Skip to main content

Privacy Policy

Last updated: August 15, 2026

This policy explains how OpsSeek processes personal data for its accounts, authentication, Operator profiles, private customer project requests and early-access requests.

Who is responsible

The controller responsible for OpsSeek is:

RD Interactive
Rene Dressel
Im Höfchen 2
53809 Ruppichteroth
Germany

Privacy enquiries can be sent to hello@opsseek.com.

Data we process

  • Account data: name, email address, email-verification status, account role and account timestamps.
  • Authentication data: a securely hashed password when password sign-in is used, session identifiers, session expiry, and time-limited verification, password-reset and magic-link records.
  • Security data: IP address and user agent when supplied during a session, rate-limit records, and limited technical server and security logs needed to operate and protect the service.
  • Connected account data: provider, provider account ID, linking status, and basic profile information such as name, email address, verified-email status or profile image when Google or GitHub supplies it through the standard sign-in flow. OpsSeek does not request Google Drive, Gmail or GitHub repository content for sign-in.
  • Project-request data: your name, email address, optional company details, the private brief you submit, budget and timing context, selected skills, links, optional attachments, preferred-Operator context, and first-party source information such as UTM parameters, referrer and landing page.
  • Early-access data: your normalized email address, selected area of interest, confirmation and unsubscribe status, consent version and timestamps, and limited first-party source information such as campaign, referrer and landing page. An early-access request does not create an account or a project brief.

Why we use this data

We use this data to create and secure accounts, verify email addresses, provide password, magic-link, Google and GitHub sign-in, link multiple sign-in methods to one internal user identity, recover accounts, prevent abuse, and respond to support or privacy requests.

If you submit a project request, we use the information to review your needs, identify potentially suitable AI Operators, communicate with you about the request and, if you ask us to proceed, arrange a later introduction. Submitting a request does not create a customer account and does not subscribe you to marketing.

If you separately request early access, we use your confirmed consent to send focused OpsSeek early-access updates and relevant invitations. The request remains pending until you confirm the email link. You can unsubscribe at any time through the link in an early-access message. If the same confirmed email address later submits a project brief, OpsSeek may mark the early-access record as converted for first-party funnel measurement; this does not create or infer a customer identity.

Depending on the context, processing is necessary to provide the service you request, to pursue legitimate interests in reliable and secure service operation, or to meet legal obligations. Where another legal basis is required, we will provide the relevant information at that time.

Cookies and sessions

OpsSeek uses technically necessary cookies for secure sessions and OAuth sign-in state. Production session cookies are protected with Secure and HttpOnly settings where applicable. OpsSeek does not currently use advertising cookies or non-essential analytics cookies.

Email delivery

Verification, password-reset, magic-link, project-request acknowledgement and early-access confirmation messages are sent through OpsSeek's own Mailcow SMTP infrastructure using Nodemailer. The recipient address and message delivery data are processed for that purpose. Sign-in links are time-limited and must be kept confidential.

Google and GitHub sign-in

If you choose Google or GitHub, that provider authenticates you and sends OpsSeek the account information permitted by the sign-in request. The provider processes data under its own terms and privacy policy. You can review the Google Privacy Policy and the GitHub Privacy Statement. OpsSeek does not automatically merge accounts based on similar profile details. Additional sign-in methods must be securely connected to the same internal user identity.

Storage and recipients

Account, authentication and project-request data are stored in OpsSeek's self-hosted PostgreSQL database. The application is deployed on infrastructure managed through Coolify, and authentication email is delivered through self-hosted Mailcow infrastructure. Optional project attachments are stored in OpsSeek's private, S3-compatible Garage storage and are accessible only through authorized administrative access. Data is disclosed only where needed to operate these services, when you choose an OAuth provider, or where required by law.

Retention

Account data is generally retained while the account is active. Sessions and verification records are retained until they expire, are used or are revoked, subject to routine technical cleanup. Rate-limit and operational log data is retained only as long as reasonably needed for security and reliable operation. Exact retention periods are still being finalized. Project requests and their attachments are retained while needed to handle the enquiry, maintain the marketplace record and meet applicable obligations; an exact project-request retention schedule is still being finalized. Pending and confirmed early-access records are retained while needed to administer the early-access programme, document consent and measure conversion. Unsubscribed status may be retained where necessary to honor the opt-out and demonstrate the request history. Some information may need to be retained longer to meet legal obligations or resolve security incidents.

Security

OpsSeek uses measures including encrypted HTTPS transport, securely hashed passwords and one-time links, protected session cookies, server-side access checks, rate limiting, restricted account linking and data minimisation. No online service can guarantee absolute security.

Your rights

Subject to applicable law, you may have rights to access, correct, erase, restrict or object to processing of your personal data, receive portable data, and complain to a competent data-protection authority. Contact hello@opsseek.com to make a request. We may need to verify your identity before acting on it.

Changes to this policy

We may update this policy as OpsSeek changes or legal requirements develop. The date at the top identifies the current version.