Privacy Policy
Last updated: August 14, 2026
This policy explains how OpsSeek processes personal data for its current account, authentication and account-security features.
Who is responsible
The controller responsible for OpsSeek is:
RD InteractiveRene Dressel
Im Höfchen 2
53809 Ruppichteroth
Germany
Privacy enquiries can be sent to hello@opsseek.com.
Data we process
- Account data: name, email address, email-verification status, account role and account timestamps.
- Authentication data: a securely hashed password when password sign-in is used, session identifiers, session expiry, and time-limited verification, password-reset and magic-link records.
- Security data: IP address and user agent when supplied during a session, rate-limit records, and limited technical server and security logs needed to operate and protect the service.
- Connected account data: provider, provider account ID, linking status, and basic profile information such as name, email address, verified-email status or profile image when Google or GitHub supplies it through the standard sign-in flow. OpsSeek does not request Google Drive, Gmail or GitHub repository content for sign-in.
Why we use this data
We use this data to create and secure accounts, verify email addresses, provide password, magic-link, Google and GitHub sign-in, link multiple sign-in methods to one internal user identity, recover accounts, prevent abuse, and respond to support or privacy requests.
Depending on the context, processing is necessary to provide the service you request, to pursue legitimate interests in reliable and secure service operation, or to meet legal obligations. Where another legal basis is required, we will provide the relevant information at that time.
Cookies and sessions
OpsSeek uses technically necessary cookies for secure sessions and OAuth sign-in state. Production session cookies are protected with Secure and HttpOnly settings where applicable. OpsSeek does not currently use advertising cookies or non-essential analytics cookies.
Email delivery
Verification, password-reset and magic-link messages are sent through OpsSeek's own Mailcow SMTP infrastructure using Nodemailer. The recipient address and message delivery data are processed for that purpose. Sign-in links are time-limited and must be kept confidential.
Google and GitHub sign-in
If you choose Google or GitHub, that provider authenticates you and sends OpsSeek the account information permitted by the sign-in request. The provider processes data under its own terms and privacy policy. You can review the Google Privacy Policy and the GitHub Privacy Statement. OpsSeek does not automatically merge accounts based on similar profile details. Additional sign-in methods must be securely connected to the same internal user identity.
Storage and recipients
Account and authentication data are stored in OpsSeek's self-hosted PostgreSQL database. The application is deployed on infrastructure managed through Coolify, and authentication email is delivered through self-hosted Mailcow infrastructure. Data is disclosed only where needed to operate these services, when you choose an OAuth provider, or where required by law.
Retention
Account data is generally retained while the account is active. Sessions and verification records are retained until they expire, are used or are revoked, subject to routine technical cleanup. Rate-limit and operational log data is retained only as long as reasonably needed for security and reliable operation. Exact retention periods are still being finalized. Some information may need to be retained longer to meet legal obligations or resolve security incidents.
Security
OpsSeek uses measures including encrypted HTTPS transport, securely hashed passwords and one-time links, protected session cookies, server-side access checks, rate limiting, restricted account linking and data minimisation. No online service can guarantee absolute security.
Your rights
Subject to applicable law, you may have rights to access, correct, erase, restrict or object to processing of your personal data, receive portable data, and complain to a competent data-protection authority. Contact hello@opsseek.com to make a request. We may need to verify your identity before acting on it.
Changes to this policy
We may update this policy as OpsSeek changes or legal requirements develop. The date at the top identifies the current version.