Privacy

Privacy Policy

This notice explains what the Brokerr project operator processes through the public website, documentation, and hosted OAuth gateway, and how that differs from an independently operated self-hosted Brokerr instance.

Effective 18 August 2026 · Last updated 18 August 2026

1. Scope

This policy covers services operated by the Brokerr project operator:

It does not govern Plex, Jellyfin, Emby, AniList, MyAnimeList, TMDB, SIMKL, Trakt, Letterboxd, Discord, or other third-party services. Those services process data under their own policies. Independently hosted Brokerr instances are controlled by their respective operators, not by us.

2. Data we process and retention

ContextDataRetention
Website and documentationIP address, request time, requested host and path, method, response status, user agent, and basic transport metadata in reverse-proxy security logs. Query parameters and request headers are excluded from those logs.Up to 14 days.
OAuth handoffSelected provider, random session identifiers, hashed claim credential, encrypted provider context and token bundle, status, and timestamps. OAuth codes and tokens are exchanged with the provider selected by you.Authorization sessions expire after 10 minutes. A completed token bundle remains claimable for up to 5 minutes. Encrypted payloads are removed immediately after acknowledgement, cancellation, or expiry. Terminal session metadata is retained for up to 14 days.
Gateway securityEvent type, outcome, provider, response status, error category, and HMAC-derived client or session fingerprints. Client fingerprints rotate daily and the security event log does not contain raw IP addresses, tokens, OAuth codes, states, account IDs, or callback URLs.Security events are retained for up to 14 days. Rate-limit buckets are removed after their window expires.
Token refreshAn opaque encrypted refresh handle is processed when a self-hosted instance requests a refresh. The gateway decrypts it for the selected provider and returns a replacement bundle or handle.The raw handle and provider token are processed for the request and are not written to gateway application or security logs.
CorrespondenceYour email address, message, and any information you choose to include in a privacy or support request.For as long as needed to answer the request, document compliance, or resolve a dispute, then deleted when no longer necessary.

Cookies and analytics

The public website, documentation, and hosted OAuth gateway do not use advertising cookies or first-party product analytics. The gateway does not require a browser account cookie. A self-hosted Brokerr instance uses an essential login session cookie, but that cookie is controlled by the instance operator and is outside our hosted-service processing.

4. Sharing, processors, and international transfers

We do not sell personal data. Data is disclosed only as needed to operate the services:

  • Cloudflare provides DNS, reverse-proxy, and security services for public endpoints and may receive network and request metadata.
  • Hosting infrastructure stores the gateway database and minimized operational logs under the operator's control.
  • Your selected media provider receives the OAuth authorization or refresh request necessary to connect that account.
  • Authorities or professional advisers may receive data only where legally required or necessary to establish, exercise, or defend legal claims.

Cloudflare and selected providers may process data outside the European Economic Area. Their own privacy notices describe the locations and safeguards they use. Brokerr does not send an OAuth request to a provider until a user or self-hosted instance initiates that connection.

5. Security

Gateway token bundles and provider context are encrypted at rest with AES-256-GCM. Claim credentials are stored only as hashes, sessions are short-lived, delivery requires a separate claim secret, and payloads are erased after acknowledgement, cancellation, or expiry. Access and security logging is minimized, rate-limited, and retained for bounded periods. No internet service is risk-free, so please report suspected exposure promptly to the privacy contact below.

6. Self-hosted Brokerr instances

Brokerr is self-hosted software. Library metadata, viewing history, ratings, mappings, credentials, run history, artwork, and exports are stored by the instance selected by its operator. The software contains no project-operated usage analytics or crash reporting. It communicates with configured sources, targets, mapping services, notification endpoints, and—only when selected—the hosted OAuth gateway.

We cannot access or erase data held only on an independent instance. The person or organization operating that instance decides its purposes, users, retention, security, and legal obligations. Instance operators should read theself-hosted privacy and data-flow guide.

7. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also lodge a complaint with the CzechOffice for Personal Data Protectionor your local EEA supervisory authority.

Privacy-minimized records may not let us identify a person without additional details. When making a request, include the service used, approximate UTC date and time, provider, and relevant technical context, but never send OAuth tokens, passwords, claim secrets, or an unsanitized database.

8. Changes to this policy

Material changes will be published on this page with a new last-updated date. The source history of this page also provides a public record of changes once the project repository is published.

9. Contact

Privacy questions and requests can be sent to [email protected]. Do not include provider credentials or exported personal data unless we explicitly request a secure transfer method.