Privacy Policy
Last updated
This is the privacy policy of Aevonix B.V., trading as Frenzy ("Frenzy", "we", "us", or "our"), a sabotage leaderboard at frenzy.run. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch implementing legislation.
1. Controller contact details
| Name | Aevonix B.V., trading as Frenzy |
| Established in | The Netherlands |
| Business registration | KVK 42123774, VAT NL869834216B01 |
| Registered address | Heresstraat 1, 9665 NV Oude Pekela, the Netherlands |
| Privacy email | hello@frenzy.run |
| Website | https://frenzy.run |
We are not required to appoint a Data Protection Officer (DPO). For privacy questions or to exercise any of the rights below, email hello@frenzy.run.
2. What personal data we process
2.1 Account data
- Email address, used to send a passwordless login link (no password is ever created or stored)
- Hashed, single-use login tokens — never the plaintext link that was emailed to you
- Registration and login timestamps
- An optional second address for notifications only, if you give us one. It is never used to log in, is never verified, and carries none of the ownership meaning your login email does — it exists mainly for accounts that sign in with X and so have no login email at all
- If you sign in with X: the account id X gives us, your handle, and your avatar URL. Never your X password, and never your X email address — we do not ask X for it. Your account is tied to the numeric id, not the handle, so renaming yourself on X does not detach it
2.2 Entry data
- Entry name, URL, domain, tagline, logo, and emoji/color you submit — this is public, shown on the board
- The date your entry's domain was last verified as matching your account email's domain
- Board position history and click count
Your account email is never shown publicly and is never attached to your entry on any public page — only the entry's own public fields above are.
Public listings. Rank, name, tagline, logo, and click count on the board are public — anyone can see them, including search engines. Do not submit a destination if you do not want that information shown. To show a logo, we fetch publicly available metadata (favicon, Open Graph image) from the URL you submit; that fetch may disclose to the destination that Frenzy requested the page. If your site's own metadata doesn't yield a usable icon, we also try two public favicon lookup services — DuckDuckGo's and Google's — sending them only the bare domain, nothing about you or any visitor; neither is contacted when anyone other than us looks at the board.
2.3 Attack, shield and payment data
- The tier, amount paid, and target/attacker entries for every attack you buy or receive
- A snapshot of the attacking and the target entry's name and domain, written onto the attack record at the moment of purchase and never changed afterwards — this is what keeps an attack readable after either entry is renamed or deleted
- For every shield you buy: the pack, the number of charges, the amount paid, the payment reference, and a snapshot of the defended entry's name and domain — the same kind of record as an attack, kept for the same reason. Unlike an attack, a shield purchase is not published on the board; it is your own record and ours
- Whether a payment was later refunded or charged back, and when
- Payment is processed by Mollie — we never see or store your card number
2.4 Technical and security data
- Your IP address, salted and hashed before it is stored or counted — used to rate-limit entry submissions, attacks, and abuse reports, and to cap how many simultaneous live-update connections one visitor can hold open. Frenzy itself never keeps your IP in plaintext, in its database or in memory
- Session cookie for your login — see §3
- Web server access logs, which are the one exception to the line above: like almost every web server on the internet, the one in front of Frenzy records your IP address in plaintext alongside the time, the page requested, and your browser's user agent. We use them only for security and abuse investigation, and they are rotated away — see §6
2.5 Email communications
Every email Frenzy can send you, in full: a login link when you sign in; a submission confirmation when you submit an entry while logged out, which is the link that actually creates it; a confirmation link when you set or change your notification address; a "you got frenzied" notice when one of your entries is attacked; a receipt when you pay for an attack or for shield charges; a moderation notice if we hide or remove one of your entries; and, only for an account that asked for a login link and never clicked it, up to three reminders before that unverified account is deleted (§6). That is the complete list. We do not send marketing email, and there is no newsletter to be added to.
The two receipts are the one kind you cannot turn off, and that is deliberate: they are the record of money you actually paid us, including the payment reference your bank will ask for. Opting out of notices never suppresses them, because charging someone and then withholding the receipt would be both wrong and the surest way to leave you unable to recognise a charge on your statement. They carry no unsubscribe header for the same reason. Everything else above is either something you asked for by clicking, or the frenzied notice, which you can opt out of at any time.
