export default function PrivacyPage() { return (
Last updated: September 2026
Sloth Manager is a self-hosted application operated by the organisation that deployed it (the operator). This notice describes what personal data Sloth Manager stores, why it stores it, and how long it is kept. It applies to all users of this installation.
| Data | Purpose | Retention |
|---|---|---|
| Username | Identifies you within the application and appears in the audit log | Until the account is deleted by an administrator |
| Password (bcrypt hash) | Authenticates you on login — the original password is never stored | Until the account is deleted or the password is changed |
| Data | Purpose | Retention |
|---|---|---|
| Username, timestamp, action, DNS provider, zone, record details | Maintains an accountable history of all DNS record changes made through the application | Rolling window of the latest 500 entries; oldest entries are removed automatically |
| Data | Purpose | Retention |
|---|---|---|
| Email address (SMTP "To" field) | Sends DNS-change notifications to the configured recipient | Until removed from Settings by an administrator |
| API tokens / URLs (Gotify, ntfy, webhook) | Delivers notifications to the configured channels | Until removed from Settings by an administrator |
If single sign-on is enabled, Sloth Manager receives your username and email address from Authentik during login. Only the username is stored locally (as a user account). No SSO tokens or session data are persisted beyond the duration of your login session.
Login sessions use a short-lived JWT token stored in your browser's local storage. It expires automatically and contains only your username and user ID.
Personal data is processed on the basis of legitimate interests — specifically the secure operation of the DNS management tool and maintaining an accountable record of infrastructure changes. User accounts are required to access the application.
Sloth Manager does not share personal data with third parties. Data is stored locally on the server where the application is hosted. Notification channels (Gotify, ntfy, SMTP, webhooks) receive message content only — they do not receive account data.
DNS operations are performed against the configured DNS providers (Cloudflare, Loopia, Pi-hole, Azure DNS, cPanel, Technitium). These providers receive only the DNS record data necessary to fulfil each operation — not user or account information.
Under the GDPR you have the right to access, correct, or erase your personal data. Contact the operator of this installation to exercise these rights. Administrators can:
You can change your own password at any time in 👤 My Profile.
All data is stored on the server where this instance of Sloth Manager is hosted. The operator is responsible for securing that server, applying backups, and ensuring appropriate access controls. Passwords are stored as bcrypt hashes (cost factor 10) and are not recoverable.
For questions about how your data is handled, contact the administrator of this Sloth Manager installation.