158 lines
5.9 KiB
JavaScript
158 lines
5.9 KiB
JavaScript
export default function PrivacyPage() {
|
|
return (
|
|
<div className="privacy-page">
|
|
<h2>Privacy Notice</h2>
|
|
<p className="privacy-updated">Last updated: September 2026</p>
|
|
|
|
<section>
|
|
<h3>1. About this notice</h3>
|
|
<p>
|
|
Sloth Manager is a self-hosted application operated by the organisation that deployed it
|
|
(the <strong>operator</strong>). This notice describes what personal data Sloth Manager
|
|
stores, why it stores it, and how long it is kept. It applies to all users of this
|
|
installation.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>2. Data we store</h3>
|
|
|
|
<h4>User accounts</h4>
|
|
<table className="privacy-table">
|
|
<thead>
|
|
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr>
|
|
<td>Username</td>
|
|
<td>Identifies you within the application and appears in the audit log</td>
|
|
<td>Until the account is deleted by an administrator</td>
|
|
</tr>
|
|
<tr>
|
|
<td>Password (bcrypt hash)</td>
|
|
<td>Authenticates you on login — the original password is never stored</td>
|
|
<td>Until the account is deleted or the password is changed</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
<h4>Audit log</h4>
|
|
<table className="privacy-table">
|
|
<thead>
|
|
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr>
|
|
<td>Username, timestamp, action, DNS provider, zone, record details</td>
|
|
<td>
|
|
Maintains an accountable history of all DNS record changes made through
|
|
the application
|
|
</td>
|
|
<td>Rolling window of the latest 500 entries; oldest entries are removed automatically</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
<h4>Notification settings</h4>
|
|
<table className="privacy-table">
|
|
<thead>
|
|
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr>
|
|
<td>Email address (SMTP "To" field)</td>
|
|
<td>Sends DNS-change notifications to the configured recipient</td>
|
|
<td>Until removed from Settings by an administrator</td>
|
|
</tr>
|
|
<tr>
|
|
<td>API tokens / URLs (Gotify, ntfy, webhook)</td>
|
|
<td>Delivers notifications to the configured channels</td>
|
|
<td>Until removed from Settings by an administrator</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
<h4>SSO (Authentik)</h4>
|
|
<p>
|
|
If single sign-on is enabled, Sloth Manager receives your <strong>username</strong> and
|
|
<strong> email address</strong> from Authentik during login. Only the username is stored
|
|
locally (as a user account). No SSO tokens or session data are persisted beyond the
|
|
duration of your login session.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>3. What we do not store</h3>
|
|
<ul>
|
|
<li>Browser cookies or tracking identifiers</li>
|
|
<li>IP addresses or device information</li>
|
|
<li>Analytics or usage statistics</li>
|
|
<li>Any data from third-party advertisers</li>
|
|
</ul>
|
|
<p>
|
|
Login sessions use a short-lived JWT token stored in your browser's local storage.
|
|
It expires automatically and contains only your username and user ID.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>4. Legal basis for processing</h3>
|
|
<p>
|
|
Personal data is processed on the basis of <strong>legitimate interests</strong> —
|
|
specifically the secure operation of the DNS management tool and maintaining an
|
|
accountable record of infrastructure changes. User accounts are required to access
|
|
the application.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>5. Data sharing</h3>
|
|
<p>
|
|
Sloth Manager does not share personal data with third parties. Data is stored locally
|
|
on the server where the application is hosted. Notification channels (Gotify, ntfy,
|
|
SMTP, webhooks) receive message content only — they do not receive account data.
|
|
</p>
|
|
<p>
|
|
DNS operations are performed against the configured DNS providers (Cloudflare, Loopia,
|
|
Pi-hole, Azure DNS, cPanel, Technitium). These providers receive only the DNS record
|
|
data necessary to fulfil each operation — not user or account information.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>6. Your rights</h3>
|
|
<p>
|
|
Under the GDPR you have the right to access, correct, or erase your personal data.
|
|
Contact the operator of this installation to exercise these rights. Administrators can:
|
|
</p>
|
|
<ul>
|
|
<li>View and update your username in <strong>Settings → Users</strong></li>
|
|
<li>Delete your account in <strong>Settings → Users</strong></li>
|
|
<li>Clear the audit log via the Diagnostics page</li>
|
|
</ul>
|
|
<p>
|
|
You can change your own password at any time in <strong>👤 My Profile</strong>.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>7. Data location & security</h3>
|
|
<p>
|
|
All data is stored on the server where this instance of Sloth Manager is hosted.
|
|
The operator is responsible for securing that server, applying backups, and ensuring
|
|
appropriate access controls. Passwords are stored as bcrypt hashes (cost factor 10)
|
|
and are not recoverable.
|
|
</p>
|
|
</section>
|
|
|
|
<section>
|
|
<h3>8. Contact</h3>
|
|
<p>
|
|
For questions about how your data is handled, contact the administrator of this
|
|
Sloth Manager installation.
|
|
</p>
|
|
</section>
|
|
</div>
|
|
);
|
|
}
|