Data Processing & Privacy Position (GDPR)
SCaptcha is self-hosted. SoftCreatR does not receive or process end-user data during normal operation.
Position statement
SCaptcha runs entirely within your WoltLab Suite installation. All verification data stays inside your infrastructure unless you enable an optional external lookup.
For standard self-hosted deployments, no processing relationship is created between you and SoftCreatR.
Where SCaptcha sends data
Core verification
Each challenge uses its own cryptographically random 32-byte salt. Your WoltLab installation validates the salt, hash, algorithm, answer, and HMAC against the issuing session. The challenge expires after 60 seconds and does not require an external CAPTCHA provider.
Proxy check
This option is off by default. If you enable it, SCaptcha sends the visitor's public IP address to proxycheck.io for proxy, VPN, or Tor evidence. SCaptcha 2.3.0 sends tag=0 by default; administrators can opt in to provider logging. The IP address is transmitted for every lookup either way.
Security cookies
A pre-submit marker and the optional text/audio proof are valid for 5 minutes. Under-Attack mode uses a signed, user-agent-bound access cookie for 5 to 30 minutes; the default is 10. Sentinel can store a server-side rejection in a separate signed cookie for 10 minutes. Sentinel itself is off by default.
Analytics and retention
Request analytics are on by default. Logs can contain linkable operational data, including IP address, user agent, request, network and location fields, reasons, and submitted browser telemetry. Retention defaults to 90 days and can be set from 1 to 3,650 days. Turning analytics off stops new collection but does not erase existing rows or exports.
Roles under GDPR
You act as the data controller for any personal data processed by SCaptcha. SoftCreatR is not a data processor in normal self-hosted use because we do not receive the data.
As a result, a Data Processing Agreement under GDPR Art. 28 is typically not required for standard deployments.
Download the Data Processing Agreement (DPA)