Privacy Policy
Last updated 20 September 2026
Who is responsible
Rocoto (https://www.rocoto.space) is run by the operator of Rocoto. For any privacy question write to yakhv67@gmail.com.
What Rocoto stores
- Your account: username, e-mail address and a password (stored only as a one-way hash, never in readable form).
- Your profile and settings: picture, banner, bio, colours, wallpaper, custom style code, profile song, privacy choices and blocked people.
- What you share: posts, comments, polls and votes, sticky notes, uploaded pictures, audio and video, pathways you create or join, friends and friend requests, your Top 8, notifications and chat messages.
- Technical data: when you visit, the web server records your IP address, the page requested and your browser type in a log. The site also uses your IP address briefly to limit abuse (for example too many login attempts).
Pictures you upload are re-saved on the server: their size may be reduced and hidden data such as camera and location details is removed.
Why, and on what legal basis
- To run your account and the features you use (contract, Art. 6(1)(b) GDPR).
- To keep the site secure, prevent spam and abuse, and fix errors, including the server log (legitimate interest, Art. 6(1)(f)).
- To send you e-mails you asked for: verification and password reset (contract).
- To count visits with analytics, only if you accept it (consent, Art. 6(1)(a)). You can withdraw consent at any time with "Cookie settings" in the page footer.
Cookies and similar storage
- Login cookie (essential): a signed cookie called
session keeps you logged in and protects forms against forgery. It is deleted when you log out or after it expires. It needs no consent.
- Your cookie choice: your answer to the cookie notice is saved in your browser (local storage) so we do not ask again.
- Analytics (optional): if you accept, Rocoto loads Umami, a privacy-friendly analytics tool that Rocoto hosts itself. It sets no cookies and does not see your posts or messages. It records which page was opened, the referring site, browser, device type and country.
Who else receives data
- Hosting: Rocoto runs on a server of Hetzner Online GmbH in Helsinki, Finland. Hetzner processes data on our behalf.
- E-mail: verification and password reset e-mails are sent through Google's Gmail service, so Google receives your e-mail address and the message.
- Icons and scripts: while you are logged in, the icon font comes from Font Awesome (Fonticons, Inc., USA), and the chat page loads a script from cdnjs (Cloudflare, Inc., USA). Those services see your IP address and browser type when they deliver the file.
- Spotify: a profile song is a Spotify player. It is only loaded after you click "Play this profile's song". Then Spotify (Spotify AB, Sweden) receives your IP address and may set its own cookies, under Spotify's privacy policy.
- Other members: what you post is visible to logged-in members according to your privacy settings. Your profile can be limited to friends in Settings.
Google, Fonticons and Cloudflare are based in the USA. They use standard contractual clauses or comparable safeguards for transfers from the EU.
Rocoto does not sell your data and shows no advertising.
How long data is kept
- Account, profile and content: until you delete your account. Deleting it removes your account and content from the live site. Copies in backups are overwritten within about 14 days.
- Unverified accounts: the verification link is valid for 15 minutes; an unverified account can be replaced by a new registration with the same name.
- Server logs: about two weeks.
Your rights
You can ask for access to your data, correction, deletion, restriction, a copy in a common format, and you can object to processing based on legitimate interests. You can delete your account yourself in Settings. For anything else write to yakhv67@gmail.com. You also have the right to complain to your local data protection authority.
Children
Rocoto is for people aged 16 and over. If you believe someone younger has an account, tell us and we will remove it.
Security
Connections use HTTPS, passwords are hashed, and the server is protected by a firewall and limits on repeated login attempts. No system is perfectly secure; tell us at once if you find a problem.
Changes
If this policy changes, the date at the top changes. For big changes, members are told on the site.