Privacy Policy
Last updated: May 27, 2026
OpenBinary is an independent security research project. This policy describes what data we collect, how we use it, and your rights.
1. What We Collect
Automatically collected
- Usage analytics — page views, search queries, and interaction events via Tell (our analytics provider). This includes your IP address, browser type, and referring URL.
- Server logs — IP address, request path, timestamp, and user agent for API requests. Retained for up to 90 days.
Account information
- Authentication — creating an account or joining a workspace uses WorkOS Magic Auth (passwordless email sign-in), which collects your email address. We store your email, workspace memberships, and any API keys you generate. We do not store passwords.
Uploaded content
- Binaries — when you upload a binary, we store it for analysis. Binaries are stored by content hash (SHA-256). Identical binaries uploaded by different users are stored once.
- Analysis results — metadata, capabilities, and behavioral analysis derived from uploaded binaries; metadata-level results may be displayed in the public corpus. Decompilation and source reconstruction are produced only when a user initiates them, and access to that output is gated behind authenticated, paid tiers — not displayed publicly.
What we do NOT collect
- We do not store passwords — sign-in is passwordless (email magic-link)
- We do not use advertising trackers or sell data to third parties
2. How We Use Your Data
- To operate and improve the Service
- To perform binary analysis and display results
- To understand usage patterns and improve search quality
- To detect and prevent abuse
3. Data Sharing
We do not sell your personal data. We may share data with:
- Tell (analytics) — anonymized usage events
- WorkOS (authentication) — your email address, to operate passwordless sign-in
- Hosting providers — server infrastructure necessary to operate the Service
- Law enforcement — only when required by valid legal process
4. Data Retention
- Server logs: up to 90 days
- Analytics data: per Tell's retention policy
- Uploaded binaries and analysis: retained indefinitely unless removed via DMCA takedown or at our discretion
5. Cookies
The Service uses minimal cookies for analytics and functionality. We do not use advertising or tracking cookies. You can disable cookies in your browser settings, though some features may not work as expected.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request deletion of your personal data
- Opt out of analytics tracking
- Request removal of analysis results for binaries you own
To exercise these rights, contact privacy@openbinary.org.
7. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from children.
8. Changes
We may update this policy at any time. Changes take effect when posted. Material changes will be noted by updating the "Last updated" date.
9. Contact
Privacy questions: privacy@openbinary.org