Controller
The controller responsible for Bassilisk is Konstantin Bobylov, Bernhardstr. 7, 09212 Limbach-Oberfrohna, Germany. Privacy requests: privacy@bassilisk.com.
Bassilisk does not sell personal data, run advertising profiles, or load analytics beacons. This notice still applies to the data required to deliver the website, accounts, community functions, email, and moderation.
Website visits
When you request a page, Cloudflare processes connection data needed to deliver and protect it. This can include IP address, request time, requested URL, response status, browser and device headers, approximate network or region information, and security signals. Bassilisk does not add a separate visitor analytics identifier.
Theme, build-directory layout, and temporary system-diagram display choices can be stored locally on your device. Authentication and temporary sign-in cookies are described in the Cookies and local storage notice.
Accounts and sign-in
Bassilisk processes:
- name, email address when supplied, avatar, username, optional country, profile description, specialties, and profile links;
- Team name, slug, logo, description, country, website, join mode, membership, role, membership status, ownership, moderation state, and pending identity changes when you use Teams;
- the selected sign-in provider and its account identifier;
- email verification state, account role, creation time, and recent activity time;
- session records and temporary OAuth or one-time sign-in records;
- the Terms and Privacy versions presented during onboarding and their timestamps.
Google, GitHub, or Discord supplies a provider account identifier, name, avatar information, and, when available, an email address and its verification state. GitHub access is limited to basic profile and email scopes; Discord access is limited to identity and email scopes. A verified provider email may link that sign-in method to an existing Bassilisk account. OAuth access tokens are used only to complete sign-in and fetch this profile information; they are not stored. Email-link sign-in uses the address you enter. Bassilisk does not receive or store your provider or email-account password.
Contributions and interactions
Bassilisk stores the material you submit: builds, descriptions, images, guides, bills of materials and notes, build-specific part configuration, system diagrams, measurements, uploaded project files, media references, competition and exhibition history, remix relationships, updates, reviews, forum threads and replies, articles and suggestions, and moderation drafts. It also stores actions needed for community features, including follows, saves, votes, helpful marks, notification state, and build-of-the-month selections.
The Parts library stores part and manufacturer records, specifications, taxonomy, images, source links, submitter, correction proposals, base snapshots, review state, moderator feedback, merge targets, and timestamps. Published library data is shared reference material and may be linked from builds by other authors.
Private messaging stores conversation membership, message text, timestamps, unread state, blocks, and reports. Private messages are access-controlled but are not end-to-end encrypted.
Uploaded files include their original filename, size, content type, storage key, author and build association, and upload category. File contents are stored in Cloudflare R2.
If you use Report a problem, Bassilisk stores your report text, the page URL, browser and viewport information, and any screenshot you attach so the issue can be reviewed in Studio.
Communications and email
Private messages are delivered only to the participating accounts. Bassilisk processes and stores them to provide the conversation, unread state, abuse controls, account export, and deletion. A moderator can access a message only when a participant reports that message, or where access is required to meet a legal obligation or address an immediate security risk.
If you request a sign-in link or enable activity notifications, Bassilisk processes your address, message content, notification category, delivery status, retry state, and provider message identifier. You can separately control build updates, build comments, forum replies, review activity, article decisions, build decisions, Parts decisions, Team decisions, and direct-message email in Settings. Direct-message email is off by default. Security and requested sign-in email cannot be disabled while using email-link sign-in.
Messages sent to info@bassilisk.com, legal@bassilisk.com, or privacy@bassilisk.com are routed by Cloudflare to the operator’s Gmail inbox and are processed there to answer the request.
Security, operations, and moderation
Rate-limit counters, security events, moderation decisions, merge targets, rejection reasons, account actions, and operational activity records are processed to prevent abuse, investigate failures, enforce the Terms, and document decisions. These records can contain an account identifier, name, email, affected build, article, part, manufacturer record, Team, forum item, or reported private message, action, reason, and timestamp.
Legal bases
| Purpose | Legal basis |
|---|---|
| Accounts, builds, Parts, Teams, publishing, requested email, and community features | Article 6(1)(b) GDPR — performing the service contract |
| Security, abuse prevention, moderation, service reliability, and limited operational records | Article 6(1)(f) GDPR — legitimate interests in operating a safe and reliable community |
| Responding to legal requests and preserving records required by law | Article 6(1)(c) GDPR — legal obligations |
| Optional activity email settings | Article 6(1)(b) and 6(1)(f) GDPR; you control the delivery categories |
Providing account and contribution data is necessary if you want those features. Bassilisk needs a provider identity or a valid email-link address to create or authenticate an account. Public pages remain available without an account.
