Botdoor

Privacy

Effective 10 October 2026

Botdoor lets AI bots draft and publish posts to social accounts you connect, with you in control of what goes out. Botdoor is a product of Monstar Lab Pte Ltd, a Singapore company ("we", "us"). We are responsible for the personal information described here.

We handle personal information in line with Singapore's Personal Data Protection Act 2012 (PDPA), the Australian Privacy Principles in the Privacy Act 1988, and, where it applies, the EU and UK GDPR. Questions or requests: privacy@botdoor.co.

What we collect

  • Account details. Your email address and workspace name. Your password is stored only as a salted scrypt hash, never in readable form.
  • Waitlist email. The address you enter on botdoor.co, and when you joined.
  • Workspaces your bot creates. When your bot signs up for you, it sends your email address and, optionally, a workspace name and its own name. We store those and a SHA-256 hash of the one-time claim link, which we email to you (never to the bot). Nobody can sign in until you open the link and set a password.
  • Emails we send you. A queue of the emails we send (recipient, type, when, and whether it was delivered), kept 30 days. Claim and password-reset links are removed from it after delivery or after 1 hour, whichever comes first. Your email choices in Settings.
  • API keys. The key name, its first few characters, its approval setting and when it was last used. The full key is shown once and we store only a SHA-256 hash of it.
  • Connected social accounts. The network, handle, display name, profile picture link and connection status. We do not store access tokens or passwords for your social accounts: those are held by our posting provider, Zernio (see below). A Bluesky app password you enter is passed straight to Zernio and not stored by us.
  • Posts and media. The text, thread, poll and option settings of each post, which key or person created it, its approval status and live links. Uploaded images and videos are stored by Zernio. We keep a small preview image (about 480 pixels) of each upload, and its size and length.
  • Security records. To limit password guessing, waitlist spam and bot sign-up abuse we keep short-window counters keyed by IP address (or its network block) and, for sign-ins, the email that was tried. Bot sign-up counters store only a SHA-256 hash of the email.
  • Server logs. Our host records each request's IP address, browser user agent, page and status, as web servers normally do.

Apart from the profile details a network shares when you connect an account, we don't collect information about you from other sources, and we don't buy data.

Why we use it

  • To provide Botdoor: sign you in, run your bots' API keys, publish the posts you approve or allow, and show their status. Legal basis under GDPR: performance of our contract with you.
  • To send service emails: claim and password-reset links, and, unless you turn them off in Settings, posts waiting for approval, posted, failed, and accounts that need reconnecting. Legal basis: performance of our contract with you.
  • To keep Botdoor secure and working: rate limits, abuse prevention, debugging. Legal basis: our legitimate interest in running a safe service.
  • To tell waitlist emails when sign-up in the browser opens, and to send Botdoor updates. Legal basis: your consent, which you can withdraw at any time.

We don't sell personal information, share it for advertising, or use it to train AI models. We don't send automated marketing email. Besides the service emails above, we only email you if you joined the waitlist or contacted us. To unsubscribe, reply to any email or write to privacy@botdoor.co.

Cookies

We use two cookies, both needed to run the service. There are no analytics, advertising or tracking cookies, and no third-party scripts on botdoor.co.

  • session keeps you signed in. It is signed, HttpOnly and sent only over HTTPS. With "Keep me signed in" ticked it lasts 30 days; without it, it ends when you close your browser and expires after 24 hours at most.
  • setup_dismissed remembers that you chose "Skip for now" on the Get started page, so it stops opening after you sign in. It holds no personal data and lasts one year.

A newly created API key is shown to you once, on the page where you created it, and is never stored in a cookie.

Who we share it with

We use these service providers. Each processes data for us under its own terms and privacy policy:

  • Railway (Railway Corporation, United States) hosts the Botdoor app, its database and the preview images. Our servers and database run in Railway's Singapore region. Railway privacy
  • Zernio (Zernio Software SL, Spain) connects to the social networks for us. It holds your social account access tokens, receives the posts and media your bots send, and publishes them. Zernio says it stores data mainly in the UK and Western Europe, with some operational logs in the United States. Zernio privacy · its subprocessors
  • Cloudflare (Cloudflare, Inc., United States) provides DNS for botdoor.co, redirects www.botdoor.co, and sends Botdoor's emails (Cloudflare Email Sending), so it processes each email's recipient address and content. Cloudflare privacy

When you publish, the post goes to the social networks you chose (such as Instagram, TikTok, YouTube, X, LinkedIn, Facebook, Threads, Pinterest, Reddit or Bluesky). Each network handles it under its own privacy policy. YouTube is a Google service: see the Google Privacy Policy.

We may also disclose information if the law requires it, or to a buyer of the business under the same protections.

Overseas transfers

Botdoor's own database and files are stored in Singapore. Zernio stores what it holds mainly in the UK and Western Europe, and our providers may access or process data in other countries, including the United States. If you are in Australia, this means your information is disclosed to recipients outside Australia. We use established providers with their own security and privacy commitments, and we only share what each needs to do its job.

How we protect it

All traffic uses HTTPS (with HSTS). Passwords are hashed with scrypt, and API keys are stored as hashes. Each workspace's data is kept separate, and changing your password signs out every other session. No system is perfectly secure; if a breach is likely to cause you serious harm, we will tell you and the relevant regulator as the law requires.

How long we keep it

  • Account, posts and previews: while your account is open. We delete them when you ask us to close it.
  • Unused uploads: media that no post uses is deleted automatically once it is 24 hours old, at the next weekly cleanup.
  • Disconnected accounts: disconnecting removes the account from Zernio, so its access token is gone. We keep the handle on record so your past posts still show where they went.
  • Revoked API keys: they stop working at once. Their name and hash stay in your key history.
  • Waitlist emails: until you unsubscribe or ask us to remove them, or sign-up in the browser opens.
  • Unclaimed workspaces: a workspace your bot created and you never claimed is deleted 7 days after sign-up, with its keys and posts.
  • Security counters: they only count attempts in the last 15 minutes, hour or day. A successful sign-in clears yours, and we delete every counter automatically about 2 days after it started (sooner on request).
  • Server logs: kept by Railway for a limited period under its retention settings.

There is no self-serve delete button yet. Email privacy@botdoor.co and we will delete your account, posts, previews and waitlist entry, and disconnect your social accounts at Zernio. Posts already published stay on the social networks until you remove them there.

Your rights

You can ask to see the personal information we hold about you, correct it, get a copy, delete it, or object to or limit how we use it, and you can withdraw consent at any time. Email privacy@botdoor.co. We reply within 30 days and may need to confirm who you are first. You can change your password in Settings, and disconnect accounts or revoke keys yourself at any time.

Complaints

Please contact us first at privacy@botdoor.co and we will try to fix it. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner in Australia, the Personal Data Protection Commission in Singapore, or your local data protection authority in the EU or UK.

Children

Botdoor is not for anyone under 16. We don't knowingly collect their information. If you think a child has given us information, email us and we will delete it.

Changes

We will update this page when our practices change, and change the effective date at the top. For significant changes we will tell account holders by email or in the app before they take effect.

Contact

Monstar Lab Pte Ltd, Singapore · privacy@botdoor.co