Privacy Policy
LAST UPDATED 10 AUGUST 2026
This policy describes what Ownora collects and what it deliberately does not. It is written to match how the software actually behaves, not as a generic template.
What we collect
When you create an account
- Your email address, so we can verify you are a distinct person and send account email.
- Your name and chosen handle, which appear publicly on the ideas you post.
- Your password, stored only as an Argon2id hash. We cannot read it, and we cannot recover it for you.
- Optionally, a bio, country and city. Your city is hidden unless you explicitly make it public.
When you use the site
- The ideas you post and their content. Published ideas are public; drafts are visible only to you.
- Which ideas you expressed interest in or joined.
- A record of sensitive account actions in an append-only audit log, which cannot be edited or deleted afterwards.
What we deliberately do not store
- Your IP address. IP addresses are hashed with a keyed HMAC the moment they arrive and the original is discarded. The hash lets us detect abuse patterns; it cannot be reversed into an address.
- Your email address in our email delivery records. Those store a hash of the recipient, not the address itself.
- Usable session or reset tokens. Only hashes are stored, so a database leak yields no working login or reset link.
- Payment details. Ownora takes no payments at all in its current form.
What other people can see
Your name, handle, bio and published ideas are public. Your email address is never shown to anyone.
Interest is aggregate only. When you say you want an idea, others see the count increase — nobody, including the idea's creator, sees that it was you. What software a business needs can reveal a great deal about how it operates, so we treat it as commercially sensitive by default.
Joining is different. Joining a project is a public act within that project: the creator can see who joined, because joining means asking to be involved.
Analytics
If analytics are enabled on this deployment we use Google Analytics 4 to count page views and key actions such as sign-ups. We do not send your email address, name, or the content of anything you post. Search terms are not sent as free text.
We send transactional email only — address verification, password resets, and notifications about your own projects. There is no marketing list. Delivery is handled by Resend, who process the message in order to deliver it.
How long we keep things
- Sessions expire after 30 days, or 7 days of inactivity.
- Verification and password reset links expire within 24 hours and work once.
- Account data is kept until you delete your account.
- Audit log entries are retained after deletion, without identifying content. That log exists to make sensitive actions reviewable, so it cannot be selectively rewritten.
Deleting your account
You can delete your account from your settings. Your profile is anonymised in place: your email, name, bio and handle are removed. Ideas you published stay up, attributed to a deleted user, because other people registered interest in them and removing them would silently change a number other people are relying on.
If you want an idea gone as well, archive it before deleting your account, or contact us.
Your rights
Depending on where you live you may have the right to access, correct, export, or erase your personal data, and to object to some processing. Contact us and we will action it. We will not make you jump through hoops for it.
Children
Ownora is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If this policy changes materially we will say so on the site rather than quietly updating the date at the top.
Contact
Questions about any of this: get in touch.