Privacy Policy
This Privacy Policy explains how maxitom ("we", "us", "the Service") collects, uses, stores, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is the operator of the maxitom platform, reachable via the official Discord community linked on the platform. For any privacy-related request, contact us through the channels listed in Section 12.
2. Data We Collect
2.1 Account Data
- Username — chosen by you at registration.
- Access key / password — stored only as a cryptographic hash; never in plain text.
- Discord account data — if you choose to sign in or link via Discord OAuth: Discord user ID, username, and avatar URL.
- TOTP secret — if you enable two-factor authentication, the shared secret is stored encrypted.
2.2 Usage & Technical Data
- Session data — active session identifiers, script execution counts, and timestamps used to operate the service.
- IP addresses — processed transiently for security, rate limiting, and abuse prevention (firewall). Not stored in long-term analytics.
- Script content — source code you upload is stored to provide the distribution service.
- Comments — content you post on script pages, linked to your username and Discord avatar.
2.3 Data We Do Not Collect
- We do not use third-party advertising trackers.
- We do not sell, rent, or share your personal data with data brokers.
- We do not collect precise geolocation, device fingerprinting for advertising, or behavioral profiles.
3. Legal Bases for Processing (Art. 6 GDPR)
| Purpose | Data | Legal Basis |
|---|---|---|
| Providing the service (accounts, script hosting, sessions) | Account data, script content | Art. 6(1)(b) — Contract performance |
| Security, abuse prevention, firewall | IP address, session metadata | Art. 6(1)(f) — Legitimate interest |
| Discord sign-in / linking | Discord ID, username, avatar | Art. 6(1)(a) — Consent |
| Optional analytics / preferences | Theme, cookie-consent choice | Art. 6(1)(a) — Consent |
4. Cookies & Local Storage
We use strictly necessary browser local storage only — no third-party tracking cookies. These entries are required for the service to function and are exempt from consent under Art. 5(3) of the ePrivacy Directive:
| Key | Purpose | Duration |
|---|---|---|
| theme | Remembers your light/dark appearance preference | Until cleared |
| acousticState | Remembers your sound-effects preference | Until cleared |
| cookieConsent | Stores your cookie-consent decision | Until cleared |
| Session token | Keeps you signed in securely | Session / until logout |
With your consent (via the cookie banner), we may use privacy-respecting, aggregate analytics to improve the platform. Declining does not affect core functionality. You can withdraw consent at any time by clearing your browser storage.
5. Third-Party Processors
- Cloudflare, Inc. — hosting, CDN, DDoS protection, and Turnstile bot verification. Data is processed on Cloudflare's global network under their Data Processing Addendum.
- Discord, Inc. — only if you choose Discord sign-in; governed by Discord's Privacy Policy.
- Cloudflare Turnstile — a privacy-first CAPTCHA alternative used for security verification; it does not use cookies for tracking.
Where data is transferred outside the EEA, it is protected by adequacy decisions or Standard Contractual Clauses (SCCs).
6. Data Retention
- Account data — kept while your account is active; deleted within 30 days of an erasure request.
- Script content — kept until you delete it or request account erasure.
- Session / execution logs — retained for a maximum of 90 days for security auditing, then purged.
- IP-based firewall entries — temporary; automatically expire.
7. Your Rights (Art. 15–22 GDPR)
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your account and associated data.
- Restriction — request limited processing of your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Lodge a complaint — with your local supervisory authority.
To exercise any right, contact us via the channels in Section 12. We respond within 30 days.
8. Data Security
- All traffic is encrypted in transit via TLS (HTTPS).
- Passwords and access keys are stored as salted cryptographic hashes.
- Two-factor authentication (TOTP) is available and recommended.
- Access to production data is restricted to authorized operators only.
9. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it promptly.
10. Automated Decision-Making
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be announced via the platform's release notes. The "last updated" date at the top reflects the current version.
12. Contact
For any privacy question, data request, or GDPR inquiry, reach out through the official maxitom Discord community (linked on the homepage) and ask for a platform operator. We aim to respond within 30 days.