Your data at Bothlo
Privacy Notice
This notice explains what personal data Bothlo uses, why, for how long, with whom it is shared, and what rights you have.
1. Controller
The controller is Monika Kaźmierczak, a natural person in Poland, address [ADRES OPERATORA]. Privacy contact: contact@bothlo.com. No data protection officer has been appointed: [POTWIERDZIĆ PO OCENIE, CZY IOD JEST WYMAGANY].
2. Where data comes from
Data comes from you, your use of Bothlo, other users who report content, Google when you choose Google OAuth, browser/device security signals provided through Cloudflare Turnstile, and service providers operating the platform. Bothlo does not ask Google for Gmail, Drive, contacts or other Google API data.
3. Processing purposes, data, legal bases and retention
| Purpose and data | Legal basis | Recipients | Retention |
|---|---|---|---|
| Account and authentication: email, Supabase user ID, username, password verifier managed by Supabase, confirmation/recovery events, session and login metadata; Google ID, email, name and profile image if Google OAuth is chosen. | Art. 6(1)(b) GDPR — perform the account service and take steps requested before registration. Security records may also rely on Art. 6(1)(f). | Supabase; Google for an OAuth flow chosen by the user; authorised operator personnel. | For the account lifetime; then deletion or anonymisation, subject to backups, security evidence and claims for [OKRES RETENCJI DO POTWIERDZENIA]. |
| Age and legal onboarding: date of birth, age status, parent/guardian email for ages 13–15, consent request and confirmation audit, document versions and acceptance time. | Art. 6(1)(c) GDPR where needed to meet legal duties concerning children and proof of compliance; Art. 6(1)(b) to provide an eligible account; parental authorisation/consent where legally required. Exact child-consent basis requires Polish-law review. | Supabase; Resend and its mail infrastructure for consent messages; parent/guardian; authorised moderator. | For the account and afterwards only as needed to prove valid onboarding, handle withdrawal or legal claims: [OKRES RETENCJI ZGÓD DO POTWIERDZENIA]. Raw one-time tokens expire after 48 hours and are stored hashed. |
| Public profile and content: username, optional avatar and bio, Community Topics, official arguments, comments, replies, stance, timestamps and public aggregate statistics. | Art. 6(1)(b) GDPR — publish and operate the service requested by the member. Art. 6(1)(f) may apply to preserving coherent anonymised discussions and defending claims. | Public internet users; Supabase; Netlify for delivery of the site; other users. | Until removed or account deletion. After deletion, identity fields are anonymised; contributions may remain where needed for thread integrity, votes, moderation or claims. Backups follow [BACKUP RETENTION TO CONFIRM]. |
| Participation and platform integrity: votes, Best Argument choice, hearts/reactions, participant IDs, matchmaking, debate results, points, ranking, streak/freeze records and server timestamps. | Art. 6(1)(b) GDPR to provide official debate functions; Art. 6(1)(f) to prevent manipulation and preserve result integrity. | Supabase; public receives only the interface's published results and aggregates. | For the account/service history and as needed to keep completed debates auditable; exact deletion/anonymisation schedule: [OKRES RETENCJI AKTYWNOŚCI DO POTWIERDZENIA]. |
| Safety, reports and moderation: reports, reporter ID where signed in, target content, reason, description, content snapshots/context, moderator actions, restrictions, bans, decision reasons, appeal and review history. | Art. 6(1)(b) to enforce the Terms; Art. 6(1)(f) for user safety, abuse prevention and legal claims; Art. 6(1)(c) where notice-and-action or other law requires processing. | Authorised moderators/admins; Supabase; Resend for important decision emails; competent authorities or rights holders when legally required. | For review and appeal plus a proportionate evidence/claims period: [OKRES RETENCJI MODERACJI DO POTWIERDZENIA]. Appeal deadline in the current system is 30 days. |
| Illegal-content notices and rights requests: content reference, problem type, explanation, name if given, contact email, good-faith statement, request fingerprint, correspondence, request type and outcome. | Art. 6(1)(c) where applicable legal duties require receiving/handling notices and GDPR requests; otherwise Art. 6(1)(f) for safety, legal compliance and defence of claims. | Authorised reviewers; Supabase; contact email routing providers; competent authorities where required. | Until resolved and then for [OKRES RETENCJI ZGŁOSZEŃ DO POTWIERDZENIA], taking limitation periods, legal duties and abuse prevention into account. |
| Security and availability: IP address, user agent, request timing, session/token metadata, rate-limit counters/fingerprints, audit trails, error and infrastructure logs, Turnstile browser/device signals. | Art. 6(1)(f) GDPR — legitimate interests in preventing bots, fraud, unauthorised access and service failure. These interests are balanced against users through minimisation, access controls and limited retention. | Supabase, Netlify, Cloudflare Turnstile and their subprocessors; authorised operator personnel. | Provider and application log periods: [OKRESY LOGÓW SUPABASE/NETLIFY/CLOUDFLARE DO POTWIERDZENIA]. Rate-limit data is kept only as technically needed. |
| Transactional email and support: recipient email, email event, delivery status/provider ID, support message and correspondence. System messages include Auth, parental, deletion and moderation messages. | Art. 6(1)(b) for account/service messages; Art. 6(1)(c) for legally required notices; Art. 6(1)(f) for support and delivery evidence. Marketing consent is not used because Bothlo sends no marketing mail. | Supabase Auth, Resend, Cloudflare Email Routing and the operator's destination Gmail account for contact mail. | Delivery outbox and support correspondence for [OKRES RETENCJI E-MAILI DO POTWIERDZENIA]; provider logs according to the verified account settings and contracts. |
4. Public data
Bothlo is designed for public debate. A username, avatar, biography, topics, arguments, comments, replies, stance labels and published aggregates may be visible to anyone and indexed or copied by third parties. Email, full date of birth, parent email, Auth data, private report contact details and raw security records are not intended to be public. Do not publish another person's personal data or information you want to keep private.
