Privacy notice
Privacy and contact
Byteland (byteland.dev) is a community site that draws developers as a night city. This notice explains which personal data is processed when you use the site, why, who receives it, how long it is kept and what your rights are. It is the English version of our notice under Türkiye’s Personal Data Protection Law No. 6698 (KVKK); if the two differ, the Turkish text prevails. Byteland is run by one person; “we” in this notice is that person.
In short
- You need no account to look around. A visitor’s IP address is handled briefly and in memory only, to stop abuse and to count visits; it is never written to disk.
- If you sign in with GitHub or Discord we receive your public account details: username, display name, avatar, account number. We never see your password, your code or your private repositories, and we do not store your email address.
- Your building, your profile and what you write in rooms are public. The names of projects you mark private never appear anywhere.
- In voice rooms, audio and screen sharing never pass through our server and are never recorded. Because the connection is direct, the browsers of the other people in the room see your IP address.
- No advertising, analytics or tracking cookies. Our cookies exist only to make sign-in work, so we do not show a cookie banner.
- We do not sell your data or use it for advertising.
1Data controller
The data controller is Kaan Çelebi, who runs byteland.dev. For any question or request about your personal data: iletisim@byteland.dev. Other ways to reach us are under Contact.
2What we process
Everyone who visits
| Data | Why | Where, how long |
|---|---|---|
| IP address | Rate limits and abuse prevention (sign-in, search, counting, messages) | In the server’s memory, at most 15 minutes after your last request. Never written to disk. |
| IP address and browser details (User-Agent) | Counting a visit to a building once per person per day | A one-way digest (hash) is made from the IP, the browser and the date; the digest stays in memory until the day ends. The IP itself is not kept. |
| Visit and view counts | The “Popular” list; showing owners how many people looked at their building | Who looked is never kept; how often each building, project and billboard was seen is. Daily counts for 60 days, totals for as long as the site runs. |
| Search terms | Showing search results | Not stored on the server. Your recent searches stay in your own browser. |
The server keeps no access log (which IP opened which page). Bots and automated browsers are left out of the counts.
People who sign in with GitHub or Discord
| Data | Why | Where, how long |
|---|---|---|
| Account details: GitHub or Discord account number, username, display name, avatar address | Opening your account, tying your building to you | While your account exists. We ask GitHub for no extra permissions and Discord for identify only. The sign-in token (OAuth) is used once and not kept. We neither ask for nor store your email address. |
| When you joined and last signed in | The newest residents list, account management | While your account exists. |
| Session | Remembering that you signed in | Only a digest of a random session key is stored; 30 days or until you sign out. |
| Your profile and building settings: name, bio, location, pronouns, links (including an email address if you add one), the photo and billboard image you upload, your LED sign text, project visibility, projects you add by hand, “looking for help” notes | Showing everyone the same building | Until you change them or ask us to delete them. Public, except private projects. |
| The last copy of your GitHub profile (your public profile and repositories) | Keeping your building up when GitHub is slow or unreachable | Refreshed whenever your building is opened; while your account exists. |
| What you write in rooms: messages, forum threads, replies, reactions; author and time | Running project rooms | Public. Until you or the room owner delete it; each channel keeps its newest 500 messages and older ones are removed automatically. |
| Notifications: who mentioned you, who replied to your thread, a short excerpt | The notification bell | The newest 60 per person. |
| Removal list | Letting room owners remove someone from their rooms | Until the owner lifts it. |
| Voice rooms: which room you are in, whether your microphone and screen sharing are on | Running voice rooms | In memory only, while you stay in the room. Public: anyone looking at the site can see it. |
In voice rooms, audio and screen sharing travel encrypted from browser to browser (WebRTC); they never pass through our server and are never recorded. To make the connection, your IP address is passed to the browsers of the other participants and to a STUN server (Google or Cloudflare). Your browser only turns on your microphone after you allow it.
GitHub users who have not signed in
Anyone can search for or open any GitHub username on Byteland (for example byteland.dev/@username). A building is then drawn from that person’s public GitHub details: name, avatar, bio, location, account creation date, website and social accounts, public repositories. These are read from GitHub’s public interface, held in the server’s memory for 30 minutes and never written to disk; visits to the building may be counted. If you do not want these details shown on Byteland, write to us.
When you write to us
We use your email address and what you write only to answer you and handle your request. Correspondence is kept for at most one year after the matter is closed.
Byteland is not meant for children under 13; GitHub and Discord also require you to be at least 13 to open an account. We do not ask for special categories of personal data (health, religion, biometrics and the like); please do not put such details in your messages or profile.
3Purposes and legal grounds
We collect data automatically: from your browser while you use the site, from the GitHub or Discord sign-in flow, and from GitHub’s public interface. Our legal grounds are those in Article 5(2) of the KVKK:
| Purpose | Legal ground |
|---|---|
| Opening your account, keeping your session; providing your building, rooms, notifications and voice rooms | Entering into and performing a contract (Art. 5(2)(c)): by signing in you use Byteland’s service. |
| Showing public profile details from GitHub and Discord | Data made public by the person themselves (Art. 5(2)(d)). |
| Security, rate limits, fighting spam and abuse, backups | Legitimate interest (Art. 5(2)(f)). |
| Visit and view counts, the “Popular” list | Legitimate interest (Art. 5(2)(f)). Who looked is never kept. |
| Answering data protection requests and lawful requests from authorities | Legal obligation (Art. 5(2)(ç)). |
| Answering you when you write to us | Legitimate interest (Art. 5(2)(f)). |
We do not rely on consent for any processing.
