Privacy notice

What we record when you visit, ask for access or sign in, what sits in your browser, who processes it, and what you can do about it. Short and in plain words, on purpose.

Who we are

The controller is Songbird AI BV, Rue Emile Wittmann 50, 1030 Schaerbeek, Belgium, enterprise and VAT number BE 1033.450.866. open-climate.ai is its trading name.

What our servers record

Every request is logged with your IP address truncated before it is written (the last octet of an IPv4 address, the last 80 bits of an IPv6 address), the route it hit, the time, and the family of your browser. The truncated address is kept as it is: we do not look up a country or a company from it. Searches, downloads, exports and matching jobs are recorded the same way, so we can see which features are used and keep the service up.

Every request also carries a session id: a random identifier created when the page loads, held in the tab's memory and never stored on your device, that ties the requests of a single visit together. It is written to the log whatever you answer to the bar, because it is how one visit is told from another when nothing else identifies you. It is replaced by a new one the moment you answer, so what you did before your answer cannot be joined to what you do afterwards, and it is gone when you close the tab.

Raw events are kept for 90 days. After that they are exported to our own object storage in the EU and deleted from the database. Records that tie events together (an anonymous id, a link to an account) are kept for 13 months after their last activity, then deleted. Daily totals with no id in them are kept indefinitely.

Cookies and local storage

No identifier for your browser is stored until you accept the bar at the bottom of the page. What is stored before that is only what the site needs to work: your theme, your answer to the bar, your sign-in session, one receipt per search so your free searches can be counted, and a few short notes about where you were and what you have already been shown. What is stored, and when:

NameKindWhat it doesLifetime
ocai_themeStrictly necessaryRemembers your light or dark theme choice.1 year
ocai_consentStrictly necessaryRemembers your answer to the bar, so it is not asked again.13 months
portal:search-meterStrictly necessaryCounts the free searches you have used, so your allowance survives a reload. It holds one signed receipt per search: the receipt names the search, not your browser, and carries no search text.2 days
ocai.open-data.credit:Strictly necessaryRemembers that you ticked the credit box before a download, so you are asked once rather than on every file. One entry per account signed in on this browser, holding nothing but the fact that the box was ticked.Until you clear your browser storage
portal:unlocked:Strictly necessaryRemembers that a factor's full values have already been revealed on this tab, so the reveal plays once instead of on every visit. One entry per factor, holding nothing but that fact.Until you close the tab
portal:return-toStrictly necessaryHolds the page you were on when signing in interrupted you, so you land back on it afterwards. Written when you start signing in, and deleted the moment you come back.Until you come back from signing in
portal:oidc-probeStrictly necessaryA one-character test write that checks whether this browser lets us keep you signed in across a reload. It holds nothing about you and is deleted in the same instant it is written.Removed immediately
__Secure-ocai_aid, ocai.aidAnalytics, only after you acceptAn anonymous id that links your visits to each other and, if you sign in, to your account, including after you sign out. Set by the server as a cookie and mirrored in local storage, so a cleared cookie jar does not turn you into a new visitor.13 months
Sign-in sessionStrictly necessaryKeeps you signed in: a cookie on our sign-in server and a browser session entry that ends when you close the tab.Your session

Written by the sign-in library

Signing in itself is handled by an open-source library, oidc-client-ts, which writes two entries of its own under names it chooses. We do not write them, but they are on your machine, so they are listed here too. They are the browser side of the sign-in session above, and they appear only once you start signing in.

NameKindWhat it doesLifetime
oidc.user:<authority>:<client id>Strictly necessaryHolds the tokens that keep you signed in, in the tab's own storage, so reloading the page does not sign you out. The parts in angle brackets are our sign-in server and this site's identifier, which is what you would see in the name.Until you close the tab
oidc.<state id>Strictly necessaryHolds one sign-in attempt while it is under way: the secret that proves the reply belongs to your request, and the page to bring you back to. The library deletes it the moment you come back; an attempt you abandon leaves one behind.Until you come back from signing in

Change your choice

Withdrawing consent stops the analytics id from being set and deletes it from this browser. It does not remove you from our records: we keep one line saying that this browser asked not to be counted, and nothing else. That line is what makes the refusal stick, and it is deleted thirteen months after the last time we saw this browser. What was recorded before your refusal stays counted, and keeps its ids until the following night, when a job clears them, along with the truncated address and the browser family, from every event we still hold. Events leave the database after 90 days, into an archive we keep as files: a month archived after your refusal is written without your ids, your truncated address or your browser family, a month archived before it keeps them, and nothing expires those files on its own, so clearing that copy is something we do by hand if you ask us to. The bar comes back so you can answer again, and accepting again resumes the counting from that moment: the refusal is lifted for this browser and, if you were signed in when you refused, for your account. It does not bring back what has already been cleared.

Analytics

Analytics is first-party and in-house: our own code, on our own servers, feeding our own dashboards. No advertising, no remarketing, no third-party analytics script, no session replay, and no data sold or shared for anyone else's marketing. We count pages, searches, downloads and the steps of a sign-up so we can tell which parts of the site work.

We also record where a visit came from, so we can see whether people reach us through a search engine, a link on LinkedIn, an assistant such as ChatGPT, or a newsletter. Two things are kept. The first is the host name of the referring site, for example www.linkedin.com: never the full address, and never what was searched for. It is part of the page view itself, so it is recorded for every visit, including one that declines analytics storage. The second is the utm_source, utm_medium and utm_campaign parameters that a shared or advertised link sometimes carries; those are kept only for visitors who accept analytics storage or sign in, and only once, as the first campaign we saw. Both describe the link, not the person.

Forms

A form on this site (early access, talk to us, a file to try) stores what you type: your name, work e-mail, company, role, message, and the file if you attached one. We use it to answer you and to judge the fit. A copy reaches us by e-mail through Mailgun EU and is mirrored to our CRM in Notion.

Your e-mail address is also hashed, and that hash, never the address, is what links the form to your anonymous analytics id, so we can see which pages a lead read before writing to us.

Accounts

Sign-in runs on Keycloak, which we host ourselves, so your password never leaves our servers. You can also sign in with Google, in which case Google gives us your e-mail address and name and nothing else. An account record holds your e-mail, display name, API keys, and what the account did: which jobs ran, when, and with which result.

Who else sees it

We use a small number of providers that process data only on our instructions:

  • OVHcloud (France): hosting, database, object storage, backups.
  • Sentry (EU region): error and performance monitoring, configured not to receive personal data.
  • Mailgun EU: transactional and support e-mail.
  • Google Workspace: our own e-mail and documents.
  • Odoo: customer relationship management.
  • Notion: customer relationship management, being retired in favour of Odoo.

Your rights

You can ask for a copy of your personal data, have it corrected or deleted, restrict what we do with it, object to processing based on our legitimate interest, and withdraw consent at any time. We answer within one month and do not ask you to justify a request.

Write to hello@open-climate.ai.

If you think we have got it wrong, you can complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be, or to the authority where you live or work.