ScotNet Privacy & Operating Principles
Collect less, keep it private, publish only what people actually need.
ScotNet is privately operated infrastructure for personal, family and limited trusted use. It is not built to monetise attention, construct user profiles or resell activity data.
Operator and scope
ScotNet is operated privately by an individual in the United Kingdom. Where UK data-protection law applies, the operator is the data controller for information processed by the services described here.
This policy covers the main ScotNet site and the shared operating principles used across related ScotNet services. A specialist service may publish additional terms where its function requires them.
What ScotNet does not do
- No advertising network, behavioural profiling or cross-site tracking.
- No sale, rental or commercial transfer of personal data.
- No third-party analytics beacon on the main public pages.
- No public dump of raw weather, monitoring or security datasets.
- No deliberate collection of information merely because it might be useful later.
Browser storage
The main public site does not use tracking cookies. The theme and Gizmo interface may use local browser storage to remember display preferences and limited on-device interaction state.
- This information stays in your browser and is not used for advertising.
- You can remove it by clearing site data.
- Blocking local storage may reset preferences but does not prevent access to core pages.
Operational and security logging
Public services may record limited connection and security metadata needed to diagnose faults, enforce rate limits, investigate abuse and protect systems.
- Examples include timestamp, source network address, requested service, result code and a security category.
- Passwords, authorisation headers, cookies and message bodies are not intended to be copied into routine security logs.
- Logs are not used to build marketing profiles or measure personal engagement.
- Routine operational logs are normally rotated within 30 days. A relevant subset may be retained longer during an active investigation, abuse case or legal obligation.
Contact forms and messages
When you contact ScotNet, the details you choose to submit are processed so the message can be delivered and answered. Limited technical metadata may also be used to detect automated abuse.
- Anti-abuse controls may include rate limits, hidden fields, timing checks, signature validation and DNSBL checks.
- No third-party advertising or behavioural CAPTCHA service is required by the main contact route.
- Messages are not reused for marketing.
Contact anti-abuse: ScotNet checks contact submissions against its local bl.scott.ovh DNSBL. The operator can enable additional DNSBL providers; when enabled, the submitting IP address is necessarily queried against those providers. Third-party providers are disabled by default. Contact notifications may be sent to ScotNet's private operator chat and contain submission metadata, not the message body.
Weather and weather history
Station observations, forecasts and detailed weather history are collected by private scheduled jobs. Raw cache files and the history database are stored outside the public website document root.
- Current station weather is refreshed every minute; forecasts are refreshed every 30 minutes.
- Detailed observations are normally retained privately for 90 days.
- Daily summaries may be retained longer for trend comparisons.
- Public pages render bounded readings, summaries and charts without a public JSON feed or database download.
- The station identifier, precise coordinates, provider credentials and private file paths are not intentionally published.
Status and external monitoring
The public status page is generated from a private monitoring cache. It publishes simplified service states, confirmed recent history and selected aggregate Miko external-monitor statistics.
- Brief failures are confirmed before they become public incidents.
- Monitor IDs, raw heartbeat payloads, latency samples, internal endpoints and full event histories remain private.
- The removed global monitor alert bar is not used; visitors can check the status page or Gizmo when they need current service health.
- Gizmo v1.0.1 reads the same minimised, server-rendered status page rather than a raw monitoring API.
DNS and DNSBL services
ScotNet Secure DNS is intended for trusted use and is operated without advertising identifiers or commercial DNS profiling. Short-lived operational data may exist when required for reliability and abuse control.
bl.scott.ovh records network reputation and security decisions about IP addresses. A listing represents observed network behaviour, not a conclusion about a person. Public transparency is intentionally limited to self-checks, published reason text and process information rather than a scrapeable ledger.
BackToYou and other services
BackToYou and other ScotNet services publish only the information needed for their stated purpose. Where a user controls public content, the service is designed to expose only the fields intentionally selected for publication.
Lawful basis
- Legitimate interests: operating services, maintaining security, preventing abuse and diagnosing faults.
- Consent or user request: processing information voluntarily submitted through a contact or service form.
- Legal obligation: retaining or disclosing limited information where UK law requires it.
Your rights
- Request access to personal data held about you.
- Request correction of inaccurate information.
- Request erasure where information is no longer required.
- Request restriction or object to processing in appropriate circumstances.
- Raise a concern with the UK Information Commissioner’s Office.
Requests need enough information to identify the relevant service or message without requiring ScotNet to collect additional unnecessary identity data.
Policy changes
This page is updated when ScotNet’s infrastructure, retention rules or public data boundaries materially change. Release-level changes are recorded in the ScotNet version history.
Contact messages
When you use the ScotNet contact form, the message and reply address are stored privately in encrypted form so they can be reviewed and deleted from the Contact Centre. Delivery copies are sent only to the operator-enabled destinations, which can be Synology Chat, email, both or neither.
Anti-spam controls use short-lived signed form tokens, bounded rate state and keyed one-way hashes rather than retaining the sender's raw IP address in the message record. The sender address may be checked against the ScotNet DNSBL and any additional DNSBLs explicitly enabled by the operator; those checks use the normal DNSBL lookup form derived from the sender IP.
If live chat is enabled, the accepted message can open an encrypted temporary chat transcript. The visitor receives an in-memory/session-tab bearer token for that conversation; Synology Chat replies are accepted only through the configured outgoing webhook token and conversation code. Live transcripts expire automatically and can be closed or deleted by the operator.
Stored contact messages are subject to the configured retention period (180 days by default) and can be deleted earlier by the operator.