Privacy Policy
Last updated: 14 August 2026
StoatBoard ("we", "us", "the Service") is a personal project operated from France. This Privacy Policy explains what personal data we collect, why we collect it, the legal basis under the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679), and your rights regarding that data.
By using StoatBoard, you acknowledge that you have read and understood this Policy.
1. Data Controller
The data controller for StoatBoard is the operator of this personal project, based in France. We do not operate under a registered legal entity. For any data-related request, contact us at:
We will respond to all requests within 30 days in accordance with Article 12 GDPR.
2. Data We Collect and Legal Bases
We only collect what is strictly necessary to operate the Service. For each category of data, we indicate the applicable legal basis under Article 6 GDPR.
| Data | Purpose | Legal Basis |
|---|---|---|
| Username, email address, hashed password | Account creation and authentication | Art. 6(1)(b) — performance of contract |
| Server and bot listing data (name, description, invite or installation link, tags, category, icon, website, and bot identifier when applicable) | Verification, moderation, display, and management of directory listings | Art. 6(1)(b) — performance of contract |
| IP address | Rate limiting and abuse prevention (stored temporarily in Redis cache, TTL ≤ 24 hours) | Art. 6(1)(f) — legitimate interest (preventing abuse) |
| Votes, bumps, ratings, reviews, and reports | Ranking public listings, enforcing cooldowns, publishing feedback, and handling abuse or moderation requests | Art. 6(1)(b) — performance of contract |
| Public Stoat bot account metadata | Confirming that a submitted identifier belongs to a bot account and keeping its public name and icon accurate | Art. 6(1)(b) and Art. 6(1)(f) — contract performance and fraud/impersonation prevention |
| Session cookie | Maintaining your authenticated session | Art. 6(1)(b) — performance of contract (essential) |
| Stoat identity link data (Stoat ID, challenge status, expiry, and cryptographic hashes of temporary proofs) | Proving that the account holder controlled the linked Stoat account while preventing copied-code takeover, conflicts, and abuse. We never request or store a user's Stoat session token. | Art. 6(1)(b) and Art. 6(1)(f) — service performance and security/fraud prevention |
| Developer application metadata, exact redirects, domain proofs, encrypted client credentials, and security history | Operating Continue with StoatBoard, displaying trustworthy consent information, verifying domains, rotating credentials, enforcing ownership, and investigating abuse | Art. 6(1)(b) and Art. 6(1)(f) |
| OIDC authorization records (user/application IDs, granted scopes, consent time, opaque protocol artifacts, expirations, consumption, and revocation) | Completing requested sign-in, issuing minimum authorized claims, detecting replay, and allowing immediate revocation | Art. 6(1)(b), Art. 6(1)(a) for optional claim sharing, and Art. 6(1)(f) for security |
| Product analytics data (events, page views, session replay metadata, technical context) | Understanding usage, debugging issues, and improving product UX after an explicit analytics choice. For signed-in users, analytics may be linked only to the internal account ID. We do not send the account name, email address, or raw search text to PostHog. | Art. 6(1)(a) — consent, which can be withdrawn at any time |
| Email address (transactional) | Sending account and service emails (verification, security resets, moderation notices, listing/boost operational reminders) | Art. 6(1)(b) and Art. 6(1)(f) — contract performance and legitimate interest |
| Payment and credit events (Ko-fi transaction ID, amount, currency, payer name/email when provided) | Crediting Pulse balance, fraud prevention, accounting traceability, and support handling for virtual currency operations. | Art. 6(1)(b) and Art. 6(1)(f) |
| AI processing inputs (server or bot name, descriptions, category, and tags) | Generating optional suggested SEO descriptions for listings and admin queue workflows. | Art. 6(1)(b) and Art. 6(1)(f) |
We do not use your data for automated legal or similarly significant decision-making.
3. Data Retention
- Account data (username, email, hashed password): retained for as long as your account is active. Account deletion removes your user record and related linked records immediately (subject to short technical delay and limited backup/log retention).
- Server and bot listing data: retained while the listing exists. Soft-deleted records may be retained temporarily (e.g., 14-day operational retention) before permanent purge.
- IP addresses: stored in Redis with a maximum TTL of 24 hours and automatically purged thereafter.
- Session cookies: expire when you log out or after 30 days of inactivity.
- Stoat link challenges: expire after 10 minutes. Expired challenge records, which contain only hashed temporary proofs, are automatically deleted within 30 days.
- OIDC protocol artifacts: authorization codes, access tokens, refresh tokens, interactions, and grants carry their documented expiry and expired records are purged by the daily retention job. Revoked authorization records and developer security events are retained for up to one year for abuse and incident investigation.
- Developer applications: application, client, redirect, domain-proof, and active authorization records remain while the project or account exists. Revoking access makes tokens unusable immediately even when a minimal audit record is temporarily retained.
