e621:privacy policy (locked)

Too Long, Didn't Read

We collect only the bare minimum amount of information that is necessary to protect the service against abuse. We do not sell your information to third parties, and we only use it as this document describes.

What information e6AI collects and why

Information from webserver logs

We collect the following information in webserver logs from every visitor:

  • The Internet Protocol (IP) address
  • The date and time of the request
  • The page that was requested
  • The browser user agent string

These items are collected to ensure the security of the service (see "legimitate interests" in the GDPR), and are deleted after 25 days to balance it with user privacy.

Information in cookies

Our cookies for any users of the service may contain this information:

  • The unique session token for the website
  • User preferences
  • One or more "flash" messages (temporary notifications of an action's success or failure, to be displayed at the top of the next page load and then deleted)

Additionally, cookies of users that are logged in will contain this information:

  • An encrypted authentication secret unique to the user to persist their login

Because these are required for authentication, user security, or customization, which are all "legitimate interests", we cannot ask for consent to use cookies.

Information in user-submitted content

User-submitted content is considered by e6AI to collectively refer to any content that you may submit to the site, which includes, but is not limited to, comments, images, dmails, posts, reports, source changes, tag changes, favorites, and votes.

User-submitted content by users (authenticated or not) may have any or all of the following information collected at the time of submission, visible only to site staff:

  • The IP address
  • The browser user agent string
  • The page that initiated the submission

These items are only used for the "legitimate interests" of identifying and controlling abuse of the service and are not shared with any external party.

Information from users with accounts

If you create an account, we require some basic information at the time of account creation, as follows:

  • A username, shown on your profile and user-submitted content
  • A password, stored only as a cryptographic hash
  • An email address, shown only to site staff and used as a means of contact for account control and user requested notifications (verification emails, password reset emails, dmail notifications)

We also store your IP address whenever you log in for security reasons.

Information shared with third-party services

We use a few services for security purposes which use personal information. These are as follows:

  • To protect against Denial-of-Service attacks or similar abuse of our service, we use Cloudflare as a reverse proxy, which uses browser fingerprints and cookies. The Cloudflare Privacy Policy can be found here.
  • To protect against spam, reCaptcha is used. Their privacy policy can be found here.

Information sharing with other parties

Besides services we rely on for security purposes, we only share personal information with third parties in response to court orders.

We display certain statistics about how users use e6AI (for example, about uploads), without any personal or personally-identifying information.

Most forms of user-submitted content (such as comments or uploads) are viewable by anyone, and as such, may be accessed freely by third parties, including search engines. If a person's personal information is put in such content, we may remove if it we deem it to be too sensitive; inform us if you believe something has been shared that is sensitive.

How we secure your information

e6AI takes all measures reasonably necessary to protect account information from unauthorized access, alteration, or destruction.

While in transit, your data are always protected by the latest version of Transport Layer Security (TLS) our software supports. Between our data processor Cloudflare and our service, we use TLS to secure it during transit.

Passwords are hashed using bcrypt.

No method of transmission, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security; we only make a best effort.

Complaints and account Personally-Identifiable Information wiping

If you have concerns or objections about the way e6AI is handling your personal information, please let us know immediately. You may contact us by emailing us directly at [email protected].