export default function PrivacyPage() { return (

Privacy Notice

Last updated: September 2026

1. About this notice

Sloth Manager is a self-hosted application operated by the organisation that deployed it (the operator). This notice describes what personal data Sloth Manager stores, why it stores it, and how long it is kept. It applies to all users of this installation.

2. Data we store

User accounts

DataPurposeRetention
Username Identifies you within the application and appears in the audit log Until the account is deleted by an administrator
Password (bcrypt hash) Authenticates you on login — the original password is never stored Until the account is deleted or the password is changed

Audit log

DataPurposeRetention
Username, timestamp, action, DNS provider, zone, record details Maintains an accountable history of all DNS record changes made through the application Rolling window of the latest 500 entries; oldest entries are removed automatically

Notification settings

DataPurposeRetention
Email address (SMTP "To" field) Sends DNS-change notifications to the configured recipient Until removed from Settings by an administrator
API tokens / URLs (Gotify, ntfy, webhook) Delivers notifications to the configured channels Until removed from Settings by an administrator

SSO (Authentik)

If single sign-on is enabled, Sloth Manager receives your username and email address from Authentik during login. Only the username is stored locally (as a user account). No SSO tokens or session data are persisted beyond the duration of your login session.

3. What we do not store

Login sessions use a short-lived JWT token stored in your browser's local storage. It expires automatically and contains only your username and user ID.

4. Legal basis for processing

Personal data is processed on the basis of legitimate interests — specifically the secure operation of the DNS management tool and maintaining an accountable record of infrastructure changes. User accounts are required to access the application.

5. Data sharing

Sloth Manager does not share personal data with third parties. Data is stored locally on the server where the application is hosted. Notification channels (Gotify, ntfy, SMTP, webhooks) receive message content only — they do not receive account data.

DNS operations are performed against the configured DNS providers (Cloudflare, Loopia, Pi-hole, Azure DNS, cPanel, Technitium). These providers receive only the DNS record data necessary to fulfil each operation — not user or account information.

6. Your rights

Under the GDPR you have the right to access, correct, or erase your personal data. Contact the operator of this installation to exercise these rights. Administrators can:

You can change your own password at any time in 👤 My Profile.

7. Data location & security

All data is stored on the server where this instance of Sloth Manager is hosted. The operator is responsible for securing that server, applying backups, and ensuring appropriate access controls. Passwords are stored as bcrypt hashes (cost factor 10) and are not recoverable.

8. Contact

For questions about how your data is handled, contact the administrator of this Sloth Manager installation.

); }