OpenIssuesSign in

Privacy Policy

Last updated 10 August 2026

OpenIssues collects bug reports and feedback through shareable links. This policy explains what we store when you report an issue or run a workspace, why we store it, and how long it stays.

1. Data controller

The controller of your personal data is Shortcodes Roman Szymański, VAT ID 8871788633, ul. Okrzei 28, 55-080 Kąty Wrocławskie, Poland.

For anything related to this policy or your data, write to roman.szymanski@shortcodes.pl. We have not appointed a Data Protection Officer — the law does not require us to — so data questions come straight to us at that address.

2. Data we collect

Account data

Your email address, a display name, and the timestamp of your email verification. OpenIssues is passwordless — we never ask for, and never store, a password. If you register a passkey, we store its public credential, never a private key. If you invite someone to a workspace, we store the email address you enter until they join or the invitation is withdrawn.

Content you submit

Issue titles, markdown descriptions, comments, and any images or files you upload. Anything you write into an issue is data you choose to give us — please don't put sensitive personal data into a bug report. When you submit through a submission link, your report — its content, and the email address and name on your account — becomes visible to the owner of that workspace and to the members of the project it lands in, and the owner receives an email notification. That is the whole point of the link, but it means the people on the other side see what you send.

Technical data

Session records containing your IP address and browser user agent, kept so we can keep you signed in and detect abuse, plus standard server logs. We also record product events (a form was opened, an issue was submitted, a sign-in link was sent or used) to measure whether the product works. Those records are pseudonymous: they hold an account or record id and a hashed link token — never message content, and never your email address.

3. Legal basis for processing

Contract (Art. 6(1)(b) GDPR) — running your workspace and handling your submissions: storing your issues, routing them to the right project, and sending the notifications the service is built on. This is also why we create your account. When you report an issue through someone's submission link, you give your email address and confirm that an account linked to it is created for you — that account is what lets you open your issue later, follow its status, and reply. It is a step taken at your request to deliver the service, not something we do on the side, so we rely on the contract basis rather than on consent. We record the moment you confirmed it so both sides have a trail. Providing your email is optional, but without it we cannot create the account or give you a way back to your submission.

Legitimate interest (Art. 6(1)(f) GDPR) — keeping the service secure and available: rate limiting, anti-spam protections on public forms, and diagnosing failures.

Consent (Art. 6(1)(a) GDPR) — we rely on consent only for things that are genuinely optional and that we would ask about separately. Today the service sets no optional cookies and sends no marketing, so consent is not a basis for the core service; if that ever changes, we will ask you first, and you will be able to withdraw at any time without affecting the rest of the service.

4. How we use your data

  • Authenticating you — sending single-use sign-in links to your email address and, if you set one up, verifying your passkey.
  • Delivering the service — storing issues, comments and attachments, and showing them to the people authorised in the relevant project.
  • Notifying the right people by email when an issue arrives or someone replies.
  • Protecting the service — throttling requests, blocking abuse of public submission links, and investigating incidents.
  • Understanding product usage in aggregate, through the pseudonymous event records described above.

We do not profile you, we do not run advertising, and we do not sell or share your data with anyone for their own purposes.

5. How long we keep it

  • Sign-in links — valid for 15 minutes and usable once; the record is marked as consumed and expires on its own.
  • Unconfirmed submissions — if you start a report through a public link but never confirm it by email, the draft and the email address attached to it are deleted after 7 days by an automatic daily clean-up.
  • Orphaned uploads — images and files that end up attached to no issue are deleted, including the stored object, after 8 days.
  • Account and content — kept while your account exists. Deleting your account removes it, together with the issues, comments and uploads tied to it.
  • Product events — the pseudonymous records described above outlive the account they reference. They carry no email address and no content, and once the account is gone the id they hold no longer resolves to anyone.
  • Session and log records — a session expires after a period of inactivity (a couple of hours by default) and is then discarded; server logs are kept only as long as we need them to investigate problems and are rotated regularly.

6. Your rights under the GDPR

You have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing;
  • receive your data in a portable format;
  • withdraw a consent you gave, without affecting what happened before you withdrew it;
  • lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO).

You can delete your account yourself from the account settings in the app, and you can pull your issues, comments and projects out as JSON at any time through the REST API or over MCP. For anything else, email roman.szymanski@shortcodes.pl and we will respond within one month.

7. Security

Access is passwordless by design: there is no password to leak or reuse. Every issue lives behind authentication, and access is checked per record — not by an unguessable URL. Uploaded images and attachments are stored in a private bucket and served only through an access-checked route, never a public URL. All traffic is served over TLS.

8. Who is the controller of your data

For your account and how you sign in — your email address, display name, passkey, sessions — Shortcodes Roman Szymański is the data controller.

For the content of a report you submit through someone else's workspace, the person or organisation running that workspace decides what happens with it: they are the controller of that content, and OpenIssues stores and processes it on their behalf, as their processor under a data processing agreement. If you want a submission you made to a third party's workspace corrected or erased there, reach out to that workspace owner; we will act on their instructions. For your own account and the issues in your own personal projects, Shortcodes Roman Szymański is the controller and you can reach us directly.

9. Who processes data on our behalf

We keep the list of processors short, and all of them operate within the European Union:

  • Mailgun (EU region) — delivery of sign-in links and notification emails.
  • An EU-based S3-compatible object storage provider — storage of uploaded images and attachments.
  • OVH — hosting of the application and database.

They act on our instructions only, under data processing agreements. We do not pass your data to anyone else, except where the law requires it.

10. International transfers

Your data is stored and processed in the European Union. We do not transfer it outside the European Economic Area.

11. Cookies

OpenIssues sets a small number of cookies to keep you signed in, protect forms against cross-site request forgery, and remember interface preferences such as your theme. We set no analytics, advertising or third-party tracking cookies. The details are in the Cookie Policy.

12. Changes to this policy

If we change how we handle your data, we update this page and the date at the top. Material changes are communicated by email to registered users.

13. Contact

Shortcodes Roman Szymański, ul. Okrzei 28, 55-080 Kąty Wrocławskie, Poland — roman.szymanski@shortcodes.pl.

>_ ready

Start collecting issues in the next two minutes

Sign in with an email link — we don't do passwords either.

Start collecting issues
OpenIssues

Lightweight issue collection — one link for the people reporting, MCP for your agent.

Product

How it worksMCP for agentsFAQ

Legal

PrivacyTermsCookies
>openissues— collect · resolve · ship

© 2026 OpenIssues · Updated August 2026 · beta