Privacy Notice
Last updated: 1 August 2026.
This notice explains how we handle personal data under the Swiss Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) and its implementing Ordinance (DPO, SR 235.11).
1. Who is responsible for your data
AS213376 (“Moulticast”) is an IPv6-only network operated for research and education purposes. Moulticast is the controller for the processing described here, within the meaning of Art. 5(j) FADP.
You can reach us about anything in this notice at
noc (at) moulticast -dot- net.
2. What this notice covers
This notice applies to:
- the public website at
moulticast.netandwww.moulticast.net; and - applications hosted on
moulticast.netsubdomains that let you sign in with a third-party account.
It does not apply to external sites we link to, such as PeeringDB, or to the authentication providers themselves. Those operate under their own privacy notices and decide independently how they process your data.
3. The public website
The public website sets no cookies, loads no third-party scripts, fonts, or images, and performs no analytics, tracking, or profiling. You can browse it without providing any personal data.
It is served as static files by SourceHut Pages (pages.sr.ht). As with any web
server, our hosting provider necessarily processes connection data — including
your IP address — in order to deliver the pages to you. Please refer to
SourceHut’s own privacy policy for details of their processing and retention.
4. Signing in with a third-party account
Applications on our subdomains may offer sign-in via Google, GitHub, Discord, or comparable providers. We do not receive or store your password with any of these providers. When you choose to sign in, the provider asks you to authorise the release of a limited set of profile data, which we then receive.
What we receive depends on the provider and on the scopes the application requests. Typically:
| Provider | Data we typically receive |
|---|---|
Account identifier (sub), email address and its verification status, display name, profile picture URL, locale | |
| GitHub | Numeric user ID, username, display name, avatar URL, and email address if that scope is granted |
| Discord | User ID, username and global display name, avatar hash, and email address if that scope is granted |
| Other providers | An equivalent minimal set: a stable account identifier, a display name, and an email address where required |
We request the narrowest scopes each application needs — in most cases an identifier and an email address. We do not receive your contacts, repositories, files, servers, or message history, and we do not post on your behalf.
5. Other data we process
- Account data. The identifier linking your account to the provider you signed in with, plus any profile details you choose to add.
- Content you submit. Anything you deliberately enter into an application.
- Server and application logs. IP address, timestamp, request path, HTTP status, and user agent. Because AS213376 is IPv6-only, these are IPv6 addresses; they are personal data under the FADP just as IPv4 addresses are.
- Security events. Sign-in attempts, including failed ones, and abuse signals.
We do not deliberately collect sensitive personal data within the meaning of Art. 5(c) FADP, and we ask you not to submit any.
6. Why we process it
We process personal data only for the purposes set out below, which are recognisable to you from this notice and from the context in which you provide the data:
| Purpose | What this involves |
|---|---|
| Providing the Services | Creating your account, authenticating you, and running the application you asked for |
| Security and abuse prevention | Keeping the network and services secure, detecting and investigating abuse, diagnosing faults |
| Legal compliance | Meeting obligations that apply to us under Swiss law |
| Optional communications | Only where you have asked for them, such as a mailing list you opted into |
Under the FADP, a private controller does not need to point to a statutory “legal basis” in order to process personal data. Instead we are bound by the processing principles in Art. 6 FADP — lawfulness, good faith, proportionality, purpose limitation, recognisability, and accuracy — and by the data security requirement in Art. 8 FADP. We keep processing to what these purposes actually require.
Where processing would otherwise breach your personality rights under Art. 30 FADP — for example if we processed data against your express objection — we will only continue where there is a justification under Art. 31 FADP, meaning your consent, an overriding private or public interest, or a legal requirement.
Providing data is not a statutory requirement. It is necessary to hold an account: if you do not sign in, you cannot use the applications that require an account, though the public website remains fully available.
We do not sell personal data, and we do not use it for advertising.
7. Cookies and similar technologies
Applications that offer sign-in use a session cookie or equivalent local storage strictly necessary to keep you logged in. Without it, you could not stay signed in.
Art. 45c lit. b of the Telecommunications Act (TCA, SR 784.10) allows processing of data on your device where you are informed about it and about your right to refuse. This notice is that information, and you can refuse by blocking or deleting cookies in your browser — though sign-in will then not work. We use no non-essential or advertising cookies; if that ever changes, we will say so here first.
