Privacy Policy

This Privacy Policy explains what data The Bin collects, why it is collected, and how it is used to operate and secure the service.

Last updated: May 19, 2026

1. Data We Collect

2. Why We Collect Data

We collect data to run the service, keep you logged in, protect accounts, prevent abuse, enforce policies, and provide support. This includes anti-scraping controls, suspicious login detection, moderation workflows, and bot/download auditing.

2.2 Why We Keep Subscription and Payment-Status Logs

We keep subscription and payment-status records so we can accurately manage access to subscriber-only features and keep role assignments in sync with current subscription state.

These logs are used for operations, security, and support, and are not sold.

2.1 No Data Sales

We do not sell user data to anyone in any shape or form.

3. Log Retention

Operational logs may be retained for up to 1 year for security, abuse prevention, and support review. In limited cases, relevant records may be retained longer where required for legal compliance or active investigations.

3.1 Retention by Category

Retention periods may differ by category based on risk, support needs, and legal obligations.

3.2 Extended Retention Cases

Some records may be retained beyond normal periods when reasonably necessary for legal obligations, dispute resolution, abuse investigations, account security incidents, fraud prevention, or enforcement appeals.

4. Third-Party Services

The Bin may interact with third-party services and APIs (such as Discord and VRChat) to provide features. The Bin does not modify your third-party account profile settings by default; authenticated sessions are used to communicate with required APIs.

The service may also render, proxy, or link to third-party-hosted images/files where metadata points to external URLs.

4.1 Third-Party Platform Data

When features depend on third-party platforms, we may process account identifiers, role data, API responses, and status metadata required to provide those features. Third-party platforms operate under their own privacy policies and terms.

4.2 Third-Party Limitations

Third-party providers can change API behavior, privacy controls, or policy rules at any time. Those changes may impact feature availability, data handling scope, or account workflows.

5. Security Measures

We use access controls, role checks, logging, and abuse-detection systems to protect the service. Suspicious sign-ins (including unusual VPN/proxy behavior) may trigger automatic logout, temporary lock, or re-verification.

5.1 Access Controls and Monitoring

Security systems may include role-based access controls, command-level audit logs, login/session validation, request-rate controls, and anomaly detection. These controls help prevent unauthorized access and reduce abuse risk.

5.2 Incident Response

When suspicious or abusive behavior is detected, we may investigate relevant logs, temporarily restrict access, require re-verification, or take moderation action. Investigation records may be retained for incident response and prevention of recurrence.

6. User Rights and Requests

You may request account/privacy assistance through official support channels. We may need to verify identity before processing requests. Some records may be retained where required for legal or security reasons.

Data removal instructions are available at /data-removal.

Data removal requests are available. When requested, we will review and remove eligible data where possible, except for records we must retain for security, abuse prevention, or legal compliance.

6.2 Data Access and Correction

You may request correction of inaccurate account-linked data where practical. Some operational logs are immutable audit records and may be preserved as-is to protect integrity of moderation and security history.

6.3 Request Verification

Before processing sensitive privacy requests, we may require verification steps to confirm account ownership and prevent unauthorized disclosure or tampering.

6.1 Age Enforcement

The service is for users age 13 and older. If we determine a user is under 13, the associated account and IP may be blocked from accessing the site.

7. Data Sharing and Disclosure

We do not sell personal data. We may share limited data with service providers or platforms strictly as needed to run core features, enforce security controls, process support operations, or comply with legal obligations.

8. Cookies and Session Technologies

Session and cookie-based mechanisms are used to keep users authenticated, protect accounts, and maintain secure feature access. Disabling required cookies/session storage may prevent normal login and account functionality.

9. Cached and Derived Data

To improve reliability and performance, The Bin may store cached and derived records, including normalized metadata snapshots, local thumbnail/icon copies, and computed counters used by list/detail pages.

10. International and Regional Use

Users are responsible for compliance with local privacy and data-use laws in their jurisdiction. Where local law grants additional rights or restrictions, those laws may apply to your use of the service.

11. Policy Updates

This policy may be updated over time. Continued use of the service after updates means you accept the revised Privacy Policy.

12. Contact

For privacy questions, contact support through the official support path or the Discord server.

13. Processing Boundaries

We process data only for service operation, abuse prevention, security, compliance, and support. We do not use account data for unrelated profiling, behavioral advertising, or third-party ad targeting.

14. Categories of Data Subjects

15. Data Sources

16. Access Control to Stored Data

Stored data is intended to be accessed on a least-necessary basis for operations and user support. Public routes only expose data intended for public rendering, while protected routes enforce account/session checks.

17. Data Accuracy and Sync Behavior

Some values are synchronized from third-party APIs and can be stale, unavailable, or temporarily inconsistent due to upstream outages, cache timing, or delayed refresh cycles.

18. Incident and Abuse Handling Data

When abuse or suspicious behavior is detected, additional analysis of relevant technical metadata may be required to protect users and the service.

Investigation records may be retained longer than default retention windows when necessary for safety, dispute, or compliance reasons.

19. Data Portability and Export Scope

Where practical, account-linked records may be summarized for support/export requests. Export scope may exclude internal security heuristics, abuse-detection internals, and records that would materially weaken platform safety controls.

20. Deletion Scope and Exceptions

Deletion requests are reviewed by data category. Some categories are removable quickly; others may be retained in minimal form for legal/security requirements.

If complete deletion is not possible for a category, records may be minimized, restricted, or de-identified where practical.

21. Storage and Processing Detail

Service data is processed by application components that may use JSON files, database-backed state stores, and operational log files. Different features may read/write data in different storage layers for reliability and recovery.

Storage paths, file formats, and internal schemas can change as the service evolves; policy obligations remain based on data category and purpose, not a fixed implementation detail.

22. Automated Risk Controls

Some security and anti-abuse controls are automated. These systems may temporarily restrict actions when risk signals are detected (for example unusual request patterns, suspicious login context, or policy-evasion behavior).

23. Privacy Request Handling Timeline

Privacy and account-data requests are reviewed in queue order and prioritized by risk/severity. Timing can vary based on verification status, request scope, and whether legal/security review is required.

24. What We Do Not Intentionally Collect

We do not intentionally collect sensitive categories beyond what is operationally necessary for account/service functionality. We do not intentionally build behavioral advertising profiles from private account records.

If users submit optional content that includes personal information, that information may be processed only as needed to deliver the requested service behavior or support outcome.

Related pages: Docs - Terms - Data Removal - About