Privacy Policy
openchair (the "Service") is a community-based research platform about reclined working environments. This policy explains what personal data we collect, why, how long we keep it, and what rights you have.
1. What we collect
1.1 When you sign in with Google / YouTube
Sign-in is available only through Google OAuth. When you sign in we receive and store:
- Your Google account identifier (sub), email address, display name and profile picture URL.
- Your YouTube channel, via the
youtube.readonlyscope: channel ID, channel title, handle (@…) and thumbnail URL. If you have no channel or decline the scope you can still sign in; these fields stay empty.
We do not store YouTube access tokens. The token is used once, during sign-in, to look up your channel and is then discarded. We do not request refresh tokens (offline access). Your channel details are re-fetched and refreshed each time you sign in.
1.2 Data created while you use the Service
- Posts and comments you write, with creation and edit timestamps.
- A session cookie (
oc_session, keeps you signed in for 30 days) and a short-lived cookie used only during the sign-in handshake (oc_oauth, 10 minutes). - Standard request logs kept by our hosting provider, Cloudflare (IP address, user agent, path, time). We run no analytics or advertising trackers.
2. Why we use it
- To identify you and keep you signed in.
- To attribute posts and comments to you (name, or your YouTube handle and thumbnail).
- To run the community: spam and abuse handling, and determining administrator rights.
- To keep the Service reliable and diagnose failures.
3. How long we keep it
- Account data: until you ask us to delete it.
- Posts and comments: hidden immediately when you delete them; kept internally for a retention window so reply threads keep their shape, then purged. Deleted together with your account on request.
- Sessions: removed at expiry (30 days) or when you log out.
- Infrastructure logs: per Cloudflare's retention (a matter of days).
4. Third parties
We never sell personal data. The following providers process data on our behalf to run the Service:
- Google LLC — authentication and channel lookup through the YouTube Data API. This Service uses YouTube API Services. By signing in you also agree to the YouTube Terms of Service; Google's handling of your data is governed by the Google Privacy Policy.
- Cloudflare, Inc. — hosting, database (D1) and request logs.
- YouTube embeds — videos in posts are embedded from
youtube-nocookie.com; YouTube may set its own cookies and process data when you play a video.
5. Your rights
- You can ask to access, correct or delete your data, or delete your account, at the contact below. We act without undue delay.
- You can revoke this Service's access to your Google / YouTube data at any time in your Google account security settings. After revocation we fetch nothing new; data already stored is deleted on request.
- You can block cookies in your browser, but you will not stay signed in.
6. Children
The Service is not directed at children under 14 and we do not knowingly collect their data.
7. Security
All traffic is encrypted with HTTPS. Session cookies are HttpOnly, Secure and SameSite. Administrator rights are granted only to designated accounts.
8. Changes
Changes are posted on this page with a new effective date. Material changes are announced within the Service.
9. Contact
Data controller: the openchair operator · support@openchair.tech
개인정보처리방침 (한국어 요약)
시행일 2026-09-16. 위 영어 본문이 정본이며, 이 요약은 편의를 위한 것입니다.
수집 항목. 로그인은 Google OAuth로만 이루어집니다. Google 계정 식별자·이메일·표시 이름·프로필 사진 URL과, youtube.readonly 범위를 통한 YouTube 채널 ID·이름·핸들·썸네일 URL을 저장합니다. 채널이 없거나 권한을 거부해도 로그인은 가능합니다. YouTube 액세스 토큰은 저장하지 않으며 새로고침 토큰도 요청하지 않습니다. 그 밖에 작성한 글·댓글, 세션 쿠키(30일), Cloudflare의 기본 요청 로그를 보관합니다. 분석·광고 추적 도구는 쓰지 않습니다.
이용 목적. 회원 식별과 로그인 유지, 글·댓글 작성자 표시, 커뮤니티 운영, 서비스 안정성 확보.
제3자. Google LLC(인증, YouTube Data API), Cloudflare, Inc.(호스팅·DB·로그), YouTube 임베드(youtube-nocookie.com). 서비스는 YouTube API 서비스를 사용하며 로그인 시 YouTube 서비스 약관에도 동의하게 됩니다. Google의 처리는 Google 개인정보처리방침을 따릅니다. 개인정보를 판매하지 않습니다.
이용자의 권리. 열람·정정·삭제와 계정 삭제는 support@openchair.tech로 요청할 수 있습니다. Google/YouTube 접근 권한은 Google 계정 보안 설정에서 언제든 철회할 수 있습니다.
보관 기간. 계정 정보는 삭제 요청 시까지, 삭제한 글·댓글은 즉시 숨김 후 일정 기간 뒤 파기, 세션은 30일 만료 또는 로그아웃 시 삭제. 만 14세 미만은 대상이 아닙니다.