Privacy Policy
This website does not use advertising or behavior analytics. The hosting provider may process connection data to serve and protect the site. This is separate from the data processed by SCaptcha in a WoltLab installation.
Settings Storage
Your language and display settings are saved in your browser. They are not used to track you across websites.
Where SCaptcha sends data
Core verification
Each challenge uses its own cryptographically random 32-byte salt. Your WoltLab installation validates the salt, hash, algorithm, answer, and HMAC against the issuing session. The challenge expires after 60 seconds and does not require an external CAPTCHA provider.
Proxy check
This option is off by default. If you enable it, SCaptcha sends the visitor's public IP address to proxycheck.io for proxy, VPN, or Tor evidence. SCaptcha 2.3.0 sends tag=0 by default; administrators can opt in to provider logging. The IP address is transmitted for every lookup either way.
Security cookies
A pre-submit marker and the optional text/audio proof are valid for 5 minutes. Under-Attack mode uses a signed, user-agent-bound access cookie for 5 to 30 minutes; the default is 10. Sentinel can store a server-side rejection in a separate signed cookie for 10 minutes. Sentinel itself is off by default.
Analytics and retention
Request analytics are on by default. Logs can contain linkable operational data, including IP address, user agent, request, network and location fields, reasons, and submitted browser telemetry. Retention defaults to 90 days and can be set from 1 to 3,650 days. Turning analytics off stops new collection but does not erase existing rows or exports.
Website Hosting
This website is hosted by Netlify. While we don't collect any data, Netlify may collect basic server logs as part of their hosting service:
Netlify Privacy PolicyContact
If you have any questions about this privacy policy, please contact us:
info@softcreatr.dev