5. Providers and transfers
- Supabase provides authentication, PostgreSQL, storage, realtime and Edge Functions. The project region is [REGION SUPABASE DO POTWIERDZENIA]. Supabase's DPA provides SCCs for restricted transfers; the actual account DPA and selected region must be confirmed.
- Netlify is configured as the static host. Requests may include IP address, headers and requested paths. Confirm the deployed site/account, DPA, subprocessors and log settings: [KONFIGURACJA NETLIFY DO POTWIERDZENIA].
- Google provides optional OAuth using only openid, email and profile. Google may act under its own privacy terms during the sign-in flow.
- Cloudflare Turnstile processes browser/device and network signals to prevent automated abuse. Cloudflare Email Routing forwards mail sent to contact@bothlo.com to the operator's Gmail inbox. Confirm the account DPA and routing settings.
- Resend sends transactional email from auth.bothlo.com through server-side configuration. Its DPA incorporates EU SCCs and it uses subprocessors, including providers in the United States. Confirm the executed DPA and account settings.
- jsDelivr delivers the Supabase browser library and Google Fonts delivers Manrope and Space Grotesk. Loading them exposes ordinary request data such as IP address and user agent. Consider self-hosting these assets before launch and confirm provider terms.
Some recipients are outside the EEA. Where no adequacy decision applies, the relevant provider contract may use European Commission Standard Contractual Clauses and supplementary safeguards. Bothlo must document the contracts and transfer assessment before launch: [TRANSFER IMPACT ASSESSMENT / DPA CONFIRMATION].
6. Cookies, storage and PWA cache
Bothlo uses essential browser storage for the Supabase session, a safe post-login return path, parental-email resend suppression and an optional local public-configuration override. The service worker caches only same-origin application-shell files and does not cache Supabase Auth, API responses, user data or config.js. Turnstile and Google may use their own essential storage during their flows. No advertising or analytics tracker was found in the audited code. See the Cookie Notice.
Provider references
Current official references: Supabase DPA and regions; Netlify Privacy Statement; Google OAuth scopes; Turnstile documentation and Cloudflare DPA; Resend DPA and subprocessors. Provider terms can change and account-specific settings still require confirmation.
7. Automated processing
Server logic automatically calculates debate matches, results, points, rankings, daily topics, streaks, rate limits and access status according to platform rules. A basic pre-filter can classify content/report priority as normal, suspicious or urgent. It does not by itself remove ambiguous content merely because it has many reports. Account and content sanctions are subject to moderator action and eligible appeals. Bothlo does not use advertising profiling.
8. Children
No account is allowed under 13. Users aged 13–15 need a parent or legal guardian. The child and parent receive simple information about public content, data use, withdrawal and deletion. Parent emails are used for the consent process, not marketing. Users aged 16+ complete onboarding themselves. If Bothlo learns that an ineligible account was created, access may be restricted and the data handled in line with law.
9. Deletion and anonymisation
Account deletion removes the Auth account through a protected server function, clears date of birth and parent email from active account data, replaces the username with a deleted-account label, clears bio/avatar, and attempts to remove the stored avatar file. Contributions and system records may remain anonymised where erasing them would break discussion context, vote integrity, safety records or legal obligations. Provider backups may persist until their normal cycle expires. Bothlo does not promise immediate erasure where law permits or requires retention.
10. Your GDPR rights
Subject to conditions and exceptions, you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawfulness. You may also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent authority. Use Your data rights while signed in or email contact@bothlo.com. Bothlo may verify identity and normally responds within the period required by law.
11. Changes
The version and effective date are displayed above. Material changes will be communicated where required, and renewed acknowledgement may be requested. Contact Bothlo for earlier versions.