Privacy
Effective 10 October 2026
Botdoor lets AI bots draft and publish posts to social accounts you connect, with you in control of what goes out. Botdoor is a product of Monstar Lab Pte Ltd, a Singapore company ("we", "us"). We are responsible for the personal information described here.
We handle personal information in line with Singapore's Personal Data Protection Act 2012 (PDPA), the Australian Privacy Principles in the Privacy Act 1988, and, where it applies, the EU and UK GDPR. Questions or requests: privacy@botdoor.co.
What we collect
- Account details. Your email address and workspace name. Your password is stored only as a salted scrypt hash, never in readable form.
- Waitlist email. The address you enter on botdoor.co, and when you joined.
- Workspaces your bot creates. When your bot signs up for you, it sends your email address and, optionally, a workspace name and its own name. We store those and a SHA-256 hash of the one-time claim link, which we email to you (never to the bot). Nobody can sign in until you open the link and set a password.
- Emails we send you. A queue of the emails we send (recipient, type, when, and whether it was delivered), kept 30 days. Claim and password-reset links are removed from it after delivery or after 1 hour, whichever comes first. Your email choices in Settings.
- API keys. The key name, its first few characters, its approval setting and when it was last used. The full key is shown once and we store only a SHA-256 hash of it.
- Connected social accounts. The network, handle, display name, profile picture link and connection status. We do not store access tokens or passwords for your social accounts: those are held by our posting provider, Zernio (see below). A Bluesky app password you enter is passed straight to Zernio and not stored by us.
- Posts and media. The text, thread, poll and option settings of each post, which key or person created it, its approval status and live links. Uploaded images and videos are stored by Zernio. We keep a small preview image (about 480 pixels) of each upload, and its size and length.
- Security records. To limit password guessing, waitlist spam and bot sign-up abuse we keep short-window counters keyed by IP address (or its network block) and, for sign-ins, the email that was tried. Bot sign-up counters store only a SHA-256 hash of the email.
- Server logs. Our host records each request's IP address, browser user agent, page and status, as web servers normally do.
Apart from the profile details a network shares when you connect an account, we don't collect information about you from other sources, and we don't buy data.
Why we use it
- To provide Botdoor: sign you in, run your bots' API keys, publish the posts you approve or allow, and show their status. Legal basis under GDPR: performance of our contract with you.
- To send service emails: claim and password-reset links, and, unless you turn them off in Settings, posts waiting for approval, posted, failed, and accounts that need reconnecting. Legal basis: performance of our contract with you.
- To keep Botdoor secure and working: rate limits, abuse prevention, debugging. Legal basis: our legitimate interest in running a safe service.
- To tell waitlist emails when sign-up in the browser opens, and to send Botdoor updates. Legal basis: your consent, which you can withdraw at any time.
We don't sell personal information, share it for advertising, or use it to train AI models. We don't send automated marketing email. Besides the service emails above, we only email you if you joined the waitlist or contacted us. To unsubscribe, reply to any email or write to privacy@botdoor.co.
Overseas transfers
Botdoor's own database and files are stored in Singapore. Zernio stores what it holds mainly in the UK and Western Europe, and our providers may access or process data in other countries, including the United States. If you are in Australia, this means your information is disclosed to recipients outside Australia. We use established providers with their own security and privacy commitments, and we only share what each needs to do its job.
How we protect it
All traffic uses HTTPS (with HSTS). Passwords are hashed with scrypt, and API keys are stored as hashes. Each workspace's data is kept separate, and changing your password signs out every other session. No system is perfectly secure; if a breach is likely to cause you serious harm, we will tell you and the relevant regulator as the law requires.
How long we keep it
- Account, posts and previews: while your account is open. We delete them when you ask us to close it.
- Unused uploads: media that no post uses is deleted automatically once it is 24 hours old, at the next weekly cleanup.
- Disconnected accounts: disconnecting removes the account from Zernio, so its access token is gone. We keep the handle on record so your past posts still show where they went.
- Revoked API keys: they stop working at once. Their name and hash stay in your key history.
- Waitlist emails: until you unsubscribe or ask us to remove them, or sign-up in the browser opens.
- Unclaimed workspaces: a workspace your bot created and you never claimed is deleted 7 days after sign-up, with its keys and posts.
- Security counters: they only count attempts in the last 15 minutes, hour or day. A successful sign-in clears yours, and we delete every counter automatically about 2 days after it started (sooner on request).
- Server logs: kept by Railway for a limited period under its retention settings.
There is no self-serve delete button yet. Email privacy@botdoor.co and we will delete your account, posts, previews and waitlist entry, and disconnect your social accounts at Zernio. Posts already published stay on the social networks until you remove them there.
Your rights
You can ask to see the personal information we hold about you, correct it, get a copy, delete it, or object to or limit how we use it, and you can withdraw consent at any time. Email privacy@botdoor.co. We reply within 30 days and may need to confirm who you are first. You can change your password in Settings, and disconnect accounts or revoke keys yourself at any time.
Complaints
Please contact us first at privacy@botdoor.co and we will try to fix it. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner in Australia, the Personal Data Protection Commission in Singapore, or your local data protection authority in the EU or UK.
Children
Botdoor is not for anyone under 16. We don't knowingly collect their information. If you think a child has given us information, email us and we will delete it.
Changes
We will update this page when our practices change, and change the effective date at the top. For significant changes we will tell account holders by email or in the app before they take effect.
Contact
Monstar Lab Pte Ltd, Singapore · privacy@botdoor.co