01. Scope
This policy covers MansionNET's public and community-facing services, including:
- the MansionNET website;
- IRC and IRC webchat;
- SearXNG search;
- the MansionNET Forum;
- MansionNET Git / Forgejo;
- MansionNET Radio;
- the temporary file-hosting service;
- the ASCII generator;
- the public status service; and
- supporting infrastructure used to operate and protect those services.
02. What MansionNET may process
Different services need different information to function.
Information you deliberately provide
If you create an account or publish content, MansionNET may store information such as your:
- username or nickname;
- email address where the service requires one;
- account settings and authentication information;
- forum posts and private messages;
- Git repositories, issues, comments and other repository activity;
- IRC registration data and MemoServ content;
- files deliberately uploaded to a service; and
- other information you choose to submit or publish.
This is service content, rather than operational logging. It normally remains for as long as the account, content or service requires it, or until it is deleted.
Connection and operational information
Internet services necessarily receive some technical information when you connect to them. Depending on the service, this can include:
- IP address;
- connection time;
- requested path;
- browser or client information;
- referrer information;
- TLS or connection status; and
- security or abuse-prevention events.
MansionNET does not keep all of this information for every service. Public access logging is disabled where it is not useful, and retained operational information is subject to the service-specific periods described below.
Security information
MansionNET may temporarily process connection information for rate limiting, spam prevention, abuse handling, bans and other security measures.
Active bans and similar security rules may remain until their configured expiry or until they are removed by an administrator. Short-lived automated security state can expire much sooner.
If information needs to be preserved because of a specific security incident or abuse investigation, it may be retained beyond its normal automatic rotation period for the duration of that investigation.
03. Service-specific privacy and retention
MansionNET website and public web services
Most MansionNET public web services do not keep conventional public access logs.
The reverse-proxy host keeps general operational system logs for 14 days, with daily journal files and storage limits.
Individual services that intentionally keep access information are described separately below.
SearXNG Search
MansionNET SearXNG does not maintain an intentional search history.
Search query text is excluded from MansionNET operational logs. SearXNG service journals are retained for 7 days, and public reverse-proxy access logging for the search service is disabled.
Temporary hashed information may be used for rate limiting and abuse prevention.
Because SearXNG is a metasearch engine, searches are sent to the selected upstream search providers. Autocomplete and similar functions may also contact the provider configured for that feature.
Image proxying is enabled so that supported image results can be retrieved through MansionNET rather than requiring your browser to contact the source directly.
IRC
Ordinary IRC channel and private-message content is not logged by MansionNET.
The IRC servers do keep limited operational and security information necessary to run the network. This can include connection addresses, timestamps, TLS events, joins, security events and similar server information.
IRC operational and security logs are retained for 7 days, with daily rotation and storage limits.
The public IRC webchat forwards a visitor's real IP address to the IRC server so that normal IRC network security and abuse controls still work.
IRC Services such as NickServ may deliberately store account information including registration details, authentication data, account settings and MemoServ messages. These follow the relevant account or content lifecycle rather than the seven-day operational-log period.
Anope service logs are retained for 7 days, and 3 database backup copies are retained.
Valid bans and security rules remain until their configured expiry or administrative removal.
IRC webchat
The public MansionNET webchat does not provide persistent user accounts, message history or file uploads.
Messages are handled as part of the live IRC connection and are not stored by the webchat as conversation history.
The IRC host's 7-day operational-log policy still applies to the underlying network connection.
MansionNET Forum
The forum deliberately stores the information needed to provide a discussion service, including accounts, posts, topics, private messages and attachments.
phpBB does not retain visitors' public IP addresses as permanent account, post or private-message records. The application sees the internal reverse-proxy address instead.
Current operational retention is:
| Information | Retention |
|---|---|
| Web-server access logs | 7 days |
| Host operational journal | 14 days |
| Login sessions | approximately 1 hour |
| Login-attempt state | approximately 6 hours |
| User warnings | approximately 90 days |
| Administration/moderation history | approximately 90 days |
Posts, topics, attachments and private messages follow their normal content lifecycle rather than being automatically removed after these periods.
Standard account removal may anonymise an account while leaving existing discussions intact.
A fuller removal of authored content and attachments is available by contacting the MansionNET administrator.
Private messages that have already been delivered to another user may remain in that recipient's mailbox after account removal, with the former sender anonymised.
MansionNET Git / Forgejo
Forgejo stores the information required to provide Git hosting, including user accounts, repositories, organisations, issues, comments, SSH public keys, authentication information and project activity.
The public Forgejo access log contains connection and request metadata and is retained for 144 hours (6 days).
Query strings and query information in Referer headers are removed before these requests are written to the access log.
Other Forgejo retention periods are:
| Information | Retention |
|---|---|
| Host operational journal | 14 days |
| System notices | 30 days |
| Actions logs | 30 days |
| Actions artifacts | 30 days |
| Contribution/activity history | 365 days |
| Actions run/job history | 365 days |
Repositories and other deliberately created project content remain according to their account and repository lifecycle rather than these logging periods.
Forgejo provides normal self-service account deletion. Where a stronger erasure is required, an administrator can perform an administrative purge.
Transactional account email, such as registration, notifications or password-related messages, may be delivered through MansionNET's external mail provider.
Anti-abuse and scraper protection
MansionNET uses security systems to protect public services against abusive automated traffic and scraping.
