sunken.ink

Privacy Policy

What we collect, why, how long we keep it, and what you can make us do about it.

Last updated 19 September 2026

The short version

This summary is here to help you read the rest. The full text below is what applies.

  • We collect what you type in and almost nothing else. No analytics, no advertising, no third party trackers.
  • Three cookies: one keeps you signed in, one remembers your wiki language, one tells us when two accounts are the same browser.
  • Your profile and your posts are public. Your email address and password never are.
  • You can see, correct, export or delete your data by asking us.

Calypso is the data controller for personal data processed on sunken.ink.

You can reach us about anything in this policy at [email protected].

Because the site is operated from Norway, the General Data Protection Regulation applies, along with the Norwegian Personal Data Act that implements it.

Everything below is either something you typed in yourself or something the site had to record in order to work. There is no hidden collection.

When you create an account

  • Your username, and a lowercase copy of it used to stop two people taking the same name.
  • Your email address, and whether you have confirmed it. Confirming is what lets you post and it is the only way we can get you back into your account if you lose the password, so we send a link to it when you sign up and again whenever you ask.
  • Your password, stored only as a scrypt hash with a unique salt. We never store or see the password itself.
  • The date you joined.

When you ask to get back in

  • A one time link, stored only as a hash, which expires after a day and stops working once it has been used. Asking for a new one cancels the last. We do not record what you typed into the recovery forms, and those forms answer the same way whether or not they matched an account, so nobody can use them to find out who is registered here.

What you choose to put on your profile

  • Your avatar choice, ink colour, name colour and name glow.
  • Whether you present as an Inkling or an Octoling.
  • Your short bio and your About Me text.
  • Your pronouns and your gender, if you fill them in.
  • The pride flags you choose to show, if any.
  • Your stat.ink name, if you add one, which links your profile to your own battle record on that site.
  • Your Nintendo Switch friend code, if you add one. It is shown on your profile to anyone who can see it, which is everyone, so only add it if you want people to add you.
  • Which of your badges you chose to wear on your posts.

All of these are optional except the username, email and password, and all of them can be changed or emptied at any time from your settings.

Two more things can appear on your profile: a custom title and a name effect. Either can be granted by staff or bought with Golden Eggs at the exchange. One you bought you can change or take off yourself from the exchange page; one staff gave you, ask a staff member about.

What the site records as you use it

  • The threads and posts you write, with the time you wrote them and any time you edited them.
  • The hour on your own clock when you posted, sent by the form as a number from 0 to 23, nothing more. It exists for one badge and is never combined with anything else.
  • Whether a reply of yours woke a thread that had been quiet for a month. A yes or no on the post, for one badge.
  • Which posts you have voted on and which way, ink or splat. One vote per post, and you can take it back or flip it.
  • Counts of your posts, threads and ink received, your net reputation from votes on your posts, and the time of your most recent post, which is used for the posting cooldown.
  • Your Golden Eggs. The balance, the lifetime total you have earned, and a ledger of every change: what earned or cost the eggs, what it points at (a post, a badge, a purchase, the member you sent a gift to), and when. Eggs are points the site gives out for activity, described in the Terms of Service. The first visit of each day pays out once, and the ledger row for it is how the site knows it already has.
  • What you have bought from the exchange, which avatar frame you wear, and which shouts you have posted in the shoutbox, with their times.
  • The time you were last active. One timestamp, overwritten each time, written at most once a minute. It is what the "online now" list on the forum reads, so it shows who has been here in the last five minutes. It is not a history: there is no record of when you visited yesterday, and there is no log of which pages you looked at.
  • The badges you have earned or been granted. Which of them you wear is listed above, because that one is your choice.
  • Which team you called in a running Splatfest, if you called one.
  • Which replay codes you have looked up while signed in. Codes are not personal to you and identify a battle, not a person.
  • Who you have blocked. One way and private: the person you blocked is never told, and blocking only changes what you see.
  • Any report you file on a post: which post, why, and anything you typed. Staff see your name on it.

What identifies your machine

We keep three signals so one person cannot quietly run several accounts. All three are stored as keyed hashes, never as the thing itself, and they are never sold, shared or used for advertising.

  • A device token. A random value in a cookie called `sunken_device`. It means nothing outside this site and identifies a browser, not a person.
  • A browser fingerprint. A single hash your browser computes from things it already tells every website: your user agent, screen size, timezone, language, processor count, and how it draws a test image. We store the hash, not the parts.
  • Your IP address, as a keyed hash, plus the first half of the address in readable form so staff can tell a household apart from a school.

