Privacy Policy
Last updated: August 10, 2026
open-record.org helps people request, organize, and understand personal records. We collect only the information needed to operate the service, respond to requests, and maintain account security.
Information We Process
We may process contact details, request metadata, user-provided files or messages, authentication records, and operational logs needed to provide and secure the service.
How We Use Information
We use information to provide user-directed record request workflows, send authorized messages, maintain security, debug reliability issues, and comply with legal obligations.
Subprocessors
These are every third party that processes personal information on our behalf, what they do, and where your data physically sits. Your data is stored in the European Union. Several of these companies are US-incorporated, which is a separate question from where the data lives — we name both.
| Subprocessor | What it does | Where your data sits |
|---|---|---|
| Cloudflare (US) | Application hosting, request routing, database connection pooling, and the private object storage holding your uploads and the files controllers send back. Cloudflare Email Service is staged but is not active for live user email while its message- processing location remains under review. | Stored files: European Union (R2 EU jurisdiction). Application traffic is processed on Cloudflare's network. Live email remains on Mailgun EU until the Cloudflare email review is resolved. |
| Neon (US) | The database: your account, the organizations you trace, the requests we send for you, and their replies | Frankfurt, Germany |
| Mailgun (US) | Sending your data requests and receiving the replies, including any attachments controllers send | European Union (Mailgun EU region) |
| OpenAI (US) | Reading fields off an identity document, only if you upload one (see below) | United States |
You do not need to connect a mailbox to keep a request current. If a data holder contacts you directly, you can record only the date, channel, and broad response type. We label that as information you reported—not as a message open-record.org independently observed. You may separately choose to forward or upload relevant evidence.
The optional identity-document extraction described below is an explicit transfer to OpenAI in the United States. We do not activate a new email-processing path until its processing locations and safeguards are documented here.
Identity Document Processing
If you upload an identity document, the image is stored in private, EU-resident object storage and is sent once to OpenAI (a US-based subprocessor) to extract document fields such as name and expiry date. The extraction result only assists a manual review by the open-record.org operator — verification decisions are always made by a person. Every access to your identity document is logged, raw images are deleted on a fixed retention schedule (90 days after verification, 7 days after rejection), and you can request earlier deletion at any time.
Your Choices
You can contact us to request access, correction, deletion, or export of personal information associated with your use of open-record.org.
Contact
For privacy questions, contact alberto@open-record.org.