- Moderation/report data: retained as needed for moderation, abuse prevention, and legal compliance.
- Payment and Pulse ledger data: retained as long as required for fraud prevention, accounting traceability, dispute handling, and legal obligations.
4. Third-Party Services and International Transfers
We use the following sub-processors. Some of these services may process personal data outside the EU/EEA. Where applicable, such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46 GDPR).
- Cloudflare, Inc. (USA) — CDN, DDoS protection, DNS, and Cloudflare Turnstile (anti-bot challenge). Cloudflare may process request metadata (including IP addresses) through its global network. Privacy Policy
- Self-Hosted Infrastructure (France) — PostgreSQL database self-hosted on our own infrastructure via Coolify. Your account and directory listing data is stored on servers we control.
- Resend, Inc. (USA) — Transactional email delivery (verification, security, moderation, and service reminder emails). Only necessary recipient and message data is transmitted. Privacy Policy
- PostHog, Inc. (EU — Frankfurt, Germany) — Optional product analytics (page views, click patterns, feature usage, and session recordings). PostHog is not initialized before consent. When accepted, all replay text and inputs are masked, marked private elements are blocked, network headers and bodies are excluded, and URLs are sanitized. For authenticated users, analytics may be associated only with the internal account ID. Privacy Policy
- Ko-fi Labs, Ltd. (UK) — Payment platform used for Pulse purchases. We receive transaction metadata sent by Ko-fi webhooks (for example transaction IDs, amounts, currency, payer email/name where available). Privacy Policy
- Google LLC (Gemini API) — Optional AI-assisted generation of SEO suggestions from listing content submitted by users/admin workflows. Privacy Policy
- Redis (self-hosted / managed) — In-memory cache for rate limiting. Stores IP addresses with short TTL. No data is shared with third parties via this service.
Applications you authorize are recipients chosen by you, not our sub-processors. Before sharing, the consent screen identifies the application, owner, exact domain, verification status, and requested scopes. The application receives only the approved claims: an opaque StoatBoard subject and, when separately requested and approved, profile data, linked Stoat ID, or a verified email address. The developer is responsible for its own privacy notice, purpose, security, and retention after receipt.
We do not sell, rent, or share your personal data with any third party for advertising or unrelated marketing purposes.
Bot invite links, publisher websites, and support links lead to third-party services. When you choose to follow one, that service may receive your IP address and browser metadata under its own privacy policy. StoatBoard does not control the bot developer's subsequent processing inside Stoat.
Payment metadata may also be processed to prevent fraud, resolve payment disputes, and enforce no-refund and anti-chargeback policies in accordance with our Terms.
5. Cookies
We use strictly necessary storage. PostHog cookie/localStorage is created only after you accept optional analytics. You can reject or withdraw consent at any time through “Cookie preferences” in the footer. For full details, see our Cookie Policy.
6. Security
We implement appropriate technical and organisational measures to protect your data:
- Passwords are hashed using bcrypt (12 rounds) and are never stored in plaintext.
- All connections use HTTPS/TLS encryption.
- Access to the database is restricted to server-side application code only.
- IP addresses used for rate limiting are stored ephemerally and purged automatically.
7. Your Rights (GDPR)
As a data subject under the GDPR, you have the following rights:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can correct inaccurate or incomplete data via your account settings or by contacting us.
- Right to erasure (Art. 17): You can delete your account at any time from your account settings. We will process deletion within 30 days.
- Right to restriction (Art. 18): You can ask us to restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20): You can request an export of your personal data in a structured, machine-readable format (JSON). Send your request to [email protected] and we will fulfil it within 30 days.
- Right to object (Art. 21): Where we process data on the basis of legitimate interest (Art. 6(1)(f)), you may object to that processing, including certain operational reminder emails.
- Right to withdraw consent (Art. 7(3)): You can withdraw optional analytics consent at any time through “Cookie preferences” in the footer, without affecting processing that occurred lawfully before withdrawal.
To exercise any of these rights, email [email protected]. We may ask you to verify your identity before processing your request.
8. Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with the French data protection authority:
CNIL (Commission Nationale de l'Informatique et des Libertés)
www.cnil.fr/en/complaints
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the CNIL within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.
- Notify affected users without undue delay when the breach is likely to result in a high risk to their rights, in accordance with Article 34 GDPR.
Notification to affected users will be made by email to the address registered on their account, and/or via a prominent notice on the Service.
If you suspect a security incident involving your personal data on StoatBoard, please notify us immediately at [email protected].
10. Children's Privacy
The Service is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal data, please contact [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where feasible, notify registered users by email. If an analytics change requires renewed consent, we will invalidate the previous consent version and ask for a new choice before optional analytics starts again.
12. Contact
For any privacy-related question or request, contact us at:
Related legal documents: Terms of Service · Cookie Policy · Content Policy · DMCA / Takedown · Legal Notice.