Two accounts matching on the device token or the fingerprint is what marks an account as a duplicate. A shared address alone never is, and never restricts anyone. If an account is restricted, the addresses it was used from are recorded. A new account from one of those addresses is not restricted for that reason: it only causes a note for a staff member to look at, described under Moderation records below. It takes a browser match as well before anything happens.

Moderation records

  • Whether a post of yours is waiting for staff approval, and whether a reply of yours revived a dead thread.
  • Whether your account is restricted, and the name of the account you were found to be duplicating, if any. Both appear on your profile.
  • Any mark on your account (Stained, Catfish, Liar, Misinformer, Leaker, Pile-On, Vote Farmer, Doxxer, Bigot, Art Thief, Spoiler, Brigader, Serial Reporter, Stalker, Pirate, Impostor), which is a badge put on by an administrator for a rule broken, or by the software in the case of Stained and Catfish. It appears on your profile and on every post you make, it does not expire, and it is a moderation record: it stays until an administrator removes it, and who put it on and when is recorded. The Rules say what each one means and how to appeal it.
  • A note for staff, which you are not told about. If you sign up from an address a restricted account also used, but your browser does not match, we put a short line on your account saying so, for a staff member to read. Nothing about your account changes, you are not notified, and it is usually nothing: a household or a school is one address. A staff member clears it once they have looked. We do this because we have a legitimate interest in noticing ban evasion, and because the alternative, restricting you for it, would be worse and unfair.
  • Every action staff take on your account, with who did it and when.
  • A count of views per thread. This is a number on the thread, not a record of who viewed it.
  • Your role, and whether your account is suspended.

Technical data

  • A session record when you sign in, holding a hashed version of your session token, your account id, and when the session expires. The token itself is only ever in your own browser.
  • Our server and Njalla process your IP address and browser user agent in the ordinary course of serving pages and keeping logs. We do not use this to build a profile of you.
  • No analytics of any kind. There is no Google Analytics, no Plausible, no Matomo, no pixel.
  • No advertising and no advertising identifiers.
  • No third party trackers, no social media buttons that phone home, and no embedded content that reports back.
  • No fingerprinting for tracking. We do compute one browser fingerprint, and it is described in full above. It is used for exactly one thing, telling whether two accounts are the same person, it never leaves this site, and it is stored as a keyed hash that means nothing anywhere else. We do not use it to follow you between pages, to build a profile of you, or to recognise you when you are signed out.
  • No file uploads. Avatars are chosen from a fixed set of images we host ourselves, so you cannot accidentally upload a photograph with location data in it.
  • No fonts loaded from someone else's server. The typefaces are downloaded when the site is built and served from our own domain, so your browser never contacts a font provider.
  • No location data, no contacts, no device sensors.
  • No payment information, because nothing here costs money.

To run your account and show your posts. Your username, profile fields, posts and session are processed because we cannot provide the site to you without them. Legal basis: performance of a contract, GDPR Article 6(1)(b).

Where a member is too young to be bound by the Terms of Service under Norwegian law, that contract basis does not work for them, so the same processing rests instead on our legitimate interest in running a forum that people can actually use. Legal basis: legitimate interests, Article 6(1)(f). Nothing about what we collect or how we treat it changes; only the basis does. The minimum age for an account is 13, and it is stated in the Terms.

To keep the site working and safe. Session records, the posting cooldown, login attempt limits, view counts and moderation records are processed because we have a legitimate interest in a site that functions and is not overrun by spam or abuse. Legal basis: legitimate interests, Article 6(1)(f). We have weighed this against your interests and consider it proportionate, because the data involved is minimal and is not used for anything else.

To answer you when you contact us. Legal basis: legitimate interests, Article 6(1)(f).

To comply with the law where we are required to retain or disclose something. Legal basis: legal obligation, Article 6(1)(c).

Special category data. Your gender, your pronouns and the pride flags on your profile can reveal things that GDPR treats as special category data under Article 9, including sexual orientation and, in some cases, health or belief. We process these only because you chose to make them public on your own profile, which is the exception in Article 9(2)(e) for data you have manifestly made public. They are always optional, they are blank by default, you can clear them at any time, and nothing else on the site is decided by them.

Public to anyone, including people who are not signed in and search engines: your username, avatar, ink colour, name colour and glow, species, bio, About Me, pronouns, gender, flags, badges and which you wear, any custom title or name effect you have, any avatar frame you wear, your stat.ink name and Switch friend code if you added them, join month, post and thread counts, ink received, your reputation and the tier name it puts you in, your Golden Egg balance, whether you are online now, your role if you are staff, everything you post, and anything you say in the shoutbox.

