Privacy Policy

OrigamiSite is designed to work with very little personal data. This policy explains what stays on your device, what reaches our servers, why it is processed, and the choices available to you.

Last updated 11 August 2026

Who we are and scope

OrigamiSite is operated by Morteza Rahi, who is the controller of personal data described in this policy. Privacy questions and rights requests for origamisite.com can be sent to hello@origamisite.com.

This policy applies to the website, folding studios, Quiet Garden, Quiet Gallery, account sign-in and shared fold pages. A third-party site you choose to open has its own privacy policy.

The short version

You can fold without an account. We do not run advertising, sell personal data, use cross-site tracking pixels or build advertising profiles.

Text entered in “leave something behind” stays on your device. It is not included in account sync, Gallery posts, share cards or link previews.

Data kept on your device

The following is stored in your browser:

  • sound, ambient sound, motion and contrast preferences;
  • your Quiet Garden while you use the service as a guest;
  • private reflections, only when you explicitly choose to keep them; and
  • a local record of Gallery reactions to help avoid accidental repeat actions.

Clearing site data in your browser removes this information. We cannot restore guest-only data or private reflections because we do not receive them.

Account and sign-in data

If you choose to sign in, we process your email address, a display name derived from it, session records and your synced Garden. A Garden record can include the model, paper, duration, title, fold/cut counts and the geometry and operation history needed to restore a creation. Private reflections are removed before sync.

Sign-in codes are delivered by Resend. We store a keyed hash of the code, challenge timing and attempt count. We also derive a keyed, non-reversible request fingerprint from the request IP address to enforce rate limits; the raw IP is not stored in the application database for this purpose. Hosting and security providers may retain ordinary request logs, including IP address and browser information, under their own controlled retention schedules.

A fold becomes public only when you deliberately choose “Share to gallery”. The model, paper colour, display name, creation date and optional caption can then be viewed by anyone and may appear in search or link previews.

Public posts never include your email address or private reflection. Contact us to remove a Gallery post. Removing a post does not control copies that another person may already have saved or shared elsewhere.

Why we process data

  • Provide the account and Garden sync: performance of the service contract you request.
  • Deliver and verify sign-in codes: performance of the service contract and account security.
  • Prevent abuse and protect the service: our legitimate interest in keeping sign-in, Gallery and infrastructure secure.
  • Publish a Gallery fold: your requested action and consent, which you may withdraw by asking us to remove it.
  • Meet legal obligations: where applicable law requires a limited record or response.

Service providers and transfers

We use Railway for application hosting and PostgreSQL storage, Resend for transactional sign-in email, and Cloudflare for DNS and related network security. They process limited data on our behalf or as independent controllers for their own account, security and compliance operations.

These providers may process data outside your country, including outside the UK or EEA. Where GDPR transfer rules apply, we rely on applicable adequacy arrangements, the providers’ data-processing terms and safeguards such as the European Commission’s Standard Contractual Clauses. You may ask us for more information about the relevant safeguard.

We may disclose information when required by law, to protect people or the service, or in connection with a genuine business transfer. We do not disclose it to data brokers or advertisers.

Cookies and local storage

After sign-in, OrigamiSite sets a strictly necessary, HttpOnly session cookie. It is Secure in production, uses SameSite=Lax, and expires after 30 days unless you sign out sooner. No advertising or analytics cookie is set by the application.

Browser local storage supports the guest Garden and preferences described above. These features do not follow you across unrelated websites. Because the application uses only necessary storage and user-requested local functionality, it does not show an advertising-cookie consent banner.

Retention

  • Sign-in codes stop working after 10 minutes and challenge records are cleared routinely.
  • Session cookies and sessions expire after 30 days; signing out ends the current session.
  • Account and synced Garden data remains until the account is deleted.
  • Gallery posts remain until removed by you or us.
  • Security, infrastructure and backup records are retained only as operationally or legally necessary.

When deletion is requested, data is removed from active systems and then ages out of protected backups according to the relevant provider’s backup cycle, unless a legal obligation requires limited retention.

Security

We use short-lived one-time codes, hashed authentication material, HttpOnly production cookies, rate limiting, validated API payloads and restricted service credentials. No internet service can promise absolute security. Please contact us promptly if you believe your account or data has been compromised.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to or export personal data, and to withdraw consent. Our GDPR page explains these rights and how to make a request.

We do not use your data for automated decisions that have legal or similarly significant effects.

Children

The account and community features are intended for people aged 13 or over and are not directed to younger children. Where local law requires parental permission at a higher age, a parent or guardian should supervise use. If you believe a child provided account data without required permission, contact us so we can remove it.

Changes and contact

We will update the date above when this policy changes. If a change materially affects account data, we will provide a prominent notice or email where reasonably possible. Questions and requests should be sent to hello@origamisite.com.

Questions about this page? Write to hello@origamisite.com.