; legal obligation (art. 6(1)(c)) |
| Abuse prevention, rate limiting, security | Legitimate interest (art. 6(1)(f)) |
| Product improvement from aggregated usage | Legitimate interest |
| Answering support emails | Contract; legitimate interest |
| Legal and tax record-keeping | Legal obligation |

## 3. Retention

- Account data: for the life of the account. After you delete the account, we delete or anonymize it within 30 days, unless law requires us to keep it longer.
- Request logs: 90 days. After that we keep only aggregated statistics.
- Connected agents: access tokens expire after one hour. Refresh tokens rotate and expire after 30 days. When you disconnect a client in the dashboard, its API key and all its tokens are revoked at once.
- Platform requests: until we build it or you withdraw the request. We review and delete inactive requests after 24 months.
- Invoices and billing records: 7 years, as tax law requires.
- Backups: encrypted, rotated on a fixed schedule.

## 4. Recipients and processors

We share personal data only with processors we need to run the service:

- **Stripe.** payment processing and invoices.
- **Google.** sign-in, if you choose to sign in with Google.
- **Cloud providers.** hosting, databases, encrypted backups, and media delivery.

We do not sell personal data. We do not build advertising profiles. Where a processor is outside the EEA, transfers rely on adequacy decisions or standard contractual clauses.

## 5. Security

Passwords and API key secrets are stored only as hashes. Connected agents sign in through OAuth 2.1 with PKCE. All traffic is encrypted (TLS). Access to production data is restricted and logged.

## 6. Your rights

Under the GDPR you can ask for access, correction, deletion, restriction, and portability of your data. You can object to processing based on legitimate interest. Write to hello@openhandle.dev. You can also file a complaint with your supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.

## 7. Public social media data

The service reads **public** data from public accounts on Instagram, TikTok, and X, on behalf of our customers: profiles, posts, comments, followers, and search results. This data can contain personal data of platform users who are not our customers. The service is read-only. It never likes, follows, posts, comments, or messages on any account. The [public data notice](/legal/public-data-notice) explains this in plain words.

- **What we process.** Only what the platform shows to anyone: public profile fields, public post content and metrics, public comments and their authors, and public follower lists. We do not read private accounts or private content. A request for a private profile returns an error. A number the platform hides is returned as null, never guessed.
- **When we process it.** Only when a customer asks for a specific profile, post, or search. We do not crawl the platforms on our own. We use upstream data providers behind the scenes to read this data.
- **Legal basis.** Legitimate interest (art. 6(1)(f)): giving programmatic access to information the person has made public, for purposes such as analytics, research, and monitoring by our customers. Customers act as independent controllers of the data they retrieve.
- **Cached answers.** We cache answers for up to 31 days so repeat reads are cheaper and faster. After that they expire.
- **Identity history.** We remember which handle belongs to which platform ID, so a rename does not break a reference. That record is an ID and a handle, nothing else. We keep it for one year after we last saw the alias.
- **Media.** We use our own cache and CDN to deliver requested media. We do not keep permanent copies.
- **Request logs.** Operational metadata about each request, such as the endpoint, timing, result, and charge, for 90 days. Never the content.
- **Your rights as a platform user.** If you own an account and do not want it readable through Openhandle, email hello@openhandle.dev with the profile link. The [public data notice](/legal/public-data-notice) has a link that fills in the email for you. The profile goes on a block list. New requests for it return an error and are not billed. Cached answers for it are removed. Cached copies expire within 31 days at most, and we remove them sooner when we process your request. Logs that mention the profile age out within 90 days. To remove data at the source, contact the platform. Content you make private or delete on the platform stops being readable through us.
- **What we do not do.** We do not build advertising profiles. We do not sell datasets. We do not try to identify people or combine data across platforms beyond what a customer asks for in one request.

## 8. Changes

We post changes to this policy here and update the effective date. We announce material changes that affect customers by email or in the dashboard.
