Ruination BotsBack to site

Privacy Policy

Last updated 2026-09-03

This policy explains what personal data Ruination Bots processes, why, on what legal basis and for how long, and what rights you have. It is written to meet Articles 12 to 14 of the General Data Protection Regulation (GDPR) together with the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

Ruination Bots has not opened yet: there is no signup, and the pages you can reach are this one, the Legal Notice and a contact form. So this policy is short, and deliberately - it covers what actually happens when you visit, and nothing else. It will grow when the service does.

1.Who is responsible

The controller for the processing described in this policy, within the meaning of Art. 4(7) GDPR, is:

Controller
Youri Hoffmann
Address
c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Germany
Data protection officer
We are not required to appoint one under Art. 37 GDPR / § 38 BDSG and have not done so. Please direct all privacy enquiries to the address above; they are handled by the operator personally.

2.Technical logs

Our hosting providers keep short-lived server logs containing IP addresses and request metadata for the operation and security of the service, for at most 30 days. This happens whenever a page is served, whether or not you have an account.

Legal basis
Art. 6(1)(f) GDPR. Our legitimate interest is keeping the service available and being able to investigate an attack on it. We weighed this against your interests and reduced it accordingly: request bodies are never logged, nothing is used to build a profile, and the logs expire on their own.
Kept
at most 30 days.

3.Analytics and tracking

We use no third-party web analytics, no advertising networks, no tracking pixels and no profiling on this website. Nothing on these pages reports your visit to anyone, and there is no third-party script to report it with.

4.Cookies and local storage

We store information on your device only where it is strictly necessary to provide the service you requested. Under § 25(2) no. 2 TDDDG that requires no consent, which is why you are not shown a cookie banner. We would rather not have one than have one that asks for nothing.

These public pages set nothing of their own - no cookie, no local storage, no identifier. Cloudflare, which sits in front of them and is listed under who else sees your data, sets one cookie of its own when it has to tell automated traffic from people. That is a security measure rather than a measurement of you, and it is strictly necessary in the same sense.

NameTypePurposeDuration
cf_clearanceCookieSet by Cloudflare once your browser has passed its bot check, so that the check does not have to be repeated on every request.One year, or until you clear it.

5.The launch notification list

The front page has a form that takes an email address so we can tell you, once, when the service opens. That announcement is the only message we send unless you separately ask for more.

A second box, and it is optional. Under the first one there is a second, unticked box asking whether you also want occasional emails about the product after launch. It is a separate decision and it is never a condition: the announcement is sent either way, and leaving it empty changes nothing else. Ticking it changes exactly one thing about what we store, which is that your address is kept until you withdraw instead of being deleted a week after the announcement.

Confirmation first. Anyone can type anyone's address into a public form, so entering one does not put it on the list. We send a single, deliberately plain email asking whether the request was yours, and nothing is recorded as a subscription unless you click the link in it. If it was not you, ignoring that email ends the matter and you will not hear from us again. The link stops working after 72 hours.

What we collect
Your email address, your language, the times the request and the confirmation arrived, salted one-way hashes of your address and of the two IP addresses they came from, the exact wording you agreed to, and which of the two boxes you ticked. Not your name, and not your browser user agent.
Why
To send you one email announcing that the service is open, and to be able to show that you asked for it. If you ticked the second box, also to send you occasional emails about the product: a handful a year, never anybody else’s advertising.
Legal basis
Your consent, under Art. 6(1)(a) GDPR and § 7(2) no. 2 UWG, for the emails themselves. For keeping the consent record afterwards, Art. 6(1)(f) GDPR: our legitimate interest is being able to demonstrate consent as Art. 7(1) GDPR requires, and to defend a claim that we mailed somebody who had not asked. That is also what fixes its length, at §§ 195 and 199(1) BGB.
Kept
A request nobody confirms is deleted after 7 days. A confirmed address is deleted within 7 days of the announcement going out, and immediately if you withdraw before then. If you ticked the optional second box, your address is instead kept until you withdraw, which every email we send links to in one click. What outlives all of those is the record described above with the address removed from it, until the end of the third calendar year after the request (§§ 195, 199(1) BGB).
Recipients
Our email provider, as a processor under Art. 28 GDPR, and our network provider, which sees the request in transit. Both are listed under who else sees your data. Nobody else, and nothing is passed to anyone for their own advertising.
Withdrawal
At any time, under Art. 7(3) GDPR, from the link in either email or by writing to [email protected]. It takes effect immediately and deletes the address. The link in the confirmation email works before you confirm as well as after, so if that email was not something you asked for you can have the address deleted straight away rather than waiting for the request to expire. Withdrawing does not affect the lawfulness of anything sent before it.

