Stoat Supplement
Read together with the shared Privacy Policy. This supplement only covers what is specific to Stoat; everything else (your GDPR rights, the data controller, law-enforcement disclosure, children’s privacy, storage location, the change process and contact details) is in the shared policy.
Effective for Stoat: 30 Jul 2026
About Stoat
Stoat is a chat application that allows you to communicate with other users through instant messaging, voice or video calls. Stoat is an open-source project; the source code is available on our GitHub.
What we collect on Stoat
- Account Information: We collect data when you register for an account, such as the registered e-mail address, hashed password, and chosen username.
- Servers and Groups: If you create or join a group/server, we collect and store the names of the group/server to provide the service.
- Your Content: To provide the service, we must store your messages and any content such as attachments and reactions.
- Legal Responsibility: To ensure that users satisfy the legal age requirement to use the platform and to provide additional safety for minors, we must collect the user’s date of birth.
- Abuse Prevention: To prevent our service from being attacked and protect your account, we collect your IP address and a short device description for each session, and also temporarily store some device information after initial registration.
- Self-hosted instances: Since self-hosted instances aren’t operated by us, we cannot enforce our own Privacy Policy, Community Guidelines or Terms of Service there. Please visit self-hosted instances at your own discretion.
Service providers for Stoat
In addition to the providers listed in the shared policy, Stoat uses:
- Hetzner, provides us with cloud services to run Stoat.
- Ionos, provides us with cloud services to run Stoat.
- Backblaze, provides us with cloud services to store media at scale.
- hCaptcha, provides us with the tools necessary to stop abuse of our platform (more details in the hCaptcha section below).
- Scaleway, provides us with transactional email delivery.
Changes to service providers and processing regions
We may add, replace or change operational service providers, their subprocessors or processing regions without advance notice to you where reasonably necessary to operate, secure, scale or improve the existing functions described in this policy. For Stoat, these functions include hosting and infrastructure, media storage and delivery, transactional email, security and abuse prevention, real-time messaging, and voice and video communications. This includes adding processing capacity in new regions to maintain or improve real-time voice and video service.
We will update the named provider list above promptly after a change. This exception concerns advance notice to users only; it does not limit any contractual or legal duties concerning processors, subprocessors or international transfers.
We will give advance notice in accordance with the shared Privacy Policy if a change introduces a new processing purpose, materially different categories of personal data or recipients, or a material reduction in your rights or the safeguards used for international transfers.
hCaptcha
This section has been adapted from hCaptcha’s documentation.
We use the hCaptcha anti-bot service (hereinafter “hCaptcha”) on our website. This service is provided by Intuition Machines, Inc., a Delaware US Corporation (“IMI”). hCaptcha is used to check whether the data entered on our website (such as on a login page or contact form) has been entered by a human or by an automated program. To do this, hCaptcha analyzes the behavior of the website or mobile app visitor based on various characteristics. This analysis starts automatically as soon as the website or mobile app visitor enters a part of the website or app with hCaptcha enabled.
When using the Stoat App, hCaptcha will only begin analysis when you:
- Submit a login request.
- Submit a registration request.
- Submit a password reset / email resend request.
For the analysis, hCaptcha evaluates various information (e.g. IP address, how long the visitor has been on the website or app, or mouse movements made by the user). The data collected during the analysis will be forwarded to IMI.
Data processing is based on Art. 6(1)(f) of the GDPR (DSGVO): the website or mobile app operator has a legitimate interest in protecting its site from abusive automated crawling and spam. IMI acts as a “data processor” acting on behalf of its customers as defined under the GDPR, and a “service provider” for the purposes of the California Consumer Privacy Act (CCPA). For more information about hCaptcha and IMI’s privacy policy and terms of use, please visit the following links: https://hcaptcha.com/privacy/ and https://hcaptcha.com/terms.