Data Privacy Statement

How we handle your data, what we collect, and what we will never do.

Last updated: April 2026

Our Principle

Ordinary Friend exists because we believe people deserve to see the value they created on social media — not have it extracted from them again. Every decision we make about data starts from that principle.

What We Collect

When you express interest via our early access form, we collect your name, email address, and which insight dimension you're most curious about. That's it.

If you contact us as a researcher, we collect your name, email, institution, research interest area, and your message.

We do not use tracking pixels, third-party analytics, or advertising cookies on this site.

What Happens When You Upload

Your Meta data export (.zip file) is uploaded over an encrypted TLS connection to our servers hosted on Vercel (a SOC 2 Type II compliant infrastructure provider). Your ZIP is processed in memory — we never write your raw data to disk or a database.

We extract aggregate statistics from your messages, posts, comments, and connections — things like message counts by year, connection totals, and activity patterns. These statistics are sent to OpenAI's API for AI-powered narrative analysis. OpenAI does not use API data for training and deletes it after processing per their data usage policy.

Your raw data is never stored. Once your portrait is generated, the original file is discarded. Only anonymized, aggregated insights are retained — and only if you opt into research.

Research Datalake

If you explicitly opt in, anonymized behavioral metrics may be contributed to an academic research datalake. This requires a separate, clear consent step — it never happens by default.

Anonymized records contain only aggregate patterns:

  • No names, usernames, or identifiers
  • No message content or post text
  • No photos, files, or media
  • No information that could be traced back to you

Research data is made available to vetted academic researchers studying prosocial behavior, digital wellbeing, and platform design. Because data is fully anonymized and aggregated, individual records cannot be identified or extracted.

What We Will Never Do

  • Store your raw data — it is processed in memory and immediately discarded
  • Sell or share your data with advertisers or data brokers
  • Use your data for ad targeting of any kind
  • Share your raw data with any third party (AI providers receive only aggregate statistics and do not retain them)
  • Allow anyone to re-identify you from anonymized research data
  • Share your email address with third parties

Your Rights

Your raw data is never stored, so there is nothing to delete. Your portrait exists only in your browser session — close the tab and it's gone.

If you opted into the research datalake, your contribution is fully anonymized and aggregated. Because no personally identifiable information is retained, individual records cannot be traced back to any user.

You own your data. We just help you read it.

Third-Party Services

We use the following services to operate Ordinary Friend:

  • Vercel — serverless hosting and processing (SOC 2 Type II compliant, data encrypted in transit)
  • OpenAI — AI analysis for portrait narrative generation (receives only aggregate statistics, not raw data; API data is not used for model training and is deleted after processing)

No other third parties receive your data.

Contact

Questions about how we handle data? Email sarah@darkridge.com.