Website privacy policy
For riot-the-clanker.com: the site, its addon gallery and the online flasher. Short version: no ads, no analytics, no tracking cookies, and nothing is sold. The site keeps only what it needs to run and to let people publish addons.
Who we are
This site is run by Riøt (RiotTheClanker on GitHub), an individual developer. "We" and "us" below mean Riøt. This policy covers this website (riot-the-clanker.com), its addon gallery and its online flasher.
When you browse the site
The site is hosted on Cloudflare. To send you a page, Cloudflare handles your IP address, your browser's user agent and the address you asked for, as any web host must. We can see short-lived request logs and error logs from Cloudflare for troubleshooting; Cloudflare keeps these for a limited time (days, not months). We don't use them to build profiles of anyone.
There are no analytics, advertising or tracking scripts on this site.
To show the latest releases, the site's server asks GitHub for public release information. That request contains nothing about you.
Other services your browser talks to
Some parts of the site load things from other companies. When your browser does that, those companies receive your IP address and browser details, under their own privacy policies:
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com), for the site's typefaces, on every page. Google's policy.
- cdnjs (cdnjs.cloudflare.com), for a zip library on the ProtoFace flasher page.
- GitHub (github.com, avatars.githubusercontent.com), when you download a release, sign in, or view your profile picture on the addon pages. GitHub's policy.
The site never loads or fetches the links written inside addons. Those are only contacted by the radar app, on the device of someone who installs the addon.
The online flasher
The ProtoFace flasher runs in your browser. The site fetches the firmware you pick from GitHub and hands it to your browser, which writes it to the Pico drive you choose. Nothing on your computer or the board is sent to us.
Signing in with GitHub
You only need to sign in to publish addons. Browsing, checking a file and installing addons don't need an account.
When you sign in, GitHub tells us your public profile: your numeric GitHub id, your username and the address of your profile picture. We ask GitHub for no other permissions. We don't receive your email address or your password, and we don't keep the access token GitHub hands us: it is used once to read your public profile and then thrown away.
Your profile is kept in a signed cookie in your browser for up to 30 days, or until you sign out. It is also stored with any addon you publish.
Publishing and reporting addons
What you publish is public. The addon file, its screenshots, your GitHub username and profile picture, and the dates you published are shown to everyone and can be downloaded by anyone. Don't put personal information, or anyone else's, in an addon.
We also keep:
- Install counts for each addon. Only a running total; not who installed it.
- Upload records (your GitHub id and the time) to limit how often anyone can publish. These are deleted after two days.
- Reports: the reason and any note you write. If you're signed in, your GitHub id is kept with it. If not, we keep a keyed hash of your IP address instead of the address itself, to stop report floods. Reports are kept while we handle them and as a record of moderation.
You can delete your own addons at any time from their pages. The id stays reserved for you so that nobody else can publish something different to the people who installed yours. To have your uploader record removed completely, contact us.
Cookies
The site sets two cookies, both only for signing in and both strictly necessary for it:
| Name | What it's for | How long |
|---|---|---|
rtc_session | Keeps you signed in | 30 days, or until you sign out |
rtc_oauth | Checks the sign-in really came back from GitHub | 10 minutes, during sign-in |
If you never sign in, the site sets no cookies at all.
Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you may have the right to see the personal data we hold about you, to have it corrected or deleted, to object to how it's used, and to complain to a data protection authority. We hold very little: at most your public GitHub profile, your addons and any reports you've made. Contact us and we'll help. We don't sell or share personal information for advertising.
We keep this data because it is needed to run the service you asked for (publishing addons) and because we have a legitimate interest in keeping the site working and free of abuse.
The site isn't aimed at children under 13, and GitHub accounts require users to be at least 13.
Changes
If this policy changes, the new version will be posted here with a new date. The history of every change is public in the site's repository.
Contact
Reach us on Telegram (@RiotTheClanker) for anything private, or an issue on GitHub for anything that can be public.