Privacy
Openlike exists to move less information, more deliberately.
Effective July 24, 2026
Who's responsible
Openlike is operated by AurumSpire LLC, a Pennsylvania company and the data controller for everything described here. Reach us at support@openlike.app.
What a public page shows
A first name, a note form, and — only if its owner chooses to add one — a photo. No last name, no bio, nothing else. Page photos are served through links that expire within minutes and are tagged so search engines don't index them. A paused page is indistinguishable from one that never existed, photo included.
If you leave a note
What you submit. First name, age, which app, short fields copied from your own dating profile, an optional photo, optional contact, optional email — and, if the page's owner set a verification question, your short answer to it. Your note goes only to the person whose page you used; your contact is shown only if they approve.
Your photo. Downscaled in your browser before upload, stripped of location and camera metadata (EXIF) on our server, stored privately, and visible to exactly one person. It's deleted the moment your note is declined, or when that account is deleted.
The fingerprint. With each note we store a one-way SHA-256 hash of your network and browser details plus a secret. It can't be reversed into your identity. It exists for two things: one note per person, and keeping declines silent and permanent.
Screening. Automated moderation (Llama Guard, running on our hosting provider's AI infrastructure) reads sender-typed fields before the receiver does. A vision model on the same infrastructure looks at any photo you attach; a photo it doesn't clear is shown blurred until the receiver taps to view it. If a note is flagged, we log a category code — never your words, and never the photo itself.
Your email, if you leave one. Used for exactly one message — "you were recognized" — sent through Resend, then deleted. If your note is declined instead, the address is deleted without any email. It's never used for anything else.
If you claim a link
Your account. Email, a password stored only as a modern hash (scrypt) — never plain text — your first name, and the contact line you choose to reveal to approved senders.
Your page photo, if you add one. Optional and off by default. Like every photo we touch, it's stripped of location and camera metadata (EXIF) on upload. Removing it in Settings deletes the file immediately; deleting your account deletes it too.
One cookie. A single session cookie keeps you signed in for up to 30 days. It does nothing else.
Your stats. Page views and note counts are aggregate daily numbers. We don't record who visited your page — no visitor identities, no IP logs, no user agents.
What we never do
No analytics scripts, ad pixels, or third-party trackers — on any page. No selling or renting anyone's information. No logging of note contents. No integration with any dating app. No cookies beyond the one that keeps you signed in.
And a decline sends nothing, ever. A declined sender sees exactly what a still-sealed sender sees.
How long things live
Sessions expire after 30 days, or the moment you log out.
Rate-limit counters hold an IP address briefly for abuse prevention and erase themselves automatically — within roughly an hour for notes, a day for signups.
Bot checks. Signups and note submissions run Cloudflare Turnstile invisibly; its handling is described in Cloudflare's Turnstile Privacy Addendum.
Declined notes. The photo is deleted immediately. The remaining fields are kept, hidden from everyone, for one reason: making the decline silent and permanent requires remembering it. They're erased when the receiver's account is deleted.
Write-in app names survive only as aggregate counts ("12 people typed X"), detached from any note.
Deleting your account is immediate and permanent: your page, your notes, their photos, and your block list all go at once. There is no grace period and no soft copy.
Who touches data
Cloudflare hosts all of Openlike — servers, database, photo storage, the Turnstile bot check, and the AI moderation that screens notes. Data lives on Cloudflare's network, primarily in the United States.
Resend delivers the single optional "you were recognized" email.
Sentry receives server-side error reports so we can fix crashes — scrubbed of URLs, note contents, and user identity before they leave our code.
Your rights
Email support@openlike.app to access, correct, or receive a copy of your data; deletion is self-serve in Settings and needs no email.
If you're in the EEA or UK: we process data to provide the service you asked for (contract), to prevent abuse (legitimate interests), and — for the optional sender email — with your consent, which leaving the field blank withholds. Data is processed in the United States. You can also complain to your local data-protection authority.
California residents can send CCPA requests to the same email. We don't sell personal information, so there's nothing to opt out of.
The fine print
Adults only. Openlike is 18+. Under-18 ages are rejected at the form and at the database, and if we learn we hold a minor's information anyway, we delete it.
Security. Passwords are stored so that nobody — including us — can read them back. Fingerprints can't be reversed into a person. Photos reach exactly one reader. Note contents stay out of every log. No system is perfectly secure, but the less we keep, the less there is to lose.
Changes. Updates are posted here with a new date; material changes get a clear notice on the site.
Privacy questions: support@openlike.app