Privacy notice
We process only what is needed to run the community, keep accounts secure and moderate content. This notice explains where information comes from, how it is used, when it becomes public, and how you can manage it.
Last updated: September 5, 2026
1. Scope
This notice covers the Builders’ Port website and its account, discussion, interaction, search, image and moderation features. Services you reach through third-party sites or links are governed by those third parties’ own privacy rules.
2. What we process
- Account data: display name, email address, verification status, username, avatar, and a secure hash of your password. We never store a readable plaintext password.
- Third-party sign-in data: when you choose to sign in or link with Google or GitHub, we receive the account identifier, basic profile, email address and the authorisation data needed to complete sign-in.
- Profile and public content: your bio, personal website, GitHub/X links, and the posts, replies, tags and images you choose to publish.
- Interaction and moderation data: likes, bookmarks, view-deduplication records, reports, content revisions, moderation reasons and admin audit records. Bookmarks are private by default.
- Device and security data: session identifiers, IP address, browser or device user agent, request timestamps and the error logs needed for sign-in, protection and troubleshooting.
- Communication data: the recipient address, message content and delivery status needed to send verification or password-reset email.
3. Why we use it
- To create and maintain accounts, and to handle sign-in, email verification, password resets and third-party account linking.
- To display, search and manage community content, including replies, accepted answers, likes, bookmarks, view counts and image access.
- To detect spam, abnormal access and account abuse, to enforce the community guidelines and to act on reports.
- To send the service email you trigger yourself, to keep the service stable, and to improve the product.
- To meet legal obligations, respond to lawful requests from authorities, and protect the rights of users, the platform and the public.
4. Cookies and local identifiers
Once you sign in, the authentication system uses the security cookies required to keep your session. A session normally lasts up to 7 days and may be refreshed while you use the site. When you read a post without signing in, the site sets an HttpOnly random identifier named bbs_visitor to deduplicate view counts for the day; it normally lasts 1 day.
- These identifiers exist for sign-in, security and basic statistics. They are not used for cross-site advertising.
- You can clear or block cookies in your browser, but features that depend on being signed in — such as bookmarks — may then stop working.
- The site currently runs no personalised advertising and does not sell personal information.
5. Public content
Posts, replies, usernames, display names, bios and the public links you fill in are visible to anyone on the internet, and may appear in the sitemap, in search results or in third-party caches. Hiding or deleting content on the site does not necessarily remove external search caches or copies other people have saved. Credentials, email addresses and bookmarks are never shown as public profile data.
6. Service providers
We use trusted providers to run the site. The specific vendors may change as the infrastructure changes; the main categories are:
- Vercel: hosting, edge network, serverless functions and private image storage.
- A managed PostgreSQL service: account, content, interaction and moderation data.
- Resend or another email service: verification, password-reset and other necessary service email.
- Google and GitHub: authentication only, and only when you choose to sign in or link an account with them.
7. Sharing, disclosure and cross-border processing
We do not hand personal information to third parties in order to sell user profiles. To deliver the features above, the necessary data may be processed by infrastructure, email or sign-in services located in different countries or regions. Those providers process data under their own terms and privacy policies. Beyond what is necessary to provide the service, what you have authorised, or what the law requires, we do not disclose personal information to unrelated third parties.
8. Retention and deletion
- Accounts and community content are normally kept while the account or the content exists. When you delete content or make a valid deletion request, we act on it within a reasonable scope.
- Security logs, reports, revisions and audit records are kept for as long as needed to resolve disputes, prevent abuse and meet legal obligations.
- Temporary images that were never attached to a post normally enter automatic cleanup after 24 hours.
- Where the law requires continued retention, or immediate deletion is technically impractical, we restrict processing to storage and security protection only.
- Copies in backups, search caches or third-party caches may take extra time to rotate out or expire.
9. Your choices and rights
- You can view and correct your display name, bio and public links in settings. A username currently cannot be changed after it is created.
- You can remove bookmarks, sign out, delete eligible content of your own, or ask us to act on your account and personal information.
- You can choose not to use Google/GitHub sign-in, and you can revoke the authorisation from that third-party account at any time.
- To access, copy, correct, delete or restrict the processing of your personal information, email support@bbs.ss with “Privacy request” in the subject. We may need to verify that the account is yours.
10. Security measures and residual risk
We use transport encryption, server-side access control, password hashing, private object storage, session protection and audit logging of admin actions to reduce risk. No internet service can promise absolute security. Please use a unique strong password, protect your third-party accounts, and avoid leaving secrets in public content.
11. Minors
This community is aimed at people who build and run software commercially, and is not directed at children under 14. Minors should use the service with guardian guidance and should not submit sensitive personal information. If you believe we have collected a minor’s information by mistake, please contact an admin.
12. Contact and updates
For privacy questions, account data requests or security incidents, write to support@bbs.ss. Please do not attach passwords, complete secret keys or unnecessary identity documents to an email or a public post. We update this page when the way we handle information changes materially, and note it in the page date or an announcement.