Privacy policy
OpenSoft (opensoft.tools) helps teams find open source alternatives to the SaaS they pay for. This page explains what we collect, why, and what you can ask us to do with it. Last updated 8 October 2026.
The short version
- You can browse the directory and play SaaS Hunt without an account. Your wish list then stays in your browser.
- If you sign up, we keep your email address, your wish list and, if you sign in with Google or GitHub, your name and profile picture.
- We don't sell your data, show ads, or use advertising or analytics trackers.
- Email vaibhav@gridbits.in and we'll send you your data or delete it.
What we collect
When you browse
Our host, Cloudflare, processes the technical details of each request (such as your IP address and browser) to serve the site and protect it from abuse. We don't run analytics or advertising scripts.
The site saves a few things in your browser's local storage so it works without an account: your wish list, whether you've signed in, the team size you picked in SaaS Hunt, and display preferences such as a collapsed sidebar. This stays on your device. Clearing your browser's site data removes it.
When you create an account
- With email and a password: your email address and a one-way hash of your password. We never store the password itself.
- With Google or GitHub: the account ID that Google or GitHub gives us, plus your verified email address, name and profile picture. We ask only for this basic profile (Google:
openid,email,profile; GitHub:read:user,user:email). We can't see your password, your files, your repositories or anything else in those accounts. - Your wish list: the tools you added and the open source alternative and estimated savings for each.
- Sign-in records: a session cookie that keeps you signed in for up to 30 days (we store only a hash of it), and, for 24 hours, the time of any failed password attempt for an email address, so we can block password-guessing.
When you ask for a deployment quote
We collect your name, work email, phone number and the project and tool you asked about. We use them to reply to your request.
Why we use it
- To sign you in, keep your wish list across visits and devices, and keep accounts secure.
- To answer quote requests and provide the deployment help you ask for.
- To run, secure and fix the site.
We don't use your data for advertising and we don't sell or rent it to anyone.
Google user data
When you sign in with Google, we receive your Google account ID, email address, whether Google has verified it, your name and your profile picture. We use them only to create and sign in to your OpenSoft account and to show who is signed in. We don't transfer this data to anyone except as needed to run the service (our hosting provider), to comply with the law, or with your permission. We don't use it for advertising, and we don't let people read it except to provide support you ask for, for security, or to comply with the law.
OpenSoft's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who else handles it
- Cloudflare hosts the site and stores account data in its D1 database.
- Google and GitHub handle sign-in if you choose them. Their own privacy policies apply on their sites.
- Slack receives quote requests in our team's workspace so we can reply to them.
How long we keep it
- Your account and wish list: until you delete your account.
- Sessions: until you sign out, or 30 days at most.
- Failed sign-in attempts: 24 hours.
- Quote requests: as long as we need them to handle your request and follow up.
Your choices and rights
You can ask us to show you the data we hold about you, correct it, export it, or delete your account and wish list. Email vaibhav@gridbits.in from the address on your account. We'll reply within 30 days. Depending on where you live, you may also have the right to object to or restrict how we use your data and to complain to your data protection authority.
You can also disconnect OpenSoft from your account at any time in your Google account settings or your GitHub authorized apps. This doesn't delete your OpenSoft account, so ask us if you want that too.
Security
Connections to the site are encrypted. Passwords are stored only as salted hashes, session tokens only as hashes, and sign-in cookies can't be read by scripts on the page. No system is perfectly secure. If we learn of a breach affecting your data, we'll tell you as the law requires.
Children
OpenSoft is a tool for businesses and isn't meant for children under 16. We don't knowingly collect their data.
Changes
If we change this policy, we'll update the date at the top. If a change is significant, we'll tell signed-in users by email or on the site before it takes effect.
Contact
Questions or requests: vaibhav@gridbits.in.