Privacy
Privacy Policy
OpenSourcesAI is a developer-first project. We keep data collection limited to basic site operation, analytics, voluntary forms, optional email updates, and browser demo functionality.
This policy covers the OpenSourcesAI website and the OpenSourcesAI iOS app. Where the two behave differently, the difference is stated rather than averaged — most notably, the iOS app collects no analytics at all.
Last updated: 3 August 2026.
Hosting and logs
OpenSourcesAI uses Netlify hosting and related infrastructure, with Cloudflare providing DNS, content delivery, and security filtering in front of it. Because Cloudflare sits in front of the site, it processes requests to OpenSourcesAI before they reach our hosting. Like most websites, these providers may process server logs such as IP address, request path, browser details, referrer, and timestamps for security, debugging, reliability, and abuse prevention.
The same applies to requests the iOS app makes to our public catalog endpoints. The app sends no account or device identifier with those requests, but the network request itself is still ordinary traffic, and hosting and network logs may record it as described above.
Analytics
The site may use basic behavior analytics to understand page visits, navigation patterns, and technical issues. Microsoft Clarity may be used to improve usability through aggregated behavior analytics such as clicks, scrolls, page interactions, and session diagnostics. Ahrefs Web Analytics may be used alongside it for basic traffic counting (pageviews, visitors, referral sources).
Cookies and tracking choices
OpenSourcesAI uses a small number of cookie and browser-storage categories. You can accept all of them, reject the non-essential ones, or manage each category individually using the cookie banner shown on your first visit, or at any time through the Privacy choices link in the site footer.
Necessary and security storage. Used to operate core site functionality (such as remembering your theme preference) and to protect forms and infrastructure from abuse, including Cloudflare Turnstile. These are always active and do not require consent, since the site cannot function or stay secure without them.
Analytics measurement. Used to understand page visits, navigation patterns, and feature usage (Google Analytics, Microsoft Clarity, and Ahrefs Web Analytics). No analytics cookies or browser storage are used until you accept. Microsoft Clarity and Ahrefs Web Analytics are not loaded at all before you opt in; Google Analytics loads in the cookieless mode described below.
Advertising and conversion measurement. Used to measure the effectiveness of partner and affiliate placements through Google's advertising signals, and to measure which of our own paid advertisements brought you here (the Reddit advertising pixel). Disabled by default until you accept it. The Reddit pixel is not loaded at all before you opt in.
Affiliate and partner outbound referral measurement. When you click an outbound link to a partner or affiliate tool, we record that click (and which tool it was for) so we can measure referral performance and keep our partner disclosures accurate. This click is recorded under your analytics choice, not your advertising choice, so it stops when you decline analytics. A separate advertising conversion is sent to Google's ad network for the same click, and that one follows your advertising choice.
We implement these choices using Google Consent Mode, which tells Google's tags whether analytics, advertising storage, ad user data, and ad personalization are allowed before they store cookies or use data for those purposes. Until you accept, all four are set to denied: nothing is read from or written to your device for analytics or advertising, and no persistent identifier is created for you. Google's tag does load, and sends a basic cookieless measurement signal — the page address, the referring page, and general device and browser information, with advertising identifiers redacted — which lets us count visits in aggregate without recognising you, following you between visits, or tracking you across other sites.
Reddit's pixel takes no part in Consent Mode and has no cookieless equivalent, so it is held back entirely rather than loaded in a restricted state: nothing from Reddit runs on the page unless you accept the advertising category.
Several things stay off entirely until you opt in: Microsoft Clarity, Ahrefs Web Analytics, and the Reddit pixel are not loaded at all, and the interaction events we record for our own features — such as running the compatibility checker or clicking through to a partner tool — are not sent. You can change your choice at any time, and new measurement stops immediately: from the moment you withdraw, we trigger no further events, conversions, or pixel activity. One honest caveat: a script that already loaded in your current tab (such as Clarity, if you had previously accepted) is only fully cleared on your next page load.