4Who receives it
We do not sell your data and do not share it with anyone for advertising or marketing. We use these services to run the site:
| Who | What they see | Where |
|---|---|---|
| İHS Telekom | Server hosting: all of the data above lives on this server. | Türkiye (Istanbul) |
| Cloudflare, Inc. | Every request to the site passes through Cloudflare for attack protection and fast delivery: your IP address and the technical details of the request. | USA; data centres worldwide |
| GitHub, Inc. | Signing in with GitHub takes you to GitHub’s page. Avatars and some public GitHub data load into your browser straight from GitHub, so GitHub sees your IP address. | USA |
| Discord Inc. | Signing in with Discord takes you to Discord’s page; Discord avatars load into your browser straight from Discord. | USA |
| Google LLC, Cloudflare, Inc. (STUN) | When you join a voice room, your browser asks these servers for its own public IP address. | USA |
| Other people in a voice room | Your IP address, for the direct connection. | Wherever they are |
Cloudflare, GitHub, Discord and Google are outside Türkiye, so these are transfers abroad under Article 9 of the KVKK. When you sign in to GitHub or Discord yourself, their privacy policies apply as well.
Where the law requires it, we share only what is asked for with competent public authorities and courts.
Everything public (buildings, profiles, room messages, who is in a voice room) can also be read by programs and AI agents through the site’s API and MCP server, and search engines may index it. Links in profiles lead to other sites, whose own rules apply once you are there. The share button only sends anything to X when you click it.
5Cookies and browser storage
Byteland has no advertising, analytics, social media or tracking cookies. Fonts and code come from our own server too. The cookies we use are strictly necessary for the site to work, so we do not show a cookie banner.
| Cookie | Why | How long |
|---|---|---|
bl_sid | Remembers that you signed in. JavaScript cannot read it (httpOnly) and it is only sent over HTTPS. | 30 days or until you sign out |
bl_st | Checks that a GitHub or Discord sign-in is the one you started (protection against forged requests). | 10 minutes; removed when sign-in finishes |
__cf_bm, cf_clearance | Cloudflare may set these when it runs a security check, to tell people from bots. | A short time set by Cloudflare (usually 30 minutes) |
Kept only in your browser
Some preferences never reach the server and stay in your browser’s storage (localStorage): interface language, your favourites, recent searches, which rooms you have looked at, voice room preferences (microphone, speaker, volume per person), whether you have seen the tour and the welcome screen, and a one-hour GitHub cache. We cannot see them; you can clear them by deleting the site’s data in your browser.
6Retention and deletion
- Account, settings and GitHub copy: while your account exists.
- Session: 30 days or until you sign out.
- Room messages: until you or the room owner delete them; the newest 500 per channel.
- Notifications: the newest 60 per person.
- IP address: at most 15 minutes after your last request, in memory only.
- Visit counts: daily counts for 60 days; who looked is never kept.
- Backups: the server makes a backup every day and keeps it for 14 days. Copies downloaded to a computer are kept for at most 30 days.
- Correspondence: at most one year after the matter is closed.
To delete your account, write to iletisim@byteland.dev. We delete your account, sessions, settings, what you wrote in rooms and your notifications within 30 days; copies in backups disappear on their own within 30 days as well. After your account is deleted, your public GitHub profile may still be drawn as a building when someone searches for it, like any GitHub user’s (see “GitHub users who have not signed in”).
Some things you can delete yourself: your messages, threads and replies in the room; your profile and building settings in the editor. Signing out deletes your session; you can clear browser storage in your browser’s settings.
7Security
- The site only opens over HTTPS (HSTS).
- The session cookie is closed to JavaScript and not sent with requests from other sites. The server stores only a digest of the session key, never the key itself. GitHub and Discord sign-in tokens are not kept.
- Only the necessary ports are open on the server, administrators sign in with SSH keys only, security updates install themselves and the site runs as a separate, restricted user.
- The names and details of private projects never reach any surface (site, API, MCP).
No system is perfect. If there is a data breach, we will notify the Personal Data Protection Board and the people affected as soon as possible, as Article 12 of the KVKK requires.
8Your rights
Under Article 11 of the KVKK you have the right to:
- learn whether your personal data is processed,
- ask for information about it if it is,
- learn the purpose of the processing and whether the data is used accordingly,
- know the third parties in Türkiye or abroad that receive it,
- have it corrected if it is incomplete or wrong,
- have it deleted or destroyed under the conditions of Article 7 of the KVKK,
- have corrections, deletions and destructions passed on to the third parties that received the data,
- object to a result against you that comes solely from automated analysis of your data,
- claim compensation if you suffer damage from unlawful processing.
If you are in the EU or the UK, we honour the rights the GDPR gives you in the same way.
How to apply: write to iletisim@byteland.dev with your name, your Byteland or GitHub/Discord username and your request. We may ask for something that shows the account is yours (for example a small check from the linked GitHub account). If you would rather apply in writing or by registered electronic mail (KEP), as the Turkish rules on applications allow, we will send you the address by email.
We answer within 30 days, free of charge (KVKK Art. 13). If you are not satisfied with the answer or get none within 30 days, you can complain to Türkiye’s Personal Data Protection Board (KVKK Art. 14, kvkk.gov.tr).
9Changes
As the site gains features we update this notice and the date at the top changes. We announce important changes on the site. If we ever add an ad network or an analytics tool, we will ask for your consent before setting their cookies.
10Contact
You can reach us about anything to do with Byteland:
- Emaililetisim@byteland.devData requests, account deletion, bugs and ideas, content reports, advertising and sponsorship
- GitHubgithub.com/kaanisthatyouThe founder’s account
- DiscordCommunity server
- InstagramAnnouncements
- XAnnouncements
Inappropriate content: a room’s owner can delete any message in it and remove the person who wrote it from their rooms. If you cannot reach the owner or the content is illegal, email us with a link to the message and we will look at it as soon as we can. Found a security issue? Please email us before posting about it publicly (subject: Security).