Privacy Policy
Last updated: June 2026
1. About this Policy
Logora (“we”, “our”, or “us”) operates the OpenModeration platform, available as self-hosted open-source software and as a managed cloud service (“the Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use OpenModeration. We are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable French data protection laws.
2. Data Controller
Logora, a French company, is the data controller for personal data processed through the OpenModeration cloud service. For self-hosted deployments, you are the data controller — Logora has no access to your data.
3. Hosting and Data Location
All cloud service data is hosted on OVH infrastructure within the European Union. Data never leaves EU territory unless you explicitly configure a third-party provider outside the EU via Bring Your Own Keys (BYOK).
4. Self-Hosted Deployments
When you deploy OpenModeration on your own infrastructure, we have zero access to your data. All content, moderation results, API keys, and configuration remain entirely on your servers. Your data never touches our systems. You are fully responsible for your own data processing compliance as the data controller.
5. Data We Collect (Cloud Service)
When you use our managed cloud service, we process the following categories of data:
5.1 Account Information
- Email address, full name, and company name
- Billing details (processed by our payment provider; we do not store full credit card numbers)
- Account preferences and settings
5.2 Content Submitted for Moderation
- Text content sent to the moderation API for analysis
- Metadata associated with the content (e.g., language, source identifier)
- Stored according to your configured data retention policy (default: 1 year)
5.3 Moderation Results
- Provider responses, category scores, and moderation decisions
- Audit trail records (timestamp, provider used, decision rationale)
- Retained for compliance and transparency reporting purposes
5.4 Usage Data
- Request volume, latency metrics, and provider usage statistics
- Aggregated and anonymized for service monitoring and improvement
- No individual content or personal data is used for analytics
6. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR:
- Performance of a contract (Article 6(1)(b)): to provide the moderation service you subscribed to, including content analysis and result delivery.
- Legitimate interest (Article 6(1)(f)): service improvement through anonymized usage analytics, security monitoring, and fraud prevention.
- Legal obligation (Article 6(1)(c)): retaining records as required by applicable law, including DSA compliance obligations.
7. Cookies and Tracking
Our website (openmoderation.com) uses Umami, a privacy-focused analytics tool, to understand how visitors interact with our site. Umami does not use cookies, does not collect personal data, and does not track users across sites. All analytics data is anonymized and hosted on our own infrastructure. No personal identifiers are collected.
Our cloud service application (app.openmoderation.com) uses essential session cookies required for authentication and security. These are strictly necessary cookies that do not require consent under the ePrivacy Directive.
8. Third-Party Providers
When you use BYOK (Bring Your Own Keys), content is sent directly from your account to your chosen moderation provider (e.g., OpenAI, Azure, Mistral). Their respective privacy policies apply to that processing. Logora does not intermediate or store provider API keys in this mode beyond encrypted configuration storage.
When you use platform-managed keys, Logora sends content to providers on your behalf under Data Processing Agreements where applicable. A list of current sub-processors is available upon request at privacy@openmoderation.com.
9. International Data Transfers
We do not transfer personal data outside the European Union by default. If you use BYOK with a provider located outside the EU, you are responsible for ensuring appropriate safeguards (e.g., Standard Contractual Clauses) are in place for that transfer.
10. Data Retention
You control data retention for content and moderation results through your workspace dashboard settings. The default retention period is 1 year. You may configure longer or shorter periods as your compliance requirements dictate.
- Account data: retained for the duration of your account plus 30 days after deletion.
- Billing data: retained for 10 years as required by French tax law.
- Audit logs: retained according to your configured policy (default: 1 year).
11. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit: All API and web traffic uses TLS 1.3.
- Encryption at rest: Provider API keys are encrypted with AES-256-GCM.
- Key hashing: API keys stored in the database are hashed with SHA-256.
- Access control: Strict role-based access, multi-factor authentication for administrative access.
- Infrastructure: OVH EU data centers with ISO 27001, SOC 1/2, and HDS certifications.
12. Your Rights (GDPR)
As a data subject, you have the following rights under the GDPR:
- Right of access (Article 15): obtain confirmation and a copy of your personal data.
- Right of rectification (Article 16): correct inaccurate or incomplete data.
- Right to erasure (Article 17): request deletion of your data (“right to be forgotten”).
- Right to restriction (Article 18): limit processing under certain conditions.
- Right to portability (Article 20): receive your data in a structured, machine-readable format.
- Right to object (Article 21): object to processing based on legitimate interest.
- Right to withdraw consent (Article 7): where processing is based on consent.
To exercise any of these rights, contact our DPO at privacy@openmoderation.com. We will respond within one month. You also have the right to lodge a complaint with the CNIL (French Data Protection Authority).
13. Children’s Privacy
OpenModeration is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to active cloud service users and posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact
For any questions about this Privacy Policy or your personal data: