Privacy

What this site knows about you.

The product handles your code and your prompts. This website holds three things at most: request logs, an account if you sign in, and what you type into its two forms. Each is described below.

What we collect

The one thing serving a website unavoidably collects is request logs: when you load a page, the server receives your IP address, the URL requested, and your browser's self-description, and keeps standard logs of that for a limited time. We use those logs only to serve the site and to defend it against abuse.

Accounts and cookies

Browsing sets no cookies. Signing in with GitHub or Google sets two: a short-lived cookie that protects the sign-in handshake, and a signed session cookie that keeps you signed in for 30 days. Both are HttpOnly and Secure, and neither is used for advertising or tracking. From the provider we receive your name, email, and avatar, and nothing else; no password ever touches this site. The account page shows everything we hold and carries the delete button, which removes your profile and session immediately.

Forms

The session request form stores what you type in it, one request per email address. The review form stores your name, role, email, and the quote; a review is published only after we verify the session it came from, and your email is never published. Submissions caught by the spam trap are discarded, not stored.

Analytics

None run today. The code ships with a switch for Google Analytics and the switch is off. If it ever flips on, this page describes it first, and visitors sending Do Not Track or Global Privacy Control are never measured either way.

Third parties

Cloudflare hosts this site, so the request logs above are processed by Cloudflare on our behalf, and the accounts, sessions, requests, and reviews live in Cloudflare's key-value store. Fonts and every other asset are served from this domain: no font CDNs, no trackers, no embedded widgets. Signing in necessarily tells GitHub or Google that you signed in here, and your avatar on the account page loads from their servers. If you email us, our email provider processes the message the way any mail service does. If you buy seats, payment runs entirely on Stripe: Stripe collects and processes your name, email, and card details under its own privacy policy, and we never see or store your card number.

Email you send us

If you write to hello@opnflr.com, we receive your address and whatever you choose to send. We use it to reply and to arrange early access, we keep it as ordinary correspondence, and we do not sell it or add it to marketing lists. Ask and we will delete the thread.

Where AI is involved

OpenFloor builds AI tooling, so this deserves a plain statement: this website runs no AI. There is no chatbot here, nothing you do on these pages is sent to a model, and we do not use email you send us to train one. Inside the product, agent sessions do involve AI systems reading repository contents; retention and privacy for those raw agent logs is listed on the home page as a decision still open, and the product will carry its own policy before that data is collected from anyone outside the team.

Retention

Sign-in sessions expire after 30 days. Account records, session requests, and reviews stay until deleted: your account by you on the account page, the rest on request.

Your choices

Signing out ends the session; deleting your account removes your profile and session immediately. For a session request, a review, or correspondence you want corrected or deleted, email hello@opnflr.com and we will do it. If the law where you live grants you rights over personal data, the same address is where you exercise them.

Changes

If this site ever starts collecting more than this page describes, this page changes first and the date below moves.

Last updated August 20, 2026. Questions: hello@opnflr.com.