Open Secret Privacy Policy
Effective September 23, 2026
Information We Collect
We collect account information such as email address, username, display name, bio, profile photo, authentication status, settings, subscription status, and security preferences. To protect accounts, test reliability, and prevent abuse, security and audit events may include IP address, approximate network region, user-agent information, request route, response status, timestamps, app version, device locale/time zone, hashed install identifiers, and a hashed device fingerprint. We also collect the posts you save, creation content, captions, comments, connection labels, audio notes, messages, media metadata, reports, blocks, follows, views, saves, shares, forks, exports, passion reactions, Witness history, and recognition milestones.
Sign In With Google
If you choose to sign in with Google, Google shares your name, email address, and profile photo with us after you agree in Google's prompt. We use the email address to find your Open Secret account or create a new one, and we store it with your account. We do not use your Google name or photo on your profile; you choose a username, and you can add a profile photo yourself. We never receive your Google password, and we do not get access to your Gmail, contacts, files, or anything else in your Google account. If an Open Secret account already uses the same email address, signing in with Google opens that account. You can remove Open Secret's access at any time from your Google Account settings under third-party connections.
Messages, Media, And Storage
Profile photos may be public. Audio notes, chat media, post-cache files, Creation artifacts, and video-related media may be stored in private storage and served through short-lived signed URLs when the viewer is allowed to access them. Workshop videos must be shorter than 20 minutes. Chat videos must be smaller than 500 MB and shorter than 30 minutes. We process messages and media to send, display, protect, and enforce safety features such as one-time view, disappearing media, blocking, reporting, and abuse prevention.
How We Use Information
We use information to create and secure accounts, verify email addresses, sync Workshop and Gallery content, render creations and exports, deliver messages, process subscriptions, operate Explore and search, calculate engagement and analytics, personalize the app, send account emails, provide support, detect spam or bots, investigate reports, enforce rules, debug quality issues, measure feature reliability, and maintain service security.
Legal Bases For EEA And UK Users
When GDPR or UK GDPR applies, we process data as needed to perform our contract with you, based on your consent where required, to comply with legal obligations, and for legitimate interests such as security, fraud prevention, service improvement, moderation, analytics, and protecting users. You can withdraw consent where processing depends on consent, but that may limit some features.
Service Providers And Transfers
Open Secret uses these providers to run the service: Supabase (accounts, database, and file storage), Cloudflare (API, edge delivery, and export rendering), Google Cloud (image, audio, and speech analysis that powers Connection suggestions), Resend (account and service email), Google Sign-In (optional sign-in with a Google account), Firebase Cloud Messaging from Google (push notifications), Sentry (crash and error reports), PayPal (subscription payments, paused during the beta), and Stripe (optional identity verification for paid members). When AI-written Connection captions are switched on, short descriptions of the two posts being connected are sent to DeepSeek; that feature is currently off. Your information may be processed in the United States or other countries where these providers operate, with safeguards such as standard contractual clauses used where required by law.
Crash And Error Reports
When the app crashes, freezes, or a request to our servers fails, we send a report to Sentry so we can fix it. Reports include the app version, device model, operating system version, the screen or request involved with identifiers removed, technical error details, and a pseudonymous account ID. They do not include your email, username, messages, media, screenshots, or the content you enter. Crash reports are kept for up to 90 days.
Push Notifications
If you allow notifications, your device gets a push token from Google's Firebase Cloud Messaging, and we store it with your account so we can notify you about comments, replies, Passion, new followers, messages, and collaboration invites. Each notification is delivered through Google and includes the other person's username and a short preview, such as the start of a comment or message. You can turn each type off in Settings, turn notifications off in your phone's settings, or mute a chat. Signing out removes this device's token, and a token that has not been used for 90 days is deleted.
Automated Processing And Analytics
Open Secret may use engagement signals, reports, follows, saves, forks, views, passion reaction degrees, creation metadata, Witness recognition, and security/audit events to rank content, provide creator analytics, recommend or organize content, measure campaign or feature performance, recognize meaningful participation, and detect abuse. Raw IP addresses, raw request logs, and device fingerprint records are restricted for security and operations; advertiser-facing or partner-facing analytics should use aggregated or consent-gated data rather than raw audit records. These systems are used to operate and improve the app; they are not intended to make decisions that produce legal or similarly significant effects without human review.
Witness Recognition
When you meaningfully engage with another person's published creation, Open Secret may privately record the action, when it occurred, the creation's reach and engagement at that time, and how the creation later grows. This supports your private Witness history and recognition milestones such as Early Witness, Rising Signal, and Proven Instinct. Creators and other users cannot access your private Witness history through these features. Historical actions recorded before Witness launched may appear as Witnessed, but are not labeled early because an original metric snapshot was not available.
Your Choices And Controls
You can update profile information, upload or replace your profile photo, adjust privacy settings, block or unblock profiles, make creations private, request password reset emails, manage two-step email verification, delete messages or comments where available, review your private Witness history, and delete your account from the Profile security section.
Retention And Deletion
Your account, profile, saved posts, creations, comments, messages, follows, saves, Passion reactions, Witness history, and uploaded files are kept while your account is active. When you delete your account, these are deleted right away, and your uploaded files are removed from storage within 24 hours. Operational records are kept for no more than 90 days, and after account deletion they are no longer linked to your account. This covers request and security logs (including IP address and device details), sign-in attempts, signup security checks, push notification tokens (90 days after last use), profile-view records, profile-link history, engagement events used for ranking and analytics, bug reports and feedback, moderation reports, privacy request records, billing and subscription records, and crash reports. One-time sign-in codes and passkey challenges are deleted after 1 day. Open items, such as an unresolved report, open feedback, or a privacy request in progress, are kept until they are closed and then deleted 90 days later. Moderation reports under legal or law-enforcement review are kept until that review ends. Deleted data can remain in encrypted database backups for up to 30 days before the backups are overwritten.
GDPR And Privacy Rights
Depending on where you live, you may have the right to access your personal data, get a portable copy, correct it, delete it, restrict or object to how we use it, and withdraw consent. To make a request, open Settings, then Privacy & Legal, then Privacy requests, and choose what you need. Because you are signed in, that confirms the request comes from you. You can also email info@brionnecreations.com from the address on your account; we may ask you to confirm from that address before acting. We confirm every request by email, respond within one month, and if a request is complex we may extend this by up to two further months after telling you why. Requests are free. If you disagree with our answer, you can complain to your local data protection authority.
Security
We use technical and organizational safeguards such as authentication, private buckets, signed URLs, access checks, email verification, and security event logging. No online service can guarantee perfect security, so you should use a strong password and keep your account credentials private.
Contact
Questions about privacy can be sent to info@brionnecreations.com, or made through Privacy requests in Settings.