← MansionNET PRIVACY POLICY 01 SEP 2026

$ man mansionnet-privacy

MansionNET Privacy Policy

Last updated:

MansionNET is an independently operated and primarily self-hosted community based in Serbia.

This privacy policy explains what information MansionNET handles when you use its public and community services, why that information is needed, how long it is kept, and when information may be processed by services outside MansionNET.

The basic approach is simple: collect only what is reasonably necessary to provide and protect a service, avoid retaining user activity where it is not needed, and give operational data a defined lifecycle.

MansionNET does not use advertising networks, behavioural analytics or cross-service tracking profiles, and does not sell personal information.

01. Scope

This policy covers MansionNET's public and community-facing services, including:

  • the MansionNET website;
  • IRC and IRC webchat;
  • SearXNG search;
  • the MansionNET Forum;
  • MansionNET Git / Forgejo;
  • MansionNET Radio;
  • the temporary file-hosting service;
  • the ASCII generator;
  • the public status service; and
  • supporting infrastructure used to operate and protect those services.

02. What MansionNET may process

Different services need different information to function.

Information you deliberately provide

If you create an account or publish content, MansionNET may store information such as your:

  • username or nickname;
  • email address where the service requires one;
  • account settings and authentication information;
  • forum posts and private messages;
  • Git repositories, issues, comments and other repository activity;
  • IRC registration data and MemoServ content;
  • files deliberately uploaded to a service; and
  • other information you choose to submit or publish.

This is service content, rather than operational logging. It normally remains for as long as the account, content or service requires it, or until it is deleted.

Connection and operational information

Internet services necessarily receive some technical information when you connect to them. Depending on the service, this can include:

  • IP address;
  • connection time;
  • requested path;
  • browser or client information;
  • referrer information;
  • TLS or connection status; and
  • security or abuse-prevention events.

MansionNET does not keep all of this information for every service. Public access logging is disabled where it is not useful, and retained operational information is subject to the service-specific periods described below.

Security information

MansionNET may temporarily process connection information for rate limiting, spam prevention, abuse handling, bans and other security measures.

Active bans and similar security rules may remain until their configured expiry or until they are removed by an administrator. Short-lived automated security state can expire much sooner.

If information needs to be preserved because of a specific security incident or abuse investigation, it may be retained beyond its normal automatic rotation period for the duration of that investigation.

03. Service-specific privacy and retention

MansionNET website and public web services

Most MansionNET public web services do not keep conventional public access logs.

The reverse-proxy host keeps general operational system logs for 14 days, with daily journal files and storage limits.

Individual services that intentionally keep access information are described separately below.

SearXNG Search

MansionNET SearXNG does not maintain an intentional search history.

Search query text is excluded from MansionNET operational logs. SearXNG service journals are retained for 7 days, and public reverse-proxy access logging for the search service is disabled.

Temporary hashed information may be used for rate limiting and abuse prevention.

Because SearXNG is a metasearch engine, searches are sent to the selected upstream search providers. Autocomplete and similar functions may also contact the provider configured for that feature.

Image proxying is enabled so that supported image results can be retrieved through MansionNET rather than requiring your browser to contact the source directly.

IRC

Ordinary IRC channel and private-message content is not logged by MansionNET.

The IRC servers do keep limited operational and security information necessary to run the network. This can include connection addresses, timestamps, TLS events, joins, security events and similar server information.

IRC operational and security logs are retained for 7 days, with daily rotation and storage limits.

The public IRC webchat forwards a visitor's real IP address to the IRC server so that normal IRC network security and abuse controls still work.

IRC Services such as NickServ may deliberately store account information including registration details, authentication data, account settings and MemoServ messages. These follow the relevant account or content lifecycle rather than the seven-day operational-log period.

Anope service logs are retained for 7 days, and 3 database backup copies are retained.

Valid bans and security rules remain until their configured expiry or administrative removal.

IRC webchat

The public MansionNET webchat does not provide persistent user accounts, message history or file uploads.

Messages are handled as part of the live IRC connection and are not stored by the webchat as conversation history.

The IRC host's 7-day operational-log policy still applies to the underlying network connection.

MansionNET Forum

The forum deliberately stores the information needed to provide a discussion service, including accounts, posts, topics, private messages and attachments.

phpBB does not retain visitors' public IP addresses as permanent account, post or private-message records. The application sees the internal reverse-proxy address instead.

Current operational retention is:

InformationRetention
Web-server access logs7 days
Host operational journal14 days
Login sessionsapproximately 1 hour
Login-attempt stateapproximately 6 hours
User warningsapproximately 90 days
Administration/moderation historyapproximately 90 days

Posts, topics, attachments and private messages follow their normal content lifecycle rather than being automatically removed after these periods.

Standard account removal may anonymise an account while leaving existing discussions intact.

A fuller removal of authored content and attachments is available by contacting the MansionNET administrator.

Private messages that have already been delivered to another user may remain in that recipient's mailbox after account removal, with the former sender anonymised.

MansionNET Git / Forgejo

Forgejo stores the information required to provide Git hosting, including user accounts, repositories, organisations, issues, comments, SSH public keys, authentication information and project activity.

The public Forgejo access log contains connection and request metadata and is retained for 144 hours (6 days).

Query strings and query information in Referer headers are removed before these requests are written to the access log.

Other Forgejo retention periods are:

InformationRetention
Host operational journal14 days
System notices30 days
Actions logs30 days
Actions artifacts30 days
Contribution/activity history365 days
Actions run/job history365 days

Repositories and other deliberately created project content remain according to their account and repository lifecycle rather than these logging periods.

