Privacy Policy
Plain and short: collect only what is needed, never set analytics cookies, and lay out exactly what happens to the data we do hold.
Last updated: July 4, 2026
Overview
This Policy walks through what data we collect when you build profiles, share links, or upload images on ciota.lol, why we collect it, and how we handle it once it is in. Analytics here are deliberately light, and we do not use cookies for them. Using the Service means you accept the practices described below.
Changes to this Privacy Policy
We can update this Policy when something about how we handle data changes, like new features, new providers, or new legal requirements. Updates go live when we publish them here or send them your way another way, and continuing to use ciota.lol after that means you have accepted the new version. Worth a glance every now and then.
Information we collect
We try to collect only what is actually needed to keep ciota.lol running reliably and safely. When you sign up or manage your account, we get the details you give us, plus a few abuse-prevention signals we capture at the moment of each account action. Passwords are stored using industry-standard hashing. We log the IP used at signup and at each login for safety and fraud-prevention reasons. If you change your email, we may keep the old one on file for a short while, for account integrity, fraud prevention, or legal compliance, and we never use it to message you. Once it is no longer needed, the old address is deleted for good.
While you are signed in, we hold a server-side session so we know who you are across requests. The session record carries a session token tied to your account and some context: the IP address, the browser and operating system, a device type and device name, the city and country we estimate from your IP, a device fingerprint, and a risk score. We use this for sign-in, to surface suspicious activity, and so you can review and revoke active sessions yourself from your settings.
Public profile pages get cookie-free, lightweight analytics so creators can see how their pages perform and which links get clicked. When someone views a page or clicks one of its links, we record a small event: the page owner, the visitor IP, an estimated country and city, a device type, the browser user agent, and when the action happened. Link events also store the destination URL and label. If the visitor is signed in, the event is linked to their account so creators do not see inflated self-views, and we store a hashed Cloudflare Turnstile token used to tell humans from bots. We do not set analytics cookies for this.
When something on the site breaks or behaves oddly, we record a short diagnostic event. That can include the account ID if you are signed in, the session ID, the IP, and the browser or device type. The point is to find and fix bugs, keep things stable, and head off abuse. These logs are not used for advertising, analytics, or behavioral tracking.
Image-host uploads come with the metadata we need to actually serve the file: the account doing the upload (uploads can also be anonymous), the storage key, the original filename, file size and type, a SHA-256 hash of the contents for deduplication and integrity, the public URL and any custom domain, an optional expiry, and the upload time. Uploads made through an image-host API key are flagged as such, and we capture the request user agent at upload for abuse prevention.
When you write in, or when we send you a service email, we process the message and the metadata around it so we can answer, provide support, and let you know when something material changes for your account or for the Service.
Device signals and fraud prevention
To keep ciota.lol free of bots, spam, ban evasion, and abusive multi-account activity, we generate a device signal for account actions and certain protected requests. On the browser side we use FingerprintJS to compute a stable visitor ID from signals your browser already exposes, like browser and operating system, screen properties, installed fonts, canvas and rendering behavior, language, and timezone, along with a confidence score for how reliable that ID is.
On the server side we also derive a hashed signal from request metadata, including the IP address, user agent, and the accept, accept-language, and accept-encoding headers your browser sends. We store the device fingerprint and a risk score on your session, and we use Cloudflare Turnstile to challenge traffic that looks automated.
We use these signals to tell real visitors from automated scripts, to detect when several accounts share the same device, IP, or payment method (including ban evasion and coordinated abuse), and to enforce bans and our Terms. This is fraud and abuse prevention only. We do not use these signals for advertising or to build behavioral profiles for marketing.
Cookies
We do not use cookies for analytics on ciota.lol. The cookies and similar technologies we do use are strictly necessary: they keep you signed in, protect the account, prevent abuse, and make the core features work. Switching them off would break the Service, so we do not offer a toggle for them.
ciota.lolsits behind Cloudflare, which uses its own cookies and similar identifiers for things like load balancing, network routing, security, DDoS mitigation, and the Turnstile challenge that keeps bots out. Those Cloudflare cookies are technically necessary to keep the Service available and protected from hostile traffic. Cloudflare’s own cookie and privacy practices live at cloudflare.com/privacypolicy.
Non-essential cookies you can manage in your browser settings. Disabling the essential ones or the Cloudflare security cookies will likely break access to the Service or hurt its performance.
How we use your information
The data above is what we use to keep ciota.lol running and improving: authenticating users, maintaining secure sessions, rendering public profiles and links, measuring views and link performance without cookies, finding and fixing bugs, monitoring uptime and reliability, blocking fraud and spam, helping with support tickets, processing purchases, complying with legal obligations, and enforcing our Terms. Diagnostics and telemetry stay scoped to performance and security work, nothing else.
Marketing and communications
If you have opted in, we may send the occasional email about new features, product updates, promotions, or other ciota.lol news. We only send marketing emails where the law allows it or where you have explicitly told us yes.
Unsubscribing is one click: every marketing email has the link in the footer, and you can also write to support@ciota.lol if that is easier. Opting out does not stop the essential stuff like transactional or account emails; those keep coming.
