BondoMod Privacy Notice
Last updated: 26 September 2026
Responsible operator and contact
Responsible operator: Jürgen Ombacher
Address: [Carlo Mierendorff]
Privacy contact: [jurgenombacher@gmail.com]
What the website processes
When you register, BondoMod processes your email address, chosen username and a password hash. The original password is not stored. A profile picture is stored if you upload one. Your account also has an internal identifier and email-verification status.
Registration requires a six-digit verification code. Before verification, registration information and a hash of the code are held temporarily. Codes expire after ten minutes and permit at most five guesses. Expired registration records are cleaned up when subsequent registrations run; expiry does not mean immediate physical deletion.
Successful sign-in creates a session. The website sets a Secure, HttpOnly session cookie with a thirty-day lifetime. The server stores a keyed hash of the session token. Signing out removes that session. Changing your password revokes existing sessions.
For abuse prevention, the account service stores keyed hashes of the connecting IP address and login identifier, along with attempt timestamps. These attempt records are cleaned up after twenty-four hours when the account rate limiter runs.
The website also uses browser storage for device identifiers and optional Discord connection information. Hosting and infrastructure providers may process connection information and operational logs.
Google API access and verification emails
The operator connects a designated Gmail sender account to the server. BondoMod requests only the Gmail permission needed to send emails (`gmail.send`). It uses that connection to deliver account-verification codes to the address supplied during registration.
Website users do not need to connect a Google account or grant Gmail permissions. BondoMod does not request access to users' inboxes, contacts or existing messages. The sender's OAuth credentials are stored as server secrets, not in the public website. Recipient addresses and verification-email content are transmitted to Google to deliver these emails.
Google data obtained through this connection is used for the disclosed email-delivery purpose, not for advertising or sale. BondoMod's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Optional Discord connection
If you choose Discord sign-in, the service processes information supplied through the connection, such as your Discord identifier, username, avatar and relevant membership or role information used for access checks. Discord sign-in is optional for email-and-password registration.
Service providers
Cloudflare provides website hosting and account-service infrastructure. Google provides the Gmail email-delivery connection. Discord processes the optional Discord connection. These providers have their own privacy notices and may process data outside your country.
Account and verification processing is necessary to provide the account service you request (Article 6(1)(b) GDPR). Abuse prevention serves the legitimate interest of protecting accounts and the service (Article 6(1)(f) GDPR). Optional connections are used only when you choose them. International processing is subject to the relevant provider arrangements; contact the operator for information about the applicable safeguards.
Provider information: https://www.cloudflare.com/privacypolicy/ ; https://policies.google.com/privacy ; https://discord.com/privacy .
Retention and privacy requests
Verified account information is retained while the account exists. Contact the operator using the address above to request access, correction or deletion. A self-service account-deletion feature is not currently provided.
Where applicable under the GDPR, you may request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent where processing relies on consent. You may complain to a competent data-protection supervisory authority. Requests are handled within the legally applicable time limits; identity verification may be needed to protect your account.
Account data is retained until account deletion, unless a legal obligation or necessary legal claim requires further retention. Hosting logs and backups follow the infrastructure provider settings and applicable retention policies. Contact the operator for details about retention in those systems. BondoMod does not use the account information described here for advertising or automated decisions producing legal or similarly significant effects.
Payments
An automated paid checkout is not currently enabled. This notice must be updated before introducing payment processing or other materially different uses of personal data.