Privacy Policy
This policy explains what unreliablecode collects about you, why, who else sees it, how long it is kept, and what you can ask us to do with it. It covers the website, the API, the mobile endpoints and the paid services. It is written to be read โ where a section matters to you, the detail is there rather than hidden behind a phrase like "certain information".
1. Who is responsible
unreliablecode, operating unreliablecode.net, is the controller of the personal data described here. Questions, requests and complaints about your data go through a support ticket, which ties the request to your authenticated account โ this matters, because we will not act on a data request we cannot attribute to the account holder.
2. What we collect
What you give us directly
- Account details: username, email address, password (stored only as a salted hash โ never in a readable form), and display name.
- Profile content you choose to add: avatar, bio, links, and anything else you fill into your profile.
- Content you create: posts, comments, blogs, videos, shorts, stories, gallery items, forum threads, chat and direct messages, repositories, gists, Drive files, app submissions and server listings.
- Support correspondence: tickets, replies and any attachments you send with them.
- Commerce data: orders, invoices, wallet transactions, licence keys, HWID values registered to your licences, and the billing details a payment provider passes back to us.
- Learning data: enrolments, lesson progress, code submissions, lab sessions and issued certificates.
What we collect automatically
- IP address, and the approximate city, country, network operator and ASN it resolves to.
- Browser user agent, referring page, request paths, timestamps and response codes.
- A browser fingerprint โ a device identifier derived from browser and hardware characteristics, stored in a cookie and used to detect ban evasion, multi-accounting and fraud.
- Session and authentication records, including sign-in attempts (successful and failed), password resets and API token use.
- Security events raised by the platform's intrusion-detection system: blocked requests, matched attack signatures, rate-limit trips, and details of uploads that failed scanning.
- Operational telemetry for services you run: VPS resource usage, quota consumption, and console access records.
We do not ask for and do not want special-category data โ health, biometrics, political opinions, religious beliefs, sexual orientation. Do not put it in a profile, a ticket or a public post expecting us to protect it as such.
3. Why we hold it
- To run your account and the services โ authenticate you, show your content, deliver the feed, provision servers, apply quotas, issue certificates. Without this data the service cannot function.
- To take and reconcile payments โ generate invoices, credit the wallet, activate licences, handle chargebacks, and keep the accounting records the law requires.
- To keep the platform secure โ detect intrusion attempts, malware uploads, credential stuffing, ban evasion, fraud and abuse. This is the legitimate interest that justifies the IP logging, fingerprinting and security event records above; without them the platform gets taken apart within days.
- To communicate with you โ invoices, expiry and suspension notices, security alerts, password resets, ticket replies and platform announcements. These are service messages and are not optional while you hold an account.
- To comply with the law โ tax and accounting obligations, and responses to valid legal process.
- To improve the platform โ aggregate usage patterns, error rates and performance data, which we use in aggregate rather than to profile individuals.
4. How it is protected
Passwords are stored as salted hashes and are never recoverable, by us or by anyone else. Sensitive personal fields โ including email addresses, IP addresses and location data โ are encrypted at rest with AES-256, with a separate keyed hash used for lookups so that the encrypted value never has to be decrypted just to find a row.
Traffic to the site is served over HTTPS. Access to production systems is restricted to the operators who need it, admin actions against user records are logged, and uploads are scanned before they are made available.
No system is perfectly secure, and we do not claim otherwise. Some records created before at-rest encryption was introduced may still exist in plaintext in older rows pending migration. If we discover a breach that presents a real risk to you, we will notify affected accounts and, where the law requires it, the relevant authority.
5. Who else sees your data
We do not sell your personal data, and we do not rent mailing lists. Data reaches third parties only in these ways:
- Payment providers โ PayPal and Duitku. They receive the transaction data needed to take the payment and handle your payment credentials directly under their own privacy policies; we never receive or store full card or bank numbers.
- IP intelligence โ IP addresses are sent to
ip-api.comto resolve approximate location, network operator and whether an address belongs to a datacentre, proxy or VPN. This drives fraud detection and the security dashboard. - Malware scanning โ file hashes, and in some cases uploaded files themselves, are submitted to VirusTotal for analysis. Files submitted to VirusTotal may be retained and shared with its security-industry partners. Do not upload confidential material to public upload paths on the assumption it stays private.
- Device fingerprinting โ the fingerprinting library is loaded from its vendor's CDN, which necessarily sees your IP address and user agent.
- Advertising networks โ pages carrying third-party adverts load code from those networks, which set their own cookies and collect their own data under their own policies. We do not pass them your account details.
