Plain-language privacy at OpenList.
You can browse OpenList without creating an account. This page describes the limited information the current site collects and why.
Information you choose to send
The contact and correction form collects your name, email address, subject, message, and any opportunity ID, correction, or official source link you provide. We use it to answer you, review reports, correct listings, and protect the inbox from abuse. Please do not send school records, financial documents, passwords, government IDs, or other sensitive personal information.
Technical information
Vercel hosts the website and may process ordinary request and server logs such as IP address, browser or device information, requested URL, response status, and timing. OpenList converts limited request information into a one-way hash for contact-form rate limiting; the raw value is not stored in the contact inbox.
Cookies and analytics
When you save an opportunity, My list stores its name, page identifier, and displayed access details in your browser’s local storage. This shortlist is not uploaded to an OpenList account and does not sync between devices. Remove individual entries on My list or clear this site’s browser data to delete it.
You can optionally save matching preferences, such as grade, location, citizenship or visa answer, interests, and budget, on this browser. They do not sync across devices or create an account. Use Forget saved preferences to remove them. Applying filters puts answers in the requested page URL, which may appear in browser history and hosting logs. Check the URL before sharing it. Personal cost calculator entries stay in page memory and are cleared when the page reloads.
OpenList does not currently use advertising trackers, third-party analytics, or an account system. The current application does not set its own tracking cookies. Hosting infrastructure may use strictly necessary security or operational mechanisms under its own policies.
Where information is processed
Vercel serves the application. Supabase stores the opportunity database and private contact submissions. Official program links lead to independent third-party sites; their privacy practices apply once you leave OpenList.
Retention and deletion requests
Contact submissions are kept only as long as reasonably needed to respond, review a correction, maintain an abuse-prevention record, or resolve an operational issue. Provider backups and logs may follow the provider’s normal retention cycle. To request access to or deletion of a contact submission, use the contact form and include the email address used in the original message.
Security
OpenList limits public database permissions, validates contact submissions on the server and in the database, rate-limits repeated submissions, and keeps administrative credentials server-side. No online service can promise absolute security, so send only information needed for the report.
Students and children
OpenList is an informational directory used by students, including minors. It does not require a student profile. Younger users should involve a parent, guardian, teacher, or counselor before sending personal information or using an external application site. If a submission contains personal information that is not needed, contact us so it can be reviewed for deletion.
Updates and contact
This policy may change when the site’s actual data practices change. Material changes will be reflected on this page. Questions or deletion requests can be sent through Contact OpenList.