Spam protection. The form is defended the same way the contact form is, and for a sharper reason: a signup form sends mail to an address the person filling it in chose, so an unprotected one is a way to have our domain deliver unwanted mail to a stranger. There is a hidden field only an automated sender would fill in, a proof-of-work the browser has to compute, a limit on how many messages one connection may cause, and a separate limit on how often any one address can be sent a confirmation however many connections are used. The connection limits work from a salted, one-way hash of your IP address held only in the server's memory. As with the contact form, we deliberately use no captcha service.

The form answers the same way whatever the outcome. If an address is already on the list, the page says exactly what it says for a new one. That is deliberate: anybody can type your address into it, and an answer that varied would tell them whether you had signed up.

Age

Consent is the legal basis here, and German law sets the age for valid consent to information society services at 16 (Art. 8(1) GDPR with the German derogation). If you are under 16, do not use this form without the consent of the holder of parental responsibility. If you believe somebody under 16 has signed up without it, tell us and we will delete the record.

6.When you write to us

Our contact page lets you reach us without an account. Whatever you type there goes to our mailbox and nowhere else - it is not written to our database, so there is no second copy of your enquiry sitting in a system you would have to ask us to search.

What we collect
The category you pick, your email address, a subject, your message, and your name if you choose to give one. The name is optional and nothing depends on it.
Why
To read your enquiry, answer it, and keep track of it if it takes more than one exchange.
Legal basis
Art. 6(1)(b) GDPR where your message concerns a contract with us or steps taken before entering one; Art. 6(1)(f) GDPR otherwise, our legitimate interest being the ability to respond to people who contact us. Where a message asks us to do something the law obliges us to do - a data subject request, a takedown - Art. 6(1)(c) applies as well.
Kept
Your message is until your enquiry is fully dealt with, then deleted - unless the exchange counts as a commercial or business letter, in which case §§ 257 HGB, 147 AO require it to be kept for 6 or 10 years.
Recipients
Our email provider, as a processor under Art. 28 GDPR - the same one listed under who else sees your data. Nobody else.

Spam protection. The form is protected by a hidden field that only an automated sender would fill in, a check that the form was on screen for at least a few seconds, and a limit on how many messages one connection may send. That limit works from a salted, one-way hash of your IP address, held only in the server's memory, for at most 24 hours, and never written to disk - which is why a restart resets it. The legal basis is Art. 6(1)(f) GDPR and our interest in a contact route that still works when somebody points a script at it. We deliberately do not use a captcha service, because the usual ones would load third-party code into the page and send your IP address to their operator.

This particular form sends no automatic acknowledgement, so it cannot be used to have mail delivered to an address that is not yours. The confirmation shown on screen after sending, including its reference number, is your record that the message went out. The launch notification list does send a confirmation email, and the section on it describes what stops that being abused the same way.

7.Who else sees your data

We do not sell personal data and we do not share it for anyone else's marketing. Data is disclosed only to the providers we need in order to run the service, each bound by a data processing agreement under Art. 28 GDPR and permitted to act only on our instructions:

ProviderPurposeLocation
Supabase
Supabase, Inc., 970 Toa Payoh North, Singapore (US/EU operations)
Database, authentication and file storage for account data, bot configuration and avatars.eu-north-1 (Stockholm, Sweden) - inside the EU/EEA
Railway
Railway Corp., 2261 Market Street, San Francisco, CA 94114, USA
Application hosting for the dashboard, API and bot workers, including the job queue.europe-west4 (Amsterdam, Netherlands) - inside the EU/EEA
Cloudflare
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (German subsidiary: Cloudflare Germany GmbH, Rosenheimer Str. 143C, 81671 München, AG München HRB 242623)
Content delivery, TLS termination, DDoS protection and bot filtering in front of the website, the dashboard and the API. Sees the IP address, the request metadata and the user agent of every request, including on these public pages.Global anycast network - requests are normally served from the nearest edge location, which for European visitors is inside the EU/EEA, but EU-only processing is not contractually guaranteed on this plan
Brevo
Brevo, a trading name of SENDINBLUE SAS, 17 rue Salneuve, 75017 Paris, France (RCS Paris 498 019 298)
Delivery of every email this platform sends: the account welcome message, contact form enquiries, moderator invitations, bot alerts, the weekly recaps, and the launch notification list. Receives the recipient address and the message.Data centres in France - inside the EU/EEA. The provider states, however, that data may also reach countries without an adequacy decision, in particular the United States and India, through its own sub-processors.