8. Who your data is disclosed to
- Authentication providers — Google Ireland Ltd. / Google LLC, GitHub, Inc. (Microsoft), and Discord, Inc. — receive the fact that you are authenticating to us, as an inherent part of the sign-in you initiate.
- Our hosting and infrastructure providers, acting as processors under Art. 9 FADP, on our instructions and under contract.
- Public authorities, only where we are legally required to disclose.
9. Disclosure abroad
Google, GitHub, and Discord are established in or transfer data to the United States and other countries outside Switzerland.
Under Art. 16(1) FADP, personal data may be disclosed abroad where the Federal Council has determined that the destination state provides adequate protection; those states are listed in Annex 1 to the DPO. For the United States, this covers organisations certified under the Swiss–U.S. Data Privacy Framework, which the Federal Council recognised as providing adequate protection with effect from 15 September 2024.
Where a recipient is not covered by such a decision, we rely on the safeguards in Art. 16(2) FADP — in particular the Standard Contractual Clauses recognised by the FDPIC — or, exceptionally, on one of the grounds in Art. 17 FADP, such as disclosure being necessary to perform a contract with you. You may request details of the safeguards that apply using the contact address in section 1.
10. How long we keep data
We destroy or anonymise personal data once it is no longer needed for the purpose it was collected for, as required by Art. 6(4) FADP.
| Category | Retention |
|---|---|
| Account data | For as long as your account exists, then deleted within 30 days of deletion |
| Content you submitted | Deleted with your account |
| Server and application logs | 30 days |
| Security and abuse records | 12 months |
| Backups | 30 days rolling |
11. Data security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, and misuse, as required by Art. 8 FADP and Art. 1–6 DPO. All services are reachable over TLS, access to systems is restricted to those who need it, and we keep the data we hold to a minimum.
If a breach of data security occurs that is likely to result in a high risk to your personality or fundamental rights, we will notify the FDPIC as soon as possible in accordance with Art. 24 FADP, and inform you where this is necessary for your protection or where the FDPIC requires it.
12. Your rights
Under the FADP you have the right to:
- request information about whether we process personal data about you, and to receive the details listed in Art. 25 FADP, including the data itself, the purpose, the retention period, its origin, and the recipients of any disclosure abroad. This is normally free of charge, and we may restrict or refuse it only on the grounds in Art. 26 FADP;
- obtain your data in a portable form, or have it transferred to another controller where technically feasible, for data you provided and that we process by automated means in connection with a contract or with your consent (Art. 28 FADP);
- have inaccurate data corrected (Art. 32(1) FADP), or, where neither the accuracy nor the inaccuracy can be established, have it marked as disputed;
- object to processing, and request that we stop the processing, stop disclosing data to third parties, or delete or destroy the data (Art. 30(2)(b) and Art. 32(2) FADP);
- withdraw your consent at any time, where processing rests on it. This does not affect processing carried out before you withdrew;
- have an automated individual decision reviewed by a person, and to state your point of view (Art. 21 FADP) — see section 14.
To exercise any of these, contact us at noc (at) moulticast -dot- net. We
will respond within 30 days, and will tell you if a request needs longer. We may
ask you to prove your identity where we have genuine doubts about who is making
the request.
13. Reporting a concern
If you believe we are handling your data unlawfully, we would like the chance to address it first.
You may also report the matter to the Federal Data Protection and Information Commissioner (FDPIC), which can open an investigation under Art. 49 FADP. Note that, unlike the position in the EU, the FDPIC does not decide individual complaints on your behalf: your own claims — for information, correction, deletion, or to stop processing — are enforced through the civil courts under Art. 32 FADP and the personality-rights provisions of the Swiss Civil Code.
14. Automated individual decisions
We do not take decisions based exclusively on automated processing that have a legal consequence for you or significantly affect you, within the meaning of Art. 21 FADP. Automated anti-abuse measures such as rate limiting may temporarily restrict access, but these do not amount to decisions of that kind, and you can always contact us to have a restriction reviewed by a person.
15. Minors
Our services are not directed at young children. Where a minor is capable of judgement, Swiss law allows them to exercise their own data protection rights; where they are not, a legal representative acts for them. If you believe a child has provided us with personal data that should not have been collected, please contact us and we will delete it.
16. Changes to this notice
We may update this notice as our services change. The “last updated” date at the top reflects the current version. Where a change materially affects your rights, we will give notice by a more direct means than a silent edit — for example, a notice in the application or an email.