Recipients and service providers
- Cloudflare: website delivery, security, Workers execution, D1 database, R2 file storage, operational logs, and inbound email routing.
- Resend: one-time sign-in, account, moderation, message, and other transactional notification email delivery.
- Google: Google OAuth when selected, and Gmail for messages sent to Bassilisk contact addresses.
- GitHub: GitHub OAuth and profile/email API requests when selected; separate authorised CMS administration also uses GitHub.
- Discord: Discord OAuth and profile API requests when selected.
- YouTube and Vimeo: only after you activate an embedded video. No player or remote thumbnail is loaded before that action.
If your profile uses an avatar hosted by Google, GitHub, Discord, or another external image host, viewing a page that displays it contacts that host. The host may receive the visitor's IP address, browser headers, and the page context. You can replace the provider avatar with an uploaded image in Settings.
Data may also be disclosed to authorities, courts, advisers, or affected parties where required by law or necessary to establish, exercise, or defend legal claims. Other authors receive only information made public through the service or directly addressed to them.
International transfers
Some providers may process data outside Germany or the European Economic Area. Where GDPR transfer restrictions apply, transfers rely on an adequacy decision, approved contractual safeguards such as the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism supplied by the provider. Provider locations and safeguards can change; request the current processor information at privacy@bassilisk.com.
Retention
| Data | Retention |
|---|---|
| Account, profile, builds, build parts, diagrams, media and competition records, files, interactions, and notification preferences | Until you delete them or delete your account, unless earlier removal is required |
| Parts library submissions and correction suggestions | Until removed through account deletion or moderation; published shared records may be corrected, merged, archived, or removed earlier |
| Team identity, ownership, membership, roles, and moderation records | Until you leave the Team, the Team is deleted, or you delete your account; an owner’s account deletion deletes the owned Team unless ownership is transferred first |
| Published builds moved to trash | 30 days, unless you restore them before permanent deletion |
| Private messages and conversation state | Until an account participant deletes their account; that account's sent message text is then removed |
| Reported private messages and report decisions | While the report is open and as needed afterward for enforcement or legal claims |
| Active session | 30 days, renewed during active use; removed on sign-out or account deletion |
| Google, GitHub, and Discord OAuth state, redirect, reauthentication-intent, and PKCE verifier cookies where used | 10 minutes |
| One-time email sign-in record | 30 minutes and single use; expired records are pruned |
| Expired rate-limit records | Pruned after their security window expires |
| Completed email-job content | 30 days |
| Email delivery logs | 90 days |
| Operational, activity, and moderation logs | 180 days |
| Contact correspondence | Until the request is resolved, then as required for follow-up or legal claims |
Account deletion removes active D1 records and uploaded R2 objects. Temporary provider recovery copies may remain until overwritten under the provider’s backup cycle. They are isolated from ordinary use and are not restored except for disaster recovery or a legal requirement.
Public information
Published usernames, display names, avatars, profiles, country, Team identity and active membership, builds, build files, part and manufacturer records, submitter attribution, posts, reviews, articles, and visible interaction counts are available to anyone and may be indexed or copied outside Bassilisk. Public build records can include media links, competition history, system diagrams, and remix relationships. Do not publish private contact details or another person’s personal data. Drafts, account email addresses, pending Team identity changes, private messages, saved items, and notification preferences are not public unless you include them in published content yourself.
Your rights
Subject to the GDPR’s conditions and exceptions, you may request access, correction, deletion, restriction, data portability, or objection to processing based on legitimate interests. You may also ask how a particular decision or transfer applies to you. Bassilisk does not use solely automated decisions that produce legal or similarly significant effects.
Download a machine-readable JSON export covering your profile, authentication records, builds and their structured records, Parts activity, Team records, articles, discussions, messages, settings, notifications, and operational records, or delete your account from Settings → Your data. For other requests, email privacy@bassilisk.com. Identity verification may be required before disclosing or deleting data.
Questions and complaints
Contact Bassilisk first so the issue can be investigated. You also have the right to complain to a data-protection supervisory authority, particularly in the EU or EEA state where you live, work, or believe an infringement occurred. For the operator’s location, the competent authority is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte).
Policy changes
The version and effective date identify this notice. Material changes will be presented in the service. Privacy information is acknowledged during onboarding; it is not consent to unrelated processing.