Forgejo provides normal self-service account deletion. Where a stronger erasure is required, an administrator can perform an administrative purge.

Transactional account email, such as registration, notifications or password-related messages, may be delivered through MansionNET's external mail provider.

Anti-abuse and scraper protection

MansionNET uses security systems to protect public services against abusive automated traffic and scraping.

These systems are not used for visitor analytics.

Request-level logging for the MansionNET scraper/tarpit system is disabled. Short-lived network security sets used by that system expire after approximately 4 hours.

The host's normal operational journal is retained for 14 days.

MansionNET Radio

MansionNET Radio is configured not to build IP-based listener analytics.

Detailed listener records are cleared approximately hourly, while song/station history is retained for 60 days.

Icecast necessarily receives connection information when a listener connects. Completed Icecast log rotations older than 7 days are removed.

The currently active Icecast file rotates by size, at approximately 10 MB. This means an individual entry in the active file can occasionally remain slightly longer than seven days before that file completes its rotation.

Radio administration/audit information is retained for approximately 90 days.

The radio host's general operational journal is retained for 14 days.

Temporary file hosting

Files uploaded to MansionNET's temporary file-hosting service are deliberately short-lived.

Depending on the lifetime selected for the upload, files remain available for between 1 and 24 hours.

Expired files are checked and removed every 5 minutes.

Upload authorisation tokens expire after 15 minutes.

The service does not retain a general log of people who view or download uploaded files.

Temporary uploaded file contents are excluded from MansionNET's regular backup system.

For accountability, the service does keep a separate record associating an upload with the registered uploader and the source IP address used for that upload.

This uploader-accountability record currently has no automatic expiry period. It is retained separately from the temporary uploaded file itself and from general viewer/access logging.

ASCII Generator

The MansionNET ASCII generator runs entirely in your browser.

Images and text supplied to it are processed locally and are not uploaded to a MansionNET backend.

The service has:

  • no user accounts;
  • no database;
  • no external processing API; and
  • no public access logging.

Public status service

The MansionNET status service stores service-availability and performance information rather than visitor analytics.

Availability telemetry is retained for 365 days.

Its host operational journal is retained for 14 days, with a small size-limited application log.

The public status service does not maintain a public visitor-IP history or custom visitor analytics.

04. External services

MansionNET self-hosts its core services, but some functions necessarily communicate with outside providers.

Examples include:

  • SearXNG sending a search to the selected upstream search engines;
  • search autocomplete contacting the configured autocomplete provider;
  • Forgejo sending transactional email through an external mail provider;
  • IRC bot commands that explicitly use an AI service sending the submitted prompt to that provider;
  • YouTube or SoundCloud bot commands sending the requested query or identifier to the corresponding service;
  • DNS providers used to make MansionNET domains reachable; and
  • certificate authorities used to issue TLS certificates.

These interactions happen because the requested function requires the external service. MansionNET does not provide user information to external services for behavioural advertising or cross-service profiling.

External providers operate under their own privacy policies and retention practices.

05. Backups

MansionNET maintains backups so that services can be recovered after data loss, hardware failure or another serious incident.

Affected public MansionNET services use a rolling policy of 30 daily restore points.

There are no additional weekly or monthly archive copies for those public-service backup groups.

Backup garbage collection runs daily.

This is a policy of keeping 30 daily restore points rather than a guarantee that every backed-up byte disappears exactly 30 × 24 hours after deletion. If a backup job stops running, its most recent restore point does not automatically become 30 days old and disappear simply because no new backup replaced it.

Information deleted from a live service can therefore remain temporarily inside existing restore points until those restore points leave the rolling backup set.

Backups are maintained for disaster recovery, not as a separate archive of deleted user content.

Temporary files stored by the MansionNET file-hosting service are excluded from these backups.

06. Account and content deletion

Deletion depends on the service because different types of content behave differently.

Forgejo
Users can delete their own account through Forgejo. Administrative purge is available where stronger removal is needed.
Forum
Account deletion is handled by the MansionNET administrator. Standard deletion may anonymise the account while preserving existing discussions. Fuller removal of authored posts and attachments can be requested. Private messages already delivered to somebody else may remain in their mailbox with the sender anonymised.
IRC
Registered account data follows the account lifecycle. Valid network security records, such as active bans, remain until their configured expiry or administrative removal.

For other MansionNET services, contact the administrator where you cannot remove the relevant information yourself.

Deletion from a live service does not necessarily remove the same information immediately from an existing disaster-recovery backup. Backup copies leave the system according to the backup lifecycle described above.

07. Security

MansionNET uses technical and organisational measures intended to protect the services and the information they hold.

Public web services are provided over encrypted HTTPS connections, and encrypted protocols are used for services such as IRC where supported and configured.

Administrative systems and stored service information are access-controlled, and sensitive operational logs have restricted filesystem permissions.

No internet-connected service can be made risk-free, but MansionNET is operated with the aim of limiting both unnecessary collection and unnecessary retention.

08. Privacy requests

You can contact the MansionNET administrator if you:

  • want to know what account information is associated with you;
  • want an account removed;
  • want fuller removal of content where the service does not provide that directly;
  • believe information is being retained incorrectly; or
  • have a question about this policy.

Use the contact methods published by MansionNET or contact an administrator through the MansionNET community services.

When a request concerns an account or non-public information, you may be asked for enough information to establish that the account or content belongs to you.

Please do not publish sensitive account information in a public IRC channel or forum topic.

09. Changes to this policy

MansionNET services and their technical requirements can change.

This policy will be updated when a meaningful change affects what personal information a public MansionNET service collects, why it is processed, how long it is retained, or which outside service receives it.

The current version and its last-updated date will be published on inthemansion.com.