Files
sloth-manager/frontend/src/components/PrivacyPage.js
T

158 lines
5.9 KiB
JavaScript

export default function PrivacyPage() {
return (
<div className="privacy-page">
<h2>Privacy Notice</h2>
<p className="privacy-updated">Last updated: September 2026</p>
<section>
<h3>1. About this notice</h3>
<p>
Sloth Manager is a self-hosted application operated by the organisation that deployed it
(the <strong>operator</strong>). This notice describes what personal data Sloth Manager
stores, why it stores it, and how long it is kept. It applies to all users of this
installation.
</p>
</section>
<section>
<h3>2. Data we store</h3>
<h4>User accounts</h4>
<table className="privacy-table">
<thead>
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
</thead>
<tbody>
<tr>
<td>Username</td>
<td>Identifies you within the application and appears in the audit log</td>
<td>Until the account is deleted by an administrator</td>
</tr>
<tr>
<td>Password (bcrypt hash)</td>
<td>Authenticates you on login — the original password is never stored</td>
<td>Until the account is deleted or the password is changed</td>
</tr>
</tbody>
</table>
<h4>Audit log</h4>
<table className="privacy-table">
<thead>
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
</thead>
<tbody>
<tr>
<td>Username, timestamp, action, DNS provider, zone, record details</td>
<td>
Maintains an accountable history of all DNS record changes made through
the application
</td>
<td>Rolling window of the latest 500 entries; oldest entries are removed automatically</td>
</tr>
</tbody>
</table>
<h4>Notification settings</h4>
<table className="privacy-table">
<thead>
<tr><th>Data</th><th>Purpose</th><th>Retention</th></tr>
</thead>
<tbody>
<tr>
<td>Email address (SMTP "To" field)</td>
<td>Sends DNS-change notifications to the configured recipient</td>
<td>Until removed from Settings by an administrator</td>
</tr>
<tr>
<td>API tokens / URLs (Gotify, ntfy, webhook)</td>
<td>Delivers notifications to the configured channels</td>
<td>Until removed from Settings by an administrator</td>
</tr>
</tbody>
</table>
<h4>SSO (Authentik)</h4>
<p>
If single sign-on is enabled, Sloth Manager receives your <strong>username</strong> and
<strong> email address</strong> from Authentik during login. Only the username is stored
locally (as a user account). No SSO tokens or session data are persisted beyond the
duration of your login session.
</p>
</section>
<section>
<h3>3. What we do not store</h3>
<ul>
<li>Browser cookies or tracking identifiers</li>
<li>IP addresses or device information</li>
<li>Analytics or usage statistics</li>
<li>Any data from third-party advertisers</li>
</ul>
<p>
Login sessions use a short-lived JWT token stored in your browser's local storage.
It expires automatically and contains only your username and user ID.
</p>
</section>
<section>
<h3>4. Legal basis for processing</h3>
<p>
Personal data is processed on the basis of <strong>legitimate interests</strong> —
specifically the secure operation of the DNS management tool and maintaining an
accountable record of infrastructure changes. User accounts are required to access
the application.
</p>
</section>
<section>
<h3>5. Data sharing</h3>
<p>
Sloth Manager does not share personal data with third parties. Data is stored locally
on the server where the application is hosted. Notification channels (Gotify, ntfy,
SMTP, webhooks) receive message content only — they do not receive account data.
</p>
<p>
DNS operations are performed against the configured DNS providers (Cloudflare, Loopia,
Pi-hole, Azure DNS, cPanel, Technitium). These providers receive only the DNS record
data necessary to fulfil each operation — not user or account information.
</p>
</section>
<section>
<h3>6. Your rights</h3>
<p>
Under the GDPR you have the right to access, correct, or erase your personal data.
Contact the operator of this installation to exercise these rights. Administrators can:
</p>
<ul>
<li>View and update your username in <strong>Settings → Users</strong></li>
<li>Delete your account in <strong>Settings → Users</strong></li>
<li>Clear the audit log via the Diagnostics page</li>
</ul>
<p>
You can change your own password at any time in <strong>👤 My Profile</strong>.
</p>
</section>
<section>
<h3>7. Data location &amp; security</h3>
<p>
All data is stored on the server where this instance of Sloth Manager is hosted.
The operator is responsible for securing that server, applying backups, and ensuring
appropriate access controls. Passwords are stored as bcrypt hashes (cost factor 10)
and are not recoverable.
</p>
</section>
<section>
<h3>8. Contact</h3>
<p>
For questions about how your data is handled, contact the administrator of this
Sloth Manager installation.
</p>
</section>
</div>
);
}