These systems are not used for visitor analytics.
Request-level logging for the MansionNET scraper/tarpit system is disabled. Short-lived network security sets used by that system expire after approximately 4 hours.
The host's normal operational journal is retained for 14 days.
MansionNET Radio
MansionNET Radio is configured not to build IP-based listener analytics.
Detailed listener records are cleared approximately hourly, while song/station history is retained for 60 days.
Icecast necessarily receives connection information when a listener connects. Completed Icecast log rotations older than 7 days are removed.
The currently active Icecast file rotates by size, at approximately 10 MB. This means an individual entry in the active file can occasionally remain slightly longer than seven days before that file completes its rotation.
Radio administration/audit information is retained for approximately 90 days.
The radio host's general operational journal is retained for 14 days.
Temporary file hosting
Files uploaded to MansionNET's temporary file-hosting service are deliberately short-lived.
Depending on the lifetime selected for the upload, files remain available for between 1 and 24 hours.
Expired files are checked and removed every 5 minutes.
Upload authorisation tokens expire after 15 minutes.
The service does not retain a general log of people who view or download uploaded files.
Temporary uploaded file contents are excluded from MansionNET's regular backup system.
For accountability, the service does keep a separate record associating an upload with the registered uploader and the source IP address used for that upload.
This uploader-accountability record currently has no automatic expiry period. It is retained separately from the temporary uploaded file itself and from general viewer/access logging.
ASCII Generator
The MansionNET ASCII generator runs entirely in your browser.
Images and text supplied to it are processed locally and are not uploaded to a MansionNET backend.
The service has:
- no user accounts;
- no database;
- no external processing API; and
- no public access logging.
Public status service
The MansionNET status service stores service-availability and performance information rather than visitor analytics.
Availability telemetry is retained for 365 days.
Its host operational journal is retained for 14 days, with a small size-limited application log.
The public status service does not maintain a public visitor-IP history or custom visitor analytics.
04. External services
MansionNET self-hosts its core services, but some functions necessarily communicate with outside providers.
Examples include:
- SearXNG sending a search to the selected upstream search engines;
- search autocomplete contacting the configured autocomplete provider;
- Forgejo sending transactional email through an external mail provider;
- IRC bot commands that explicitly use an AI service sending the submitted prompt to that provider;
- YouTube or SoundCloud bot commands sending the requested query or identifier to the corresponding service;
- DNS providers used to make MansionNET domains reachable; and
- certificate authorities used to issue TLS certificates.
These interactions happen because the requested function requires the external service. MansionNET does not provide user information to external services for behavioural advertising or cross-service profiling.
External providers operate under their own privacy policies and retention practices.
05. Backups
MansionNET maintains backups so that services can be recovered after data loss, hardware failure or another serious incident.
Affected public MansionNET services use a rolling policy of 30 daily restore points.
There are no additional weekly or monthly archive copies for those public-service backup groups.
Backup garbage collection runs daily.
This is a policy of keeping 30 daily restore points rather than a guarantee that every backed-up byte disappears exactly 30 × 24 hours after deletion. If a backup job stops running, its most recent restore point does not automatically become 30 days old and disappear simply because no new backup replaced it.
Information deleted from a live service can therefore remain temporarily inside existing restore points until those restore points leave the rolling backup set.
Backups are maintained for disaster recovery, not as a separate archive of deleted user content.
Temporary files stored by the MansionNET file-hosting service are excluded from these backups.
06. Account and content deletion
Deletion depends on the service because different types of content behave differently.
- Forgejo
- Users can delete their own account through Forgejo. Administrative purge is available where stronger removal is needed.
- Forum
- Account deletion is handled by the MansionNET administrator. Standard deletion may anonymise the account while preserving existing discussions. Fuller removal of authored posts and attachments can be requested. Private messages already delivered to somebody else may remain in their mailbox with the sender anonymised.
- IRC
- Registered account data follows the account lifecycle. Valid network security records, such as active bans, remain until their configured expiry or administrative removal.
For other MansionNET services, contact the administrator where you cannot remove the relevant information yourself.
Deletion from a live service does not necessarily remove the same information immediately from an existing disaster-recovery backup. Backup copies leave the system according to the backup lifecycle described above.
07. Security
MansionNET uses technical and organisational measures intended to protect the services and the information they hold.
Public web services are provided over encrypted HTTPS connections, and encrypted protocols are used for services such as IRC where supported and configured.
Administrative systems and stored service information are access-controlled, and sensitive operational logs have restricted filesystem permissions.
No internet-connected service can be made risk-free, but MansionNET is operated with the aim of limiting both unnecessary collection and unnecessary retention.
08. Privacy requests
You can contact the MansionNET administrator if you:
- want to know what account information is associated with you;
- want an account removed;
- want fuller removal of content where the service does not provide that directly;
- believe information is being retained incorrectly; or
- have a question about this policy.
Use the contact methods published by MansionNET or contact an administrator through the MansionNET community services.
When a request concerns an account or non-public information, you may be asked for enough information to establish that the account or content belongs to you.
Please do not publish sensitive account information in a public IRC channel or forum topic.
09. Changes to this policy
MansionNET services and their technical requirements can change.
This policy will be updated when a meaningful change affects what personal information a public MansionNET service collects, why it is processed, how long it is retained, or which outside service receives it.
The current version and its last-updated date will be published on inthemansion.com.