1. Controller
The controller is the operator of the True MP NPC project and this website at truenpc.brokebackboys.org. The only public contact channel is reserved for responsible security reports; the site does not accept general visitor submissions. The project does not appoint a data protection officer because it does not conduct large-scale or high-risk monitoring.
2. Data we process
For basic audience measurement, the site processes the requested page, time, IP address, and a shortened user-agent value. The IP address and user-agent are immediately transformed with a secret-keyed, daily one-way hash; the raw values are not stored in the project database. Aggregates contain page views and estimated unique visits by day and hour. While a public page remains visible, a small activity signal updates the anonymous hash, page, and last-seen time so the administrator can see the number of visitors active within the last five minutes.
The site no longer accepts visitor messages. Historical submissions received through the removed form may remain under the retention policy below, but no public interface or API can create or read them.
If you choose “Never show again” on the AI-assistance disclosure, one non-identifying preference is stored locally in your browser. It is not transmitted to or stored by the site. Cloudflare may process connection and security data when delivering and protecting the site. Its processing is governed by Cloudflare’s applicable privacy terms.
3. Purposes and legal bases
We use aggregated audience information to understand whether project documentation is useful, and connection-derived security signals to prevent abuse. We rely on legitimate interests in operating, improving, and securing this non-commercial project. Historical submissions are retained only for the limited period stated below and are no longer collected.
4. Retention
Daily unique identifiers are deleted after 400 days. Hourly aggregates are retained for 90 days. Hourly unique identifiers, live activity records, and rate-limit records are normally deleted after two days. Historical messages from the removed form follow the previously stated retention schedule: archived records are scheduled for deletion after 180 days. Security logs held by infrastructure providers may follow their own retention periods.
5. Recipients and transfers
Data is available only to the authorised site administrator and infrastructure providers needed to host, secure, and deliver the site, including Cloudflare. Those providers may process data outside the European Economic Area under the safeguards described in their own terms. We do not sell personal data, run advertising profiles, or disclose message content publicly.
6. Your rights
Depending on the circumstances, you may have rights of access, correction, deletion, restriction, portability, or objection. Historical anonymous messages were stored without a sender identity or reply address, so the operator may be unable to associate one with a particular person. You may complain to your local supervisory authority; in Finland this is the Office of the Data Protection Ombudsman.
7. Security and changes
Administrative access is separately authenticated, stored data is kept outside the public source tree, raw IP addresses are not persisted in the application database, and submissions are validated and rate limited. No internet service can promise absolute security. Material changes to this notice will be posted here with a new update date.