Chapter 27 · operating safely

Verified-access application privacy

Understand what the source-access form collects, why it is used, how it is protected, and where legal review remains required.

1 min read·Updated 2026-07-26·3 role paths
01

Scope

This notice applies to the OGO™ Community Source verified-access application. Ordinary no-auth exploration of the hosted Studio is separate.

02

Data collected

The form collects identity, contact, GitHub, organization, category, intended-use, technology-domain, expected-user, contribution, consent, and recognition-preference information.

Security controls may create privacy-HMAC abuse identifiers, challenge records, timestamps, and rate-limit counters.

03

Purposes

Data supports manual review, rules-consent records, communication, private repository administration, access reviews, security, recognition permission, and offboarding.

04

Protection

The browser posts to a same-origin server route. Direct client Firestore access is denied. The server uses Firebase Admin. Routine logs should exclude application content and raw IP addresses.

05

Manual GitHub process

The form stores the requested GitHub username. The owner sends the invitation manually. OGO stores no GitHub token.

06

Before production launch, counsel should confirm the final privacy notice, responsible organization, retention, service providers, rights, jurisdictional notices, and contact process.