tinux.dev

Privacy

What tinux.dev stores, why it is needed, who receives it, how long it stays, and how to use your rights.

Controller
Raul Gabriel Podaru
Contact
legal@tinux.dev
Location
Zaragoza, España

Data and purposes

Account
Discord provides the account id, username, avatar and whether its email is verified. tinux.dev stores the id, username, avatar hash and first-login time, but not the Discord email address. This is needed to create and secure the account. GDPR Art. 6(1)(b); Art. 6(1)(f) for security and abuse prevention.
Your content
Host files, Cardstock boards, pictures, share records and ownership links are stored to provide the features you request. GDPR Art. 6(1)(b). Without the account and content data, account-backed features cannot work.
Reports
A report can store the target URL, category, explanation and, except for the child-safety category, the name and email supplied. Signed-in reports can also store the reporter account id. Signed-out rate limiting uses a one-way hash of the connecting IP. GDPR Art. 6(1)(f) for abuse prevention and content safety, and Art. 6(1)(c) where a legal duty applies.
Optional place
If you enable “place from this request”, Cloudflare's approximate location for that request is returned to your browser. The endpoint does not store it; the browser keeps it for one day. GDPR Art. 6(1)(a), consent, which you can withdraw by turning the option off.

Sharing and providers

Links you choose to publish through /i/, /raw/, /cs/ or /b/ can be opened by anyone who has the URL. Do not use a public link for content you want to keep private.

Cloudflare provides the site, database and object storage and therefore processes requests and stored service data. Discord handles OAuth sign-in. A YouTube or Vimeo player added to Cardstock contacts that provider only when the player is loaded.

Cloudflare and Discord can process data outside the EEA. Their current safeguards include the EU-US Data Privacy Framework where applicable and EU Standard Contractual Clauses for transfers that require them.

Cookies and this browser

tinux.dev uses only cookies needed for the requested account and OAuth flow: the session cookie lasts up to 30 days, while sign-in state and the acceptance gate are short-lived. There are no advertising or analytics cookies. Browser-only preferences and the optional saved place stay in local storage on your device.

Retention

Session
Up to 30 days, or until you sign out
Account and content
Until you delete them, the account is erased, or moderation requires removal
Rate limit
The signed-out report key is used for one hour; stale counters are removed during later cleanup
Reports
While a report is open. Closed non-child-safety reports are normally removed after 30 days. Records that must remain for a specific legal or serious-safety need are kept only while that need continues
Bans
A Discord id and reason while an active ban is needed to prevent re-entry
Saved place
One day in your browser, or until you remove it

Your rights

You can ask for access, rectification, erasure, restriction, portability where applicable, or object to processing based on legitimate interests. You can withdraw consent at any time for consent-based processing. Write to legal@tinux.dev. You can also complain to the Agencia Española de Protección de Datos.

Erasing an account removes the account, session and user content. A report or safety record may remain, with account links removed where applicable, only when a legal or serious-safety need still justifies it. tinux.dev does not make automated decisions that produce legal or similarly significant effects.