Privacy Policy

Stella Ops follows a zero‑telemetry stance: no Google Analytics, no pixels, no CDN beacons. We only keep data strictly required for security, abuse‑prevention or your optional 333‑scans/day token.

What we store & why

DataPurposeRetention
Access‑log IPDDoS & abuse detection7 days, then sha256(ip)
JWT token‑IDEnforce free‑quota (33 / 333), throttling & nag bannerHash only (sha256(id + salt)) until revoked
E‑mail (token request)Send the signed JWT & optional newsletters• **Subscribed** → kept in plain text. • **No marketing** → hashed after 7 days.
Issue‑tracker cookie
_gitea_session
Keeps you signed‑in to the self‑hosted forgeUntil logout / 30 days inactivity

Quota, throttling & the nag banner

No third‑party resources 🚫

Your rights (GDPR & equivalents)

Contact privacy@stella‑ops.org for access, rectification or erasure. We respond usually as soon as possible but allows up to 30 days.