PricingBlogFAQ
Sign In

OpenSay Privacy Policy

Last edited: Sep 4, 2026

Comprehensive privacy policy detailing data minimization, zero author tracking, encryption standards, and GDPR compliance. Effective September 4, 2026.

Privacy & Data Protection

OpenSay Global Privacy Policy

Effective Date: September 4, 2026
Policy Version: 3.2 (Enterprise)
Acceptance: Incorporated into Terms of Service
Governance: EU GDPR • UK DPA 2018 • CCPA
Heterodox Ltd., doing business as OpenSay ("OpenSay", "we", "us", or "our"), is dedicated to safeguarding the privacy and psychological safety of users communicating through our workplace platforms. This policy describes how we collect, process, protect, and minimize personal data across our services, website, and bot applications.

Low-Touch SaaS Online Acceptance: OpenSay operates as a modern, low-touch software-as-a-service platform. By purchasing a subscription, activating a trial, or installing the OpenSay application into your workspace, you acknowledge and accept our privacy practices as integrated with our Terms of Service and Data Processing Addendum (DPA).

Executive Privacy Summary (At a Glance)

Privacy Principle Operational Guarantee & Standard Detail Reference
Author Anonymity The identities of authors in anonymous interactions (messages, replies, whispers, votes) are never stored in our databases. We cannot identify who sent what. Section 4.2
Nonce-Salted Cryptographic Hashing Anonymous votes and thread pseudonyms use one-way SHA-256 with random nonces and secret rotating peppers, mathematically neutralizing rainbow table attacks. Section 4.2
Data Minimization We store only the minimal workspace, channel, and user roster metadata strictly required to operate the service. Section 1.2
AI Safety Guardrails AI moderation processes ephemeral text in-flight; prompts and responses are never used to train AI models. AI Usage Policy
Data Ownership Customers retain 100% ownership of their content. We never sell, monetize, or lease customer data. Section 3
Automated Purging All team data is permanently deleted within 14 calendar days following app uninstallation. Section 1.3

1. Information We Collect

OpenSay operates on a strict data minimization principle. Because our core user experience takes place within third-party Chat Platforms (Slack, Microsoft Teams, Google Chat), we store the minimum data required to execute requested actions.

1.1 Web Log Data

When you visit our website at opensay.co, our edge servers may automatically log standard web browser data, including your IP address, browser type and version, referring pages, timestamps, and general location telemetry for security and performance optimization.

1.2 User Profile & Account Data

To enable administrators to log into the OpenSay Dashboard and manage workspace permissions, we receive standard identity metadata via Chat Platform OAuth:

  • User display name and full name
  • Business email address
  • Workspace User ID and avatar URL
  • Workspace domain name and Channel IDs

1.3 Retention Policy & Purge Schedules

  • Active Service Data: Required workspace settings and message metadata are retained while the workspace continues to use OpenSay.
  • Uninstallation Purge: Within fourteen (14) calendar days following the uninstallation of the OpenSay application, all workspace data, cached rosters, and settings are permanently wiped from production databases.
  • Analytics Telemetry: Aggregated, non-identifiable usage statistics are retained for service reliability and system capacity planning.

1.4 Special Categories of Data (Sensitive Data)

OpenSay does not solicit, require, or intentionally process any special categories of personal data (Article 9 GDPR), including genetic, biometric, health, political, or religious data. Users are advised against submitting sensitive personal health or biometric data to anonymous channels.


Under European and UK data protection laws, OpenSay processes Personal Data under the following lawful bases:

  1. Performance of a Contract: Processing is necessary to deliver the anonymous communication, polling, and whistleblower services requested under our Terms of Service and Data Processing Addendum (DPA).
  2. Legitimate Interests: Ensuring platform security, preventing abuse and harassment via automated content moderation, and optimizing application performance.
  3. Compliance with Legal Obligations: Meeting statutory compliance, tax, and accounting requirements.

3. Confidentiality, Security & Ownership of Data

All customer content and personal data processed by OpenSay is confidential:

  • Customer Ownership: You retain 100% ownership of all content, questions, and replies submitted through your workspace.
  • No Data Monetization: OpenSay does not sell, rent, or lease personal information or customer communications to data brokers, advertisers, or third parties.
  • No AI Training: Customer content is never used to train machine learning models.

4. How We Process Anonymous Interactions

4.1 Anonymous Messages, Whispers & Replies

When an author posts an anonymous message or initiates a private whistleblower whisper, OpenSay routes the message into the target channel or secret thread without attaching the author's Slack User ID to the database record of that message. The association between the message and the sender is detached in volatile memory upon delivery.

