Privacy Policy
Effective date: 4 July 2026 Last updated: 4 July 2026
This is the English-language version, which is the authoritative version.
NM Technology Services & Solutions (Grupo NMTSS), a company registered in Mozambique,
NUIT 112059725 ("Open Tools", "we", "us", "our"), operates the Open Tools utility library at
open-tools.app (the "Service"). This policy explains what personal data we collect, why,
how we protect it, and the rights you have over it.
Open Tools is built to collect as little as possible. Most tools can be used anonymously, with no account and no sign-in. Some tools run entirely in your browser, so the file never reaches our servers. We use no third-party analytics and no advertising trackers.
1. Who is the data controller
The data controller is NM Technology Services & Solutions (Grupo NMTSS), registered in Mozambique, NUIT 112059725. Registered address: Av. Capitão Pereira do Lago, nº 1837, 7º Bairro Matacuane, Beira, Sofala, CP 2300, Moçambique. Privacy questions: legal@open-tools.app.
2. What we collect
-
Account data (only if you create an account): your email address and a scrypt password hash — we never store your plaintext password — plus an email-verified flag and timestamp.
-
Session data (only if you sign in): an opaque,
HttpOnlysession cookie (tlmk_sid), of which we store only a SHA-256 hash server-side, together with the IP address and User-Agent recorded for that session. Sessions last 7 days. -
Language preference: a functional cookie (
NEXT_LOCALE) storing your chosen interface language. -
Uploaded files (server-side tools only): files you upload for processing. These are processed and then automatically deleted — anonymous uploads after about 15 minutes, signed-in uploads after about 24 hours (a single flat window today; paid plans, coming soon, may extend this). Files for a published "QR site" are kept until you delete that site. Tools that run in your browser upload nothing.
-
Job history (only if you sign in): rows recording jobs you ran, retained per your plan (Free 7 days, Pro 90 days).
-
API keys (only if you create one): stored as a hash; the key itself is shown once at creation and never again.
-
Usage events: minimal internal events (for example, signup, login, job submitted) linked to your user id or an anonymised IP. These are used for rate-limiting, abuse prevention, and product metrics, and are not sent to any third-party analytics.
-
Billing data: none today — the Service is entirely free and no payments are processed. Paid plans are coming soon; when they launch, payment will be handled by PayPal, and we will store only your subscription status and a PayPal subscription identifier — we will not see or store your card or bank details.
-
Error logs: application error reports captured by our self-hosted error-logging tool (Bugsink/Sentry). These record application errors, not the contents of your files.
-
Support and chat data (only if you contact us): if you submit our contact form, we collect the name, email address, and message you send. If you are a signed-in user with a verified email, you may also use our live chat, in which case we store the chat transcript and your account email. Support messages and chat transcripts are stored in our self-hosted Chatwoot system, on our own infrastructure, and are used only to receive, respond to, and keep a record of your request. The live-chat widget may use local storage in your browser to maintain the chat session.
We do not sell your personal data, and we do not use your files or usage data for advertising.
3. Why we use it (purposes & legal bases)
| Purpose | Legal basis (GDPR-style) |
|---|---|
| Run the tools you use, including uploading, processing, and returning file outputs | Contract; legitimate interests |
| Create and secure your account; authenticate you (session cookie) | Contract; legitimate interests (security) |
| Provide API keys and job history | Contract |
| Rate-limit, detect abuse, and protect the Service (usage events, session IP/User-Agent) | Legitimate interests |
| Send transactional email (email verification, password reset) | Contract |
| Process subscription payments and manage entitlements (only once paid plans launch) | Contract; legal obligation (tax/accounting) |
| Host a QR site you choose to publish | Contract |
| Receive and respond to support requests, incl. the contact form and live chat (name, email, message/transcript) | Legitimate interests; consent |
| Diagnose and fix errors (self-hosted error logs) | Legitimate interests |
Where the law requires consent for a particular processing activity, we rely on your consent and you may withdraw it at any time; withdrawal does not affect processing already carried out.
4. Who we share it with (sub-processors)
We use a small set of vetted providers strictly to run the Service, sharing only what each needs under data-processing terms:
- Amazon Web Services (AWS) — compute and database hosting. Region: USA (us-east-1).
- Cloudflare — object storage (R2), DNS, email routing, and the Turnstile bot-check used on the signup and suggestion forms.
- Vercel — frontend hosting.
- Resend — transactional email (email verification and password reset), used on an interim basis (AWS SES is planned).
- Bugsink / Sentry (self-hosted) — application error logging on our own infrastructure.
- Ko-fi — optional donations, via an external link, only if you choose to donate.
Planned sub-processor (not yet active): PayPal — payment processing and subscription management. This will be used once paid plans launch; no payment data is shared with anyone today.
We may also disclose data if required by law, or where necessary to protect the rights, safety, or property of Open Tools, our users, or the public.
5. International transfers
Our core infrastructure is hosted in the United States (AWS, us-east-1), and some providers listed above (for example, Cloudflare, and PayPal once paid plans launch) operate internationally. If you are located outside the United States, including in the European Economic Area (EEA) or the United Kingdom, your personal data is transferred to and processed in the United States and other countries under appropriate safeguards — principally the Standard Contractual Clauses incorporated into our providers' data-processing agreements (for example, AWS and Cloudflare), together with the technical measures described in §8. You can request details of these safeguards at legal@open-tools.app.
6. Your rights
Depending on your jurisdiction, you may have the right to access your data, rectify it, erase it, port it (data portability), and object to or restrict certain processing.
Open Tools provides self-service controls in account settings:
- Export my data — download a copy of your account data.
- Delete my account — permanently purges your account, sessions, API keys, entitlements, and your files (and, once paid plans launch, any subscription records, cancelling any active subscription).
We do not carry out solely automated decision-making that produces legal or similarly significant effects about you, and we do not profile you for advertising.
You can also email legal@open-tools.app; we respond within 30 days. You may also complain to your local data-protection authority.
7. Data retention
We keep data only as long as needed for the purpose it was collected. Uploaded files are auto-deleted on a short schedule, sessions and tokens are short-lived, usage events are kept about 180 days, error logs about 30–90 days, and account data is kept while your account is active and permanently removed within 30 days of deletion, including from backups. The full schedule is in the Data Retention Policy.
8. How we protect it
- Encryption in transit (TLS) and encryption at rest for stored data.
- Passwords stored only as a scrypt hash; session and API keys stored only as hashes; email-verification and password-reset tokens are short-lived and single-use.
- Least-privilege service roles and access controls.
- Self-hosted error monitoring that captures application errors — not file contents — so we can keep the Service secure and working.
No system is perfectly secure, but we work to industry standards to protect your data.
9. Children
The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact legal@open-tools.app and we will delete it.
10. Cookies
We use only strictly-necessary cookies — a session cookie (tlmk_sid) and a language
cookie (NEXT_LOCALE) — plus a bot-check cookie that Cloudflare Turnstile may set on the
signup and suggestion forms. We use no analytics or advertising cookies. Full details
are in the Cookie Policy.
11. Changes
We may update this policy from time to time. We will post the new version here and, for material changes, provide notice in-app or by email. The "Last updated" date reflects the latest version.
12. Contact
NM Technology Services & Solutions (Grupo NMTSS), registered in Mozambique, NUIT 112059725. Registered address: Av. Capitão Pereira do Lago, nº 1837, 7º Bairro Matacuane, Beira, Sofala, CP 2300, Moçambique. Privacy contact: legal@open-tools.app. Support: support@open-tools.app.