1. Scope
This policy covers services operated by the Brokerr project operator:
- the Brokerr public website at https://brokerr.net;
- the documentation at https://docs.brokerr.net;
- the hosted Brokerr OAuth gateway at
auth.brokerr.net; and - privacy-related correspondence sent to the contact below.
It does not govern Plex, Jellyfin, Emby, AniList, MyAnimeList, TMDB, SIMKL, Trakt, Letterboxd, Discord, or other third-party services. Those services process data under their own policies. Independently hosted Brokerr instances are controlled by their respective operators, not by us.
2. Data we process and retention
| Context | Data | Retention |
|---|---|---|
| Website and documentation | IP address, request time, requested host and path, method, response status, user agent, and basic transport metadata in reverse-proxy security logs. Query parameters and request headers are excluded from those logs. | Up to 14 days. |
| OAuth handoff | Selected provider, random session identifiers, hashed claim credential, encrypted provider context and token bundle, status, and timestamps. OAuth codes and tokens are exchanged with the provider selected by you. | Authorization sessions expire after 10 minutes. A completed token bundle remains claimable for up to 5 minutes. Encrypted payloads are removed immediately after acknowledgement, cancellation, or expiry. Terminal session metadata is retained for up to 14 days. |
| Gateway security | Event type, outcome, provider, response status, error category, and HMAC-derived client or session fingerprints. Client fingerprints rotate daily and the security event log does not contain raw IP addresses, tokens, OAuth codes, states, account IDs, or callback URLs. | Security events are retained for up to 14 days. Rate-limit buckets are removed after their window expires. |
| Token refresh | An opaque encrypted refresh handle is processed when a self-hosted instance requests a refresh. The gateway decrypts it for the selected provider and returns a replacement bundle or handle. | The raw handle and provider token are processed for the request and are not written to gateway application or security logs. |
| Correspondence | Your email address, message, and any information you choose to include in a privacy or support request. | For as long as needed to answer the request, document compliance, or resolve a dispute, then deleted when no longer necessary. |
Cookies and analytics
The public website, documentation, and hosted OAuth gateway do not use advertising cookies or first-party product analytics. The gateway does not require a browser account cookie. A self-hosted Brokerr instance uses an essential login session cookie, but that cookie is controlled by the instance operator and is outside our hosted-service processing.
3. Purposes and legal bases
- Delivering the requested OAuth handoff and refresh: performance of the service you request, Article 6(1)(b) GDPR.
- Protecting availability, detecting abuse, and investigating incidents: our legitimate interest in operating a secure service, Article 6(1)(f) GDPR.
- Responding to messages and privacy requests: performance of requested steps, legitimate interests, or compliance with a legal obligation, depending on the request.
- Meeting applicable legal duties: Article 6(1)(c) GDPR where processing is required by law.
Automated rate limits may temporarily reject a request to protect the gateway. We do not use personal data for advertising, behavioral profiling, recommendations, or decisions producing legal or similarly significant effects.
5. Security
Gateway token bundles and provider context are encrypted at rest with AES-256-GCM. Claim credentials are stored only as hashes, sessions are short-lived, delivery requires a separate claim secret, and payloads are erased after acknowledgement, cancellation, or expiry. Access and security logging is minimized, rate-limited, and retained for bounded periods. No internet service is risk-free, so please report suspected exposure promptly to the privacy contact below.
6. Self-hosted Brokerr instances
Brokerr is self-hosted software. Library metadata, viewing history, ratings, mappings, credentials, run history, artwork, and exports are stored by the instance selected by its operator. The software contains no project-operated usage analytics or crash reporting. It communicates with configured sources, targets, mapping services, notification endpoints, and—only when selected—the hosted OAuth gateway.
We cannot access or erase data held only on an independent instance. The person or organization operating that instance decides its purposes, users, retention, security, and legal obligations. Instance operators should read theself-hosted privacy and data-flow guide.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also lodge a complaint with the CzechOffice for Personal Data Protectionor your local EEA supervisory authority.
Privacy-minimized records may not let us identify a person without additional details. When making a request, include the service used, approximate UTC date and time, provider, and relevant technical context, but never send OAuth tokens, passwords, claim secrets, or an unsanitized database.
8. Changes to this policy
Material changes will be published on this page with a new last-updated date. The source history of this page also provides a public record of changes once the project repository is published.
9. Contact
Privacy questions and requests can be sent to [email protected]. Do not include provider credentials or exported personal data unless we explicitly request a secure transfer method.