Forms and contact
If you submit a contact, sponsor, or listing form, we use the information you provide to respond, review submissions, and manage sponsor or partner conversations. Do not submit sensitive information through public forms.
Newsletter and email updates
If you subscribe to OpenSourcesAI updates, we use your email address to send site updates, model and tool notes, sponsorship updates, or related builder resources. Newsletter email addresses are processed by Buttondown, the email service provider used to operate the mailing list, and sign-ups are checked by Cloudflare Turnstile to prevent automated and list-bombing sign-ups. You can unsubscribe using the link in any newsletter email or by contacting us.
We do not sell newsletter subscriber data. If OpenSourcesAI changes email providers, subscriber data may be transferred only as needed to continue operating the newsletter and related site communications.
Browser AI playground, Compatibility Checker, and PC Builder
The Browser AI Playground is designed to run compatible demo models in the visitor's browser session when WebGPU is available. Playground prompts are not sent to OpenSourcesAI servers for inference in this MVP. The Local LLM Compatibility Checker and the Local AI PC Builder calculate their results entirely in your browser, and the hardware details and preferences you enter into either tool are not stored on OpenSourcesAI servers.
One clarification about analytics, because “runs in your browser” and “sends nothing anywhere” are not the same promise. If you have accepted analytics cookies, submitting the Compatibility Checker sends a coarse, non-identifying summary to our analytics provider: a GPU vendor category such as “nvidia” or “apple”, memory size bands such as “16-23” rather than exact figures, and the workflow you selected. The free-text you type into the CPU and GPU fields is never included, and neither is any exact memory value. If you decline analytics cookies, nothing is sent at all.
What stays in your browser. “Not stored on our servers” does not mean nothing is kept. These tools save a few things locally on your own device so you do not have to re-enter them: the processor description you typed into the Compatibility Checker, the hardware profile the site detected or you selected, any builds you saved in the PC Builder, and your cookie consent choice. All of it stays in your browser, is readable only by this site, and is never uploaded. You can remove it at any time by clearing site data for opensourcesai.com in your browser settings.
One difference worth stating plainly, because the Playground does not meet the standard the Compatibility Checker does: if you have accepted analytics cookies, the Playground reports whether WebGPU is available and, when it is, the graphics adapter name your browser exposes. That is the adapter string itself rather than the coarse vendor category the Checker sends. Prompts and generated text are never included. If you decline analytics cookies, nothing is sent.
Compatible model files may be downloaded through the browser and may be cached locally by your browser. Those downloads can involve requests to third-party model or CDN hosts, and ordinary browser, analytics, hosting, or network tooling may still process page-load metadata as described elsewhere in this policy.
OpenSourcesAI iOS app
The OpenSourcesAI iOS app is a companion to this site. It is deliberately narrower than the website in what it does with data, and the difference is worth stating plainly: the app collects no analytics, contains no advertising or tracking software, and requires no account. There is no analytics SDK, no crash-reporting SDK, and no advertising identifier in the app.
What stays on your device. Saved machine profiles, saved builds, Compatibility Checker and PC Builder results, and on-device diagnostic receipts are written to the app's local storage on your phone. They are not uploaded to OpenSourcesAI, and no profile-sync or submission endpoint is configured in the app. You can delete any of them from within the app.
Guest use only. The app runs in a local guest mode. There is no sign-in, no account identifier, and no account history sync. The Profile screen shows the current state of each of these controls so you can confirm it rather than take our word for it.
What leaves the device, and only when you ask. The app fetches the same public tool, model, and hardware catalog this website publishes, and keeps an age-labelled copy on your device so it still works offline. Those requests are ordinary network traffic, as described under Hosting and logs, and carry no identifier for you or your device. Separately, if you use the app's export or share feature, your saved data is handed to the iOS share sheet and goes wherever you choose to send it — that is an explicit action you take, and the destination is yours, not ours.
