Privacy Policy
waterhole.toot.io is a service provided by SaaS Web Internet Solutions GmbH.
General information on how we process personal data when you visit the toot.io websites is in the toot.io privacy policy. This page adds what is specific to waterhole.toot.io.
1. Who is responsible
SaaS Web Internet Solutions GmbH (toot.io, “we”, “us”)
Steinstraße 25, 76133 Karlsruhe, Germany
Phone: +49 721 18039510
Fax: +49 721 18039519
Email: hosting@toot.io
Mastodon: @hosting@toot.io
We are the controller for all processing described on this page.
2. People applying to join a Mastodon instance
What we process
We mirror the pending registrations of each participating instance from that instance’s own admin API. We do not collect anything from applicants directly. For each application:
- username, display name, profile note, avatar URL and profile URL
- email address, with its domain kept separately
- the most recent IP address Mastodon recorded for the account
- the country and network operator (ASN) derived from that address, and whether it belongs to Apple’s iCloud Private Relay or to a Tor relay
- the free-text reason given for wanting to join
- locale, signup time, whether the email address was confirmed, and whether the account was created through an app rather than the website
- the moderators’ notes and decision about the application
Why
For one purpose only: helping the instance’s moderators decide whether to admit the applicant. The data is not used for advertising, or for profiling beyond that decision. Waterhole shows advisory flags, such as a disposable email address or a signup from a datacenter network, but it never decides: a person makes every decision, through the instance’s own admin API. There is no automated decision-making within the meaning of Art. 22 GDPR.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and that of the participating instances, is to keep spam, abusive accounts and signup farms off their servers, and to support their moderators in reviewing applications. We use only what that review needs, the flags are advisory, and everything is deleted 90 days after the decision (see section 6).
Cross-instance signals
If an instance opts in and we approve it, its moderators can be told that the same email address or the same signup network is currently in use on another instance that has also opted in. This is reciprocal: an instance only sees these signals if it also contributes its own. Email addresses are compared as keyed hashes, never in the clear, and only the other instance’s domain is shown, never details of its applicants.
The same applies to two patterns that give signup farms away:
- An applicant’s reason for joining is compared with the reasons given on other participating instances. The comparison uses a fingerprint computed on this service, never the text itself, and a nearly identical reason is shown as a match.
- A burst of signups with the same email provider, username pattern and language within an hour, each from a different network, is shown as a burst.
Again, only counts and the other instances’ domains are disclosed.
Matches include applicants who have already been approved, until their application is deleted (see section 6). Because each instance’s server supplies its own registrations, the administrator of a participating instance could misuse the signals to find out whether a particular email address or network has been used to join another participating instance. Participating instances agree in our terms not to do this, and we end the participation of any instance that does, but we cannot prevent it technically.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and that of the participating instances, is to detect spam and abuse that target several servers at once, which no single instance can see on its own. Signals only run between instances that opted in and that we approved, email addresses and reasons for joining are compared only as keyed hashes and fingerprints, and other instances learn nothing but that a match exists and an instance’s domain.
3. Moderators
When you sign in with your Mastodon account, we process your Mastodon account identifier, username, display name, avatar, role, when you last signed in, an access token issued by your own instance, session records including your IP address and browser user agent, and when you consented, and to which version of this policy (see below). We also keep the notes you write, the requests you claim, and the decisions you make, together with your name, until the application they belong to is deleted (see section 6).
We use this to let you sign in, to act on your behalf towards your own instance (approving or rejecting applicants, and fetching the queue), and to show your colleagues who is working on what. Every hour we check with your instance that your account still has permission to manage users.
We ask for your consent right after you first sign in, and again whenever this privacy policy changes. Until you agree, you can only read the legal pages. If you decline, you are signed out and your record is deleted; where your notes or decisions are part of an instance’s records, it is anonymised instead, and they appear as those of a former moderator. You can withdraw your consent at any time by writing to us, with the same effect.
Legal basis: Art. 6(1)(a) GDPR.
4. Visiting this website
Server logs
When you open a page on waterhole.toot.io, our servers process:
- your IP address
- browser type and operating system
- date and time of the request
- the page requested
- the amount of data transferred
We need these to deliver the pages, and to detect and fix faults and attacks. Log files are deleted after 7 days.
Legal basis: Art. 6(1)(f) GDPR.
