Sign in

Data Privacy Statement

How we handle your data, what we collect, and what we will never do.

Last updated: April 2026

Our Principle

Ordinary Friend exists because we believe people deserve to see the value they created on social media — not have it extracted from them again. Every decision we make about data starts from that principle.

What We Collect

When you sign in with a magic link, we record your email address and a session identifier. When you choose to upload your Meta export, we store the ZIP on encrypted ephemeral disk just long enough to extract its contents into your own isolated database row, then we delete the original file.

If you contact us as a researcher, we collect your name, email, institution, research interest area, and your message.

We do not use tracking pixels, third-party analytics, or advertising cookies on this site.

What Happens When You Upload

Your Meta data export is uploaded over an encrypted TLS connection to our servers. Processing — extraction, embeddings, sentiment, relationship classification — runs entirely on our backend; the browser never sees your raw data again after the upload completes. Your data is stored in an isolated, encrypted Supabase database row keyed by your account.

Generating insights involves sending text content to Anthropic's API for AI analysis. Anthropic does not use API data for training and deletes it after processing per their data usage policy.

Your raw data and generated insights persist in your account until you request deletion. You can request full data removal at any time from your account page.

Research Datalake

If you explicitly opt in via the donate flow, anonymized aggregate metrics may be contributed to an academic research datalake. This requires two separate, non-bypassable consent checkboxes and only aggregates that satisfy a k ≥ 5 threshold are ever published.

Anonymized records contain:

  • No names or usernames
  • No message content or post text
  • No photos, files, or media
  • No personally identifiable information

Research data is made available to vetted academic researchers studying prosocial behavior, digital wellbeing, and platform design. You can withdraw consent and request removal at any time.

What We Will Never Do

  • Sell or share your data with advertisers or data brokers
  • Use your data for ad targeting of any kind
  • Share your raw data with any third party (the AI provider receives text only for processing and does not retain it)
  • Retain your data after you request deletion
  • Allow anyone to re-identify you from anonymized research data
  • Share your email address with third parties

Your Rights

You can request full deletion of all data we hold — raw uploads, generated insights, embeddings, and account information — at any time from your account page or by emailing sarah@darkridge.com. Soft-delete starts a 30-day grace window; full removal is irrevocable after that.

If you opted into the research datalake, you can withdraw consent and request removal of your anonymized record.

You own your data. We just help you read it.

Third-Party Services

We use the following services to operate Ordinary Friend:

  • Supabase — database hosting and authentication (SOC 2 Type II compliant, data encrypted at rest and in transit)
  • Anthropic — AI analysis for sentiment scoring, embeddings, and relationship classification (API data is not used for model training and is deleted after processing)

No other third parties receive your data.

Contact

Questions about how we handle data? Email sarah@darkridge.com.