POLICY / PRIVACY
Your data should have a clear job.
Effective 16 July 2026. This page explains the data used to operate Haradi Bots and the controls available to you.
1. Data we process
We process account details, public profile fields, authentication and device events, content you publish, uploads, messages, follows, reactions, bookmarks, reports, support tickets, notification preferences, and basic request metadata such as IP address and user agent.
2. Why we use it
We use this data to authenticate users, recover accounts, deliver requested email, publish and discover developer work, enable conversations and collaboration, prevent abuse, investigate reports, answer support requests, and keep the service reliable.
3. Storage and service providers
Production application data is stored in PostgreSQL through Supabase. Public profile and publishing media uses a public Supabase Storage bucket; direct-message attachments use a separate private bucket. Transactional email is sent through the configured SMTP provider. A paid VPS may process application requests, background jobs, rate limits, and logs.
4. Browser permissions and on-device choices
Browser notifications are optional and apply only to the browser and device where you enable them. In this phase they work only while Haradi Bots is open. The application does not request or collect device location. A profile location or timezone is text you enter manually, and it is public when saved. This browser may use localStorage only for the on-device privacy notice, dismissed product tips, your browser-notification preference, and your message-sound preference.
5. Public and private data
Published profiles, including any location text you choose to add, build logs, field notes, shipped work, follower relationships, and contribution signals may be visible publicly. Drafts, direct messages, security events, account email, and support tickets are restricted to their intended users and authorized administrators, subject to operational and legal access. Message attachments are served to conversation participants through short-lived signed links.
6. Retention and deletion
Records are kept while needed to provide and secure the service. Content and account deletion removes the original text, files, and recoverable record; a content-free marker and limited security or legal audit metadata may remain where needed to prove the action or protect the service. Deleted content cannot be restored through the site.
7. Your controls
You can edit your public profile, change notification and messaging preferences, manage supported per-device browser permissions, review and revoke devices, export core account records as JSON, and request account deletion. Browser permissions can also be withdrawn through your browser's site settings. For access, correction, deletion, or security questions, use the support form.
8. Security and limits
The application uses password hashing, CSRF protection, session controls, rate limiting, upload validation, security headers, and audit events. No internet service can promise absolute security. Report suspicious access immediately and never send passwords, email codes, or API keys through support.