Privacy policy

Privacy policy

How FOSS Data handles personal information for account and report access.

Published policy version

Version privacy-2026-08-19

Effective 19 August 2026

Approval scope public

FOSS Data publication

FOSS Data public research is published at www.fossdata.org.

Policy text

FOSS Data Privacy Policy

Last updated: August 19, 2026
Effective date: August 19, 2026

FOSS Data is a public-research publication operated by Exodos Labs, Inc. (“Exodos Labs”, “we”, “us”, or “our”).

This Privacy Policy applies to www.fossdata.org and www.fossdata.com, including the FOSS Data registration, authenticated research workspace, and report-delivery service (together, the “Service”). It does not govern the separate Exodos Labs platform at app.exodos.io or any other Exodos Labs service.

FOSS Data publishes research about the open-source software supply chain. The research is based on documented sources, managed snapshots, and, where indicated, anonymized and aggregated live research data. FOSS Data does not accept customer SBOM uploads, customer inventory data, or customer production data through this Service.

1. Who is responsible for the Service

The controller for personal information processed through the Service is:

Exodos Labs, Inc.
2261 Market Street, STE 22565
San Francisco, CA 94114
United States

For privacy questions or requests, contact [email protected].

EU representative

For individuals located in the European Union, Exodos Labs, Inc. has appointed the following EU Representative in accordance with Article 27 GDPR:

esb Rechtsanwälte GmbH
Schockenriedstraße 8A
70565 Stuttgart
Germany
Phone: 0711 4690580
https://www.kanzlei.de

EU data subjects and supervisory authorities may contact the EU Representative about GDPR compliance, data-subject rights, and regulatory communication.

2. Information we process

Public research visitors

When you use public FOSS Data pages, we and our infrastructure providers process limited technical information needed to deliver and secure the Service. This can include your IP address, browser and device information, request time, requested page, and security or error logs.

Registered users

If you create or use a FOSS Data account, we process your email address, a FOSS Data user identifier, account and verification timestamps, the state of your registration, and records showing which versions of the Privacy Policy and Terms of Use you accepted. We use an email-delivered one-time code for authentication; we do not require or store a FOSS Data password.

Authenticated research and report delivery

For the authenticated workspace and report delivery, we process the saved research views and filters you choose to store, report-download authorization and delivery evidence, and security and operational logs needed to prevent abuse, investigate incidents, and operate the Service.

The research itself is not a profile of you. Where the Service presents live Exodos research, it is limited to the anonymized and aggregated research projection described in the relevant methodology and source notes.

Cookies and similar technologies

The Service uses strictly necessary, secure, HTTP-only cookies for sign-in sessions, CSRF protection, and the temporary state required to complete one-time-code authentication. These cookies are not used for advertising or cross-site behavioral profiling.

3. How we use information

We use personal information to:

  • provide public research, authenticated analysis, and report downloads;
  • send, verify, and secure one-time sign-in codes;
  • create and administer FOSS Data accounts;
  • record legal acceptance and maintain operational, security, and delivery evidence;
  • respond to support and privacy requests; and
  • detect, prevent, and investigate fraud, abuse, security incidents, and service failures.

Registration does not subscribe you to marketing email. If you separately opt in to marketing communications, those communications are governed by the notice and preferences presented at the time of opt-in.

4. Legal bases

Where GDPR or UK GDPR applies, we process personal information as necessary to provide the Service you request, to comply with legal obligations, and for our legitimate interests in operating a secure research service, preventing abuse, documenting legal acceptance, and protecting our rights. Where a law requires consent, we rely on that consent and provide the relevant choice at the point of collection.

5. Service providers and disclosures

We do not sell personal information. We disclose personal information only as needed to operate the Service, comply with law, or protect the Service and its users.

Provider or recipientPurpose
HubSpotCRM contact synchronization for verified FOSS Data registrations. The synchronized FOSS Data fields are the user ID, first verified registration date, and registration method.
ResendTransactional email delivery for one-time sign-in codes and service messages.
Google Cloud StoragePrivate storage and time-limited delivery of registered reports.
CloudflareDNS, TLS, network delivery, and security protection.
Exodos Labs service providersHosting, database, monitoring, and support functions required to operate the Service.

We may disclose information to professional advisers, authorities, or other parties where required by applicable law or necessary to establish, exercise, or defend legal claims.

6. International transfers

Some providers may process information outside your country, including in the United States. Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, adequacy decisions, or supplementary protections.

7. Retention

We retain account, legal-acceptance, security, and delivery information only for as long as necessary to operate the Service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods are applied through the Service’s documented retention controls. You may request deletion of your account and personal information, subject to information we must retain for legal, security, fraud-prevention, or audit purposes.

8. Security

We use reasonable technical and organizational measures designed to protect information, including TLS in transit, access controls, signed report delivery, and audit and security logging. No service can guarantee absolute security.

9. Your rights

Depending on your location and applicable law, you may request access to, correction of, deletion of, restriction of, or objection to our processing of your personal information. You may also have rights to data portability, to withdraw consent, and to complain to a supervisory authority. To make a request, contact [email protected].

10. Children

The Service is not intended for children under 16, and we do not knowingly collect personal information from children.

11. Third-party links

The Service may link to third-party websites or source materials. Their privacy practices are governed by their own notices.

12. Changes to this policy

We may update this policy to reflect changes to the Service, law, or our operations. The published version and effective date identify the policy currently in force. Where required by law, we will provide additional notice before a material change takes effect.