The "you got frenzied" email is capped to a few per hour so one attacker can't turn it into a mail bomb. The frenzied email carries a one-click unsubscribe: your mail client's own unsubscribe button acts on it directly (RFC 8058), and the link inside the email opens a page with a confirm button. Nothing is unsubscribed by a link merely being visited or previewed, so a mail scanner, prefetcher, or corporate link rewriter cannot silently opt you out of a notification you wanted.
3. Cookies
Frenzy sets exactly one cookie: __Host-frenzy_session, an HTTP-only, signed login-session cookie, kept for up to 30 days, or until you log out or delete your account. Logging out and deleting your account both invalidate the cookie on our side and not only in your browser, so an old copy of it stops working rather than quietly staying valid for the rest of the 30 days. It is strictly necessary — it's how we know you're logged in — so it needs no consent banner under the ePrivacy rules, and we don't use it for advertising or tracking. We run no analytics and set no advertising or third-party tracking cookies. If that ever changes, we'll update this section and add a consent banner before we do it.
3a. Sponsor slots
Some boards show a sponsor slot. Those are sold directly by us and the image is a file on our own server: there is no ad network, no third-party script, no third-party cookie, and no pixel. Nothing about you is sent anywhere when one is shown to you.
We do count sponsor slots, because a sponsor is entitled to know what they bought. When a page containing a slot is rendered we add one to a counter on the sponsor's own row, and when someone clicks a slot we add one to a click counter on that same row. That is the whole of it: two running totals attached to the advertisement, no cookie, no identifier, and nothing recorded about the visitor, the visit, or which visits belong together. We can tell a sponsor how many times their image was served; we cannot tell them — or ourselves — anything about who saw it. Counting how many times we displayed something is not tracking you, and keeping that distinction is exactly why these slots use no beacon and no browser storage.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Account creation and passwordless login | Performance of contract (art. 6(1)(b)) |
| Submitting and verifying an entry | Performance of contract (art. 6(1)(b)) |
| Processing an attack purchase | Performance of contract (art. 6(1)(b)) |
| Processing a shield purchase and crediting its charges | Performance of contract (art. 6(1)(b)) |
| Emailing you a receipt for a purchase | Performance of contract (art. 6(1)(b)) — transactional, and not subject to opt-out |
| Charging and accounting for VAT or local sales tax on a purchase | Legal obligation (art. 6(1)(c)) |
| Keeping the public record of an attack after an entry or account is deleted | Legitimate interests (art. 6(1)(f)) — the buyer's record of what they paid for, and a public board whose numbers are real |
| Rate limiting and abuse prevention (hashed IP) | Legitimate interests (art. 6(1)(f)) |
| Keeping web server access logs for security and abuse investigation | Legitimate interests (art. 6(1)(f)) |
| Reviewing abuse reports | Legitimate interests (art. 6(1)(f)) |
| Sending the “you got frenzied” email | Legitimate interests (art. 6(1)(f)) — opt out any time |
| Verifying your identity through X, if you choose to sign in that way | Performance of contract (art. 6(1)(b)) — only when you start it |
We do not build profiles of you as a person and make no automated decisions with a legal or similarly significant effect on you.
5. Sub-processors and third parties
We never sell personal data. We share it only as follows:
| Recipient | Role | Purpose | Data shared | Transfer outside EEA |
|---|---|---|---|---|
| Mollie | Independent controller | Attack payment processing | The email you give Mollie at checkout, payment status | Mollie B.V. is an EU (Dutch) company; any transfer by its own sub-processors outside the EU is governed by Mollie's own privacy notice |
| X (Twitter) | Independent controller | Optional login and identity verification — only if you choose “Continue with X” | That you signed in to Frenzy with X; in return we receive your X account id, handle and avatar URL | Yes — X Corp. is a US company, and what it does with the sign-in is governed by its own privacy notice, not ours |
| Contabo | Processor | Application/database hosting; self-hosted outbound email (DirectAdmin/Exim on the same infrastructure — there is no separate third-party transactional email vendor) | All account, entry, and attack data; for email, the recipient address and message content | No — Germany (EU) |
The Role column distinguishes two relationships: a processor acts only on our instructions (GDPR art. 28); an independent controller decides its own purposes for the data it receives — Mollie processes your payment for its own regulatory and fraud-prevention obligations, governed by its own privacy notice, not just ours.
