RECEIPTS FOR OUR OWN DATA HANDLING
Privacy Policy
LAST UPDATED: 25 JUL 2026
1 / WHO WE ARE
JABRAT ("we", "us") operates this forum. For EU/EEA and UK members we act as the data controller for the personal data described below. Contact us via the Site Feedback board for any privacy request; requests are answered within 30 days.
2 / WHAT WE COLLECT
- Account data: your handle, a salted scrypt hash of your password (never the password itself), your email address, rank, trust score, optional bio, and join date.
- Email verification: when you register or reset a code we store a hashed copy of the six-digit code (never the code itself), the email it went to, attempt counts, and expiry timestamps. We use your email for exactly two things: verification codes and a one-time welcome message. No newsletters, no marketing, no digests. Your email is never shown on your profile or to other members.
- Content you post: threads, replies, reports, bookmarks, and donation messages you choose to attach.
- Security logs: authentication events (login, logout, registration, failures) with your IP address, kept for abuse prevention and account-lockout protection.
- Presence: a random per-tab identifier and last-seen timestamp powering the "online now" counter. It is not linked to your account.
- Payments: donation amount, currency, optional message, and a payment reference from our conversion partner. The partner receives your IP address to check regional availability, converts the coin you send, and settles the proceeds to our wallet. We never see or store your wallet keys.
- Analytics: aggregate product analytics (page views, feature events). We do not use advertising trackers, and analytics runs without personal profiles unless you are logged in.
- Error telemetry: crash and error reports, which may include your IP and browser details in the error context.
3 / WHY WE PROCESS IT (LEGAL BASES)
- Running the forum (accounts, posts, sessions): performance of our contract with you (GDPR Art. 6(1)(b)).
- Email verification and the welcome message: performance of contract and our legitimate interest in keeping automated signups out (Art. 6(1)(b), (f)).
- Security logging, rate limiting, lockouts: our legitimate interest in keeping the forum and its members safe (Art. 6(1)(f)).
- Donations: performance of contract and legal obligations around payment records (Art. 6(1)(b), (c)).
- Analytics and error telemetry: legitimate interest in understanding usage and fixing defects (Art. 6(1)(f)). No data is sold.
4 / HOW LONG WE KEEP IT
- Account data: until you delete your account, which you can do yourself at any time from your profile. The account locks immediately; after a 30-day grace period (during which logging in cancels the deletion) your email address, password, bio, bookmarks, and reports are erased and your posts remain under an anonymous deleted handle.
- Email verification codes: hashed codes expire after 10 minutes and the records are purged within roughly a day of expiring.
- Posts and threads: retained while the forum operates; deleted posts are soft-deleted and hidden, then purged on request.
- Authentication/security logs: kept for 90 days, then deleted automatically; webhook idempotency records are purged after 30 days.
- Presence rows: expire automatically within minutes of your tab closing.
- Donation records: kept as long as financial-record obligations require.
5 / WHO ELSE TOUCHES IT (PROCESSORS)
We use a small set of service providers, each receiving only what their job needs: a hosting and edge network provider (US/EU), a managed database provider (hosted in the US), a transactional email service (delivery of verification codes and the welcome message), a cryptocurrency conversion and settlement service, a product analytics provider (US cloud), and an error-monitoring service. Transfers outside the EU/EEA rely on the EU-US Data Privacy Framework or Standard Contractual Clauses as applicable. We do not sell personal data to anyone, ever. A current list of processors is available on request via the Site Feedback board.
6 / YOUR RIGHTS — EU / EEA / UK (GDPR)
- Access, rectify, or erase your personal data.
- Restrict or object to processing based on legitimate interest.
- Data portability for data you provided.
- Withdraw consent at any time where processing relies on it.
- Complain to your local supervisory authority.
Exercise any of these via the Site Feedback board or your profile settings. You can delete your account yourself at any time from your profile's edit panel: the account locks immediately and is permanently erased after a 30-day grace period. Logging back in during those 30 days cancels the deletion, which protects you if someone else gains access to your account. The erasure removes your handle, email, password, bio, bookmarks, and reports, and reassigns your posts to an anonymous deleted handle. Full post removal instead of anonymization can be requested via the same board.
7 / YOUR RIGHTS — UNITED STATES (CCPA/CPRA AND SIMILAR)
- Right to know: what categories of personal information we collect (Section 2 is the complete list) and why (Section 3).
- Right to delete: delete your account yourself from your profile settings; it locks immediately and is erased after a 30-day grace period.
- Right to correct: fix inaccurate personal information via profile settings or request.
- Right to non-discrimination: exercising these rights never degrades your access.
- No sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.
8 / COOKIES
We set one strictly-necessary session cookie for login. No advertising or cross-site tracking cookies exist on this site. Analytics uses first-party storage only.
9 / CHILDREN
JABRAT is not directed at anyone under 18. We do not knowingly collect data from minors; accounts found to belong to minors are removed.
10 / CHANGES
Material changes to this policy are announced on the Announcements board before they take effect, with the diff described in plain language. The date at the top always reflects the current revision.