Skip to content
Open Source Icon

Open Source Icon legal

Privacy Policy

Last updated: September 17, 2026

Overview

Open Source Icon provides icon search, recoloring, downloads, bookmarks, accounts, editor and design-tool extensions, an icon API and an MCP server for coding agents. This policy explains the information processed when you use them and the choices you have.

The short version: no advertising trackers, no analytics script on any page, no sale of data, and everything we store sits on our own server in Germany.

Information we process

Searching, copying and downloading icons needs no account, and we store nothing about it on our server. The free search allowance of a visitor who is not signed in is counted inside one signed cookie in their own browser.

When you create an account we process your email address and your name. With Continue with Google we receive your email address, your name and the address of your Google profile photo, and get no other access to your Google account. With email and password we keep the password only as a salted hash, and send a verification link that has to be opened before the first sign-in.

Before you start we ask three questions: your main role, what you mainly use icons for, and how you work. An organisation, a website, social profile handles and the newsletter are optional. We also store the bookmarks and folders you create, which are private to you. For your avatar we store only an image address — a generated avatar or your Google photo; we host no uploads. Each account also gets one license key, a random string stored with the account and shown to you in Settings; nothing is recorded against it.

Search text is processed on our own server to return matching icons. There is no third-party search provider, and we do not build search histories or profiles. Our server and Cloudflare keep short-lived technical logs — IP address, browser user agent and the requested address, which can include search text — to keep the service running, apply rate limits and investigate abuse.

Cookies and browser storage

We set no advertising cookies and no third-party cookies. This is the complete list.

  • osi_searchesCookie · 24 hours

    Counts the free searches of a visitor who is not signed in: a number and the start of the 24-hour window, signed so it cannot be edited. Created by your first search, never by a page load. It carries no identifier and nothing about it is stored on our server.

  • osi.session_tokenCookie · 30 days

    Keeps you signed in. On the live site it is the secure variant, __Secure-osi.session_token. Not readable by JavaScript.

  • osi_uiCookie · 30 days

    One character that lets a page draw the signed-in sidebar straight away. It holds no personal data and no decision on our server depends on it.

  • Browser storagelocalStorage · until you clear it

    Your theme, whether the sidebar is collapsed, how much of the free search allowance is left, and an action you started before signing in. It never leaves your browser.

Extensions, API and MCP server

The VS Code extension and the Figma plugin search a list of icon names that ships with them, so what you type there stays on your device, and they download a library's icon data from our API when you open it — opensourceicon.com is the only host they contact. They identify themselves with your license key, which they send in the request header; our technical logs see that header like any other. They create no identifier of their own, send no usage events and contain no analytics.

The MCP server runs on your own machine and reads icons from the open-source icon package installed with it; the only request it makes to us is one check that your license key is valid. Single icon SVGs and the permanent icon links under opensourceicon.com/cdn/ need no key and no account: they set no cookies, and requests to them appear in the technical logs described above.

How information is used

We use information to provide and secure the service, sign you in, send account email, keep your bookmarks, count the free search allowance, answer support requests, prevent abuse and meet legal obligations. The answers about your work help us understand who uses the product and what to build next. We do not use any of it for advertising and we do not sell it.

Running your account and sending account email is what you asked for when you signed up. Technical logs and the search allowance rest on our legitimate interest in protecting a service we give away. The newsletter rests on your consent: it is off unless you tick the box, the preference is stored with your account only, and unticking it in Settings switches it off again.

Service providers and retention

A few providers process information on our behalf, only to deliver their part of the service:

  • Hetzner Online GmbHhosting. The server and the database that hold account data are in Germany.
  • Cloudflarethe network layer in front of the site: DNS, certificates and protection against abuse. It sees the requests made to opensourceicon.com.
  • Googleonly if you choose Continue with Google.
  • Twilio SendGriddelivers account email — verification, password reset, welcome — and the newsletter if you opted in.
  • DiceBeargenerated avatar images come from api.dicebear.com. Your browser fetches the image directly, so that request is visible to DiceBear; a Google photo is fetched from Google the same way.

Your account, profile and bookmarks are kept until you delete your account, which removes them from our database at once. The search allowance lives only in the cookie in your browser, for 24 hours. Sign-in sessions and email links are removed once they expire, and technical logs are short-lived — a deletion does not reach back into them, so an entry naming your address or your license key can survive for the few days a log is kept.

Your choices

You can view and change your profile, clear its optional parts and switch the newsletter on or off in Settings at any time. Settings also deletes the account: ask for it there, open the link we email you, and the account, its sessions, its profile, its bookmarks and folders, its social links and its license key are gone. For access, a copy of your data, correction or objection, email us. If you are in the EU or the UK you can also complain to your local data protection authority.

Open Source Icon is not directed at children under 16. When this policy changes, the date at the top changes with it, and changes that materially affect people with an account are announced by email or inside the product. The rules for using the service are in our Terms of Service.

Contact

Privacy questions and requests can be sent to hello@opensourceicon.com.