Dokkan Team Sharing

Privacy Policy

Last updated: October 8, 2026

Dokkan Team Sharing (dokkants.emanuelemelini.dev) is a free, non-commercial fan site run by Emanuele Melini, an individual based in Italy, who is the data controller. You can reach me at privacy@emanuelemelini.dev.

You can browse every page without an account. Personal data is collected only when you sign in, and only what the site needs to work.

What is collected and why

  • Your account. Your email address and whether it is verified, the id of your account at the sign-in provider you chose (Discord, Google or Twitch), the name and profile picture link that provider shares (used only to suggest a handle, never shown), and the handle and game version you pick. This is needed to give you an account (performance of a contract, GDPR Art. 6(1)(b)).
  • Display preference. Whether card pages show the still or the animated artwork by default, stored with your account until you change it or delete the account. Same legal basis as above.
  • What you post. Clears (teams, builds, notes and proof links), comments, tips (short advice with an optional link) and votes. Clears, comments and tips are public together with your handle. Votes count toward public scores, including the Helpful count on tips, but who voted is not shown. Same legal basis as above.
  • Your public profile. Your handle has a public page at /users/your-handle. It shows your handle, the game version you play, the month you joined, how many clears you shared, how many upvotes they received and how many comments you wrote, and the list of your clears. It never shows your email, your sign-in provider, its name or picture, or your role. The profile of a suspended account is not shown. If you change your handle, your old handles stay reserved for your account so nobody else can take them, and links to them lead to your new one. Same legal basis as above.
  • Reports and moderation. When you report a clear, a comment or a tip, the site stores your account, the post, the reason you picked, the details you wrote, if any, and the time. Only moderators (accounts the site owner gives the admin role) see reports; the author of the post is not told who reported it. When a moderator hides or restores a post, closes reports or suspends an account, an entry goes into a moderation log: the moderator's account and handle, the action, the id of the post or account and of its author, how many reports it closed, a private note of the moderator and, for a suspension, its end and reason. The log never copies the text of the post. If your account is suspended, the end date and the reason are stored with your account and shown to you. This keeps the site safe and fair for its users (legitimate interest, GDPR Art. 6(1)(f)).
  • Security. While you are signed in, your session is stored with the IP address and browser identifier it started from, and short-lived counters by IP address and email address limit sign-in attempts and sign-in emails. This protects the site and its users from abuse (legitimate interest, GDPR Art. 6(1)(f)).

There are no passwords, and the access tokens of sign-in providers are not kept. There are no ads, no analytics, no trackers, and your data is never sold.

Cookies

One cookie keeps you signed in, and a few short-lived ones protect the sign-in step from forgery while it happens. They are strictly necessary, so no consent banner is needed. Nothing is set when you only browse.

If you switch a card's artwork between still and animated on its page, your browser remembers that choice in its local storage, for the last 200 cards. It stays on your device and is never sent to the site; clearing your browser data removes it.

Who else handles the data

These services process data on the site's behalf, only to run it:

  • Vercel (hosting of the site)
  • Supabase (the database)
  • Cloudflare (domain and card images)
  • Resend (sending sign-in emails)

The provider you sign in with (Discord, Google or Twitch) handles that step under its own privacy policy. Some of these services may process data outside the European Union, with the safeguards the GDPR requires, such as the European Commission's standard contractual clauses.

How long it is kept

  • Your account and what you post: until you delete them.
  • Your old handles: as long as your account exists. Deleting the account frees them, and someone else can then pick them.
  • Sessions: 30 days after your last visit, then removed.
  • Sign-in links: 10 minutes. Sign-in counters: 1 hour. The sign-in email log: 1 day.
  • Reports: until a moderator handles them, then 180 more days. They are deleted earlier if you delete your account, or when the reported post is deleted.
  • A suspension's end date and reason: until a moderator lifts it, or until you delete your account.
  • The moderation log: kept without a time limit, so that every decision can be checked and undone. When an account is deleted its entries stay, but only with ids that no longer lead to any account; a moderator's entries also keep the handle they had.

Deleting your account from Settings removes it immediately, together with everything you posted: clears, comments, tips, votes and the reports you sent. Copies inside database backups disappear when those backups expire, within 30 days.

Your rights

You can ask to access, correct, export or delete your data, to restrict its use, or object to it, by writing to privacy@emanuelemelini.dev. You can delete your account yourself at any time. You can also complain to the Italian data protection authority (Garante per la protezione dei dati personali, garanteprivacy.it) or to the authority of the country where you live.

Age

You must be at least 16 years old to create an account.

Changes

If this policy changes, this page and its date are updated, and important changes are announced on the site before they apply.