- Infrastructure and delivery โ hosting providers, the SMTP service that sends platform email, and the CDNs serving fonts, icons and libraries.
- Alerting โ where configured, security and billing alerts are relayed to operator channels such as Discord or Telegram. These carry event details, which can include usernames and IP addresses.
- Law enforcement and legal process โ where we are legally obliged to disclose, or where disclosure is necessary to prevent serious harm. Child sexual abuse material is reported without exception.
- A successor โ if the platform is transferred to new operators, account data transfers with it, subject to this policy.
6. What is public by default
Some things are public because the feature only works that way. Assume the following can be seen by anyone, indexed by search engines and archived by third parties beyond our control:
- your username, display name, avatar and profile page;
- posts, comments, blogs, videos, shorts, gallery items and forum activity;
- public repositories and public gists, including everything in their commit history โ a secret committed once and removed later is still in the history;
- leaderboard standing, ranks, badges and public statistics;
- App Store submissions and Minecraft server listings;
- certificates, through their public verification link.
Direct messages, private repositories, private gists, Drive files, tickets, invoices and wallet history are not public. Global chat and group chats are visible to their participants. Nothing on a shared platform is a substitute for encryption you control โ do not send credentials or sensitive documents through chat.
7. Cookies and local storage
We use cookies and browser storage for:
- Session cookies โ keeping you signed in. Strictly necessary; the site cannot work without them.
- CSRF tokens โ protecting forms against cross-site request forgery. Strictly necessary.
- The fingerprint cookie โ a device identifier, retained for up to a year, used for fraud and ban-evasion detection.
- Preferences in local storage โ your chosen background theme, dismissed announcements and similar interface state. This stays in your browser.
- Third-party advertising cookies โ set by advert networks on pages that carry adverts, under their own policies. Blocking them affects adverts, not the platform.
You can clear or block cookies in your browser. Blocking the strictly necessary ones will sign you out and break form submission.
8. How long we keep it
- Account and profile data โ while the account exists, and for a short wind-down period after deletion while backups rotate out.
- Content you posted โ until you delete it. Deleted content is removed from the live platform; copies may persist briefly in backups, and anything others reshared through platform features stays with those copies.
- Invoices, payments and wallet history โ retained for as long as tax and accounting law requires, typically several years, even after account deletion. We cannot delete these on request.
- Security and access logs โ retained on a rolling window sized for incident investigation, then discarded. Records tied to an active abuse investigation or a legal hold are kept until it concludes.
- Server and lab data โ reclaimed on the schedule in the Billing & Refund Policy. Once reclaimed it is unrecoverable.
- Support tickets โ kept as a service record so history is available to whoever handles your next issue.
9. Your rights and choices
Depending on where you live you may have some or all of the following rights. We apply them to every account regardless of jurisdiction, to the extent doing so does not conflict with another legal obligation:
- Access โ ask for a copy of the personal data we hold about you.
- Correction โ fix inaccurate details. Most of it you can edit yourself from your profile and account settings.
- Deletion โ ask for your account and personal data to be deleted. Financial records, and data under legal hold or needed for fraud prevention, are retained as described above.
- Export โ receive your content in a portable form. Repositories and Drive files you can already clone and download yourself.
- Objection and restriction โ object to processing based on legitimate interest, including some security processing. Note that objecting to core security processing may mean we cannot continue to provide the account.
- Complaint โ raise the matter with your local data protection authority if you believe we have handled your data unlawfully. We would rather you came to us first.
Requests go through a support ticket from the account concerned. We respond within 30 days, and will tell you if a request needs longer or cannot be fulfilled in part, with the reason.
10. Children
The platform is not intended for children under 13, and accounts require the minimum age set out in section 3 of the Terms of Service. We do not knowingly collect data from children below that age.
If you believe a child under the minimum age holds an account, tell us through a support ticket. We will verify and delete the account and its data.
11. International transfers
The platform is operated from Indonesia and its infrastructure, payment providers and service vendors are located in several countries. Using unreliablecode necessarily involves transferring your data to those countries, whose data-protection laws may differ from your own. We only use vendors that offer protections appropriate to the data they handle.
12. Changes to this policy
We update this policy when what we do with data changes. The effective date at the top of the page shows the current version, and material changes โ a new category of data, a new recipient, a materially different purpose โ are announced before they take effect.
If you do not accept a change, you can close your account. Continuing to use the platform after a change takes effect means you accept the updated policy.
Questions about this document
Anything specific to your account, an invoice or a takedown request should go through a support ticket so it is on the record and reaches someone who can act on it. General questions are fine in the community channels.