Add Privacy Policy — 13 sections, public-facing
This commit is contained in:
155
privacy-policy.md
Normal file
155
privacy-policy.md
Normal file
@@ -0,0 +1,155 @@
|
||||
# Privacy Policy
|
||||
|
||||
**Last updated:** 2026-07-09
|
||||
|
||||
This Privacy Policy explains how Majjo Duran collects, uses, stores, and protects your data when you use our services. It works alongside our Terms of Service and should be read together with them.
|
||||
|
||||
We collect the minimum data reasonably needed to operate, secure, and monitor our services. We do not sell your data. We do not run advertising tracking.
|
||||
|
||||
---
|
||||
|
||||
## 1. Service Scope
|
||||
|
||||
This policy applies to all services covered by our Terms of Service:
|
||||
|
||||
- **Plex** — media streaming and playback
|
||||
- **Seerr** — media request management
|
||||
- **Bitwarden (Vault)** — password and credential management
|
||||
|
||||
Supporting infrastructure such as security monitoring, access logging, and analytics operates behind these services. Data processed by this infrastructure is covered by this policy.
|
||||
|
||||
## 2. Data We Collect
|
||||
|
||||
When you use our services, we may collect and process the following categories of data:
|
||||
|
||||
- **Account and identity data** — usernames, email addresses where applicable, Discord usernames if used for support or access, service roles and permissions.
|
||||
- **IP and network data** — IP addresses, ASN/provider, VPN/datacenter/proxy classification, country or region from GeoIP where available.
|
||||
- **Device and client data** — device name, platform, app or browser type, device identifiers where provided by the service.
|
||||
- **Playback and media activity** — watch history, user statistics, media titles and metadata, playback devices, timestamps, bandwidth, transcode, and session data where available.
|
||||
- **Request activity** — Seerr requests, approval/denial status, requester, requested media, timestamps, and request history.
|
||||
- **Vault and authentication data** — Bitwarden access metadata, login and session events, known-device checks, failed authentication and security events where logged.
|
||||
- **Access and security logs** — request metadata including IP, host, path, method, status code, timestamps, duration, routed service, and TLS/router metadata.
|
||||
- **Enforcement data** — bans, suspensions, blacklists, VPN/datacenter/proxy violations, scanner and probing records, abuse and security incident notes.
|
||||
- **Support communications** — Discord, email, or other support messages related to account, access, or service issues.
|
||||
|
||||
Data is only acquired when you actively use our services. We do not collect data without your knowledge.
|
||||
|
||||
## 3. How We Use Your Data
|
||||
|
||||
Data is used for:
|
||||
|
||||
- Operating and maintaining the services
|
||||
- Monitoring performance and resource utilization
|
||||
- Analyzing user activity for service optimization
|
||||
- Security monitoring, abuse prevention, and threat detection
|
||||
- Enforcing compliance with our Terms of Service
|
||||
- Providing user-facing features such as playback history and dashboards
|
||||
- Training internal AI models (see Section 4)
|
||||
|
||||
Data will not be shared with third parties except as required by law or as necessary to operate and protect the services.
|
||||
|
||||
## 4. AI & Automated Processing
|
||||
|
||||
Your data may be processed by AI and automated systems as part of service operation, security monitoring, and improvement.
|
||||
|
||||
- **Local AI** — Internal systems may process service data for security analysis, abuse detection, and operational tasks.
|
||||
- **Cloud AI** — Data may be processed by cloud-based AI providers for inference and analysis. Our current cloud provider (Ollama) operates under a zero-log-retention and zero-training policy, meaning your data is not stored or used for training by the provider.
|
||||
|
||||
**AI Training:**
|
||||
|
||||
Service data, including user-linked and identifiable data, may be used to train internal AI models. These models are:
|
||||
|
||||
- **Internal-only** — never sold, published, or shared with third parties
|
||||
- **Access-controlled** — accessible only by Majjo and authorized management members (currently none exist)
|
||||
- **Not user-facing** — models are used for administration and security, not exposed to users
|
||||
|
||||
Raw passwords, secrets, private vault contents, and credential material are never used for AI processing or training, regardless of consent.
|
||||
|
||||
## 5. Data Retention
|
||||
|
||||
We retain data for as long as necessary to operate, secure, and enforce our services. Specifically:
|
||||
|
||||
- **Service and activity data** (playback history, request history, dashboards) — retained indefinitely to provide user-facing history features and service functionality.
