Security
How accounts, payments and data are protected — and how to tell us if we have got something wrong.
Last updated: 14 September 2026
Reporting a vulnerability
If you have found a security issue, email mail@anir0y.in. Include enough detail to reproduce it. Reports go directly to Animesh Roy, who runs OpenHour and reads them himself.
Please give us a reasonable opportunity to fix an issue before disclosing it publicly, and do not access, modify or delete data that is not yours while testing. We will not pursue action against researchers who act in good faith under those terms.
Accounts and access
- Sign-in is Google OAuth only. OpenHour never asks for, sees or stores a password for your account.
- Sessions expire after 30 days.
- The admin area is not reachable by ordinary accounts; it does not acknowledge its own existence to them.
- Accounts used to operate OpenHour and its providers follow industry-standard protections, including multi-factor authentication.
Payments
- Payments are handled by Razorpay on Razorpay-hosted pages. Card and UPI details are never sent to, processed by, or stored on OpenHour.
- Incoming payment webhooks are rejected unless they carry a valid signature.
- Bank details you save for payouts are encrypted with AES-256-GCM before being written to the database.
Data protection
- Calendar access tokens are encrypted with AES-256-GCM at rest, as are payout bank details.
- All traffic is served over HTTPS and the site sets HSTS, so browsers refuse to connect insecurely.
- Responses carry protections against MIME sniffing, clickjacking and referrer leakage.
Backups and availability
Data is backed up continuously. In the worst case a restore could lose up to the most recent hour of changes. OpenHour runs on Cloudflare's network, and the database is Cloudflare D1.
Deleting your data
Ask us to delete your data and we act within 24 hours. Deletion is permanent: once done, the data cannot be recovered, including from backups as they age out. Send the request from your account email to mail@anir0y.in.
If something goes wrong
If a breach affects your data we will post a notice on this site and email affected users immediately, rather than waiting until we understand the full picture. A root cause analysis follows once the investigation is complete.
Testing
OpenHour is tested internally and has been through an external audit. Testing is ongoing rather than a one-off exercise, and findings are fixed before they are published.
Who we share data with
These are the only third parties that process OpenHour data:
- Cloudflare — hosting, database and caching.
- Razorpay — payments, refunds and payouts.
- Resend — transactional email.
- Google — sign-in, and calendar sync if you connect a Google calendar.
- Microsoft — calendar sync if you connect an Outlook calendar.
What each one receives, and why, is set out in the privacy policy.
Who operates OpenHour
OpenHour is operated by Animesh Roy, a sole proprietor based in India. There is no company; the proprietor is personally responsible for the service.
301, A block, Sai Rasik ResidencyVittal Rao Nagar, Hi-Tech City, MadhapurImage Hospital LaneHyderabad, Telangana 500081IndiaGrievance officer
Animesh Roy
mail@anir0y.in · +91 70758 81337
Complaints are acknowledged within 48 hours and resolved within 30 days.