6. Retention periods
| Data type | Retention | Reason |
|---|---|---|
| Account data (email address, login timestamps) | Until you delete your account | There is a delete-account control on your account page: it deletes the account, its entries, and its login tokens straight away. You can also ask us by email instead. |
| An account that requested a login link but never clicked it (email address only — nothing was ever verified) | Deleted automatically after 30 days, with reminder emails on day 7 and day 15 and a final notice on day 26 | An unclicked login link means nothing was ever proven about that email address, so we don't keep it indefinitely on the strength of a request alone. This never applies to an account that has actually logged in, by email or by X. |
| Entry data | Until you delete the entry, we remove it, or you delete your account | Product feature — your entry stays on the board while it is active. Deleting it does not delete the attack records it appears in; see the next row. |
| Attack records (positions, amounts, timestamps, and the entry name and domain as they were at the time) | Kept indefinitely, as part of the public leaderboard's permanent history — including after either entry, or either account, is deleted | Someone paid for every one of these. Deleting your entry or your whole account takes you off the board, but the attacks you bought and the attacks bought against you stay public and stay attributed to the name and domain in use when they happened. This is the one thing account deletion does not reach — see §8. Your email address was never part of the record. |
| Shield purchase records (pack, charges, amount, payment reference, and the defended entry's name and domain as they were at the time) | Kept indefinitely as a financial record — but the link to your account is removed when you delete it | Someone paid for every one of these, and tax law requires us to be able to account for the money. Unlike an attack record it is never published. Deleting your account severs the account link on these rows, so what remains says what was bought and for how much, not who bought it; deleting the entry likewise severs the entry link, leaving only the name-and-domain snapshot from the time. |
| Hashed IP addresses (rate limiting) | Until the rate-limit window ends, then deleted by a sweep that runs at most once an hour | Kept only long enough to enforce a short, fixed window. The sweep is what makes that a real bound rather than an intention — without it the rows would sit there forever. |
| Login tokens (hashed, single-use) | Deleted once used or expired, by that same hourly sweep — and immediately when you delete your account | A login link is single-use and short-lived, so the hashed row has no purpose afterwards. We never store the plaintext link that was emailed to you. |
| Web server access logs (plaintext IP, timestamp, request, user agent) | Rotated and deleted by the host's log rotation, no longer than 30 days | Security and abuse investigation only. Not analytics, not joined to your account, and not used to build any profile of you. |
| Abuse reports | Retained for moderation history | Needed to spot repeat abuse and to justify a removal decision if it is challenged. |
7. Security
- TLS for all connections
- Login tokens: hashed, single-use, short-lived
- IP addresses: salted and hashed everywhere the application stores or counts them — in the database and in memory alike — and never kept in plaintext by Frenzy itself. The web server's own access logs are the single exception; see §6
- Sessions: HTTP-only, secure cookies
If a personal data breach poses a risk to your rights and freedoms, we report it to the Dutch data protection authority within 72 hours of becoming aware of it (GDPR art. 33), and notify affected users without undue delay if the risk is high (GDPR art. 34).
8. Your rights
| Right | Description |
|---|---|
| Access (art. 15) | Request what data we hold about you |
| Rectification (art. 16) | Have inaccurate data corrected |
| Erasure (art. 17) | Delete your account and its data yourself from your account page, or ask us to |
| Restriction (art. 18) | Have processing temporarily restricted |
| Portability (art. 20) | Receive your data in a machine-readable format |
| Objection (art. 21) | Object to processing based on legitimate interests |
We respond within one month.
You do not have to email us to exercise erasure. There is a delete account control on your account page that immediately deletes your account, its entries, and its login tokens, and invalidates any session cookie for it. What deletion cannot reach is the public record of attacks bought or received (§6). We keep those on overriding legitimate grounds — the record of what other people paid for, and the integrity of a board whose entire premise is that its numbers are real — which is a recognised limit on erasure where processing rests on legitimate interests (art. 17(1)(c), read with art. 21(1)). Those records never contained your email address, and after deletion they carry only the entry name and domain as they stood at the time of the attack. If you think that balance is wrong in your case, tell us at hello@frenzy.run and we will look at it individually.
9. Children
Frenzy is for adults (see Terms §2 Eligibility). We do not knowingly collect personal data from children. If you believe a child has used the Service, contact hello@frenzy.run and we will delete the data we can identify.
10. Complaints
If you are unhappy with how we handle your data, contact hello@frenzy.run first. You also have the right to lodge a complaint with your national data protection authority — for the Netherlands, that is the Autoriteit Persoonsgegevens.
11. Changes to this policy
We may update this policy when the service or applicable law requires it. For material changes we will notify active account holders by email at least 30 days before the change takes effect.