We may also disclose data where we are legally obliged to, for example to law enforcement on a valid order, or where necessary to establish, exercise or defend legal claims (Art. 6(1)(c) and (f) GDPR).

8.Transfers outside the EU/EEA

Some of the providers above are established in the United States or operate infrastructure there. Where personal data leaves the EU or EEA, the transfer is covered by one of the safeguards in Chapter V GDPR - as a rule the European Commission's Standard Contractual Clauses under Art. 46(2)(c), supplemented by technical measures such as encryption in transit and at rest, and where applicable the adequacy decision for the EU–U.S. Data Privacy Framework under Art. 45.

You can request a copy of the safeguards in place at [email protected]. We would also point out honestly that United States authorities may have access rights that have no equivalent under EU law, and that enforceable data subject rights against such access may be limited.

9.Your rights

You have the following rights in respect of your personal data:

  • Access (Art. 15 GDPR) - confirmation of whether we process your data, a copy of it, and the details of that processing.
  • Rectification (Art. 16 GDPR) - correction of inaccurate data and completion of incomplete data.
  • Erasure (Art. 17 GDPR) - deletion where one of the listed grounds applies.
  • Restriction (Art. 18 GDPR) - of processing in the cases set out there.
  • Data portability (Art. 20 GDPR) - the data you provided, in a structured, commonly used, machine-readable format.
  • Objection (Art. 21 GDPR) - to processing based on legitimate interests, on grounds relating to your particular situation. Where data is processed for direct marketing you may object at any time, without giving reasons, and we will stop.
  • Withdrawal of consent (Art. 7(3) GDPR) - at any time, with effect for the future.
  • Complaint (Art. 77 GDPR) - to a supervisory authority, in particular in the member state of your residence, place of work or the alleged infringement.

To exercise any of these, write to [email protected]. We answer within one month and will tell you if we need longer, as Art. 12(3) GDPR permits in complex cases. There is no charge unless a request is manifestly unfounded or excessive.

Competent supervisory authority

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf

10.Whether you have to provide data

You are under no obligation to give us anything, and there is no contract or law requiring you to. Two places on this site accept data at all. The contact form needs an email address for the single reason that we cannot answer you without one, and a name only if you feel like giving one. The launch notification list needs an address because an announcement has to be sent somewhere; refusing has no consequence beyond not being told, and the front page tells you what the product is either way.

11.Automated decision-making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR. Automated technical measures such as rate limiting and abuse detection may temporarily restrict access to the API; these are protective measures, they are reviewable by a human on request, and they do not evaluate personal aspects.

12.Security

We apply technical and organisational measures appropriate to the risk under Art. 32 GDPR, in particular:

  • TLS encryption for all traffic between your browser, our API and our providers.
  • Least-privilege access: administrative database credentials exist only on the server side and are never exposed to the client.
  • Request bodies excluded from all application logging, because they can carry credentials.
  • Automatic expiry of the logs we do keep, and hashing of IP addresses rather than storing them.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours under Art. 33 GDPR and inform you directly where Art. 34 requires it.

13.Children and young people

Where we rely on your consent, German law sets the age for valid consent to information society services at 16 (Art. 8(1) GDPR in conjunction with the German derogation).

Today that means one thing: the launch notification list. It is the only processing on this site that consent is the basis for, and it is the only thing on these pages a person under 16 should not use without the consent of the holder of parental responsibility.

If you believe somebody under 16 has given us consent without that authorisation, contact us at [email protected] and we will delete the record and stop anything it would have caused to be sent.

14.Changes to this policy

We update this policy when the service changes or the law does. The date at the top always shows the current version. The service is not open yet, and this policy describes only what happens while that is true - opening it up will add the sections that then apply, in the same change that makes them apply.