Public if your account is restricted: that it is restricted, and, where the cause was a second account, the username of the other account. Both appear on your profile for anyone to read.

Public if you are caught running more than one account: an automated account called Catfish posts a thread on a public board naming the original account and listing every duplicate found, with the date each was made. It contains usernames and dates and nothing else: never your email address, never an address you connected from, never the device token or fingerprint that detected it, and no other personal data of any kind.

We publish it because a rule against running several accounts cannot be enforced quietly. Legal basis: legitimate interests, Article 6(1)(f). We have weighed it against your interests and consider it proportionate, and these are the limits we put on it:

  • It only fires on a device or browser fingerprint match, never on a shared address.
  • The thread is locked when it is created, so it cannot become a pile-on.
  • It names accounts, not people. We do not publish anything that identifies you outside this site.
  • If staff decide it was wrong, the mark is cleared and the thread is deleted, not corrected in place, so a withdrawn accusation leaves nothing behind.
  • You can object to it under your right to object below, and ask us to take it down.

All of this is in the Rules and the Terms before you create an account.

Never public: your email address, your password hash, your session records, and your IP address.

Treat anything you type into a post or a profile field as permanently public. Other members can quote it, and search engines can index it, before you change your mind.

The site sets three cookies, and each one only when you do something that needs it.

  • sunken_session. Set when you sign in. Holds a random session token. It is marked HttpOnly so scripts cannot read it, SameSite Lax so it is not sent from other sites, and Secure in production so it only travels over HTTPS. It expires after thirty days, or immediately when you sign out.
  • wiki_lang. Set when you pick a language on the wiki. Holds nothing but the two letter code of the language you chose, so the wiki can show you that language next time. It identifies nobody and is sent nowhere else. It lasts a year, and picking English again or clearing your cookies removes it.
  • sunken_device. Set when you create an account or sign in, and never before. A random value with no meaning outside this site. It is how we tell that two accounts are being run from the same browser. It is HttpOnly, so scripts cannot read it, and it lasts a year. It is never used to follow you anywhere else, because it means nothing anywhere else.

That is the whole list. There is no analytics cookie and no advertising cookie.

If you are only reading the site, none of them are set and nothing is computed about your browser. No cookie, no fingerprint, nothing. You have to sign up or sign in first, and by then you have read what this page says.

There is no cookie banner, and this is why. The session cookie is strictly necessary to keep you signed in, which is a service you asked for. The language cookie honours a choice you made yourself by picking a language. The device cookie and the fingerprint are set only as part of creating or using an account, which is a service you asked for and which the Rules say is limited to one account per person. Under the Norwegian rules on cookies and equivalent technologies, that is what a strictly necessary purpose means. If we ever add a cookie that is not one of these, we will ask you first.

We do not sell your data. We do not share it for advertising. We do not trade it.

Three companies handle it, acting on our instructions and nothing more:

  • Cloudflare, which sits in front of the site. Every request reaches it before it reaches us, so it sees your address, and it runs the check that tells people apart from robots on the signup and password forms. It is also why your address is hidden from the wider internet: what our server records is what Cloudflare passes on.
  • Njalla, which rents us the server the site runs on.
  • Resend, which carries email to and from [email protected], and sends the confirmation and password reset messages. If you write to us, Resend handles that message, including your address and anything you put in it, on its way to us. It processes email only. It is never given your account, your posts or anything else on this site.

The database is a file on that same server. No separate company stores it, no analytics service receives it, and nothing about your account is sent anywhere else.

We will disclose data to the authorities where we are legally required to. If we receive such a request we will tell you, unless we are legally prohibited from doing so.

If the site is ever transferred to someone else, we will tell you before it happens and you will have the chance to delete your account first.

We prefer processors inside the EEA, and as things stand both of ours are in it: the server is in Europe and Resend handles our email in its Ireland region, which we chose for that reason. Where a processor stores or handles data outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses, or by an adequacy decision for the country concerned.

You can ask us at [email protected] which processors are in use and where they hold data, and we will tell you.

  • Your account and profile: until you ask us to delete it.
  • Your posts: until you delete them, or until the site closes.
  • Session records: until they expire, at most thirty days, or until you sign out.
  • Server logs, including IP addresses: kept by our host for a short operational period and then discarded. We do not maintain our own long term log archive.
  • The staff action log: kept indefinitely. It records who on staff did what and when, which is what makes staff accountable for their own decisions, so it survives the account it was about. After an account is deleted the entries keep the internal account id and the staff member's name, and no longer resolve to a person.
  • Everything else about moderation, such as a restriction, a duplicate mark or a staff note: kept while the account exists, and for up to two years after a permanent ban so that ban evasion can be recognised.
  • Identity marks, meaning the device token, fingerprint and address hashes: kept while the account exists, and for two years after a permanent ban for the same reason.
  • Recorded addresses from restricted accounts: two years, the same as everything else here. An address on that list does not restrict anyone by itself, it only raises a note for staff, so there is no case for keeping it longer than the ban it came from. A staff member can remove one sooner.
  • Correspondence with us: up to two years after the matter is closed.

