Privacy policy
Last updated 14 August 2026 - Open Beta.
Open Bracket is a public open beta run by one person. This notice describes the service as it operates today. It will receive focused solicitor review before paid subscriptions are enabled.
Open Beta risk note
Production uses automated encrypted daily backups stored separately in Cloudflare R2, with the 30 most recent backups retained and integrity checks available. This reduces risk but does not promise uninterrupted availability or zero data loss while the beta is still evolving.
Who is responsible
Adam Ashton, operating Open Bracket as an individual, is the data controller. Contact playopenbracket@gmail.com or use the support page for any privacy request.
What is collected and why
- Account and sign-in details. Your email, handle, display name, and sign-in state are needed to create and operate your account. Django receives your password securely in memory and forwards it to Supabase Auth. Open Bracket does not store the password itself; Supabase stores the protected authentication record. We also record the versions of the Terms and Privacy policy you accepted and your confirmation that you are at least 13. We do not collect a date of birth.
- Challenge activity. Attempts, submitted source code, execution results, solve times, streaks, and completion history provide the game, official judging, rankings, and recovery of pending submissions.
- Guest play. A signed cookie links a guest attempt for up to seven days. Code sent for sample verification is processed by the server and Judge0 but is not retained as a guest submission. The browser keeps the editable code locally.
- Abuse prevention. Open Bracket uses a keyed one-way hash of your IP address for short-lived rate-limit counters. The raw IP is not stored in those counters or attached to your profile. Cloudflare Turnstile also processes request and device signals to distinguish people from automated abuse.
- Operational and error data. Minimal product events show whether core journeys work. Sentry receives scrubbed error reports; request bodies, cookies, authorization headers, source code, passwords, and token-shaped fields are removed.
- Billing data. When Open Bracket+ becomes available, Paddle will act as merchant of record. Card details stay with Paddle. Open Bracket stores the customer and subscription references needed to grant access and stop future billing.
Lawful bases
- Contract: account access, challenge play, judging, results, and any subscription you request.
- Legitimate interests: service security, abuse prevention, reliability, debugging, and understanding whether core features work, balanced against the limited data used.
- Legal obligation: billing, tax, dispute, fraud, and rights requests where applicable.
- Consent: only where a future optional feature specifically asks for it. Open Bracket currently sends no marketing email.
Service providers and international transfers
- Railway - application hosting.
- Supabase - database and authentication.
- Judge0 via RapidAPI - isolated code execution and timing.
- Resend - verification and password-reset email.
- Cloudflare - DNS, Turnstile, and encrypted R2 backup storage.
- Sentry - scrubbed error monitoring.
- Paddle - billing when subscriptions are enabled.
Some providers process data outside the UK. Transfers rely on an applicable UK adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum. Contact the controller to ask which safeguard applies to a provider or to request information about it. Data is not sold and there are no advertising or marketing trackers.
How long data is kept
- Account details, official source code, results, and history remain while the account exists, then are deleted through the account deletion flow unless law requires a limited billing record to remain.
- Guest identifiers and unfinished guest attempts expire after seven days.
- Rate-limit counters are automatically deleted after no more than 24 hours and are excluded from backups.
- Encrypted database backups run daily and retain the 30 most recent copies. Deleted live data may therefore remain in a backup for up to about 30 days before automatic expiry.
- Paddle, Sentry, Cloudflare, Railway, Supabase, Resend, and RapidAPI keep provider-side records under their own retention rules and legal duties.
Your rights
UK data protection law may give you rights to access, correct, erase, restrict, object, and receive a portable copy of your personal data. You can delete your account from the Account page. See deleting your data for the backup detail and guest requests. You can also complain to the UK Information Commissioner's Office at ico.org.uk.
Children
Open Bracket is not directed at children and is intended for people aged 13 and over. Account creation requires a confirmation that the user is at least 13. We do not knowingly collect personal data from anyone under 13.
Changes
Material changes will be reflected here with a new updated date, especially before paid subscriptions are enabled.