Links out to this website. Opening a model profile, hardware guide, or deployment fix from the app loads a page from opensourcesai.com in an in-app browser. Once you are on a web page, the website portions of this policy apply to that page, including the cookie and analytics choices described above.
The on-device diagnostic. The app includes a secondary, clearly-labelled diagnostic that measures the phone it runs on. Its results stay on the device, are not submitted anywhere, and are not published or compared. Evidence submission is off and no endpoint for it is configured.
If any of this changes — for example if a future version adds accounts, sync, or optional evidence submission — it will be disclosed here and in the app before it is switched on, not after.
Community forum
Forum content is stored using Supabase, a hosted database provider. Discussion pages are currently read-only for visitors: there is no posting or account interface on the site, so no forum account, username, or post content is being collected from visitors at this time. If public posting is enabled in the future, this section will be updated before it opens, and any information you choose to post to a public discussion should be treated as public.
Service providers
We use service providers to operate this project, including hosting, content delivery and security, analytics, forms, email delivery, and database hosting. The current providers are Netlify (hosting), Cloudflare (DNS, content delivery, security filtering, and Turnstile), Google (Analytics and advertising measurement), Microsoft (Clarity), Ahrefs (Web Analytics), Reddit (advertising measurement), Buttondown (newsletter), and Supabase (forum database). These providers may process limited technical metadata such as IP address, browser/device information, referrer, page URL, timestamps, form fields you submit, and email subscription status when needed to provide their services.
These providers operate in the United States and, in some cases, globally distributed infrastructure. If you access OpenSourcesAI from outside the United States, information described in this policy may be processed in the United States or in other countries where those providers operate.
No selling personal information
OpenSourcesAI does not sell personal information. We may use service providers for hosting, analytics, email, and form handling, but those providers are used to operate the site rather than sell visitor data.
Anti-bot protection and website security
To protect our registration channels, newsletter sign-up modules, and underlying hosting infrastructure from automated malicious threats, scraping engines, and list-bombing bot configurations, this site implements Cloudflare Turnstile. Turnstile is a modern, privacy-focused alternative to legacy CAPTCHA platforms provided by Cloudflare, Inc.
Operation: Cloudflare Turnstile evaluates browser telemetry, TLS signatures, and client properties to differentiate human visitors from automated scripts. This may present a brief visual confirmation widget (“Managed Mode”) or complete silently in the background. This data is not used for ad profiling. Your interaction with this security layer is governed by the Cloudflare Turnstile Privacy Addendum.
Your choices and requests
Analytics and advertising. Change or withdraw your consent at any time using the Privacy choices link in the site footer. Withdrawal stops new measurement immediately; a script that already loaded in your current tab is fully cleared on your next page load. The iOS app has no analytics to opt out of.
Newsletter. Unsubscribe using the link in any newsletter email, or contact us and we will remove you.
Data held on your device. Machine profiles, saved builds, and diagnostic receipts in the iOS app are stored locally and can be deleted in the app, or removed entirely by deleting the app. Because we never receive them, we cannot delete them for you.
Access, correction, and deletion. Depending on where you live, you may have the right to request access to, correction of, or deletion of personal information we hold about you, and to object to or restrict certain processing. In practice the personal information we hold is limited to newsletter subscription details, anything you sent us through a form, and technical logs. Send requests to the privacy contact below and we will respond as required by applicable law. We will not discriminate against you for making a request.
Children
OpenSourcesAI is a technical resource intended for a general adult audience. The site and the iOS app are not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at the address below and we will delete it.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new “Last updated” date. Material changes to what the iOS app collects will be disclosed before the change takes effect, not after.
Operator and privacy contact
OpenSourcesAI is the operator of this site and acts as the data controller for the personal information described in this policy.
Privacy questions and data requests can be sent to [email protected]. General privacy questions can also be sent to [email protected].
Postal mail can be sent to OpenSourcesAI, PO Box 338, Sebastopol, CA 95473.