4.2 Cryptographic Hashing with Random Nonce & Pepper (Rainbow Table Protection)

In order to enforce one-vote-per-person in anonymous polls, record karma ratings, and maintain consistent thread pseudonyms (such as OP, R1, R2) without storing identifiable user IDs, OpenSay utilizes one-way cryptographic hashing reinforced by per-interaction random nonces and secret rotating peppers:

  • Nonce & Pepper Combination: Every hash input incorporates the user ID combined with unique, unpredictable per-interaction nonces (such as thread timestamps, poll identifiers, or random salts) alongside an external 256-bit cryptographic pepper: sha256(interactionNonce || userId || secretPepper).
  • Immunity to Rainbow Table Attacks: Because Slack user IDs follow predictable structural formats, a bare hash could theoretically be susceptible to precomputed dictionary lookups. The mandatory injection of random interaction nonces and a segregated 256-bit pepper mathematically invalidates precomputed dictionary attacks and rainbow table lookups, preventing an adversary from dehashing or deanonymizing user IDs.
  • External Secret Segregation: The secret pepper is stored securely as a Cloudflare Worker runtime secret and is strictly segregated from the application database. Historical peppers are permanently purged upon scheduled weekly rotation.
  • Forward Privacy: Even in the theoretical event of a full database compromise, the pseudonymized hashes cannot be reversed or correlated across interactions back to individual users.

4.3 Zero Access to Private Channels

By design, OpenSay cannot read messages in any channel or conversation where the bot has not been explicitly invited. We do not access customer files, attachments, or background team conversations.


5. Third-Party Subprocessors & Infrastructure

OpenSay engages a small, audited group of industry-leading infrastructure partners to deliver high-availability cloud hosting, DDoS mitigation, and AI content moderation:

  • Cloud Infrastructure & Storage: Google LLC (Google Cloud Platform & Cloud Firestore, AES-256 encrypted at rest).
  • Edge Routing & Network Security: Cloudflare, Inc. (Global Anycast Edge Network, TLS 1.3, DDoS protection).
  • AI Content Moderation: Cloudflare Workers AI (Meta Llama 3.2 / 3.1 - Default Edge Engine) and Google Gemini 2.5 Flash Lite (Selectable Engine), both operating under Paid Enterprise Tiers with zero model training guarantees.
  • Payment Processing: Paddle Payments Limited (Merchant of Record, PCI-DSS Level 1 compliant).

A complete, live registry with international transfer safeguards is maintained at our Subprocessors Registry.


6. International Data Transfers

OpenSay delivers services using globally distributed, tier-1 cloud infrastructure. Cross-border transfers of Personal Data originating in the European Economic Area (EEA), United Kingdom, or Switzerland are protected by statutory transfer mechanisms:

  1. Standard Contractual Clauses (EU SCCs): Transfers from the EEA are governed by European Commission Decision 2021/914 (Module 2: Controller-to-Processor), incorporated into our Data Processing Addendum (DPA).
  2. UK International Data Transfer Addendum: Transfers subject to UK GDPR are governed by the UK ICO Addendum (Version B1.0).
  3. Data Privacy Framework: Primary U.S. infrastructure providers (Google LLC and Cloudflare, Inc.) are certified under the EU-U.S. Data Privacy Framework (DPF) and the UK Extension to the EU-U.S. DPF.

7. Technical and Organizational Security Measures (TOMs)

OpenSay maintains rigorous organizational and technical safeguards:

  • Encryption in Transit: Strict TLS 1.3 transport encryption enforced on all public web and webhook endpoints.
  • Encryption at Rest: AES-256 encryption across all databases, storage volumes, and backup snapshots.
  • Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) required for internal engineering systems.
  • Vulnerability Management: Automated CI/CD security scanning, dependency vulnerability auditing, and third-party penetration testing.

Full details are available at the OpenSay Security Portal.


8. Your Data Protection Rights

Under applicable data protection legislation (including EU GDPR, UK GDPR, and CCPA), you have the right to:

  • Access & Portability: Request a copy of personal information we hold about you.
  • Rectification: Request correction of any inaccurate or incomplete personal information.
  • Erasure ("Right to be Forgotten"): Request permanent deletion of your personal information.
  • Restriction & Objection: Object to or request restriction of our processing of your personal data.

To exercise any of these rights, or if you have questions regarding this Privacy Policy, please contact our Data Protection Officer:


9. Cookies & Web Analytics

OpenSay uses first-party session cookies and privacy-preserving analytics to understand website performance and improve user onboarding. We do not use third-party advertising cookies or cross-site tracking pixels. You can manage your cookie preferences at any time via your browser settings or our Cookie Policy.