Privacy notice
What this site stores, why, who receives it, how long, and how to erase it. Written for GDPR Art. 13. If a line here disagrees with the code, the code is what happens; write to the email and the line gets fixed.
- Controller
- the person who runs tinux.dev, Spain
- [email protected]
- Languages
- English and Spanish
Controller
The controller is the row at the top of this page. No data protection officer is appointed. Art. 37 does not require one for this site.
Sign-in
Discord OAuth with scopes identify and email. The email scope is requested so Discord will say whether the address is verified. The address itself is not written to the database. On first sign-in, D1 stores the Discord user id, username, avatar hash, and first-login time. The same session cookie opens tinux host and Cardstock.
Legal basis: Art. 6(1)(b), the account you asked for. Art. 6(1)(f) for abuse handling and bans.
- tinux_host_session
- HttpOnly, 30 days, Secure, SameSite=Lax. The account.
- OAuth
- State and return path, two cookies, 10 minutes, only during sign-in.
- Gate
- 10 minutes. Records that you ticked 14+, the privacy notice, and the terms, so the Discord redirect can run.
What is not stored
- Discord email
- The email scope is only so Discord will say whether the address is verified. The address is not written to D1.
- Street address
- Not collected. Not published.
- Settings in this browser
- Theme, sky mode, Cardstock look, intro flag. They stay on this machine.
Cardstock
After you sign in: board JSON up to 400 KB, pictures in R2 under 200 KB each, 8 MB per account. Picture URLs are /cs/ plus an id. Those URLs are public. Anyone who has one can fetch the file. A share link is /b/ plus a token and is public, noindex, one board, archive stripped. Pictures on a shared board stay at /cs/ after sharing stops.
tinux host
If you are on the whitelist: files in R2, up to 95 MB each, 200 MB per account. Public at /i/ and /raw/.
Reports
The URL, the category, the explanation, and if you gave them a name and email (not collected for child sexual abuse material). The connecting IP is stored for one hour to cap 5 stored notices. Failed attempts do not count. Legal basis: Art. 6(1)(c) and (f), DSA Arts. 16 and 18, and Spanish criminal law on reporting.
Bans
A banned Discord id and the reason typed at the ban stay in D1 so that id cannot open a new session. Content is erased. Legal basis: Art. 6(1)(f) and Art. 17(3)(b) for the id itself.
Vigil and the hub sky
Vigil stores one cached status payload in D1. It is not about you.
The sky on the hub can use an approximate latitude and longitude Cloudflare already attached to the request. That call is off until you turn on "place from this request" in the gear. Then the browser keeps a copy in localStorage under tinux-place for a day. Legal basis: Art. 6(1)(a), that switch.
This browser
ePrivacy Art. 5(3). The session cookie is strictly necessary for the account you asked for. The other cookies in Sign-in exist only for that flow.
Fonts are files on tinux.dev. Pages do not load fonts.googleapis.com.
A YouTube or Vimeo player on a Cardstock card is not requested until you press load on that player. Then that company sees the request. Discord's CDN sees a request if a share page loads an avatar.
Who else sees it
Cloudflare (Pages, D1, R2, request logs). Discord (OAuth). Both are in the United States. Transfers use the EU-US Data Privacy Framework where those companies are listed, otherwise the standard contractual clauses those products ship.
How long
- Session
- 30 days, or until you sign out
- Boards and host files
- Until you delete them, or the owner does
- Reports
- Until the notice is closed, then 30 days. A child-sexual-abuse notice is kept as long as a police file needs it
- Ban ids
- Until the owner unbans
- Place in this browser
- One day, or until you turn the switch off
Your rights
Access, rectification, erasure, restriction, portability, objection, complaint to the Agencia Española de Protección de Datos at aepd.es.
Cardstock: Settings → Files exports JSON and can erase every board on the account. tinux host: delete a file from the library. Either: Settings or the host page, "erase this account", which drops boards, host files, the session, and the user row. The owner account cannot use that button. A ban reason stays if you were banned.
No automated decision with legal effect is run on you.