Cookies
This service sets up to three cookies, all first-party. The first two are needed for it to work; the third is set only if you ask for it. None is used for tracking, analytics or advertising, and nothing is stored in your browser’s local storage.
| Cookie | What it holds | How long it lasts |
|---|---|---|
_waterhole_session |
Protection against forged form submissions, one-off status messages, and short-lived sign-in state (a random value that ties the Mastodon login back to your browser, and the page to return to afterwards) | Until you close your browser |
session_id |
A reference to your sign-in, set only once you have signed in | Until you sign out, after 24 hours without use, or at the latest 7 days after signing in |
recent_instances |
Only if you tick “Remember this instance in this browser” when signing in: the domains of up to five Mastodon instances you chose to remember, so the sign-in page can offer them again | 90 days after your last sign-in. Signing in without the tick, or Forget on the sign-in page, removes an entry sooner |
All three are signed or encrypted so they cannot be tampered with, cannot be read by scripts on the page, and are only ever sent back to this service.
Legal basis: for _waterhole_session and session_id, § 25(2) no. 2 TDDDG for
storing them and Art. 6(1)(f) GDPR for processing their contents. For
recent_instances, your consent, given by ticking the box: § 25(1) TDDDG and
Art. 6(1)(a) GDPR.
5. Who receives data
- Mastodon instances. Decisions go back to the instance they belong to, through its admin API, made with the deciding moderator’s own access token. The administrators of each instance can see its applicants and moderators here.
- Other participating instances receive only what section 2 describes: that a match or a burst exists, and the domain of the instance it involves.
- Hosting. This service runs on the same infrastructure as toot.io. Our hosting providers, who process data on our behalf under data processing agreements, are named in the toot.io privacy policy.
- Error reports. When something in this service breaks, a technical error report is sent to our own GlitchTip server so that we can fix it. A report says where in the software the error happened and which page or background task was running. It is configured not to include applicants’ email addresses, IP addresses or reasons for joining, or moderators’ notes, and it does not identify the signed-in moderator; cookies, form contents and search terms are removed before it is sent.
We do not share data with anyone else. IP geolocation uses public-domain datasets, and we also download Apple’s list of iCloud Private Relay addresses and the Tor Project’s list of Tor relays. Your IP address is not sent to any of them: every lookup happens on our own server.
All processing takes place within the European Union.
6. How long we keep data
- Applications: 90 days after an application is decided (here or directly in Mastodon) or withdrawn, it is deleted with everything about it: the applicant’s data, the moderators’ notes, the automated flags and the decision. Only the Mastodon account’s numeric ID is kept, while the instance uses this service, so that the application is not imported again while the instance still lists it as pending. An application can also be purged earlier; see section 8. An application that is never decided is kept for as long as it is pending on its instance. (Mastodon itself removes applications whose email address is not confirmed within a week; they are then deleted here 90 days later.) If the instance stops using this service and does not return within 14 days, all its applications are deleted, together with the stored account IDs.
- Moderators: sessions end after 24 hours without use, or at the latest 7 days after signing in. Your account record and access token are kept while your instance uses this service. If it stops (its authorisation is removed or blocked, or it does not accept changed terms in time) and does not return within 14 days, your record is deleted along with your instance’s applications. It is also deleted when you decline or withdraw consent, or when you ask us to.
- Server logs: 7 days (see section 4).
- Error reports: 30 days.
7. Security
Access tokens and email addresses are encrypted at rest. Access to an instance’s data requires both DNS authorisation from the instance’s administrator and a Mastodon login with permission to manage users on that instance. All connections are encrypted (HTTPS).
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20).
Right to object (Art. 21 GDPR): where we process your data on the basis of Art. 6(1)(f) GDPR, you may object at any time, on grounds relating to your particular situation.
Where processing is based on your consent, you may withdraw it at any time, with effect for the future.
To exercise any of these rights, contact us at hosting@toot.io. Applicants may also turn to the Mastodon instance they applied to, which holds the original registration.
Erasure of an application: besides us, the moderators of the instance you applied to can purge your application from this service at any time. Purging deletes it straight away, rather than 90 days after the decision, with everything about it (see section 6), and it is not imported again. It does not change anything on the Mastodon instance itself: to have your account or application removed there, contact that instance.
You also have the right to lodge a complaint with a data protection supervisory authority. Ours is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg):
Heilbronner Straße 35, 70191 Stuttgart, Germany
Postfach 10 29 32, 70025 Stuttgart, Germany
Email: poststelle@lfdi.bwl.de
Web: www.baden-wuerttemberg.datenschutz.de
Last updated: 2026-09-19
Document fingerprint 43e79e0e00.
Instances accept these documents by publishing their combined fingerprint in DNS.