|
||||
- **Access and security logs** — retained as needed for diagnostics, performance monitoring, and security analysis.
|
||||
- **Enforcement data** (bans, suspensions, blacklists, abuse records) — may be retained permanently to prevent evasion and protect the services.
|
||||
- **Support communications** — retained as long as needed for support and enforcement purposes.
|
||||
|
||||
Data related to suspected abuse, compromise, or security incidents may be retained longer than standard retention periods where necessary to investigate, prevent recurrence, or enforce access restrictions.
|
||||
|
||||
Users may request deletion of their data (see Sections 9–10), but some data cannot be deleted where it is required for security or enforcement.
|
||||
|
||||
## 6. Data Storage Location
|
||||
|
||||
All sensitive data is stored within the European Union. The vast majority of data is hosted in Majjo's private infrastructure in Stockholm, Sweden. No sensitive service data is currently stored on servers outside the EU.
|
||||
|
||||
Some infrastructure providers may process limited data (such as email routing or DNS) as part of operating the services. These are listed in Section 7.
|
||||
|
||||
## 7. Data Sharing & Third Parties
|
||||
|
||||
We do not sell your data. We do not voluntarily share your data with unrelated third parties.
|
||||
|
||||
The following providers may process limited data when necessary to operate, host, or support the services:
|
||||
|
||||
- **Infrastructure and hosting providers** — process data such as IP addresses and traffic metadata as part of hosting and routing.
|
||||
- **Email providers** — process data necessary for email delivery and support communications.
|
||||
- **Discord** — processes messages, usernames, and related data when support is conducted through Discord.
|
||||
|
||||
Data may be disclosed to legal authorities only where required by law.
|
||||
|
||||
## 8. Cookies & Sessions
|
||||
|
||||
Cookies, session tokens, and local storage are used only for service-related purposes:
|
||||
|
||||
- Login sessions and authentication
|
||||
- Security and access control
|
||||
- User preferences and settings
|
||||
|
||||
We do not use advertising cookies. We do not use unrelated tracking cookies. We do not use cookies for any purpose not connected to our services.
|
||||
|
||||
## 9. Your Rights
|
||||
|
||||
You have the following rights regarding your personal data:
|
||||
|
||||
- **Access** — You may request a copy of the personal data we hold about you.
|
||||
- **Modification** — You may request corrections to your data if it is inaccurate or incomplete.
|
||||
- **Deletion** — You may request deletion of your data, subject to the limits in Section 10.
|
||||
- **Data Portability** — You may request a copy of your data in a structured, machine-readable format.
|
||||
- **Withdrawal of Consent** — You may stop using the services at any time. Note that service data needed for security and enforcement may still be retained as described in this policy.
|
||||
|
||||
To exercise any of these rights, contact management using the information in Section 12.
|
||||
|
||||
## 10. Data Deletion Limits
|
||||
|
||||
You may request deletion of your identifiable data. However, some data cannot be deleted:
|
||||
|
||||
- Security records, ban records, and blacklists retained to prevent evasion
|
||||
- Enforcement data required to maintain the integrity of the services
|
||||
- Data within rotated backups that may persist until the retention window expires
|
||||
- Data required for ongoing security operations
|
||||
|
||||
Requesting deletion of data required for security or enforcement purposes may result in loss of access or blacklisting, as that data is necessary to operate the services safely.
|
||||
|
||||
## 11. Children's Data
|
||||
|
||||
Our services are not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete it. Parents or guardians who believe their child has provided data may contact us using the information in Section 12.
|
||||
|
||||
## 12. Changes to This Policy
|
||||
|
||||
We reserve the right to update this Privacy Policy periodically. When changes are made:
|
||||
|
||||
- Users will be notified by email and via our Discord server's announcement channel
|
||||
- Continued use of the services after notification constitutes acceptance of the updated policy
|
||||
- The updated policy takes effect immediately upon publication
|
||||
|
||||
## 13. Governing Law & Severability
|
||||
|
||||
This Privacy Policy is governed by the laws of Sweden and the European Union. If any provision of this policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
|
||||
|
||||
---
|
||||
|
||||
**Contact**
|
||||
|
||||
For questions, concerns, or requests regarding this Privacy Policy:
|
||||
|
||||
- Discord: `@majjoduran`
|
||||
- Email: `support@majjoduran.xyz`
|
||||
Reference in New Issue
Block a user