Privacy Notice

Last updated: 1 August 2026.

This notice explains how we handle personal data under the Swiss Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) and its implementing Ordinance (DPO, SR 235.11).

1. Who is responsible for your data

AS213376 (“Moulticast”) is an IPv6-only network operated for research and education purposes. Moulticast is the controller for the processing described here, within the meaning of Art. 5(j) FADP.

You can reach us about anything in this notice at noc (at) moulticast -dot- net.

2. What this notice covers

This notice applies to:

It does not apply to external sites we link to, such as PeeringDB, or to the authentication providers themselves. Those operate under their own privacy notices and decide independently how they process your data.

3. The public website

The public website sets no cookies, loads no third-party scripts, fonts, or images, and performs no analytics, tracking, or profiling. You can browse it without providing any personal data.

It is served as static files by SourceHut Pages (pages.sr.ht). As with any web server, our hosting provider necessarily processes connection data — including your IP address — in order to deliver the pages to you. Please refer to SourceHut’s own privacy policy for details of their processing and retention.

4. Signing in with a third-party account

Applications on our subdomains may offer sign-in via Google, GitHub, Discord, or comparable providers. We do not receive or store your password with any of these providers. When you choose to sign in, the provider asks you to authorise the release of a limited set of profile data, which we then receive.

What we receive depends on the provider and on the scopes the application requests. Typically:

ProviderData we typically receive
GoogleAccount identifier (sub), email address and its verification status, display name, profile picture URL, locale
GitHubNumeric user ID, username, display name, avatar URL, and email address if that scope is granted
DiscordUser ID, username and global display name, avatar hash, and email address if that scope is granted
Other providersAn equivalent minimal set: a stable account identifier, a display name, and an email address where required

We request the narrowest scopes each application needs — in most cases an identifier and an email address. We do not receive your contacts, repositories, files, servers, or message history, and we do not post on your behalf.

5. Other data we process

We do not deliberately collect sensitive personal data within the meaning of Art. 5(c) FADP, and we ask you not to submit any.

6. Why we process it

We process personal data only for the purposes set out below, which are recognisable to you from this notice and from the context in which you provide the data:

PurposeWhat this involves
Providing the ServicesCreating your account, authenticating you, and running the application you asked for
Security and abuse preventionKeeping the network and services secure, detecting and investigating abuse, diagnosing faults
Legal complianceMeeting obligations that apply to us under Swiss law
Optional communicationsOnly where you have asked for them, such as a mailing list you opted into

Under the FADP, a private controller does not need to point to a statutory “legal basis” in order to process personal data. Instead we are bound by the processing principles in Art. 6 FADP — lawfulness, good faith, proportionality, purpose limitation, recognisability, and accuracy — and by the data security requirement in Art. 8 FADP. We keep processing to what these purposes actually require.

Where processing would otherwise breach your personality rights under Art. 30 FADP — for example if we processed data against your express objection — we will only continue where there is a justification under Art. 31 FADP, meaning your consent, an overriding private or public interest, or a legal requirement.

Providing data is not a statutory requirement. It is necessary to hold an account: if you do not sign in, you cannot use the applications that require an account, though the public website remains fully available.

We do not sell personal data, and we do not use it for advertising.

7. Cookies and similar technologies

Applications that offer sign-in use a session cookie or equivalent local storage strictly necessary to keep you logged in. Without it, you could not stay signed in.

Art. 45c lit. b of the Telecommunications Act (TCA, SR 784.10) allows processing of data on your device where you are informed about it and about your right to refuse. This notice is that information, and you can refuse by blocking or deleting cookies in your browser — though sign-in will then not work. We use no non-essential or advertising cookies; if that ever changes, we will say so here first.

8. Who your data is disclosed to

9. Disclosure abroad

Google, GitHub, and Discord are established in or transfer data to the United States and other countries outside Switzerland.

Under Art. 16(1) FADP, personal data may be disclosed abroad where the Federal Council has determined that the destination state provides adequate protection; those states are listed in Annex 1 to the DPO. For the United States, this covers organisations certified under the Swiss–U.S. Data Privacy Framework, which the Federal Council recognised as providing adequate protection with effect from 15 September 2024.

Where a recipient is not covered by such a decision, we rely on the safeguards in Art. 16(2) FADP — in particular the Standard Contractual Clauses recognised by the FDPIC — or, exceptionally, on one of the grounds in Art. 17 FADP, such as disclosure being necessary to perform a contract with you. You may request details of the safeguards that apply using the contact address in section 1.

10. How long we keep data

We destroy or anonymise personal data once it is no longer needed for the purpose it was collected for, as required by Art. 6(4) FADP.

CategoryRetention
Account dataFor as long as your account exists, then deleted within 30 days of deletion
Content you submittedDeleted with your account
Server and application logs30 days
Security and abuse records12 months
Backups30 days rolling

11. Data security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, and misuse, as required by Art. 8 FADP and Art. 1–6 DPO. All services are reachable over TLS, access to systems is restricted to those who need it, and we keep the data we hold to a minimum.

If a breach of data security occurs that is likely to result in a high risk to your personality or fundamental rights, we will notify the FDPIC as soon as possible in accordance with Art. 24 FADP, and inform you where this is necessary for your protection or where the FDPIC requires it.

12. Your rights

Under the FADP you have the right to:

To exercise any of these, contact us at noc (at) moulticast -dot- net. We will respond within 30 days, and will tell you if a request needs longer. We may ask you to prove your identity where we have genuine doubts about who is making the request.

13. Reporting a concern

If you believe we are handling your data unlawfully, we would like the chance to address it first.

You may also report the matter to the Federal Data Protection and Information Commissioner (FDPIC), which can open an investigation under Art. 49 FADP. Note that, unlike the position in the EU, the FDPIC does not decide individual complaints on your behalf: your own claims — for information, correction, deletion, or to stop processing — are enforced through the civil courts under Art. 32 FADP and the personality-rights provisions of the Swiss Civil Code.

14. Automated individual decisions

We do not take decisions based exclusively on automated processing that have a legal consequence for you or significantly affect you, within the meaning of Art. 21 FADP. Automated anti-abuse measures such as rate limiting may temporarily restrict access, but these do not amount to decisions of that kind, and you can always contact us to have a restriction reviewed by a person.

15. Minors

Our services are not directed at young children. Where a minor is capable of judgement, Swiss law allows them to exercise their own data protection rights; where they are not, a legal representative acts for them. If you believe a child has provided us with personal data that should not have been collected, please contact us and we will delete it.

16. Changes to this notice

We may update this notice as our services change. The “last updated” date at the top reflects the current version. Where a change materially affects your rights, we will give notice by a more direct means than a silent edit — for example, a notice in the application or an email.