Privacy policy
Privacy policy
How FOSS Data handles personal information for account and report access.
Published policy version
Version privacy-2026-08-19
Effective 19 August 2026
Approval scope public
FOSS Data publication
FOSS Data public research is published at www.fossdata.org.
Policy text
FOSS Data Privacy Policy
Last updated: August 19, 2026
Effective date: August 19, 2026
FOSS Data is a public-research publication operated by Exodos Labs, Inc. (“Exodos Labs”, “we”, “us”, or “our”).
This Privacy Policy applies to www.fossdata.org and www.fossdata.com, including the FOSS Data registration, authenticated research workspace, and report-delivery service (together, the “Service”). It does not govern the separate Exodos Labs platform at app.exodos.io or any other Exodos Labs service.
FOSS Data publishes research about the open-source software supply chain. The research is based on documented sources, managed snapshots, and, where indicated, anonymized and aggregated live research data. FOSS Data does not accept customer SBOM uploads, customer inventory data, or customer production data through this Service.
1. Who is responsible for the Service
The controller for personal information processed through the Service is:
Exodos Labs, Inc.
2261 Market Street, STE 22565
San Francisco, CA 94114
United States
For privacy questions or requests, contact [email protected].
EU representative
For individuals located in the European Union, Exodos Labs, Inc. has appointed the following EU Representative in accordance with Article 27 GDPR:
esb Rechtsanwälte GmbH
Schockenriedstraße 8A
70565 Stuttgart
Germany
Phone: 0711 4690580
https://www.kanzlei.de
EU data subjects and supervisory authorities may contact the EU Representative about GDPR compliance, data-subject rights, and regulatory communication.
2. Information we process
Public research visitors
When you use public FOSS Data pages, we and our infrastructure providers process limited technical information needed to deliver and secure the Service. This can include your IP address, browser and device information, request time, requested page, and security or error logs.
Registered users
If you create or use a FOSS Data account, we process your email address, a FOSS Data user identifier, account and verification timestamps, the state of your registration, and records showing which versions of the Privacy Policy and Terms of Use you accepted. We use an email-delivered one-time code for authentication; we do not require or store a FOSS Data password.
Authenticated research and report delivery
For the authenticated workspace and report delivery, we process the saved research views and filters you choose to store, report-download authorization and delivery evidence, and security and operational logs needed to prevent abuse, investigate incidents, and operate the Service.
The research itself is not a profile of you. Where the Service presents live Exodos research, it is limited to the anonymized and aggregated research projection described in the relevant methodology and source notes.
Cookies and similar technologies
The Service uses strictly necessary, secure, HTTP-only cookies for sign-in sessions, CSRF protection, and the temporary state required to complete one-time-code authentication. These cookies are not used for advertising or cross-site behavioral profiling.
3. How we use information
We use personal information to:
- provide public research, authenticated analysis, and report downloads;
- send, verify, and secure one-time sign-in codes;
- create and administer FOSS Data accounts;
- record legal acceptance and maintain operational, security, and delivery evidence;
- respond to support and privacy requests; and
- detect, prevent, and investigate fraud, abuse, security incidents, and service failures.
Registration does not subscribe you to marketing email. If you separately opt in to marketing communications, those communications are governed by the notice and preferences presented at the time of opt-in.
4. Legal bases
Where GDPR or UK GDPR applies, we process personal information as necessary to provide the Service you request, to comply with legal obligations, and for our legitimate interests in operating a secure research service, preventing abuse, documenting legal acceptance, and protecting our rights. Where a law requires consent, we rely on that consent and provide the relevant choice at the point of collection.
5. Service providers and disclosures
We do not sell personal information. We disclose personal information only as needed to operate the Service, comply with law, or protect the Service and its users.
| Provider or recipient | Purpose |
|---|---|
| HubSpot | CRM contact synchronization for verified FOSS Data registrations. The synchronized FOSS Data fields are the user ID, first verified registration date, and registration method. |
| Resend | Transactional email delivery for one-time sign-in codes and service messages. |
| Google Cloud Storage | Private storage and time-limited delivery of registered reports. |
| Cloudflare | DNS, TLS, network delivery, and security protection. |
| Exodos Labs service providers | Hosting, database, monitoring, and support functions required to operate the Service. |
We may disclose information to professional advisers, authorities, or other parties where required by applicable law or necessary to establish, exercise, or defend legal claims.
6. International transfers
Some providers may process information outside your country, including in the United States. Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, adequacy decisions, or supplementary protections.
7. Retention
We retain account, legal-acceptance, security, and delivery information only for as long as necessary to operate the Service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods are applied through the Service’s documented retention controls. You may request deletion of your account and personal information, subject to information we must retain for legal, security, fraud-prevention, or audit purposes.
8. Security
We use reasonable technical and organizational measures designed to protect information, including TLS in transit, access controls, signed report delivery, and audit and security logging. No service can guarantee absolute security.
9. Your rights
Depending on your location and applicable law, you may request access to, correction of, deletion of, restriction of, or objection to our processing of your personal information. You may also have rights to data portability, to withdraw consent, and to complain to a supervisory authority. To make a request, contact [email protected].
10. Children
The Service is not intended for children under 16, and we do not knowingly collect personal information from children.
11. Third-party links
The Service may link to third-party websites or source materials. Their privacy practices are governed by their own notices.
12. Changes to this policy
We may update this policy to reflect changes to the Service, law, or our operations. The published version and effective date identify the policy currently in force. Where required by law, we will provide additional notice before a material change takes effect.