Legal bases
Where the law (such as the GDPR) asks us to identify a legal basis for processing, here are the ones we rely on: performing our contract with you (running the Service, including paid features), our legitimate interests (security, abuse prevention, cookie-free analytics, product improvement), your consent where we ask for it, and our legal obligations alongside lawful requests we receive.
Data retention and deletion
Data sticks around only as long as the purposes in this Policy, or the law, require it. Analytics and diagnostic events are retained so creators can see historical performance and so we can investigate abuse, and they are removed when they are no longer needed or when the account is deleted. Sessions end when they expire or you revoke them. Image-hosting records live as long as the files do, or until any expiry configured for the file runs out.
Once a deletion request is verified, your personal account data and the content you posted are permanently removed from our active systems, and there is no rolling that back. A handful of system logs and backups linger for a short while for security, integrity, and legal-compliance reasons, then get rotated out automatically. After that, deleted data is not kept around for analytics, business reasons, or any other operational use.
Disclosure of your information
We do not sell personal data, full stop. We do share data with service providers who process it on our behalf to actually deliver the Service: cloud hosting, content delivery and edge security, payment processing and billing, email delivery, and anti-abuse tooling. Each of those is locked into confidentiality and use-limitation obligations.
We may also disclose information when the law or valid legal process requires it; when it is needed to protect users, the public, or the Service; or as part of a corporate transaction involving ciota.lol, in which case any successor will be bound by terms at least as protective as the ones in this Policy. Legal process and law-enforcement requests can be sent to legal@ciota.lol.
Third-party links and services
ciota.lolpages link out to third-party sites, services, and profiles that we do not run or control. The moment you follow one of those links or interact with content from another platform, the data you share there is governed by that third party’s own privacy policy, terms, and data practices, not ours. We do not monitor, endorse, or take responsibility for how those services collect, use, or protect your information.
That covers any link or embed someone has put on their ciota.lol page, plus any integration or external platform you have connected to your own account. Before you click through or hand any personal data to a third party, take a look at their privacy policy.
Payments and billing
Card payments on ciota.lol run through Stripe, our authorized card-payments processor. PayPal payments run through Paddle, our authorized PayPal processor. Whichever rail you use, your card or PayPal details, billing address, and transaction data are collected and stored by the processor under their own privacy and security policies, not ours.
ciota.lol does not receive or store full card numbers or PayPal credentials. The only payment data we keep is the slim slice we need to verify the purchase, activate the right features, prevent fraud, and back up support. Sensitive payment info travels straight between you and the processor over an encrypted connection.
For the full picture on how each processor handles your personal and payment data, their privacy policies are at stripe.com/privacy (Stripe) and paddle.com/legal/privacy (Paddle).
International transfers
Our infrastructure and service providers operate across more than one country. Where the law calls for it, we put cross-border transfer safeguards in place and apply technical and organizational measures so your information stays protected wherever it is processed.
Security
Personal data is protected with a mix of administrative, technical, and physical safeguards, including encrypted transport, access controls, and ongoing monitoring. No system is fully bulletproof, so we will not claim absolute security. If you think someone got into your account who should not have, write to support@ciota.lol right away.
Data protection rights
Under the EU’s General Data Protection Regulation (GDPR) and comparable regimes elsewhere, you have specific rights over the personal data we hold. ciota.lol applies these principles globally, so wherever you are based, you can ask us to confirm whether we hold information about you, request a copy of that data, and receive it in a commonly used digital format. If anything we hold is wrong or incomplete, you can ask us to correct or update it.
You can also ask for your data to be deleted outright. Once we have verified your identity and confirmed the request, we will permanently wipe your personal information and posted content from our active systems, except for the slim retention we need for legal obligations, fraud prevention, dispute resolution, or service integrity. If you think we are processing your data unlawfully or going past the consent you gave, you can ask us to pause certain processing or object to processing based on legitimate interest entirely.
When our use of your data is based on consent, you can withdraw it whenever you like, and that does not change the legality of anything we did before you pulled it. ciota.lol does not run automated decision-making or profiling that would have a significant legal or personal effect on you. If you are not happy with how we are handling your data, you have the right to lodge a complaint with your local data-protection authority. We would ask you to talk to us first so we can try to fix it directly, but the right is yours either way.
To view, edit, correct, or delete personal information, the quickest path is your account settings; otherwise email support@ciota.lol. If you have lost access to your account, support can still process a manual deletion request. We respond to verified data requests within the deadlines the relevant law sets, and we may ask for reasonable identity proof first so we do not end up handing your data to the wrong person.
Children’s information
ciota.lol is not built for children under 13, or whatever higher minimum age applies in your country. We do not knowingly collect personal information from anyone below the applicable age. If you think a child has shared personal information with us, write to support@ciota.lol and we will take it from there.
Contact
Questions, concerns, or anything that needs sorting out, write to support@ciota.lol. Legal requests and data protection matters go to legal@ciota.lol.
See also our Terms of Service.