Site policy
Privacy Policy
This policy explains how RootBadger handles account data, public discussion content, private messages, moderation records, logs, cookies, analytics choices, and privacy requests.
Last updated: June 25, 2026
Who we are
RootBadger is an independent discussion platform for hierarchical rb.* groups and threaded posts. For privacy and data requests, contact RootBadger at admin@rootbadger.com.
Information we collect
- Account data: username, email address, password hash, email verification status, account security data, and sign-in records.
- Profile and preference data: display name, bio, website, interests, signatures, posting headers, contact-display settings, newsletter preferences, notification preferences, image preferences, invite links, and theme choices.
- Public discussion data: posts, replies, group proposals, group ownership/moderation records, hashtags, public profile fields, signatures, headers you choose to show, vote/useful-mark signals, and RSS/search-visible content.
- Private messages: messages sent between users, including related metadata needed to deliver and display them.
- Moderation and safety data: reports, cancel requests, bans, standing events, useful-mark audit records, image review records, webhook records, and moderation logs.
- Authentication data: session records, remember-me tokens if selected, mobile app tokens, password reset tokens, and passkey metadata if you use passkey login.
- Logs and technical data: IP address, device/browser information, request timestamps, URLs requested, authentication events, security events, and error/abuse-prevention records.
How we use information and why
- Service operation: to create accounts, authenticate users, show posts, send messages, manage subscriptions, operate RSS/search, and provide requested features.
- Security and abuse prevention: to detect spam, malicious links, flooding, attacks, evasion, account abuse, and other harmful activity.
- Moderation: to review reports, group proposals, image attachments, cancel requests, bans, standing events, and community safety issues.
- Communication: to send verification emails, password resets, account/security notices, direct-reply notifications you enable, private-message notices, and newsletters if you opt in.
- Optional analytics: only after you accept analytics cookies/scripts, to understand site usage and improve RootBadger.
- Legal compliance: to respond to lawful requests, preserve necessary records, or protect RootBadger and its users.
Depending on the situation, the legal basis may be service operation/contract, legitimate interests such as security and moderation, consent for optional analytics and optional email preferences, or legal obligation.
Public content notice
RootBadger is a public discussion platform. Public posts, replies, group pages, selected profile fields, signatures, visible headers, hashtags, and RSS-visible content may be publicly accessible, searchable, indexed by search engines, syndicated through RSS, quoted by other users, archived by third parties, or copied outside RootBadger. Do not post private information you do not want to be public.
Cookies and analytics
RootBadger uses necessary first-party cookies for sessions, CSRF protection, sign-in, security, theme choice, and privacy choices. Optional analytics are off by default and are loaded only after you accept analytics. You can change your choice from the footer Cookie settings link.
See the Cookie Policy for details.
Retention
- Account records are generally retained while your account exists.
- Public posts and replies may remain to preserve thread integrity. If an account is deleted or anonymized, RootBadger may detach or anonymize public content instead of breaking discussions.
- Private messages are retained while needed to provide the messaging feature, unless deleted or hidden according to available controls and operational retention needs.
- Security logs, access logs, moderation records, reports, bans, standing events, and abuse-prevention records are retained only as long as needed for security, reliability, dispute handling, legal obligations, and platform integrity.
- Backups may retain deleted or changed data for a limited rolling period before they expire from backup rotation.
RootBadger should define exact operational retention windows for logs, backups, moderation records, and deleted accounts as the platform matures.
Sharing and service providers
RootBadger may use service providers for hosting, server operation, backups, email delivery, DNS, security, and optional analytics if enabled by consent. Providers process information only as needed to provide those services. RootBadger may also disclose information when required by law, to protect the service, to investigate abuse, or to address security incidents.
If optional analytics are accepted, Google Analytics/Tag Manager may process analytics data. If analytics are rejected, RootBadger does not load those Google analytics scripts.
International transfers
RootBadger and its providers may process information in countries other than your own. Where applicable, RootBadger expects providers to use appropriate safeguards for cross-border processing.
Your privacy rights
Depending on where you live, you may have rights to access, correct, erase, restrict, export, or object to processing of your personal data. You may also withdraw consent for optional analytics at any time using Cookie settings, and you may complain to your local data protection authority.
To make a request, email admin@rootbadger.com or see Privacy Requests. RootBadger will generally respond within 30 days and may need to verify your identity before acting on a request.
Account deletion and public post behavior
RootBadger does not currently provide fully automated self-service account deletion or data export. You can request deletion, anonymization, correction, or export by emailing admin@rootbadger.com. Public discussion content may be retained, detached, anonymized, or removed depending on thread integrity, safety, legal, and moderation needs.
Children
RootBadger is not intended for children under 13. If RootBadger later targets users in places with higher child-consent age rules, the minimum age policy should be reviewed.
Automated decisions
RootBadger uses automated signals for security, spam prevention, moderation assistance, standing, rate limits, and reduced friction. These systems support operation and review; they are not intended to make solely automated legal or similarly significant decisions about users.
Security
RootBadger uses HTTPS, secure session handling, CSRF protection, password hashing, security headers, rate limits, moderation tools, and audit records to protect the service. No service can guarantee perfect security, so users should use strong passwords and avoid posting private information publicly.
Policy changes
RootBadger may update this policy as the site, app, infrastructure, analytics choices, or legal requirements change. Material updates should be reflected by changing the Last updated date.