Write to [email protected] from the address on your account and ask. We will act within thirty days.

When we delete an account we remove your email address, your password hash, your profile fields, your sessions and your badges.

Your posts are treated separately, and you have a choice. Tell us which you want:

  1. Delete the posts as well. We remove them. Threads you started go with them, and replies from other people inside those threads go too.
  2. Keep the posts, detached from you. We disconnect them from your account and replace the author with a deleted member placeholder, so that conversations other people took part in stay readable.

If you do not say, we will ask before doing anything. Where we keep detached posts, we do so on the basis of our legitimate interest in not destroying other people's conversations, and there is then no personal data of yours left attached to them.

Quotations of your words inside other people's posts are part of those people's posts. We will remove them on request where they contain personal data about you.

Under GDPR you have the right to:

  • Access the personal data we hold about you, and get a copy of it.
  • Rectification of anything inaccurate. Most of it you can fix yourself in settings.
  • Erasure, as set out above.
  • Restriction of processing while a dispute about accuracy or legitimate interests is being worked out.
  • Portability, meaning a copy of the data you gave us in a machine readable format, which we will provide as JSON.
  • Object to processing we carry out on the basis of legitimate interests. Tell us why and we will stop unless we have compelling grounds that override your reasons.
  • Withdraw consent at any time where consent is the basis, which on this site means clearing the optional profile fields.

Automated decisions. Two things on this site restrict an account without a person looking first, and you have the right to know how they work and to ask for a human.

  1. Votes. Members can ink or splat each other's posts. The net of those votes is your reputation, and if it falls to the bottom tier the account is restricted automatically. The input is other members' votes and nothing else. No profile field, nothing you wrote, and nothing about who you are is part of it.
  2. Duplicate detection. If the device token or browser fingerprint on your machine matches another account, the newer account is restricted automatically, the other account's name is shown on its profile, and Catfish posts the public thread described above. The inputs are those two hashes. Your address alone never does this.

Neither produces a legal effect or anything comparable to one: the consequence is that you post less freely on a hobby forum. We do not consider this to fall under Article 22, but the right to a human either way is real and stated here.

You can always ask a person. Write to [email protected] or post in the Stained Appeals board, and an administrator will look at it, tell you what triggered it, and lift it if it was wrong. Restrictions from reputation are lifted with the reputation reset, so one bad stretch is not permanent.

Beyond those two, there is no profiling, no scoring of you as a person, and no automated decision making of any kind.

To use any of these, write to [email protected] from the address on your account. We answer within thirty days. It is free. If a request is obviously excessive or repetitive we may charge a reasonable fee or decline, and we will explain why if we do.

If you think we have handled your data badly, tell us first at [email protected] and we will try to put it right.

You also have the right to complain to a supervisory authority. In Norway that is Datatilsynet, the Norwegian Data Protection Authority, at datatilsynet.no. If you live elsewhere in the EEA you can complain to the authority where you live.

  • Passwords are hashed with scrypt using a unique random salt per account. A stolen database does not give anyone your password.
  • Session tokens are random, and only a SHA-256 hash of each token is stored. The token in your browser is never written to our database.
  • Session cookies are HttpOnly, SameSite Lax, and Secure in production.
  • Sign in attempts are rate limited to slow down guessing.
  • Changing your password ends every other session on your account.
  • Posts are rendered through a formatter that produces safe output. Raw HTML from members is never inserted into a page, so one member cannot run a script against another.

No system is perfectly secure. If a breach happens that puts your rights at risk, we will tell Datatilsynet within seventy two hours of becoming aware of it, and we will tell you directly and without undue delay.

The site is not intended for children under 13, and accounts are limited to people aged 13 and over.

If you believe a child under 13 has an account here, write to [email protected] and we will remove it and their data.

When this policy changes we will update the date below and post about it on the site. Where a change materially affects how we handle your data, we will say so plainly rather than burying it.

Last updated 19 September 2026.

The Terms of Service and the Rules together form one agreement, which you accept when you create an account. The Privacy Policy is a separate notice explaining how your personal data is handled.